Data Protection Notice

18 March 2023, EMA/51067/2023

Table of contents

Data Analysis and Real World Interrogation Network (DARWIN EU®) Data Protection Notice

This Data Protection Notice (DPN) describes why and how the Coordination Centre (hereinafter the “CC”) of the Data Analysis and Real-World Interrogation Network[1] (hereinafter the “DARWIN EU®”) collects and uses your personal data to deliver its services to the European Medicines Agency (hereafter “EMA”).

The DARWIN EU® CC keeps this DPN under regular review and reserves the right to update this DPN from time to time as required and in agreement with EMA. We will notify you by means of a prominent notice on the DARWIN EU® site prior to the change becoming effective. We encourage you to check for updates to this DPN on a regular basis.

What is personal data?

'Personal data' is any information relating to an identified or identifiable natural person ('data subject'). An identifiable person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 4(1) of the General Data Protection Regulation (GDPR)[2] and Article 3(1) of the European Union Data Protection Regulation[3] (EUDPR).

Information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable does not constitute personal data. Anonymisation refers to the processing of personal data in a manner that makes it irreversibly impossible to identify an individual.

What is processing?

'Processing' of personal data means any operation or set of operations that is performed upon personal data, whether or not by automated means, such as collection, recording, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, deletion or destruction.

What principles should be complied with when processing personal data?

The DARWIN EU® CC values your privacy and data protection rights. When collecting and using personal data about you, we are committed to doing so in accordance with our obligations as set out in Union data protection legislation.

More specifically and in accordance with Article 5 of the GDPR/Article 4 of the EUDPR, we are bound by the following principles when using your personal information:

  • Lawfulness, fairness and transparency – We use your personal data lawfully, fairly and in a transparent way.
  • Purpose limitation – We collect your personal information only for specified, explicit and legitimate purposes and do not use it in any way that is incompatible with those purposes.
  • Data minimisation – We use adequate, relevant and limited to what is necessary personal data in relation to the stated purposes.
  • Accuracy – We hold your personal data accurate and up to date and we take all reasonable and necessary steps to ensure that inaccurate data, having regard to the purposes for which they are processed, are erased or rectified without delay.
  • Storage limitation – We keep your personal data only as long as necessary for the specific purposes of the described data processing.
  • Integrity and confidentiality – We keep and processes your personal information securely to protect it against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
  • Accountability – We are responsible for our data processing activities and able to demonstrate our compliance with the obligations as set out in the Union data protection legislation.

1. Who is responsible for processing your data?

1.1 Who is the data controller?

The European Medicines Agency (“EMA”) is ultimately responsible to comply with your data protection rights and freedoms. On behalf of EMA, the Head of the Data Analytics and Methods Task Force is appointed as ‘Internal Controller’ to ensure the lawful conduct of this processing operation.

You may contact the Internal Controller via the following email address:

This email address is being protected from spambots. You need JavaScript enabled to view it.

1.2 Who is the data processor?

The DARWIN EU® Coordination Centre represented by Erasmus MC acts as the data processor.

The contact details of the data processor are the following: This email address is being protected from spambots. You need JavaScript enabled to view it.

2. Purpose of this data processing

The purpose of DARWIN EU® is to establish a network of data, expertise, and services that supports better decision-making throughout the medicinal product lifecycle with reliable evidence from real world healthcare data. EMA established the DARWIN EU® CC to provide timely and reliable evidence on the use, safety and effectiveness of medicines for human use including vaccines from real world healthcare databases across the European Union (EU).

This enables EMA, the European Commission and national Competent Authorities (hereafter “NCAs”) in the European medicines regulatory network to utilise these data whenever needed throughout the lifecycle of a medicinal product.

More specifically, DARWIN EU® supports regulatory decision-making by:

  • establishing and expanding the EMA Catalogue of Real-World Data Sources including observational data sources for use in medicines regulation;
  • providing a source of high-quality, validated real world data on the use, safety and efficacy of medicines;
  • addressing specific questions by carrying out high-quality non-interventional studies including developing scientific protocols, interrogating relevant data sources and interpreting and reporting study results.

In respect of the DARWIN EU® activities, the DARWIN EU ® CC may engage with multiple data partners which may come from public and private sectors. Examples include NCAs for health and medicines regulation as well  as healthcare providers and private companies who process relevant data. Depending on the study design, data partners provide at this stage anonymised study results in response to a research query formulated by EMA in the context of medicines regulatory activities with focus on the utilisation, safety and efficacy of medicines. EMA will utilise the responses to the queries to inform its regulatory decisionmaking.
The principles of data protection do not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.

The data processing activities delivered by the DARWIN EU® CC include:

(A) Establishment and operation of the DARWIN EU® Coordination Centre

During the Establishment and Operational Phase, EMA, DARWIN EU® CC and data partners will share personal user account details to obtain access to specific tooling e.g., Cloud Services to upload study results. This toolset will grow during the establishment phase of the CC.

