At Erasmus MC we work together to improve healthcare and to promote people’s health. We do this by providing healthcare, conducting scientific research and providing education. If you are a patient, research participant, student, employee or a relation of Erasmus MC, we process your personal data.
We want to be clear about why and how we use your data. In this privacy statement you can read how we process your data, what your rights are and who to contact if you have questions about your privacy. This statement applies to all processing of personal data by Erasmus MC.
Explanation
Since 25 May 2018, the same privacy legislation has applied to the whole of the European Union (including the Netherlands). The most important privacy law is the General Data Protection Regulation (GDPR). Among other things, it specifies that we inform you in a Privacy Statement about how we process your personal data. In this Privacy Statement, terms such as 'personal data', 'processing' and 'data subject(s)' are often used. Here we explain in short what these terms mean.
Personal data is data that relates directly to a person or that can be traced back indirectly to a person. Data that can be traced directly back to a person can be a name, address, date of birth for example, or a patient number. An X-ray without a name may still be traced back to a person because of specific characteristics and can therefore also be personal data. Data about organizations is not personal data according to the GDPR.
The processing of data means all the actions we do with this data. This can be the storage of data, but also the transfer and destruction of data.
Data Subjects are the people whose personal data we use, such as patients, research participants, students, employees and others.
Information Security
We do everything we can to keep your data safe. We use physical, technical and organizational measures to protect your data. We have rules, procedures and training courses to keep your data confidential and secure. We regularly check whether these measures are still working properly. Security comes first when processing personal data.
Despite all measures we take, incidents may occur as a result of which the secure processing of personal data is temporarily not guaranteed. Such an incident can cause a data breach. In a data breach, personal data has become accessible, lost or unintentionally released without this being the intention.
In certain cases Erasmus MC is obliged to report the data breach to the Dutch Data Protection Authority, the Dutch supervisory authority. Erasmus MC reports a data breach to the Dutch Data Protection Authority if the data breach poses a risk to the data protection of the person whose data has been leaked. An example is when we sent a letter with patient information to the wrong person. However, it is not mandatory to report a data breach to the Dutch Data Protection Authority if patient data is accidentally sent to the wrong doctor. After all, a doctor has a duty of professional secrecy and knows how to handle confidential information.
Which personal data do we process and from whom?
Erasmus MC processes personal data from several categories of data subjects. We process no more data than we need to provide you with good care, to improve our care, for our administration but also to provide education. The personal data of the following categories of persons are processed. These are just examples and the list may be expanded with more categories in the future.
- Patients
- Participants in scientific research
- Applicants
- Students
- Employees
- Website visitors
For each category you can read on our websites which data we process and for which purposes we process them.