ISAC Data Protection and Privacy 2 — Questions and Answers
Question 1: Under GDPR, which legal basis would a cytometry research lab most likely rely on when processing patient samples for publicly funded clinical research?
- Legitimate interests
- Public task or scientific research (Correct answer)
- Contractual necessity
- Vital interests
Correct answer: Public task or scientific research
GDPR Article 9(2)(j) permits processing of special-category health data for scientific research in the public interest, subject to appropriate safeguards.
Question 2: A flow cytometry core facility shares de-identified cell population data with an international consortium. Which privacy risk remains even after de-identification?
- Chain-of-custody violations
- Re-identification through combination with auxiliary datasets (Correct answer)
- Breach of intellectual property rights
- Loss of data integrity during transfer
Correct answer: Re-identification through combination with auxiliary datasets
De-identified data can sometimes be re-identified when combined with other publicly available datasets, a risk known as the mosaic effect.
Question 3: Which principle requires that cytometry data collected for a specific research study should not be repurposed for unrelated commercial applications without fresh consent?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
Purpose limitation restricts use of personal data to the specific, explicit, and legitimate purposes for which it was originally collected.
Question 4: When a cytometry laboratory experiences a data breach exposing participant health records, under GDPR what is the maximum timeframe to notify the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 5: A researcher wants to retain raw cytometry FCS files linked to participant IDs indefinitely for future analysis. Which data protection principle does this violate?
- Accuracy
- Lawfulness
- Storage limitation (Correct answer)
- Data portability
Correct answer: Storage limitation
Storage limitation requires that personal data not be kept in identifiable form for longer than necessary for its purpose.
Question 6: In the US context, which federal regulation primarily governs the privacy of individually identifiable health information generated during cytometry-based clinical diagnostics?
- FERPA
- HIPAA Privacy Rule (Correct answer)
- COPPA
- FISMA
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards for protecting individually identifiable health information held by covered entities and their business associates.
Question 7: A cytometry core facility acting as a HIPAA business associate must sign which type of agreement with the covered entity before accessing protected health information?
- Data use agreement
- Business associate agreement (Correct answer)
- Material transfer agreement
- Non-disclosure agreement
Correct answer: Business associate agreement
HIPAA requires a Business Associate Agreement (BAA) between covered entities and business associates who handle protected health information on their behalf.
Under GDPR, which legal basis would a cytometry research lab most likely rely on when processing patient samples for publicly funded clinical research?