(B) Identification and approval of candidate data sources

In the DARWIN EU® data partner selection process, meta data needs to be provided about the data source(s), e.g., the total number of patients, the availability of data elements such as number of prescriptions. This will allow the CC and EMA to assess the additive value of the data source for the regulatory research questions executed in the DARWIN EU® data network. No identifiable patient or healthcare professional data is shared in this selection process. However, the DARWIN EU ® CC will compile and maintain a contact list of data partners and organisations that participate in this procedure.

(C) Onboarding of DARWIN EU® data partners

Further information is collected from data sources that are prioritised for the onboarding process. This includes a short description with characteristics of the data source including data elements, access procedures, and results of quality assurance processes. The DARWIN EU® data partner is also asked to execute the data quality dashboard tool against the Common Data Model (CDM) to generate the aggregated information. The execution process is identical to the study conduct as described below and does not involve sharing identifiable patient/healthcare professional information.

A DARWIN EU® Data Partner Agreement (see Related Documents) is setup with each selected DARWIN EU® data partner that contains clauses related to the responsibilities of the data partner and the DARWIN EU® CC for sharing of study results.

(D) Data Quality and Management

As part of the quality assurance process, the DARWIN EU® CC periodically assess the quality of the local Common Data Model (CDM) by requesting the DARWIN EU® data partners to execute the Data Quality Dashboard tool. This is typically done with each data refresh period. The DARWIN EU® data partner is asked to improve the CDM over time, if necessary. No access to the source data or identifiable patient/healthcare professional data by the DARWIN EU® CC is needed by design.

(E) Conduct of non-interventional Scientific Studies

The DARWIN EU® CC facilitate the conduct of studies, i.e., an investigation of a research question, with different complexity levels. The research question is defined by EMA, and a feasibility assessment is performed based on the available data in the meta data catalogue and the data source dashboard.

(F) Maintenance of EMA Catalogue of Real-World Data Sources and Data Dashboards

The DARWIN EU® data partners will be responsible for collating and uploading the necessary information in the public EMA data sources catalogue and keeping this up-to-date on a yearly basis. This catalogue will store personal account data but no identifiable patient/healthcare professional data. 

In addition, the DARWIN EU® CC will provide a secured data dashboard that contains information on the record count of the medical concepts in the data source. This information will be used in the study feasibility step by the DARWIN EU® CC. The univariate counts are created by executing the study code against the CDM. The results do not contain identifiable patient/healthcare professional data. No counts less than 100 will be shared with the DARWIN EU® CC. The DARWIN EU® CC will store contact details in this tool.

Note the following activities are not covered in this DPN:

  • The processing related to the visitors of the DARWIN EU® public website;
  • The processing related to the management of the CC/EMA staff’s personal data necessary for the execution of the service.

2.1 Personal data concerned

Personal data are processed for the purposes of the implementation, management and monitoring of the DARWIN EU® contractual deliverables.

In the processing activities described above we only process personal data directly collected from you when you share basic business contact data to:

  • obtain access to specific tooling, e.g., Cloud Services to upload study results.
  • setup a contract with the CC as a data partner.

No personal data are being processed by or shared with the DARWIN EU® CC and the EMA from patients or healthcare professionals that are included in the data sources that participate in the DARWIN EU® Data Network for the conduct of non-interventional scientific studies (E). No personal data is shared by the DARWIN EU® data partners with the DARWIN EU® CC since data will only be provided in aggregated and therefore anonymised format.

More information on the type of personal data being processed is provided in section 2.2.

2.2 Legal basis of the processing

The legal basis of the processing of personal data is summarised as follows:

Processing Activity

Personal Data Processed

Legal Basis

(A) Establishment and operation of the DARWIN EU® Coordination Centre

 

Personal details of members of the DARWIN EU® CC (name of the person, organisation, title, email address, phone number)

Details of the involved organisations (bank account details, address details, contact persons)

Article 5(1)(d) of the EUDPR/Article 6(1)(a) of the GDPR i.e., the data subject has given consent to the processing of his or her personal data for one or more specific purposes. 

(B) Identification and approval of candidate data sources

 

Contact details of data partners and organisations (name of contact persons, title, address, email address)

Article 5(1)(d) of the EUDPR/Article 6(1)(a) of the GDPR i.e., the data subject has given consent to the processing of his or her personal data for one or more specific purposes. 

(C) Onboarding of DARWIN EU® data partners

 

Contact details of data partners and organisations (name of contact persons, title, function, address, email address, bank account details)

 

Article 5(1)(d) of the EUDPR/Article 6(1)(a) of the GDPR i.e., the data subject has given consent to the processing of his or her personal data for one or more specific purposes. 

(D) Data Quality and Management

 

None

N/A

(E) Conduct of non-interventional Scientific Studies

 

Contact details of data partners and organisations (name of contact persons, title, address, email address)

 

 

Article 5(1)(a) of the EUDPR for the processing of personal data in the context of the DARWIN EU® CC activities i.e., processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Union institution or body. 

(F) Maintenance of EMA Catalogue of Real-World Data Sources and Data Dashboards

Contact Details of Data Partners

(name of contact persons, title, address, email address)

Article 5(1)(a) of the EUDPR for the processing of personal data in the context of the DARWIN EU® CC activities i.e., processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Union institution or body. 

