GDPR, ICSR masking, anonymization, and data protection in PV (GVP VI Addendum II, CDSCO).
21 terms
Process of removing or encoding personal data in ICSRs so that the individual cannot be identified, while retaining data needed for pharmacovigilance (GVP VI Addendum II).
Any information relating to an identified or identifiable natural person in an ICSR (e.g., name, DOB, address, identifiers). Subject to GDPR and local laws; masking required for EU submission.
Processing of personal data so that it can no longer be attributed to a specific person without use of additional information kept separately (GDPR Art 4(5)).
EU General Data Protection Regulation; PV activities may rely on legal basis such as public interest or legal obligation. Data minimization and purpose limitation apply.
Principle of collecting and retaining only personal data that is necessary for PV purposes (safety reporting, follow-up, regulatory obligations).
Unauthorized access, loss, or disclosure of personal data held for PV. May require notification to supervisory authority and data subjects under GDPR (e.g., 72 hours).
Policies and duration for retaining PV data (cases, source documents). Must align with regulatory requirements (e.g., post-authorization) and data protection law.
Assessment of risks to personal data processing; required under GDPR for high-risk processing (e.g., large-scale health data).
Legal ground for processing personal data in PV (e.g., legal obligation, public interest). Consent not required for PV in EU.
Methods to anonymize personal data (generalization, suppression, perturbation) per GVP VI Addendum II.
Risk that anonymized data can be linked back to an individual; must be assessed and minimized.
Transfer of PV data (including personal data) across borders; must comply with GDPR and local laws.
Request by data subject for access to their personal data; must be handled per GDPR (e.g., 1 month).
Right to have personal data erased under GDPR; limited where processing is for legal obligation (e.g., PV).
Disposal of PV data after retention period; must be documented and lawful.
Where consent is used (e.g., some studies), must be documented; not required for legal obligation PV in EU.
Notice to data subjects on how PV data are processed (e.g., on report form or website).
Person designated for data protection (GDPR); may advise on PV processing.
Data protection authority in EU (e.g., ICO, CNIL); breach notification and complaints.
Rule defining which fields are masked and how (e.g., DOB → age range) per GVP VI Addendum II.
Check that submitted ICSR does not contain unmasked personal data.