RDCOC-ADH-01 | Adherence Procedures | 0 |
RDCOC-ANO-01 | Anonymisation Criteria | 1 |
RDCOC-APP-01 | Supervisory Authority / EDPB Approval | 0 |
RDCOC-AUD-01 | Audits and Compliance Reviews | 0 |
RDCOC-BRE-01 | Breach Notification Procedures | 1 |
RDCOC-COM-01 | Complaint Handling | 1 |
RDCOC-CON-01 | Consent and Broad Consent | 1 |
RDCOC-DPI-01 | Data Protection Impact Assessments | 1 |
RDCOC-GOV-01 | Code Owner and Governance | 0 |
RDCOC-LAW-01 | Lawful Basis for Research | 1 |
RDCOC-MON-01 | Accredited Monitoring Body | 0 |
RDCOC-PRO-01 | Processor Engagements | 1 |
RDCOC-PSE-01 | Pseudonymisation Standards | 1 |
RDCOC-RET-01 | Retention and Archival | 1 |
RDCOC-REV-01 | Periodic Review and Update | 0 |
RDCOC-RIG-01 | Data Subject Rights and Information in Research | 1 |
RDCOC-SAN-01 | Sanctions and Suspension | 0 |
RDCOC-SCO-01 | Scope of Processing Activities | 1 |
RDCOC-TRA-01 | International Data Transfers | 1 |
RDCOC-TRN-01 | Training and Awareness | 1 |
2.1 | 2.1 Substantiate that processing is for scientific research purposes against the six key-indicative factors | 0 |
2.2-2.3 | 2.2-2.3 Research data infrastructures and ancillary operations assessed against the same factors | 0 |
3.1.1 | 3.1.1 Further processing for research is presumed compatible, but lawfulness, the Article 9 derogation and Member State limits are assessed anew | 0 |
3.1.2 | 3.1.2 Providing personal data to another controller for its research: no compatibility test, both controllers comply in full | 0 |
3.2 | 3.2 Storage limitation: determine and communicate the period before processing, store for specified future research only, review necessity and format | 0 |
4.1.1 | 4.1.1 Consent must be freely given: vulnerable participants, patients' capacity, no conditioning of care, and remuneration assessed | 0 |
4.1.2 | 4.1.2 Choose broad or dynamic consent before processing, document the choice, define the research area, keep projects within it | 0 |
4.1.2.1 | 4.1.2.1 Broad consent safeguards: detailed and continuing information, use and access controls, time limits, an oversight body, a choice tool | 0 |
4.1.3 | 4.1.3 Distinguish consent to participate in research from GDPR consent, and keep the two requests distinguishable | 0 |
4.2 | 4.2 Public interest as a legal basis needs a Union or Member State law meeting necessity and proportionality, open to private entities the law covers | 0 |
4.3 | 4.3 Legitimate interest: significant weight for research, reasonable expectations, and safeguards folded into the balancing test | 0 |
4.4 | 4.4 Special categories: determine the Article 9(2) derogation, treat inferred and collatable data as special, DPIA at large scale, Member State conditions | 0 |
4.4.2 | 4.4.2 Data manifestly made public: a high threshold requiring the data subject's own explicit, affirmative choice in context | 0 |
4.4.3 | 4.4.3 Derogations in Union or Member State law: show the law applies and implement its suitable and specific measures, adding safeguards where the law did not anticipate the risks | 0 |
5.1 | 5.1 Give data subjects a way to stay informed over long research: voluntary contact details, choice of channel, a webpage or application | 0 |
5.2 | 5.2 Information at collection, layered where appropriate; a controller without the data or contact must still inform and answer access requests through its processor or co-controll | 0 |
5.3 | 5.3 Inform before further processing for research with time to react, never knowingly delete contact details, make reasonable efforts to reach data subjects and inform indirectly w | 0 |
5.4 | 5.4 Receiving controllers inform under Article 14, including for data they generate; cooperate with providers and intermediaries; tell pseudonymised-data subjects how to exercise r | 0 |
5.4.2 | 5.4.2 Impossibility, disproportionate effort and research-impairing individual information: exemptions that still require public information and safeguards, especially for covert r | 0 |
5.5 | 5.5 Inform data subjects of changes that make earlier information obsolete, in time to act; which changes count and which do not | 0 |
6.1 | 6.1 Determine the restrictions and derogations of rights in Union or Member State law, and the additional rights, and inform data subjects of them | 0 |
6.2 | 6.2 Erasure requests: test the Article 17(1) grounds, then the Article 17(3)(d) exception restrictively and case by case, and warn of it in advance | 0 |
6.3 | 6.3 Objections: the controller bears the burden of compelling grounds; under Article 21(6) necessity for a public-interest task is strict, verified at the time of the request, and | 0 |
7.1 | 7.1 Attribute controllership functionally, document the allocation, and recognise the sponsor or protocol author as controller even without handling identifiable data | 0 |
7.2 | 7.2 Processors act within the controller's instructions and become controllers, with the liability that follows, where they decide purposes or essential means | 0 |
7.3 | 7.3 Joint controllers: joint determination of the protocol, an Article 26 arrangement reflecting differing responsibilities and made available to data subjects, processors engaged | 0 |
8.1 | 8.1 Article 89(1) safeguards assessed on nature, scope, context, purposes and risks, in addition to the GDPR's general measures, and reassessed on further processing | 0 |
8.2 | 8.2 Start with a risk analysis or DPIA that looks beyond privacy to other fundamental rights, health findings, re-identification, publication and vulnerable or related persons | 0 |
8.3 | 8.3 Anonymise where the purposes allow, otherwise pseudonymise, identify directly only where strictly necessary; decide the format at planning, keep methods state of the art and ve | 0 |
8.4 | 8.4 Genetic and biometric data: particular caution, restrictive purposes, pseudonymisation, ethical approval, federated storage with secure access, role-based controls, and communi | 0 |
8.5 | 8.5 Select further safeguards fitted to the research method from the EDPB's menu: oversight governance, enhanced transparency, consent as a safeguard, strict purpose limits, PETs, | 0 |
ART40 | Article 40 codes of conduct for research: the mechanism and the sector codes held (EDPB Guidelines 1/2019 and 04/2021; Farmaindustria, EUCROF, GEANT, CSA) | 0 |
GL | EDPB Guidelines 1/2026: what they are, what is held and their status; the framework renamed from an Article 40 code that does not exist | 0 |
INFO | Section 5: obligations to inform | 0 |
LAW | Section 4: lawfulness, consent, public interest, legitimate interest and special categories | 0 |
PRIN | Section 3: purpose limitation and storage limitation | 0 |
RIGHTS | Section 6: data subjects' rights | 0 |
ROLES | Section 7: attribution of responsibility | 0 |
SAFE | Section 8: appropriate safeguards under Article 89(1) | 0 |
SCOPE | Section 2: the concept of processing for scientific research purposes | 0 |