 

 

3. How long do we keep your data?

The retention period for each category of personal data depends on the purpose(s) for which it is collected. 

Processing Activity

Retention Period of Personal Data

(A) Establishment and operation of the DARWIN EU® Coordination Centre

Personal data are maintained for a period of five years (starting from the payment of the balance of the DARWIN EU® framework contract)

(B) Identification and approval of candidate data sources

 

Personal data are maintained for a period of five years (starting from the payment of the balance of the DARWIN EU® framework contract).

 

(C) Onboarding of DARWIN EU® data partners

 

Personal data are maintained for a period of five years (starting from the payment of the balance of the DARWIN EU® framework contract).

 

(D) Data Quality and Management

 

N/A

(E) Conduct of non-interventional Scientific Studies

 

Personal data are maintained for a period of five years (starting from the payment of the balance of the DARWIN EU® framework contract).

For the processing of personal data in the European Network of Centres for Pharmacoepidemiology and Pharmacovigilance (ENCePP) Resource Database please refer to the applicable data protection notice

(F) Maintenance of EMA Catalogue of Real-World Data Sources and Data Dashboards

Personal data are maintained for a period of five years (starting from the payment of the balance of the DARWIN EU® framework contract).

For the processing of personal data in the European Network of Centres for Pharmacoepidemiology and Pharmacovigilance (ENCePP) Resource Database please refer to the applicable data protection notice

 

Upon the completion of the retention period, your personal account data will be completely and irreversibly erased, unless it is required by law to do otherwise.

The anonymous aggregated study results will be kept as long as necessary in compliance with the pharmaceutical legislation[4]. No additional anonymisation is necessary, but the study results as a whole will be archived in an encrypted format.

4. Who has access to your information and to whom is it disclosed?

Who has access to your personal data depends on the processing activity. In general, personal account information and contact details are accessible by the staff of the DARWIN EU® CC that needs this information for the execution of the service and selected staff from EMA.  

5. Your data protection rights

As data subject (i.e., the individual whose personal data is processed), you have a number of rights as applicable :

  • Right to be informed – This Data Protection Notice provides information on how the CC and EMA collect and uses your personal data. Requests for other information regarding the processing may also be directed to the Internal Controller.
  • Right to access – You have the right to access your personal data. You have the right to request and obtain a copy of the personal data that is processed.
  • Right to rectification – You have the right to obtain - without undue delay - the rectification or completion of your personal if it is incorrect or incomplete.
  • Right to withdraw consent – You have the right to withdraw your consent to the processing of your personal data. However, this will not affect the lawfulness of any processing carried out before consent is withdrawn.

Please note that if you withdraw your consent, the Agency may not be able to provide certain services to you. The CC will advise you if this is the case at the time you withdraw your consent.

  • Right to erasure – You have the right to require the CC to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing. In certain cases your data may be kept to the extent it is necessary, for example, to comply with a legal obligation of the CC and Agency or if it is necessary for reasons of public interest in the area of public health.
  • Right to restrict processing – In a few, codified cases, you have the right to obtain the restriction of the processing, meaning that your data will only be stored, but not actively processed for a limited period of time. For more information about this right and its limitations, see the EMA General Data Protection and Privacy Statement, hosted at ema.europa.eu/en/about-us/legal/privacy-statement
  • Right to portability[5] - Where the processing is carried out based on your consent and in automated means you have the right to receive your personal data (which was provided to the EMA directly by you) in a machine-readable format. You may also ask the EMA to directly transfer such data to another controller.
  • Right to object[6] – You have the right to object at any time to this processing on grounds related to your particular situation. If you do so, EMA may only continue processing your personal data if it demonstrates overriding legitimate grounds to do so or if this is necessary for the establishment, exercise or defence of legal claims.

The rights of the data subject can be exercised in accordance with the provisions of the EUDPR/GDPR. For anything that is not specifically provided for in this Data Protection Notice, please refer to the contents of the general EMA Data Protection and Privacy Statement: www.ema.europa.eu/en/about-us/legal/privacy-statement

6. Recourse

In case you have any questions regarding the processing of your personal data, or you think that the processing is unlawful or it is not in compliance with this Data Protection Notice or the general EMA Privacy Statement, please contact This email address is being protected from spambots. You need JavaScript enabled to view it. or, the

Internal Controller at This email address is being protected from spambots. You need JavaScript enabled to view it. or the EMA Data Protection Officer at This email address is being protected from spambots. You need JavaScript enabled to view it..

You also have the right to lodge a complaint with the European Data Protection Supervisor (EDPS) at any time at the following address:

 

[1] Data Analysis and Real World Interrogation Network (DARWIN EU) | European Medicines Agency (europa.eu)

[2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

[3] Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data

[4] EudraLex - Volume 1 (europa.eu)

[5] Where the processing is based on Article 5(1)(d) of the EUDPR/ Article 6(1)(a) of the GDPR

[6] Where the processing is based on Article 5(1)(a) of the EUDPR , 6(1)(e ) or 6(1)(f) of the GDPR

 

Related content

Contact point

This email address is being protected from spambots. You need JavaScript enabled to view it.

Related documents