Written answer
Laboratory Facilities
The Minister said GDPR requires informed, explicit consent to sell or otherwise use identifiable genetic data, with additional safeguards applying after death.
4052. Deputy Natasha Newsome Drennan asked the Minister for Health if she will confirm whether a laboratory will sell the genetic data at any point; if the genetic data is used for any purpose other than producing the test report, including but not limited to research, validation, quality improvement, training, or database comparison purposes (details supplied). [58919/26]
Comment on this
All EU-based laboratories providing genetic testing services must operate under the General Data Protection Regulation (GDPR) which provides the legal framework that protects individuals’ personal data. Genetic data is considered a special category of personal data which requires higher levels of data protection, including the requirement for informed, specific, and explicit consent. Under the GDPR, any genetic data that could be traced back to an individual cannot be sold without that individual (or their parent/legal guardian) first having been informed of this intention and having given their explicit consent for that to happen. That requirement is the same even for companies outside the EU if they provide services to EU-based individuals or organisations.
The GDPR also applies to the use of genetic data for other purposes such as research, validation, quality improvement, training, or database comparison purposes: Again, the individual or their parent/legal guardian would have to have given their explicit informed consent for the data to be used in this manner. Information on how the genetic test data would be used would have been supplied to the individual or their parent/legal guardian during the consent process at the hospital or health facility where the samples for testing were taken.
I note the very unfortunate nature of the details supplied and would take this opportunity to extend my sincere condolences to the family concerned. In the case of a deceased person, the GDPR itself does not apply however other frameworks would be relevant to ensure appropriate data protection measures including national law, medical confidentiality duties, research ethics requirements, and the consent originally given by the deceased or their parent/legal guardian. The contractual conditions established between the HSE and external testing laboratories should in any event preclude any processing beyond that which was consented by the individual or their parent/legal guardian.