Arrow Left Home

Stroomdiagram - Wat voor soort overeenkomst heb ik nodig voor het uitwisselen van gegevens of lichaamsmaterialen voor wetenschappelijk onderzoek?

Scope: this guidance is meant to help you determine what type of agreement is necessary when data / human tissue is exchanged between two parties. The guidance assumes the appropriate consent has been given for secondary use of this data/material. It is also limited to exchanging between two parties (from A to B) and not multi-party (e.g. from A to B to C). The size of the parties involved can range from two to large collaborations, such as public/private partnerships. This tool should be used as a guidance; it is still crucial to check with local legal experts, especially regarding specific content of the necessary agreement! 

For valorisation, check with your local Technology Transfer Office (TTO); for Amsterdam UMC this is the IXA For privacy, check your local privacy officers.

REMARKS

  • When transferring data and/or material between two parties, an agreement between them is a must and in some cases even required by legislation. By setting up an agreement you 1) can prove that you are taking safety of the data seriously; and 2) you can setup the rules about what may and may not be done with the data by the receiving party.
  • The General Data Protection Regulation (GDPR) applies to personal data. Hence, any data with personal data, is affected by the GDPR and should therefore address it.
  • Data Sharing, Usage, Access, Transfer and Exchange Agreements are identical; in the chart we use Data Sharing Agreement.
  • Intellectual Property is part of the Data Sharing Agreement
  • Please be advised that in the end the name of the agreement is not that relevant; the content is.
  • Your data may be valuable. Always consult experts before engaging in an agreement!
  • If you plan on making your own data Open Access, please consult an expert first!

GLOSSARY

  • Controller: The data controller determines the purposes for which and the means by which personal data is processed [1]. 
  • Open access (OA): Refers to research outputs which are distributed online and free of cost or other barriers. There is some flexibility about which permission barriers to remove. For example, some OA providers permit commercial re-use and some do not [2,3]. 
  • Processor: The data processor processes personal data only on behalf of the controller. The data processor is usually a third party external to the company [1].
  • Recipient: A natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not [4].

SOURCES

  1. https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/obligations/controllerprocessor/what-data-controller-or-data-processor_en
  2. https://en.wikipedia.org/wiki/O pen_access
  3. https://legacy.earlham.edu/~peters/fos/overview.htm
  4. https://gdpr-info.eu/art-4-gdpr/
What will be transferred?

For transferring material, Party A and Party B need a Material Transfer Agreement.
Data belonging to such material can also be part of this agreement. 

Given the privacy complications when e.g. DNA is involved, it is best to contact your local TTO and discuss your specific case.

Is the data already available under an existing license?
Is the data open access?

If the data is available via Open Access, no agreement is necessary. You should be free to use the data.

Please check the license and ensure that your planned data use is compliant with the license.

Does some form of data agreement already exist between the parties involved?
Can the planned data sharing take place within the existing agreement?
If Personally Identifiable Data will be shared and this is not part of the original agreement, a different/new agreement will be necessary 

No further agreements should be necessary.

Can the existing agreement be extended with an amendment?
If Personally Identifiable Data will be shared and this is not part of the original agreement, a different/new agreement will be necessary 

Add the appropriate amendment.

Does party B process data on behalf of party A?
Have anonymisation / pseudonymisation safeguards been taken?

If Party A is sending data to Party B and/or vice versa, Party A and Party B need a Data Sharing Agreement.

Have anonymisation / pseudonymisation safeguards been taken?

For Party B to be a processor, Party A and Party B need a Data Processing Agreement. 
Please be aware that a DPA cannot exist by itself and requires the presence of a main agreement.

Take this step first!

Deel deze pagina…