Ordering data
Each data holder has its own process for data disclosure, which means that ordering procedures may vary. In order to process a request and make the necessary assessments, the data holder requires certain information from the researcher. The information requested varies between different data holders.
Ethical review and ordering data for research from data holders are two separate processes. Ethical approval in itself is no guarantee of access to data; any disclosure depends on the independent assessment of the disclosing authority.
Prepare information that may be requested when ordering data
Below is a description of common requirements and the information that often needs to be included with a request for the disclosure of data containing personal data for research purposes.
Project description – also known as a project plan or research plan
Clearly describe the research question, study design, target and study population, and planned data analysis so that the data holder can assess what data needs to be disclosed. The clearer the description, the greater the probability of receiving the correct data at the first attempt.
Detailed specification of the data requested
Specify which data is to be disclosed by indicating variables and selection criteria. This may involve defining the study population, the number of individuals to be included in the population and the time period for the requested data.
Some data holders offer special templates or tools to be used for filling in information and selecting variables. A common mistake is to request too much data or data that is not relevant to the project. Data minimisation is a fundamental data protection principle and means that each variable must be justified based on the purpose of the project and the study design.
A detailed specification of the data makes it easier for the data holder to find the right information and to carry out the secrecy assessment. If the research requires ethical review approval, the specification of the data must correspond to the information in the approved ethical review application. If the information does not match, there is a risk that an amendment application may need to be submitted to the Swedish Ethical Review Authority, which may delay the disclosure.
As a rule, only pseudonymised or anonymised data is disclosed. If personal identification numbers or other directly identifiable personal data are required, this must be justified and also described in the ethical review permit.
Information about other data to be included in the project
In addition to specifying the data that you wish to obtain from the current data holders, you may need to provide information about other data to be included in the project, for example from other data holders or data you have obtained yourself. This is necessary if the data is to be linked or otherwise combined.
Information about repeated deliveries
Indicate whether the project plans to follow up data over time and therefore needs updates, for example new data years or populations. This is necessary in order for the project's code key to be saved for a longer period of time.
Description of how data will be handled and protected
Describe how the data will be protected via technical and organisational measures after it has been disclosed. Data holders often request specific information about this in connection with disclosure, for example:
- What secrecry provision the data will be subject to after disclosure.
- How the data will be stored, including access control. Who will have access to the data and whether these persons have been informed about the meaning of secrecy.
- Whether the data will be processed by individuals not employed by the receiving research principal. This applies, for example, if data is to be transferred to other principals or organisations. In these cases, special agreements may be required (see Other permits, agreements and supporting documents below).
- How code keys for pseudonymisation will be stored.
- How the data will be handled after the project has been completed.
If the information is already included in a data management plan, it may be sufficient to attach it.
Information about which research principal the data will be disclosed to
In the case of research that requires ethical review approval, data may only be disclosed to the research principal specified in the approved ethical review application.
Signed application for ethical review and decision on approval
The disclosure of data must comply with the approval and any conditions decided by the Swedish Ethical Review Authority. The entire application, including appendices, any supplements and the decision on approval with any conditions, must be attached.
Other permits, agreements and supporting documents
In some cases, additional permits or agreements must be attached in order for the data holder to be able to disclose data, for example:
- Data processing agreement (DPA). This describes the most common requirements and what information should normally be attached to an order for the disclosure of data that includes personal data for research purposes.
- Data transfer agreement (DTA). A DTA agreement is required when data is shared with collaborating research principals within a research project or when a recipient has Among other things, the agreement specifies the types of data that can be transferred, under what preconditions, how long the data may be retained and what security measures must be followed. The agreement also ensures that recipient organisations comply with relevant data protection regulations.
- Disclosure decisions from other data holders. This is required if the requested data is to be collated with data from other sources.
- Data Protection Impact Assessment (DPIA), when such an assessment exists and is necessary.
Approval of final data specification and cost estimate
A final specification and cost estimate must usually be accepted before data can be disclosed. The cost may vary between different data controllers, but is generally charged for the time it takes to process the request. The scope and complexity of a data extraction request therefore affect the cost.
The data holder's assessment of whether the data can be disclosed
Once the data order is complete, the data holder makes an independent assessment of whether the requested data can be disclosed. A key part of this process is to conduct a secrecy assessment. Here are some examples of what is included in the assessment.
The recipient's right to process the data
- Is there a legal basis for the specific purpose of the recipient, i.e. the research principal, if personal data is to be processed?
- For research requiring ethical review:
- Is there an approved application for ethical review for the processing of the requested data?
- Is it the same research principal who is requesting the data and who has applied for and obtained the ethical approval?
- Does the application comply with the ethical approval?
If the purpose concerns research that requires ethical review, the data holder checks, for example, that:
- the description of the study population is
- the data sources and data holders are named in the approved application for ethical review
- the purpose (need) of the requested data is stated in the approved application for ethical review
- the approved application for ethical review states that a code key needs to be saved (if required)
- the approved application for ethical review justifies why personal identity numbers are required instead of pseudonymised serial numbers, if personal identity numbers are to be disclosed
- the approved application for ethical review states whether data from other data holders and data sources will be handled or collated within the project.
Assessment
- Could any person suffer harm or detriment if the data is disclosed?
- What secrecy provision is applicable for the data at the recipient of the data?
Secrecy and protection of data by the research principal
When ordering data that is subject to a secrecy provision, the data holder may request information about what secrecy provision the data will be protected by in the receiving organisation.
The legislation has facilitated access to data between public agencies through special secrecy provisions, see Chapter 11, Section 3 of the Public Access to Information and Secrecy Act (OSL).
The same rules do not apply to private entities, such as pharmaceutical companies or manufacturers of medical devices as the Public Access to Information and Secrecy Act (OSL) are not applicable for private entities. But according to Chapter 10, Section 14 of the OSL, information classified as secret may be disclosed to such entities if the risk of harm or damage can be eliminated by a confidentiality clause.
Decisions on the disclosure of data
The process for deciding on disclosure may vary between data holders. Often, an administrator or an assessment group representing different areas of competence reviews the request and makes a recommendation for a decision. The formal responsibility for reviewing and deciding on disclosure is usually delegated to a head ofoperations or lawyer. The assessments and decisions of the public agencies are based on the regulations that apply to the respective public agency.
Right to an appealable decision
If the data holder decides to refuse disclosure of data, the person who requested the information has the right to receive a formal, appealable decision of rejection. The rejection decision must contain information on how to appeal.
The body to which the appeal is to be made depends on the parties involved. A negative decision on a request for disclosure of public documents is appealed to the administrative court. When it comes to an authority's right to access documents held by another authority, the process differs: a refusal by a municipal authority is appealed to the administrative court, while a refusal by a state authority is appealed to the government.
Data processing and disclosure of data
Once the data holder has decided on disclosure, the necessary quality assurance and data processing is carried out. Disclosure usually only takes place at the request of an authorised representative of the responsible research principal, who is responsible for ensuring that the data is handled correctly. In some cases, data may be disclosed digitally via a portal or secure digital environment.
Check disclosed data
After data has been disclosed, it is important to check that the information is correct. Data holders rarely have the opportunity to retain the disclosed information in a dataset and usually only allow corrections for a limited period of time. If no deadline has been specified in connection with the disclosure, this should be discussed with the responsible administrator at the data holder. Additions of further information are not normally accepted after the deadline and require a new order.
Next step in the research data cycle
Publicerat den
Uppdaterat den