Skip to Main Content

Open science practices at Centria University of Applied Sciences

Data protection guidelines for RDI participants

The EU General Data Protection Regulation and the Data Protection Act require certain requirements to be taken into account when personal data is processed in RDI activities. In addition, RDI activities must continue to take into account any sector-specific requirements, such as legislation on medical research and research ethics principles and guidelines.

The framework for the guidelines is based on the list of  Data Protection tools for researchers, compiled by Raisa Leivonen, Senior Inspector at the Office of the Data Protection Ombudsman.

  • Centria's data protection officer is Marjaana Rahkola, 050 479 0157, tietosuojavastaava@centria.fi
  • Centria's data protection notices, data protection policy, data protection statements, and guidelines on the right to inspect and disclose data can be found on Centria's website.
  • Centria's internal data protection guidelines have been compiled in Centraali and M-Files.

1. Define the research task and the purpose of using personal data as precisely as possible in the research plan.

Personal data refers to all information that can be used to identify a person either directly or indirectly by combining individual pieces of information with other information that enables identification. Personal data includes, for example, name, address, email address, phone number, IP address, and photograph.

Personal data may only be collected and processed in accordance with the conditions specified in the General Data Protection Regulation, solely for specific, explicit, and legitimate purposes, and may not be processed subsequently for purposes incompatible with those specified.

However, scientific research purposes (including RDI activities) are not considered incompatible with the original purposes.

2. Analyze what personal data is necessary for conducting your research (amount and nature of data). Assess the necessity of personal data during the research as well, and strive to minimize the amount of personal data processed as quickly as possible.

According to the General Data Protection Regulation, personal data must be adequate, relevant, and limited to what is necessary for the purposes of processing. The processing of personal data includes all actions that are directed at personal data. Personal data may be stored in a form that allows the data subject to be identified only for as long as is necessary for the purposes of the processing.

In practice, it is advisable to collect only personal data that is relevant to RDI activities (data minimization). Therefore, always consider in advance whether personal data is necessary or whether it can be omitted altogether.

Often, the names or contact details of research subjects are no longer needed during the analysis phase, and it is advisable to delete them as soon as possible as the research progresses. Individual research subjects can also be distinguished from each other by using identifiers, such as a series of numbers (pseudonymization). However, it should be noted that contact details are also needed at a later stage in follow-up studies.

If you collect personal data, it will automatically form a personal data register, for which you must prepare a privacy policy/notice. In this case, you must also plan in advance how personal data will be collected, stored, processed, potentially disclosed, deleted, and destroyed, and describe this in the privacy policy. A pre-filled template for Centria's privacy policy/notice can be found in M-Files at Centria_Privacy Policy_Template.docx, ID13941.

3. Make a risk assessment of your processing activities and proportionate security measures accordingly for the entire processing lifecycle.

The risks associated with the processing of personal data must always be assessed before processing begins. Risk analysis is used to identify, at the planning stage, the measures that need to be taken to manage risks and ensure the proper processing of personal data. In practice, access to personal data must always be restricted to those persons who need it to carry out the research.

The risk assessment under the GDPR must be carried out from the perspective of the data subject, i.e., the controller must assess

  • what freedoms and rights of the data subject may be compromised by the processing
  • what harm may be caused to the data subject by the planned processing of personal data.

More detailed instructions on making a risk assessment can be found on the website of the Office of the Data Protection Ombudsman.

The purpose of an impact assessment is to help identify, assess, and manage the risks involved in processing personal data. An impact assessment must be carried out if the processing is likely to result in a high risk to the rights and freedoms of the data subject. An impact assessment must be carried out in particular when

  • new technology is used in the processing of personal data 
  • health data, ethnic origin, political opinions, religious beliefs or sexual orientation are processed
  • a person's personal characteristics are assessed by means of automated processing, systematically and comprehensively, and the assessment leads to decisions that have legal effects or otherwise significantly affect the person
  • an area open to the public is monitored systematically and extensively.

