HeFDI Data Week: Practical Data Protection in Research: Tools, Guidance, and Everyday Solutions
Abstract
Data protection can feel overwhelming, but it doesn't have to be. This session offers practical guidance drawn from hands-on experience in research data management (RDM), including tools, examples, and helpful resources. Whether you're just getting started or refining existing practices, the focus is on supporting everyday research work with clarity and confidence.
Full text
HeFDI Data Week 2025 Abstract: Data protection can feel overwhelming, but it doesn't have to be. This session offers practical guidance drawn from hands-on experience in research data management (RDM), including tools, examples, and helpful resources. Whether you're just getting started or refining existing practices, the focus is on supporting everyday research work with clarity and confidence. About the HeFDI Data Week: The HeFDI Data Week 2025 is a multi-day online event series which is offered in the context of the nationwide "Digitaltag. The series is aimed at researchers, teachers, students and anyone who wants to learn more about data management, FAIR data and code. Over the course of the week, various topics, developments and challenges related to research data will be covered, such as tools and offers for disciplines from NFDI consortia, legal aspects of research data management as well as research data management and artificial intelligence. The HeFDI Data Week is a programme of the federal state initiative HeFDI - Hessian Research Data Infrastructures, which is funded by the Hessian Ministry of Higher Education, Research, Science and the Arts (HMWK). DOI-Link: https://doi.org/10.5281/zenodo.15422242 . Licence information: Creative Commons Attribution 4.0 International (CC BY 4.0) Date Topic Presenter 26. June 2025 Practical Data Protection in Research: Tools, Guidance, and Everyday Solutions Neelam Vishen (Base4NFDI / University of Mannheim) gefördert durch
Practical Data Protection in Research: Tools, Guidance, and Everyday Solutions Neelam Vishen Base4NFDI University of Mannheim 26/6/2025 2
Why Data Protection is important for RDM? Data protection is essential in Research Data Management (RDM) to ensure ethical integrity, legal compliance, and the trust of participants whose data powers discovery. 26/6/2025 3
Protecting research data through legal clarity enables open, responsible science. Open Science Advocates 26/6/2025 4
Basics of GDPR 26/6/2025 5 GDPR protects personal data and privacy Applies to any data that can identify a person Sets rules for data processing
What is Personal Data? Any info relating to an identified/identifiable person Includes names, IDs, locations, metadata Combination of data can reveal identity 26/6/2025 6
GDPR Principles •Lawfulness, Fairness & Transparency →Inform participants clearly about how their data will be used in research. •Purpose Limitation →Use personal data only for the defined research purpose; avoid secondary, unapproved uses. •Data Minimisation →Collect only the data necessary for your research question —no more. •Accuracy →Ensure research data is kept accurate, especially if reused or shared. •Storage Limitation →Retain personal data only as long as needed for research or legal obligations. •Integrity & Confidentiality →Apply robust data security, especially when handling sensitive data (e.g., health, genetics). •Accountability →Keep clear records (e.g., consent forms, RoPA, ethics approvals) to demonstrate compliance. 26/6/2025 7
Legal Basis for Processing Data •Consent •Legal obligation •Legitimate interest •Public interest •Contractual necessity •Vital interest 26/6/2025 8
Roles & Responsibilities Who’s involved, and what they do: •Data Controller Defines why and how data is processed (often the university) •Data Processor Processes data on the controller’s behalf (e.g., survey platforms, cloud storage) •Researcher Collects & handles data, ensures consent, security, and anonymisation 26/6/2025 9
Practical Checklist for RDM •Define what personal data you collect •Identify legal basis •Comply with GDPR Principles when processing personal data •Obtain informed consent if needed •Secure data properly •Plan sharing and retention •Follow institutional policies 26/6/2025 16
Interactive Activity –Try iVA Tool •Follow the Link •iVA1 - https://wiki.bib.unimannheim.de/xerte/play.php?template_id=225#page1 •iVA2 - https://wiki.bib.unimannheim.de/xerte/play.php?template_id=229#page1 •iVA3 - https://wiki.bib.unimannheim.de/xerte/play.php?template_id=217#page1 26/6/2025 17 https://www.berd-nfdi.de/legal-questions/
