Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Categories
Articles

Information Sharing in Emergencies

The Information Commissioner’s new blog post explains how Data Protection law should be seen as a guide to when and how to share information in emergencies, not an obstacle to such sharing. In health emergencies three provisions are most likely to be relevant:

Explicit Consent (GDPR Art.9(2)(a)): where an individual chooses to disclose information, such as a health condition or disability, their university or college can discuss the different ways that information could be used or shared, and let the user choose which of them should be done or allowed.

Vital Interests (GDPR Art.9(2)(c)): where there is an imminent threat to life or serious injury and the individual (for example because they are unconscious) cannot give explicit, informed, consent.

Employment and other laws (GDPR Art.9(2)(b)): allow states to legislate to either allow or require sharing of health and other sensitive data. Recital 52 gives “prevention or control of communicable diseases” as an example of such legislation; Recital 53 “monitoring and alerting purposes”. Such laws must provide “appropriate safeguards for the fundamental rights and interests of [individuals]”. Schedule 1 Part 1 of the UK Data Protection Act 2018 provides a general framework; further details may be contained in emergency legislation.

The Information Commissioner’s Data Sharing Code of Practice includes a section on Data Sharing in an Urgent Situation or in an Emergency.  This stresses that organisations should try to anticipate and plan for such emergencies, but that when an unforeseen or unplanned emergency occurs, “it might be more harmful not to share data than to [proportionately] share it”.

By Andrew Cormack

I'm Chief Regulatory Advisor at Jisc, responsible for keeping an eye out for places where our ideas, services and products might raise regulatory issues. My aim is to fix either the product or service, or the regulation, before there's a painful bump!

Leave a Reply

Your email address will not be published. Required fields are marked *