DIN EN 14485-2004 Health informatics - Guidance for handling personal health data in international applications in the context of the EU data protection directive German version EN.pdf
《DIN EN 14485-2004 Health informatics - Guidance for handling personal health data in international applications in the context of the EU data protection directive German version EN.pdf》由会员分享,可在线阅读,更多相关《DIN EN 14485-2004 Health informatics - Guidance for handling personal health data in international applications in the context of the EU data protection directive German version EN.pdf(79页珍藏版)》请在麦多课文档分享上搜索。
1、M rz 2004DEUTSCHE NORM Normenausschuss Medizin (NAMed) im DINPreisgruppe 24DIN Deutsches Institut f r Normung e.V. Jede Art der Vervielf ltigung, auch auszugsweise, nur mit Genehmigung des DIN Deutsches Institut f r Normung e. V., Berlin, gestattet.ICS 35.240.808 ; 9502553www.din.deXDIN EN 14485Medi
2、zinische Informatik Anleitung zur Verwendung von pers nlichen Gesundheitsdaten in internationalen Anwendungen vor dem Hintergrund der EUDatenschutzrichtlinie;Deutsche Fassung EN 14485:2003, Text in EnglischHealth informatics Guidance for handling personal health data in international applications in
3、 the context of the EU data protection directive; German version EN 14485:2003, text in EnglishInformatique de sant Guide pour manipuler des donnes personnelles de sant dans des applications internationales dans le contexte de la directive europenne sur la protection des donnes personelles;Version a
4、llemande EN 14485 : 2003, texte en anglaisAlleinverkauf der Normen durch Beuth Verlag GmbH, 10772 Berlinwww.beuth.deGesamtumfang 79 SeitenB55EB1B3E14C22109E918E8EA43EDB30F09CC9B7EF8DD9NormCD - Stand 2007-03 DIN EN 14485:2004-032Die Europische Norm EN 14485:2003 hat den Status einer DeutschenNorm.Nat
5、ionales VorwortDiese Norm enthlt unter Bercksichtigung des Prsidialbeschlusses 13/1983 die Englische Fassung derEuropischen Norm EN 14485:2003. Diese Europische Norm wurde in der WG III Security, Safety andQuality des CEN/TC 251 Medizinische Informatik erarbeitet. Der Fachbereich G Medizinische Info
6、rmatik undinsbesondere die Mitarbeiter des Arbeitsausschusses G 4 Sicherheit des Normenausschusses Medizin(NAMed) im DIN haben an der Erarbeitung mitgewirkt.B55EB1B3E14C22109E918E8EA43EDB30F09CC9B7EF8DD9NormCD - Stand 2007-03 EUROPEAN STANDARDNORME EUROPENNEEUROPISCHE NORMEN 14485December 2003ICS 35
7、.240.80English versionHealth informatics - Guidance for handling personal health datain international applications in the context of the EU dataprotection directiveInformatique de sant - Guide pour manipuler des donnespersonnelles de sant dans des applicationsinternationales dans le contexte de la d
8、irective europennesur la protection des donnes personellesMedizinische Informatik - Anleitung zur Verwendung vonpersnlichen Gesundheitsdaten in internationalenAnwendungen vor dem Hintergrund der EU-DatenschutzrichtlinieThis European Standard was approved by CEN on 13 November 2003.CEN members are bo
9、und to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this EuropeanStandard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such nationalstandards may be obtained on application to the Ma
10、nagement Centre or to any CEN member.This European Standard exists in three official versions (English, French, German). A version in any other language made by translationunder the responsibility of a CEN member into its own language and notified to the Management Centre has the same status as the
11、officialversions.CEN members are the national standards bodies of Austria, Belgium, Czech Republic, Denmark, Finland, France, Germany, Greece,Hungary, Iceland, Ireland, Italy, Luxembourg, Malta, Netherlands, Norway, Portugal, Slovakia, Spain, Sweden, Switzerland and UnitedKingdom.EUROPEAN COMMITTEE
