Skip to main content
QUICK REVIEW

[Paper Review] Prerequisites for International Exchanges of Health Information: Comparison of Australian, Austrian, Finnish, Swiss, and US Privacy Policies

Hanna Suominen, Henning Müller|arXiv (Cornell University)|Dec 15, 2016
Ethics in Clinical Research27 references3 citations
TL;DR

This paper compares privacy policies for health data exchange across Australia, Austria, Finland, Switzerland, and the US, focusing on research use of text data. It identifies that strict pre-consent disclosure, de-identification, and data destruction requirements hinder international data sharing, despite shared principles of accountability and adequacy. The key contribution is a cross-jurisdictional analysis revealing legal and technical barriers to global health data collaboration.

ABSTRACT

Capabilities to exchange health information are critical to accelerate discovery and its diffusion to healthcare practice. However, the same ethical and legal policies that protect privacy hinder these data exchanges, and the issues accumulate if moving data across geographical or organizational borders. This can be seen as one of the reasons why many health technologies and research findings are limited to very narrow domains. In this paper, we compare how using and disclosing personal data for research purposes is addressed in Australian, Austrian, Finnish, Swiss, and US policies with a focus on text data analytics. Our goal is to identify approaches and issues that enable or hinder international health information exchanges. As expected, the policies within each country are not as diverse as across countries. Most policies apply the principles of accountability and/or adequacy and are thereby fundamentally similar. Their following requirements create complications with re-using and re-disclosing data and even secondary data: 1) informing data subjects about the purposes of data collection and use, before the dataset is collected; 2) assurance that the subjects are no longer identifiable; and 3) destruction of data when the research activities are finished. Using storage and compute cloud services as well as other exchange technologies on the Internet without proper permissions is technically not allowed if the data are stored in another country. Both legislation and technologies are available as vehicles for overcoming these barriers. The resulting richness in information variety will contribute to the development and evaluation of new clinical hypotheses and technologies.

Motivation & Objective

  • To analyze how privacy policies in Australia, Austria, Finland, Switzerland, and the US regulate the use and disclosure of personal health data for research.
  • To identify legal and regulatory barriers that impede international exchange of health information, especially across borders.
  • To assess the impact of data protection principles—such as accountability, consent, de-identification, and data destruction—on reusability of health data.
  • To evaluate how existing legislation and emerging technologies can overcome cross-border data sharing challenges.
  • To provide a foundation for harmonizing international health data exchange by identifying commonalities and divergences in policy frameworks.

Proposed method

  • Conducted a comparative legal analysis of national privacy policies from Australia, Austria, Finland, Switzerland, and the US.
  • Focused on policies governing secondary use of health data, particularly for text data analytics in research.
  • Evaluated key regulatory requirements: pre-consent information, de-identification, and data destruction upon project completion.
  • Assessed the implications of storing or processing data in foreign jurisdictions via cloud services.
  • Mapped policy elements to international data protection principles, including accountability and adequacy.
  • Identified technical and legal enablers—such as secure cloud computing and cross-border data transfer mechanisms—that could support compliant data exchange.

Experimental results

Research questions

  • RQ1How do the privacy policies of Australia, Austria, Finland, Switzerland, and the US regulate the use of personal health data for research purposes?
  • RQ2What specific legal requirements—such as consent, de-identification, or data destruction—create barriers to international data sharing?
  • RQ3To what extent do differences in national data protection laws impede cross-border health information exchange?
  • RQ4How do cloud computing and international data transfer mechanisms interact with national privacy regulations in health research?
  • RQ5What policy and technological enablers can help overcome jurisdictional barriers to global health data collaboration?

Key findings

  • All five countries apply core principles of accountability and adequacy, resulting in fundamental similarities across their privacy frameworks.
  • Pre-consent disclosure of data use purposes before data collection is a common requirement that complicates secondary data use.
  • Mandatory data de-identification and post-research data destruction significantly limit data reusability and long-term research collaboration.
  • Storing or processing health data in foreign countries via cloud services is technically prohibited without proper legal permissions under national laws.
  • Despite regulatory differences, the shared principles of data protection create a baseline for potential international harmonization.
  • The integration of secure cloud technologies and compliant data transfer mechanisms offers a viable path to overcoming cross-border data sharing barriers.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.