GDPR Compliance
ESOT is fully committed to ensuring compliance with the General Data Protection Regulation (GDPR) to safeguard the privacy and confidentiality of individuals’ data within the ESOT Registries. GDPR sets out strict guidelines and standards for collecting, processing and storing personal data. ESOT understands the sensitivity of the data collected within the registries and takes extensive measures to protect the privacy rights of individuals involved.
To comply with GDPR, ESOT implements robust data protection policies and procedures, including implementing appropriate technical and organisational measures to ensure data security. Access to personal data is strictly controlled and limited to authorized personnel with a legitimate need to access such information. ESOT also maintains data protection agreements with third-party partners and collaborators to ensure that personal data is handled in accordance with GDPR requirements.
ESOT recognises the importance of centres obtaining informed consent from patients to collect and process their data within the registries. Transparent information is provided to participants, outlining the purposes and legal basis for data processing, the rights of individuals, and how their data will be protected.
ESOT is dedicated to ongoing monitoring and reviewing its data protection practices, ensuring compliance with GDPR and evolving best practices. By adhering to GDPR standards, ESOT aims to foster trust, maintain data integrity, and protect the privacy of individuals contributing to the ESOT Registries.
As a data controller, ESOT appointed a Data Protection Officer (DPO) and a legal advisor to conduct the GDPR compliance procedure. The ESOT registries task force has established a data processing agreement (DPA) with the technical partner providing the platform’s infrastructure and data sharing agreements (DSA) with data providers. An independent Data Protection Impact Assessment (DPIA) has been conducted and can be consulted under request to the DPO (dpo@esot.org).
Data collected on the Registries Platform will be stored in the EU (Ireland) and processed by Dendrite Clinical Systems, a UK-based company; data will be released in an aggregated form only. The risk of a data breach is kept as minimal as possible, as described in the ESOT Data Breach Protocol (DBP).