Skip to content

Commit

Permalink
Merge pull request #111 from UtrechtUniversity/updates
Browse files Browse the repository at this point in the history
add privacy information sheet to privacy notices section
  • Loading branch information
DorienHuijser authored Dec 3, 2024
2 parents 93ec2de + ede7332 commit 24640e3
Show file tree
Hide file tree
Showing 34 changed files with 221 additions and 222 deletions.
1 change: 1 addition & 0 deletions assets/style.css
Original file line number Diff line number Diff line change
Expand Up @@ -250,6 +250,7 @@ button {
vertical-align: baseline;
width: auto;
margin-right: 5px;
margin-bottom: 5px;
}

button:hover,
Expand Down
100 changes: 49 additions & 51 deletions chapters/privacy-by-design.Rmd
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,7 @@ delete the (signed) consent forms as well.
:::keywords
On this page: informed consent, informing, information, transparency,
transparent, privacy notice, information letter, privacy policy
Date of last review: 2022-10-07
Date of last review: 2024-11-19
:::

**A privacy notice is any information given to data subjects about what is
Expand Down Expand Up @@ -370,57 +370,9 @@ applied, [rec. 62](https://gdpr-info.eu/recitals/no-62/){target="_blank"}).
answer your research question anymore,
[art. 14(5)](https://gdpr-info.eu/art-14-gdpr/){target="_blank"}).


### Content and examples of privacy notices
Below you can find a list of items to include in your information to data
subjects (Template) and some example sentences to (not) include in your privacy
notice (click to expand).

<a href="https://www.uu.nl/sites/default/files/RDM_Support_Template_Information_letter.pdf"
target = "_blank" style="text-decoration: none;"><button type="button">Template information letter UU</button></a>
<a href="https://www.ccmo.nl/onderzoekers/standaardonderzoeksdossier/e-informatie-proefpersonen"
target = "_blank" style="text-decoration: none;"><button type="button">Template information letter for WMO research</button></a>

<details><summary><b>Example sentences</b></summary>

<table style="width:100%">
<tr>
<th>Bad promise</th>
<th>Alternative</th>
</tr>
<tr>
<td>"After the project ends, we will delete all of your data, so that you will not be identifiable anymore."</td>
<td>"After the end of the study, we will delete the code linking your data to your name. We will store your de-identified data for 10 years for integrity purposes."</td>
</tr>
<tr>
<td>"Your data will be fully anonymised before they are shared with others."</td>
<td>"We will remove personal information that could reasonably identify you before we share any files with other researchers."</td>
</tr>
<tr>
<td>"All data that you will provide will be kept strictly confidential and will not be shared further."</td>
<td>"The main researcher will keep a link that identifies you to your coded information. They will keep this link secure and available only to the selected members of the research team."</td>
</tr>
<tr>
<td>"Your data will only be accessible by the research team, and no one else."</td>
<td>"We will only share your de-identified data with other researchers if they agree to treat your data confidentially and only after approval from the original research team."</td>
</tr>
<tr>
<td>"You can withdraw your consent from this study at any time up until the end of the research project. If you withdraw your consent, we will delete all your data from our dataset immediately."</td>
<td>"You can withdraw your consent from this study at any time, without stating a reason why and without any repercussions. Please inform the researcher about your decision. We will then delete any personal data referring to you that we still have, where this is still possible."</td>
</tr>
</table>
</details>

:::note
Utrecht University also has a
[generic privacy statement for participants of research projects](https://www.uu.nl/en/organisation/practical-matters/privacy/privacy-statements-utrecht-university/privacy-statement-participants-scientific-research){target="_blank"}.
This is not a replacement of your own information letter, but you can refer to
it in your information letter for future reference if needed.
:::