More detailed and practical examples of situations in which an impact assessment must be carried out in accordance with the General Data Protection Regulation can be found on the website of the Office of the Data Protection Ombudsman.

4. Plan procedures in advance for different situations, such as security breaches.

It is important to plan in advance how to prevent and minimize damage caused by possible personal data breaches. In the General Data Protection Regulation, a personal data breach refers to an accidental or unlawful act that results in the destruction, loss, alteration, unauthorized disclosure, or access to personal data by a party that does not have the right to process it. Please note that this can happen, for example, if a USB stick is lost or a computer is stolen.

  • Remember to protect your USB sticks, as a small USB stick can cause big problems.
  • Please note that emails containing personal data must always be sent in encrypted form. If an email sent outside Centria contains sensitive information, such as social security numbers, passport numbers, credit card numbers, etc., it must not be sent in plain text, but must always be sent by encrypted email. Internal email traffic at Centria is always encrypted and protected, so internal emails do not need to be encrypted separately. However, try to avoid sending sensitive information internally by email as well. For more information, see the data processing guidelines and Centria's information security guidelines (available on Centria).

Every Centria employee is obliged to immediately report any data security breaches or deviations that compromise data protection to the data protection officer (tietosuojavastaava@centria.fi).

5. Identify the basis for processing and update it if necessary to comply with the General Data Protection Regulation (e.g., consent).

The processing of personal data always requires a legal basis, which must be determined before processing begins. The grounds for processing personal data are set out in Article 6 of the General Data Protection Regulation. This article contains six different grounds on which personal data may be processed. In general, the legal basis for processing personal data in the RDI activities of universities of applied sciences is either the unambiguous written/verbal consent of the research subject or a scientific or historical research purpose in the public interest.

Further information on the bases for processing can be found on the website of the Office of the Data Protection Ombudsman.

If the research setting does not require consent from the research subjects for reasons outside the scope of the General Data Protection Regulation (e.g., research ethics statements), it is easiest to use scientific or historical research purposes in the public interest as the basis for processing instead of the consent of the research subjects (Article 6(1)(e) of the GDPR). However, this basis for processing cannot be used in commercial research.

Watch also: Research permit, informing research subjects, and consent

6. Identify the rights of the data subject in relation to the basis for processing and ensure that they are exercised.

The data subject has the right to obtain information about the collection and processing of their personal data, and therefore the person being investigated must be provided with the necessary information about how their personal data is processed. More detailed instructions on the rights of data subjects can be found on the website of the Office of the Data Protection Ombudsman.

Data subjects must be informed, among other things, of the purposes for which the data is processed, the processing times, the disclosure of data, and the rights of data subjects.

A pre-filled template for Centria's privacy policy/notice can be found in M-Files under the name "Centria_tietosuojaseloste_malli" ID13941.

7. Be prepared to demonstrate that data protection regulations have been taken into account in your research: document the implementation of data protection principles and other procedures in accordance with the General Data Protection Regulation.

Further information on the demonstration obligation can be found on the website of the Office of the Data Protection Ombudsman.

8. Recognize your role and responsibilities! The controller is responsible for the lawfulness of personal data processing. If you need the services of other parties in the processing of personal data, draw up a written agreement and clear instructions for

Always follow Centria's instructions. The data processing guidelines will help you choose the appropriate method for processing and storing data in each situation. The guidelines can be found in Centraalista.

9. Foster trust and ensure the conditions for future research by complying with data protection regulations and ensuring transparency and openness.

Remember to follow Centria's guidelines! Centria's data protection guidelines for RDI activities can be found at Centraali.

10. Data protection tools are an essential part of a researcher's toolkit!

Update your knowledge and follow the website of the Data Protection Ombudsman and Centria's data protection guidelines. Please also familiarize yourself with Centria's "Personnel Data Security Guide 2018," which can be found in Centraali. Please note that all Centria personnel must complete online data protection training, instructions for which can also be found in Centraali in the "Data Security Training Instructions".