Data Protection and Research in Health and Social Care

All research conducted by the HSE and its funded organisations must comply with relevant Data Protection legislation. This includes obtaining consent from the prospective participants for the processing of their personal data for research purposes as part of the overall process of obtaining consent.

Read the Health Research Data Protection Network (HRDPN) Guide document for health researchers to understand what personal data refers to, and the principles of data protection before commencing the research.

Useful Links

1. Data Protection Legislation

2. Data Protection Commission- Guidance - What are 'Personal Data' and when are they processed

 

Data Protection Impact Assessment (DPIA)

Data Protection is the means by which the privacy rights of individuals are safeguarded in relation to the collecting and processing of their personal data. DPIAs are important tools for negating risk, and for demonstrating compliance with GDPR.

A Data Protection Impact Assessment (DPIA) describes a process designed to identify risks arising out of the processing of personal data and to minimise these risks as far and as early as possible.

A DPIA is required to be completed and approved by the applicable DPO/DDPO for each clinical study, prior to the study being approved or opened for recruitment. See links below for HSE and University of Galway approved DPIA/PIA templates. These templates adhere to the clinical research quality system.   

The HSE and University of Galway approved DPIAs for clinical research data that adheres to the clinical research quality system are located here.

DPIA Templates and Tools

Risk Scoring tool to determine the need to complete a DPIA

HSE DPIA for Research -Template (HSE)

Guidance document for completing a Health Research DPIA (HSE)

University of Galway DPIA Template

Steps to follow before starting a research project that involves the use of personal data

Sharing of personal data arising from research

Access to personal data to select suitable candidates for research

Research involving the review of existing healthcare records (Retrospective Chart Review)

Consent for the processing of personal data for research purposes

Contact details for the Health Service Data Protection Officers

Practical Guidance on Data Protection for Health Researchers

Understanding GDPR, The Health Research Regulations 2018, and Subsequent Amendments

Further Information

Training

GDPR Training (HSE Only)

GDPR Training (University of Galway Only)

Templates and Tools related to Research and Data Protection