Automatic Data Gathering Requirements and Privacy Implications

Mark Meer

Trusted Information Resource
#1
Curious: say we wanted our network-connected medical device software to collect data for us. Assume, for the sake of discussion, we wanted our software to just relay to us when the software is used, from where (geographic location), and for how long. What would we have to do? Presumably:
  1. Inform users that data is being collected.
  2. Ensure that data is anonymized, so it's not personally-identifiable data that is being collected.
First, with respect to presumption (1) above, can anyone link to regulations where this is explicitly stated as a requirement? If so, what are the criteria for disclosure, and acknowledgement? For example, is it sufficient that the user is presented with a one-time notification "this software collects anonymized use data", and an "agree" button? Or is there more specific criteria/requirements that must be met?

With respect to presumption (2) above, it's unclear what is a sufficient level of anonymization. For example, the GDPR defines personal data as:
GDPR Art. 4
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
*emphasis added

So, in the example given, is collecting times and places qualify as "personal data"? In certain circumstances, one could conceivably use this data to identify an individual indirectly (e.g. by cross-referencing with hospital admission records), but such a specific circumstance (and that someone would exploit) seems incredibly remote.

Also, presumably an IP address would be considered an "online identifier"? If so, if this information is collected strictly for the sake of determining the regional location, and is then discarded, does this still qualify as the collection/processing of personal data, even though it is never stored?

Anyway, look forward to comments/discussion!
MM
 
Elsmar Forum Sponsor
Thread starter Similar threads Forum Replies Date
P Change the way you think about SPC - Automatic Data Collection Statistical Analysis Tools, Techniques and SPC 8
I ADR (Automatic Data Recorder) Calibration Requirements Calibration and Metrology Software and Hardware 2
D MSA for Attribute data - Automatic Hy-pot test machine Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 6
WEAVER Can automatic machine testers be subject to GR&R? Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 4
G GR&R in A.T.E. (Automatic Test Equipment) Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 4
P MSA on an in-line automatic X-ray thickness measuring gage Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
S Design Standards for Automatic Fare Collection System Various Other Specifications, Standards, and related Requirements 2
O IEC 61010-1 Ed 2: "Automatic Disconnection of the supply" CE Marking (Conformité Européene) / CB Scheme 3
D Back to Back MSA - Two "identical" automatic measuring systems Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 2
N Does OHSAS 18001 require organization to have AED (Automatic External Defibrillator) Occupational Health & Safety Management Standards 4
J The appropriate Attribute MSA for Automatic Visual Inspection Machine Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
E MSA for criteria Automatic Video Measurement Systems Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 1
S Smartphone based software with automatic "rating" from remote servers Medical Information Technology, Medical Software and Health Informatics 4
F CMM Scanning Feature Delays - Brown and Sharpe automatic CMM using PC-DMIS CAD 4.3 Inspection, Prints (Drawings), Testing, Sampling and Related Topics 2
L MSA in Automatic Equipment - PCB Assembly - Help! Quality Tools, Improvement and Analysis 6
W Is a Non-Automatic Weighing Instrument a Medical Device? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
optomist1 GD&T Flatness Automatic Indirect Control Rule #1 Inspection, Prints (Drawings), Testing, Sampling and Related Topics 20
B Conducting a study on Hexagon Nuts "turned" on a multi-spindle automatic lathe Statistical Analysis Tools, Techniques and SPC 9
B Attribute MSA for Visual Inspection via Camera Automatic Inspection Tool Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 5
P Gage R&R with ATE (Automatic Test Equipment) - Newbie here... Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 6
B Attribute MSA of Automatic Inspection Equipment Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 7
K Gage R&R's on automatic gages with robots Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 18
B What local standards are needed for ISO 9001 - Automatic doors ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
S Gage R&R analysis for a fully automatic machine Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 2
S How to carry out Gage R&R for automatic machines? Automated Equipment Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 22
K MSA for Steam Autoclave Automatic Controller and Measurement System Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
K GR&R for an Automatic Optical Inspection Machine (AOI) Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
Z Supplier of Automatic Gaging Systems need to be on our Approved Supplier List? IATF 16949 - Automotive Quality Systems Standard 6
Q Over sampling - Product on an automatic line with a predetermined lot size Inspection, Prints (Drawings), Testing, Sampling and Related Topics 8
J Reproducibility error between instruments for automatic measuring equipment Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 9
D Attribute Gage R&R study - Automatic machine that tests for a particular feature Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
I ATE (Automatic Test Equipment) "Gage" process for electronic modules? Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 10
G GR&R on automatic equipment such as a CMM - Do you still have to use 3 operators Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 8
T Need supplier for automatic thread inspection go / no go machine Supplier Quality Assurance and other Supplier Issues 3
B Gage R&R for Automatic Test Systems - No operator influence on readings Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 7
C Need 3 appraisers for GR&R (Gage R&R) of Automatic Test Measurements? Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
S Determining MSA Bias in Automatic Test Equipment for Electronics Modules Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 6
A Gage R&R with ATE (Automatic Test Equipment) Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 15
J How & how often to perform verification of Test Software of Automatic Test Equipment? General Measurement Device and Calibration Topics 3
Z Control Charts and sample size for automatic measurement Statistical Analysis Tools, Techniques and SPC 1
Jerry Eldred Gauge R&R studies for Automatic Gages and Test Equipment Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 3
K Transform variable data into attribute data Reliability Analysis - Predictions, Testing and Standards 24
R Clinical evaluation without clinical data - MDR Article 61(10) EU Medical Device Regulations 1
H Capability Data for Paint Thickness on Painted Parts Statistical Analysis Tools, Techniques and SPC 10
D BS EN 62304 - Medical-Relevant Data C.5 - Definition of IEC 62304 - Medical Device Software Life Cycle Processes 5
T Submitting MR Compatibility Data for 510(k) Cleared Device Other Medical Device and Orthopedic Related Topics 2
S Quality manager considering data science Quality Manager and Management Related Issues 19
A What are Practical data center best practices IEC 27001 - Information Security Management Systems (ISMS) 0
U Do we need clinical trial data for Class IIa medical device under MDR EU Medical Device Regulations 7
S Average and standard deviation of Cumulative Data Statistical Analysis Tools, Techniques and SPC 5
Similar threads


















































Top Bottom