Anonymisation •Anonymisation: All identifiers removed, irreversible Data can’t be traced back to individuals GDPR does not apply once data is fully anonymised Ideal for open sharing Risks around Anonymisation; With advanced AI, large datasets, and cross-matching techniques, even anonymised data may be re-identified in some contexts. E.g. Combining anonymised health data with location info or social media leaks, AI models trained to detect patterns or link attributes across dataset 26/6/2025 18
Practical Anonymisation Suggestions From a Legal & Research Support Perspective •Don't treat anonymisation as "done" after removing prominent identifying features. •Context is everything. •Use support tools; you don't need to be an expert. - There are user-friendly tools like ARX that help estimate whether your data is still re-identifiable. These don’t require a technical background and can support your documentation if you’re ever asked to justify your approach. •When in doubt, limit access. •Anonymisation isn’t a checkbox; it’s a responsibility. Note: The European Data Protection Board’s 2024–2025 work programme explicitly includes new guidance on anonymisation, which will most probably be available in late 2025 26/6/2025 19
Pseudonymisation •What is it? Replacing direct identifiers (e.g., names) with codes. Data can be re-linked using a separate key. •GDPR Status: Still personal data, so GDPR applies. Safer processing, but not exempt from rules. •Legal difference: Anonymisation: irreversible →outside GDPR Pseudonymisation: reversible →within GDPR •Why use it? Reduces re-identification risk →helps meet GDPR security & privacy by design. •EU Authority Guidelines: www.edpb.europa.eu/system/files/202501/edpb_guidelines_202501_pseudonymisation_en.pdf 26/6/2025 20
Pseudonymisation: Legal Tips for RDM Teams •Still Personal Data: GDPR applies fully; pseudonymised data is not exempt. •Separation of Key is Critical: Keep re-identification keys strictly separate and access limited to authorised personnel only. •Document Everything: Maintain clear records of your pseudonymisation methods and key management to demonstrate compliance. •Inform Data Subjects: Transparency in privacy notices about pseudonymisation and safeguards is legally required. •Use as Risk Mitigation: Pseudonymisation lowers risk but does not remove legal obligations —process data lawfully and securely. •Regular Review: Reassess your approach periodically to ensure compliance with evolving legal standards and reidentification risks. 26/6/2025 21
Case Study –Survey Research Scenario Scenario: A researcher plans an online survey asking about academic stress and includes demographic questions (age, gender, department). Challenges: •Consent: Can consent be truly informed and freely given online? •Storage: Where and how will the personal data be stored securely? •Anonymisation: Can answers be published without risk of identification? Solutions & Best Practices: •Use layered consent forms (with clear info and contact point) •Store raw data on institutional, encrypted storage •Apply pseudonymisation early (separate metadata from responses) •Only include personal data in a survey when it is really necessary for the main purpose of the Survey 26/6/2025 22
GDPR into Practice: Everyday Strategies •Key Takeaways Plan early: Build privacy into your research design Map your data: Know what you're collecting and why Use trusted tools: Institutional storage, survey tools with privacy settings Strict Access Controls: Only people working with the personal data/metadata can access it. Transparency: Even if the data is public or indirectly collected, when reasonably possible Keep it documented: Data protection impact, Record of Processing Activity, legal basis, consent, or justification for using public interest. 26/6/2025 23
Tools & Templates GDPR Compliance Checklist: https://gdprchecklist.io/ Anonimsation: https://www.edps.europa.eu/system/files/202104/21-04-27_aepd-edps_anonymisation_en_5.pdf Free online tool from Spain’s Data Protection Authority for GDPR compliance. Allows up to 500 processing activities to be recorded (ROPA), supports risk analysis, DPIA guidance, breach measures, and more: https://www.aepd.es/en/guides-andtools/tools/gestiona2 https://gestiona2.aepd.es/ There’s a plethora of free tools in GitHub “dsgvo - https://github.com/topics/dsgvo ” or "awesome-gdpr - https://github.com/LGPD-GDPR-Grupo-deEstudo/gdpr-awesome?tab=readme-ov-file " collections, including: Klaro (consent manager), Opendsr (data subject rights), Data Processing Agreement collection, and so on… 26/6/2025 24
What data protection challenges do you face? 26/6/2025 25