An operator who processes or continues to process personal data for health
research purposes must implement the following “appropriate and specific
measures”
17 :
a) Provisions to ensure that personal data are not processed in a manner that causes or is
likely to cause harm or damage to the data subject;
b) Suitable governance structures, including: (i) the ethical approval of health research by a
research ethics committee (if any); (ii) mentioning the involved operator; (iii) compliance by associate operators to Article 26 of GDPR; (iv) specification of all empowered
persons; (v) specification of any third-party financing or otherwise supporting the
project; (vi) the specification of any other person with whom they intend to share any
personal data (including pseudonymised or anonymous data) and the purpose of such
sharing; and (vii) the provision of training courses in the field of data protection law and
practices to people conducting health research;
c) The following processes and procedures: (i) an assessment of the implications of data
protection in health research; (ii) if the assessment indicates a high risk to the rights of
individuals, an impact assessment of the data protection should be performed; (iii) data
minimization measures (e.g. pseudonymisation); (iv) access control to prevent
unauthorized consultation, modification, disclosure or deletion of personal data;
(v) audit logs; (vi) security measures; (vii) the anonymisation, archiving or destruction
of personal data after the completion of the health research; and (viii) other technical and
organizational measures to ensure compliance with the GDPR;
d) The arrangements for ensuring the transparent processing of personal data;
e) “Explicit consent” of the data subject before the processing of his or her personal data
for a specific purpose of the health research or, more generally, in this field.
3.2 Protection of Employees’ Personal Data Processed by
Electronic Means
Perhaps one of the most debated issues in the Romanian practice are the following
two: the possibility of introducing integrity tests for employees and the issue related
to the monitoring and surveillance at the work place.
With regards to the first issue, there are no provisions in the Romanian Data
protection laws related to it, so accordingly employers have tried to interpret the laws
and make assumptions.
In addition, the object of integrity testing, Romanian employers assumed the
following:
a) Integrity tests should be conducted in good faith and will be conducted with
respect for human rights and fundamental freedoms, human and professional
dignity of the tested employees;
b) Integrity tests should not contain elements that may affect the image of the tested
person;
17 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri¼CELEX%3A52012SC0072.
298
E. Lazar and D. N. Costescu
research purposes must implement the following “appropriate and specific
measures”
17 :
a) Provisions to ensure that personal data are not processed in a manner that causes or is
likely to cause harm or damage to the data subject;
b) Suitable governance structures, including: (i) the ethical approval of health research by a
research ethics committee (if any); (ii) mentioning the involved operator; (iii) compliance by associate operators to Article 26 of GDPR; (iv) specification of all empowered
persons; (v) specification of any third-party financing or otherwise supporting the
project; (vi) the specification of any other person with whom they intend to share any
personal data (including pseudonymised or anonymous data) and the purpose of such
sharing; and (vii) the provision of training courses in the field of data protection law and
practices to people conducting health research;
c) The following processes and procedures: (i) an assessment of the implications of data
protection in health research; (ii) if the assessment indicates a high risk to the rights of
individuals, an impact assessment of the data protection should be performed; (iii) data
minimization measures (e.g. pseudonymisation); (iv) access control to prevent
unauthorized consultation, modification, disclosure or deletion of personal data;
(v) audit logs; (vi) security measures; (vii) the anonymisation, archiving or destruction
of personal data after the completion of the health research; and (viii) other technical and
organizational measures to ensure compliance with the GDPR;
d) The arrangements for ensuring the transparent processing of personal data;
e) “Explicit consent” of the data subject before the processing of his or her personal data
for a specific purpose of the health research or, more generally, in this field.
3.2 Protection of Employees’ Personal Data Processed by
Electronic Means
Perhaps one of the most debated issues in the Romanian practice are the following
two: the possibility of introducing integrity tests for employees and the issue related
to the monitoring and surveillance at the work place.
With regards to the first issue, there are no provisions in the Romanian Data
protection laws related to it, so accordingly employers have tried to interpret the laws
and make assumptions.
In addition, the object of integrity testing, Romanian employers assumed the
following:
a) Integrity tests should be conducted in good faith and will be conducted with
respect for human rights and fundamental freedoms, human and professional
dignity of the tested employees;
b) Integrity tests should not contain elements that may affect the image of the tested
person;
17 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri¼CELEX%3A52012SC0072.
298
E. Lazar and D. N. Costescu