### Form of a privacy notice
::::fyi
The format of the privacy notice is also crucial. Even if you include all
The format of the privacy notice is crucial. Even if you include all
necessary components in your privacy notice, it will **not be GDPR-compliant**
if you fail to provide the information in an appropriate form, shape and time.
::::
Expand All @@ -436,7 +388,7 @@ Tip: try these
[writing tips](https://www.researchplatform-dorp.nl/wp-content/uploads/20220329-Handleiding-PIF-beperkte_gezondheidsvaardigheden.pdf){target="_blank"},
this [language tester](https://ishetb1.nl/){target="_blank"}, or use this
[simplified information sheet](https://www.pharos.nl/kennisbank/eenvoudige-en-begrijpelijke-onderzoeksformulieren-patientinformatieformulier-pif/){target="_blank"}. Or take a look at some good
examples in terms of [language](https://www.eur.nl/en/media/2022-12-221208a2b1toestemmingethiekalgemeenbelangprivacycasus){target="_blank"} and [formatting](https://www.eur.nl/en/media/2023-05-geanonimiseerd-1-informatie-vragenlijstonderzoek){target="_blank"} (all in Dutch).
examples in terms of [language](https://www.eur.nl/en/media/2022-12-221208a2b1toestemmingethiekalgemeenbelangprivacycasus){target="_blank"} and [formatting](https://www.eur.nl/en/media/2023-05-geanonimiseerd-1-informatie-vragenlijstonderzoek){target="_blank"} (all in Dutch). You can also use the privacy information summary sheet [linked below](#content-and-examples-of-privacy-notices).

- **Easily accessible**<br>
Data subjects should be able to find the information easily. For example, publish
Expand Down Expand Up @@ -466,6 +418,52 @@ testing, or by interactions with data subjects themselves (or their
representatives).


### Content and examples of privacy notices
Below you can find a list of items to include in your information to data subjects (Template), and example of a one-page document that summarises privacy-related information, and some example sentences to (not) include in your privacy notice (click to expand).

<a href="https://www.uu.nl/sites/default/files/RDM_Support_Template_Information_letter.pdf"
target = "_blank" style="text-decoration: none;"><button type="button">Template information letter UU</button></a>
<a href="https://solisservices.sharepoint.com/:w:/s/DatamanagementFSW/EXsxJ1Nbo_VBs7wJLbXWBXcBAJ7vpOZV8EYNrrAxhO-GKA?download=1"
target = "_blank" style="text-decoration: none;"><button type="button">Privacy information summary sheet example</button></a>
<a href="https://www.ccmo.nl/onderzoekers/standaardonderzoeksdossier/e-informatie-proefpersonen"
target = "_blank" style="text-decoration: none;"><button type="button">Template information letter for WMO research</button></a> <details><summary><b>Example sentences</b></summary>

<table style="width:100%">
<tr>
<th>Bad promise</th>
<th>Alternative</th>
</tr>
<tr>
<td>"After the project ends, we will delete all of your data, so that you will not be identifiable anymore."</td>
<td>"After the end of the study, we will delete the code linking your data to your name. We will store your de-identified data for 10 years for integrity purposes."</td>
</tr>
<tr>
<td>"Your data will be fully anonymised before they are shared with others."</td>
<td>"We will remove personal information that could reasonably identify you before we share any files with other researchers."</td>
</tr>
<tr>
<td>"All data that you will provide will be kept strictly confidential and will not be shared further."</td>
<td>"The main researcher will keep a link that identifies you to your coded information. They will keep this link secure and available only to the selected members of the research team."</td>
</tr>
<tr>
<td>"Your data will only be accessible by the research team, and no one else."</td>
<td>"We will only share your de-identified data with other researchers if they agree to treat your data confidentially and only after approval from the original research team."</td>
</tr>
<tr>
<td>"You can withdraw your consent from this study at any time up until the end of the research project. If you withdraw your consent, we will delete all your data from our dataset immediately."</td>
<td>"You can withdraw your consent from this study at any time, without stating a reason why and without any repercussions. Please inform the researcher about your decision. We will then delete any personal data referring to you that we still have, where this is still possible."</td>
</tr>
</table>
</details>

:::note
Utrecht University also has a
[generic privacy statement for participants of research projects](https://www.uu.nl/en/organisation/practical-matters/privacy/privacy-statements-utrecht-university/privacy-statement-participants-scientific-research){target="_blank"}.
This is not a replacement of your own information letter, but you can refer to
it in your information letter for future reference if needed.
:::


