Personal Data Protection in Studies Conducted at the IKEM - Questionnaire

Sponsor:

CRO (if applicable):

Title of clinical study:

Identifier (e.g., EU CT number, protocol code – used to assign the questionnaire to the specific study)::

Contact (including email or phone number):


Question 1: Could you please provide a comprehensive list of all personal data categories that will be collected during the study?
Be sure to cover ordinary personal data (e.g., initials, age, gender/sex) for both patients and the study team, as well as sensitive health data (special categories of personal data under Article 9 of the GDPR, such as diagnoses, test results, genetic/biometric data, and treatments). "Personal data" means any information relating to an identified or identifiable person (hereinafter referred to as "data subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier or factors specific to the physiological, genetic, mental, economic, cultural or social identity of that person. Please specify if you will be handling biological samples from IKEM patients and describe exactly which ones. Additionally, outline the format in which the data will be transferred (e.g., pseudonymized), the exact processing purpose (e.g., clinical research), who will have access to the data, and whether any data transfers outside the EU /EEA will take place.


Question 2:
2.1: What specific system (eCRF and other electronic databases) will be used for data collection and storage?

2.2: Who operates this information system? (Please provide the company name and address). Will any processing of personal data occur outside the EU/EEA?

2.3: Do you have a confidentiality and data processing agreement with this processor in compliance with Article 28 of the GDPR?
Please confirm the existence of this agreement and verify that it covers all requirements (e.g., subject matter, duration and purpose of processing, technical security, rules for involving sub-processors, audit rights).


Question 3:
3.1: What is the intended allocation of GDPR roles? For each processing purpose, please specify whether IKEM, the Sponsor, the CRO, the eCRF provider, or any other involved entities will act as independent controllers, joint controllers, processors, or sub-processors.

3.2: Who will fulfil the information obligations towards data subjects under Articles 13 and 14 GDPR?
Please attach a draft of the GDPR information for data subjects to your email. This document has to contain all mandatory GDPR information, including contact details, the purpose of processing, patients' rights, and data retention periods.

3.3: Which legal basis under Article 6 GDPR and which condition under Article 9 GDPR applies for processing patients' personal data in connection with the study, and for what reason?
If informed consent to the processing of personal data pursuant to Article 6(1)(a) GDPR is used for "standard personal data" or explicit consent pursuant to Article 9(2)(a) GDPR is used for health data, please provide a template thereof.


Question 4:
4.1: What will the data flows look like?
Please provide a brief narrative data pathway (e.g., IKEM physician enters data into the eCRF -> data is stored on the provider's server in the Czech Republic -> the Sponsor in the Czech Republic, downloads the export.

4.2: Will pseudonymized data be transferred or made accessible to countries outside the EU/ EEA? If so, how is this transfer safeguarded?
For any transfers outside the EU/EEA, please specify the destination country, the recipient, and the specific GDPR transfer mechanism used (e.g., Standard Contractual Clauses). Furthermore, state whether a transfer impact assessment was carried out and explain how the data is secured—whether it is encrypted, who holds the encryption keys, and whether authorities in the third country may access the personal data.


Question 5:
5.1: What technical and organisational measures (TOMs) pursuant to Article 32 of the GDPR have you implemented to ensure data security (e.g., data encryption, access control, access logging)?

5.2: How do you manage employee access to IKEM data? Do you enforce the Principle of Least Privilege and Multi-Factor Authentication?

5.3: Do you engage third parties including processors or sub-processors, for the processing of personal data? How do you verify their security? If so, please provide a current list of these sub-processors and explain how you guarantee their GDPR compliance.

5.4: How do you monitor for security anomalies and handle potential data breaches? Within what timeframe will you notify us of an incident?

5.5: What is the method and frequency of your data backups? How do you test data restorability?

5.6: What are your policies regarding data retention and erasure upon contract termination?
In your response, please specify the exact retention periods and legal basis and statutory or contractual grounds for retaining the personal data after the study concludes, and identify the person or entity responsible for archiving. Please outline whether the data will be returned to IKEM, deleted, anonymised, or further processed for future research. Additionally, confirm if the deletion covers backups and subcontractors, how you will verify secure data disposal, and whether you intend to use the data for secondary analyses.


Question 6: Has a Data Protection Impact Assessment (DPIA) under Article 35 GDPR been carried out for this study?
If so, please provide a summary of the main conclusions, risk assessments, and any other information’s relevant to IKEM. If DPIA was not conducted, please provide a brief explanation.