Closed John-Holt-Tessella closed 4 years ago
GDPR applies to the processing of personal data, whether by automated or manual means.
Personal data only includes information relating to living persons who:
In short, if it is not personal data, GDPR does not apply.
Do we display personal data on the web dashboard? Yes, we do. In the following fields:
Users
- contains the names of scientists performing experiment at ISIS. Names are clearly personal data.RB Number
- why is the RB Number
personal data? Because it is the key to the Experiment Details database. If you can get access to the Experiment Details database, you can use the RB Number
to find out more about the PI and other user scientists.Does this mean we can't display these fields on the web dashboard? No, it does not mean that. GDPR permits personal data to be processed with the consent of the individual. When the PI (Principal Investigator) submits a proposal to ISIS, he is informed that certain fields will be made public, including his/her name and the names of the other scientists involved in the proposal. By submitting a proposal, the PI has given consent. Therefore, we are clear to use the Users
and RB Numbers
fields.
proposal title
, abstract
, and experimenter names
(both the PI
and Co-Is
) are public data for the following types of proposals: Direct, Rapid, Dutch, Riken, and Indian Access. Does this mean we can display any fields containing personal data on the web dashboard? No, it does not. We should only display those fields that a PI has consented to display. In fact, on a precautionary basis, we should display no more information than is necessary. The Users
and RB Number
fields are sufficient. There is no need to display any more.
Can we put the above on the wiki so we can refer back to it please?
Information is now on the wiki: https://github.com/ISISComputingGroup/ibex_developers_manual/wiki/Data-Protection
Remote access plan is in General/Files/Remote Users Sep 2020 in MS-Teams. We have implemented the agreed remote access solutions:
GDPR issues dealt with by above comments.
Ticket is complete.
Make plan T.B.C.
Acceptance criteria