## Processing register {#processing-register}

::::keywords
Expand Down
8 changes: 4 additions & 4 deletions docs/data-storage-duration.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<meta name="description" content="<p>The Data Privacy Handbook is a practical guide on handling personal data in
scientific research, created by Utrecht University’s Research Data Management
Support.</p>" />
<meta name="generator" content="bookdown 0.36 and GitBook 2.6.7" />
<meta name="generator" content="bookdown 0.41 and GitBook 2.6.7" />

<meta property="og:title" content="For how long should I store personal data? | Data Privacy Handbook" />
<meta property="og:type" content="book" />
Expand All @@ -26,10 +26,10 @@
Support.</p>" />
<meta name="twitter:image" content="https://utrechtuniversity.github.io/dataprivacyhandbook/img/cover-image-dph.png" />

<meta name="author" content="Utrecht University | Last updated: 2024-11-19" />
<meta name="author" content="Utrecht University | Last updated: 2024-12-03" />


<meta name="date" content="2024-11-19" />
<meta name="date" content="2024-12-03" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="apple-mobile-web-app-capable" content="yes" />
Expand Down Expand Up @@ -353,8 +353,8 @@
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html"><i class="fa fa-check"></i>Information to data subjects</a>
<ul>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#when-to-use-a-privacy-notice"><i class="fa fa-check"></i>When to use a privacy notice?</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#form-of-a-privacy-notice"><i class="fa fa-check"></i>Form of a privacy notice</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
</ul></li>
<li class="chapter" data-level="" data-path="processing-register.html"><a href="processing-register.html"><i class="fa fa-check"></i>Processing register</a></li>
</ul></li>
Expand Down
8 changes: 4 additions & 4 deletions docs/data-storage-how.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<meta name="description" content="<p>The Data Privacy Handbook is a practical guide on handling personal data in
scientific research, created by Utrecht University’s Research Data Management
Support.</p>" />
<meta name="generator" content="bookdown 0.36 and GitBook 2.6.7" />
<meta name="generator" content="bookdown 0.41 and GitBook 2.6.7" />

<meta property="og:title" content="How should I store personal data? | Data Privacy Handbook" />
<meta property="og:type" content="book" />
Expand All @@ -26,10 +26,10 @@
Support.</p>" />
<meta name="twitter:image" content="https://utrechtuniversity.github.io/dataprivacyhandbook/img/cover-image-dph.png" />

<meta name="author" content="Utrecht University | Last updated: 2024-11-19" />
<meta name="author" content="Utrecht University | Last updated: 2024-12-03" />


<meta name="date" content="2024-11-19" />
<meta name="date" content="2024-12-03" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="apple-mobile-web-app-capable" content="yes" />
Expand Down Expand Up @@ -353,8 +353,8 @@
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html"><i class="fa fa-check"></i>Information to data subjects</a>
<ul>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#when-to-use-a-privacy-notice"><i class="fa fa-check"></i>When to use a privacy notice?</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#form-of-a-privacy-notice"><i class="fa fa-check"></i>Form of a privacy notice</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
</ul></li>
<li class="chapter" data-level="" data-path="processing-register.html"><a href="processing-register.html"><i class="fa fa-check"></i>Processing register</a></li>
</ul></li>
Expand Down
8 changes: 4 additions & 4 deletions docs/data-storage-where.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<meta name="description" content="<p>The Data Privacy Handbook is a practical guide on handling personal data in
scientific research, created by Utrecht University’s Research Data Management
Support.</p>" />
<meta name="generator" content="bookdown 0.36 and GitBook 2.6.7" />
<meta name="generator" content="bookdown 0.41 and GitBook 2.6.7" />

<meta property="og:title" content="Where should I store personal data? | Data Privacy Handbook" />
<meta property="og:type" content="book" />
Expand All @@ -26,10 +26,10 @@
Support.</p>" />
<meta name="twitter:image" content="https://utrechtuniversity.github.io/dataprivacyhandbook/img/cover-image-dph.png" />

<meta name="author" content="Utrecht University | Last updated: 2024-11-19" />
<meta name="author" content="Utrecht University | Last updated: 2024-12-03" />