12、FOR STANDARDIZATIONCOMIT EUROPEN DE NORMALISATIONEUROPISCHES KOMITEE FR NORMUNGManagement Centre: rue de Stassart, 36 B-1050 Brussels 2003 CEN All rights of exploitation in any form and by any means reservedworldwide for CEN national Members.Ref. No. EN 14485:2003 EB55EB1B3E14C22109E918E8EA43EDB30F0
13、9CC9B7EF8DD9NormCD - Stand 2007-03 EN 14485:2003 (E)2Contents PageForeword . 5Introduction. 61 Scope 92 Normative references 93 Terms and definitions. 94 Abbreviated terms. 115 General solutions to exchanging personal health data between compliant and non-compliantcountries 115.1 General approach 11
14、6 Judging the adequacy of data protection. 126.1 General . 126.2 Content Principles. 126.3 Procedural/Enforcement Mechanisms 146.4 Third Countries that have ratified the Council of Europe Convention 108 . 146.5 Industry self-regulation 157 Making adequate provisions 167.1 Introduction . 167.2 Meetin
15、g the “Content Principles“ 167.3 Providing for the “Procedural/Enforcement Mechanisms“ 177.3.1 General . 177.3.2 Providing redress 177.3.3 Support and help to data subjects 177.3.4 Adequate compliance . 187.3.5 Onward transfers. 187.3.5 Direct marketing and sale of data 187.4 Overriding law . 188 Pe
16、rmissible derogations, Articles 26.1 and 26.2 198.1 Article 26.1 . 198.1.1 General . 198.1.2 Consent 208.2 Article 26.2 . 209 Anonymisation 209.1 Definition of personal data. 209.2 Rendering personal data anonymous. 2110 Notification to Supervisory Authorities 2110.1 Introduction . 2110.2 Implementa
17、tion of Articles 18 to 20. 2111 Steps in establishing an international application with adequate data protection safeguardsfrom the view point of an EU data controller2211.1 Introduction . 2211.2 Step One: Can the data be non-personal? . 2211.3 Step Two: Is the recipient third country an EEA country
18、? . 2311.4 Step Three: Is the recipient country recognised by the Commission as having adequatedata protection provisions?. 2311.5 Step Four: Is the recipient organisation in compliance with arrangements formally recognisedby the Commission as providing adequate data protection provisions? . 24B55EB
19、1B3E14C22109E918E8EA43EDB30F09CC9B7EF8DD9NormCD - Stand 2007-03 EN 14485:2003 (E)3Page11.6 Step Five; If the recipient third country is not EEA, has it signed the Council of EuropeConvention 108? . 2411.7 Step Six: Is the recipient country applying to become a member of the EU? 2411.8 Step Seven: Ca
20、n adequacy of data protection be established? 2411.9 Step Eight: If adequacy of data protection cannot be established can the derogations inArticle 26.1 provide a solution? 2411.10 Step Nine: If adequacy of data protection cannot be established can the derogation inArticle 26.2 regarding contractual
21、 clauses provide a solution? 2611.11 Step Ten: If transfer of personal data health data to the recipient third country is permissible hasthe recipient implemented adequate security measures and can the application proceed? . 2612 Steps in establishing an international application with adequate data
22、protection safeguardsfrom the viewpoint of a non-EU data controller. 2612.1 Establishing data protection adequacy in the EU . 2613 Model contract clauses 27Published models . 2714 Security measures 2714.1 Introduction . 2714.2 General security 2814.3 Security contracts with processors and with contr
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DINEN144852004HEALTHINFORMATICSGUIDANCEFORHANDLINGPERSONALHEALTHDATAININTERNATIONALAPPLICATIONSINTHECONTEXTOFTHEEUDATAPROTECTIONDIRECTIVEGERMANVERSIONENPDF

链接地址:http://www.mydoc123.com/p-667341.html