<p>Advancements in ICT have enabled “xR” technologies to enhance user engagement beyond entertainment, notably in the healthcare sector. These technologies can collect massive amounts of health data, which are both highly valuable in the modern data-driven economy and highly sensitive, as their processing raises important concerns for the protection of individuals’ and groups’ fundamental rights and freedoms. Based on this, the objective of this paper is twofold. First, the authors discuss the potential of xR technologies for collecting health data and raise caveats on the associated risks for fundamental rights. Second, by taking xR games as a use-case, it analyses how the GDPR’s principle of purpose limitation is affected by the EHDSR’s framework for secondary use of electronic health data. The paper shows that xR game providers may be classified as “health data holders” in certain situations, which demands the sharing of specific categories of electronic health data for secondary use within the EHDSR, alongside GDPR compliance. As its main contribution, the paper argues that the EHDSR significantly stretches the presumption of compatibility provided by the GDPR to certain purposes such as scientific research, potentially undermining its foundational safeguards. In doing so, the EHDSR risks normalizing the commodification of health data and weakening the normative integrity of the GDPR, thereby eroding its role as the cornerstone of the EU Digital Rulebook in the face of expanding data markets.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Personal Health Data in xR Games: Exploring Purpose Limitation in the General Data Protection Regulation and European Health Data Space Regulation

  • Martin Sas,
  • Elora Fernandes,
  • Marta Musidlowska

摘要

Advancements in ICT have enabled “xR” technologies to enhance user engagement beyond entertainment, notably in the healthcare sector. These technologies can collect massive amounts of health data, which are both highly valuable in the modern data-driven economy and highly sensitive, as their processing raises important concerns for the protection of individuals’ and groups’ fundamental rights and freedoms. Based on this, the objective of this paper is twofold. First, the authors discuss the potential of xR technologies for collecting health data and raise caveats on the associated risks for fundamental rights. Second, by taking xR games as a use-case, it analyses how the GDPR’s principle of purpose limitation is affected by the EHDSR’s framework for secondary use of electronic health data. The paper shows that xR game providers may be classified as “health data holders” in certain situations, which demands the sharing of specific categories of electronic health data for secondary use within the EHDSR, alongside GDPR compliance. As its main contribution, the paper argues that the EHDSR significantly stretches the presumption of compatibility provided by the GDPR to certain purposes such as scientific research, potentially undermining its foundational safeguards. In doing so, the EHDSR risks normalizing the commodification of health data and weakening the normative integrity of the GDPR, thereby eroding its role as the cornerstone of the EU Digital Rulebook in the face of expanding data markets.