<meta name="date" content="2024-11-19" />
<meta name="date" content="2024-12-03" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="apple-mobile-web-app-capable" content="yes" />
Expand Down Expand Up @@ -353,8 +353,8 @@
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html"><i class="fa fa-check"></i>Information to data subjects</a>
<ul>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#when-to-use-a-privacy-notice"><i class="fa fa-check"></i>When to use a privacy notice?</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#form-of-a-privacy-notice"><i class="fa fa-check"></i>Form of a privacy notice</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
</ul></li>
<li class="chapter" data-level="" data-path="processing-register.html"><a href="processing-register.html"><i class="fa fa-check"></i>Processing register</a></li>
</ul></li>
Expand Down
8 changes: 4 additions & 4 deletions docs/data-storage.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<meta name="description" content="<p>The Data Privacy Handbook is a practical guide on handling personal data in
scientific research, created by Utrecht University’s Research Data Management
Support.</p>" />
<meta name="generator" content="bookdown 0.36 and GitBook 2.6.7" />
<meta name="generator" content="bookdown 0.41 and GitBook 2.6.7" />

<meta property="og:title" content="Storing personal data | Data Privacy Handbook" />
<meta property="og:type" content="book" />
Expand All @@ -26,10 +26,10 @@
Support.</p>" />
<meta name="twitter:image" content="https://utrechtuniversity.github.io/dataprivacyhandbook/img/cover-image-dph.png" />

<meta name="author" content="Utrecht University | Last updated: 2024-11-19" />
<meta name="author" content="Utrecht University | Last updated: 2024-12-03" />


<meta name="date" content="2024-11-19" />
<meta name="date" content="2024-12-03" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="apple-mobile-web-app-capable" content="yes" />
Expand Down Expand Up @@ -353,8 +353,8 @@
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html"><i class="fa fa-check"></i>Information to data subjects</a>
<ul>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#when-to-use-a-privacy-notice"><i class="fa fa-check"></i>When to use a privacy notice?</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#form-of-a-privacy-notice"><i class="fa fa-check"></i>Form of a privacy notice</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
</ul></li>
<li class="chapter" data-level="" data-path="processing-register.html"><a href="processing-register.html"><i class="fa fa-check"></i>Processing register</a></li>
</ul></li>
Expand Down
8 changes: 4 additions & 4 deletions docs/data-subject-rights.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<meta name="description" content="<p>The Data Privacy Handbook is a practical guide on handling personal data in
scientific research, created by Utrecht University’s Research Data Management
Support.</p>" />
<meta name="generator" content="bookdown 0.36 and GitBook 2.6.7" />
<meta name="generator" content="bookdown 0.41 and GitBook 2.6.7" />

<meta property="og:title" content="Data Subjects’ Rights | Data Privacy Handbook" />
<meta property="og:type" content="book" />
Expand All @@ -26,10 +26,10 @@
Support.</p>" />
<meta name="twitter:image" content="https://utrechtuniversity.github.io/dataprivacyhandbook/img/cover-image-dph.png" />

<meta name="author" content="Utrecht University | Last updated: 2024-11-19" />
<meta name="author" content="Utrecht University | Last updated: 2024-12-03" />


<meta name="date" content="2024-11-19" />
<meta name="date" content="2024-12-03" />

<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="apple-mobile-web-app-capable" content="yes" />
Expand Down Expand Up @@ -353,8 +353,8 @@
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html"><i class="fa fa-check"></i>Information to data subjects</a>
<ul>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#when-to-use-a-privacy-notice"><i class="fa fa-check"></i>When to use a privacy notice?</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#form-of-a-privacy-notice"><i class="fa fa-check"></i>Form of a privacy notice</a></li>
<li class="chapter" data-level="" data-path="privacy-notices.html"><a href="privacy-notices.html#content-and-examples-of-privacy-notices"><i class="fa fa-check"></i>Content and examples of privacy notices</a></li>
</ul></li>
<li class="chapter" data-level="" data-path="processing-register.html"><a href="processing-register.html"><i class="fa fa-check"></i>Processing register</a></li>
</ul></li>
Expand Down
Binary file modified docs/dataprivacyhandbook.pdf
Binary file not shown.
Loading

0 comments on commit 24640e3

Please sign in to comment.