Legal changes - #47
Merged
Merged
Conversation
MalikaIhle
reviewed
Sep 4, 2026
MalikaIhle
left a comment
Member
There was a problem hiding this comment.
wow so very lucky to have an expert review the legal content!
|
|
||
| The person or organization that determines the purposes and means of processing personal data. | ||
|
|
||
| **In research:** This is typically the principal investigator (PI) or the research institution. If you design a study and decide what data to collect and why, you are the controller, and you carry the legal responsibility for data protection. | ||
| **In research:** This is typically the research institution, not you personally. Researchers are employed to do research, and when this includes data collection, the institution is, by extension, the controller and carries the legal responsibility, while the principal investigator (PI) carries operational responsibility in day-to-day research. This may differ, depending on contracts and exact projects, though. When you collaborate across different institutions, it gets more complicated: usually, this means that the involved institutions act as joint controllers (Art. 26), requiring them (or better: their DPOs) to allocate responsibilities between them within a written contract. |
Member
There was a problem hiding this comment.
please speall out acronyn DPO
|
|
||
| If you plan to anonymize and share the data, this should be stated in the consent form. A useful tutorial on writing GDPR-compliant consent forms for research is provided by @Hallinan2023_InformationProvisionInformed. It is also helpful to tell participants about the intended level of anonymization and what it means for them (e.g., plausible deniability). | ||
|
|
||
| Consent needs to be **freely given** (Art. 4(11)); this can be tricky in research, when mixed with a power imbalance between the researcher and participant, as it may be the case when collecting data of students or patients. In that case, consent may be invalid as a legal basis for processing of data and relying on another basis is the best way (e.g., processing in the public interest, Art. 6 (1)(e)); your institution's DPO can advise you on this. |
| 5. and did not deviate from the approved plan. | ||
|
|
||
| If someone is re-identified anyway, that is an institutional matter—reassessing the dataset, restricting access, notifying where required—not evidence of your personal fault. In our **personal opinion**, researchers who follow an approved, documented procedure have fulfilled their obligations and are not at fault. The circular logic that "someone was re-identified, therefore your anonymization was too lenient" gets the causality backward. | ||
| If someone is re-identified anyway, that is an institutional matter—reassessing the dataset, restricting access, notifying where required—not evidence of your personal fault. In this case, the participant has a right to be compensated for damages (Art. 82) and the institution may need to pay administrative fines issued by the supervisory authority (Art. 83). In our **personal opinion**, researchers who follow an approved, documented procedure have fulfilled their obligations and are not at fault. The circular logic that "someone was re-identified, therefore your anonymization was too lenient" gets the causality backward. |
Collaborator
Author
|
Sorry, Malika! I was to quick with the merge. Will add the spelling out of DPO when making |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes and clarifications to legal parts of the tutorial
Added Christian Sillaber as a contributor