Law-based and standards-oriented approach for privacy impact assessment in medical devices: a topic for lawyers, engineers and healthcare practitioners in MedTech

Yuri R. Ladeia,David M. Pereira
2024-09-18
Abstract:Background: The integration of the General Data Protection Regulation (GDPR) and the Medical Device Regulation (MDR) creates complexities in conducting Data Protection Impact Assessments (DPIAs) for medical devices. The adoption of non-binding standards like ISO and IEC can harmonize these processes by enhancing accountability and privacy by design. Methods: This study employs a multidisciplinary literature review, focusing on GDPR and MDR intersection in medical devices that process personal health data. It evaluates key standards, including ISO/IEC 29134 and IEC 62304, to propose a unified approach for DPIAs that aligns with legal and technical frameworks. Results: The analysis reveals the benefits of integrating ISO/IEC standards into DPIAs, which provide detailed guidance on implementing privacy by design, risk assessment, and mitigation strategies specific to medical devices. The proposed framework ensures that DPIAs are living documents, continuously updated to adapt to evolving data protection challenges. Conclusions: A unified approach combining European Union (EU) regulations and international standards offers a robust framework for conducting DPIAs in medical devices. This integration balances security, innovation, and privacy, enhancing compliance and fostering trust in medical technologies. The study advocates for leveraging both hard law and standards to systematically address privacy and safety in the design and operation of medical devices, thereby raising the maturity of the MedTech ecosystem.
Computers and Society
What problem does this paper attempt to address?
The problem that this paper attempts to solve is the complexity of conducting Data Protection Impact Assessments (DPIAs) in medical devices. With the implementation of the General Data Protection Regulation (GDPR) and the Medical Device Regulation (MDR), data - processing activities in medical devices need to comply with more stringent data - protection requirements. However, the combination of these regulations has made the implementation of DPIAs more complex. For this reason, the paper proposes a law - and - standard - based approach. By integrating EU regulations with international standards (such as ISO and IEC standards), it provides a unified framework to guide the implementation of DPIAs, in order to enhance the privacy and security of medical devices in design and operation. Specifically, the paper focuses on the following aspects: 1. **Integration of regulations**: Explore how to combine the requirements of GDPR and MDR to meet the data - processing needs of medical devices. 2. **Application of standards**: Analyze how standards such as ISO/IEC 29134, ISO/IEC 27701, and ISO/IEC 27002 can provide specific guidance for DPIAs, especially in terms of privacy - by - design, risk assessment, and mitigation strategies. 3. **Proposal of a methodology**: Propose a systematic DPIA method to ensure that DPIA documentation is a dynamic and continuously updated process to adapt to the ever - changing data - protection challenges. Through these measures, the paper aims to provide a comprehensive framework to help legal, technical, and medical practitioners ensure data security and personal data protection in medical devices, thereby increasing the maturity and credibility of the medical technology ecosystem.