Case study 17: Inappropriate disclosure of medical research data [2010] IEDPC 17 (2010)

Case study 17: Inappropriate disclosure of medical research data [2010] IEDPC 17 (2010)

The hospital breached the Data Protection Acts by disclosing patient data to university researchers without proper consent or ethics committee notification. Full responsibility was accepted and remedial actions were taken.

Citation
[2010] IEDPC 17
Parties
Data Controller: Affiliated Hospital; Research Collaborator: University; Regulator: Data Protection Commission; Data Subject: Patient
Jurisdiction
Ireland
Procedural Posture
Data Protection Investigation / Post Breach Review
Outcome
breach found; remedial action taken
Legal Topics
Inappropriate Disclosure, Research Ethics, Patient Consent

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 2 Authorities cited 1 Party arguments 2
Sign in to unlock

Parties

Affiliated Hospital

Data Controller

University

Research Collaborator

Data Protection Commission

Regulator

Patient

Data Subject

Procedural Posture

Data Protection Investigation / Post Breach Review

  1. 1 Was there a breach of the Data Protection Acts in the disclosure of medical research data?
  2. 2 Were proper procedures followed for patient recruitment and data handling?

Ratio Decidendi

The hospital breached the Data Protection Acts by disclosing patient data to university researchers without proper consent or ethics committee notification. Full responsibility was accepted and remedial actions were taken.

Court Disposition

breach found; remedial action taken

Orders

  • Hospital to update research ethics approval procedures.
  • Hospital to enhance data protection training for researchers.