<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1886-5887</journal-id>
<journal-title><![CDATA[Revista de Bioética y Derecho]]></journal-title>
<abbrev-journal-title><![CDATA[Rev. Bioética y Derecho]]></abbrev-journal-title>
<issn>1886-5887</issn>
<publisher>
<publisher-name><![CDATA[Observatori de Bioètica i Dret - Cátedra UNESCO de Bioética]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1886-58872022000100013</article-id>
<article-id pub-id-type="doi">10.1344/rbd2021.54.36005</article-id>
<title-group>
<article-title xml:lang="pt"><![CDATA[A Lei Geral de Proteção de Dados e suas implicações na saúde: as avaliações de impacto no tratamento de dados no âmbito clínico-hospitalar]]></article-title>
<article-title xml:lang="ca"><![CDATA[La Llei General de Protecció de Dades i les seves implicacions per a la salut: avaluacions d'impacte sobre el tractament de dades en el context clínic i hospitalari]]></article-title>
<article-title xml:lang="en"><![CDATA[The General Data Protection Law and its implications on health: impact assessments on data processing in the clinical-hospital scope]]></article-title>
<article-title xml:lang="es"><![CDATA[La Ley General de Protección de Datos y sus implicaciones para la salud: evaluaciones de impacto sobre el tratamiento de datos en el contexto clínico y hospitalario]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Vetis-Zaganelli]]></surname>
<given-names><![CDATA[Margareth]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
<xref ref-type="aff" rid="Aaf"/>
<xref ref-type="aff" rid="Ab"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Binda Filho]]></surname>
<given-names><![CDATA[Douglas Luis]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
<xref ref-type="aff" rid="Aaf"/>
<xref ref-type="aff" rid="Ab"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universidade Federal do Espírito Santo  ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Brazsil</country>
</aff>
<aff id="A1b">
<institution><![CDATA[,Erasmus+ European Commission Università Degli Studi Di Milano-Bicocca-UNIMIB ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Itália</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Universidade Federal do Espírito Santo  ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Brasil</country>
</aff>
<aff id="A2b">
<institution><![CDATA[,Università degli Studi di Milano-Bicocca  ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Itália</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>00</month>
<year>2022</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>00</month>
<year>2022</year>
</pub-date>
<numero>54</numero>
<fpage>215</fpage>
<lpage>232</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.isciii.es/scielo.php?script=sci_arttext&amp;pid=S1886-58872022000100013&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.isciii.es/scielo.php?script=sci_abstract&amp;pid=S1886-58872022000100013&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.isciii.es/scielo.php?script=sci_pdf&amp;pid=S1886-58872022000100013&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="pt"><p><![CDATA[Resumo A Lei Geral de Proteção de Dados dispõe sobre a proteção de dados pessoais e tem implicações significativas em inúmeras áreas, dentre as quais a saúde. Em âmbito sanitário, em virtude da quantidade relevante de dados sensíveis contendo informações sobre saúde, exige-se cautela dos agentes de tratamento, uma vez que seu processamento é mais suscetível de ocasionar alto risco para os direitos dos titulares. Nessa hipótese, o Regulamento Geral sobre a Proteção de Dados, a legislação europeia sobre proteção de dados pessoais, em seu art. 35, determina como obrigatória a realização das Avaliações de Impacto, o que não se demonstra evidente na legislação brasileira. Por meio de pesquisa exploratória, com base em levantamento bibliográfico e documental, investiga-se a importância dessas avaliações pelas instituições de saúde no tratamento de dados sensíveis, a fim de atestar não apenas o cumprimento com a legislação, mas igualmente com as estipulações presentes em códigos deontológicos que valorizam o sigilo, a privacidade e a confidencialidade na relação médico-paciente. Para tanto, são abordados, em um primeiro momento, os aspectos gerais da LGPD e uma perspectiva comparada em relação à GDPR. Em seguida, é exposta a associação entre o tratamento de dados sensíveis e a confidencialidade na assistência em saúde. Por fim, o trabalho conclui acerca da importância da realização da Avaliação de Impacto em dados sensíveis, ocasião em que se considera a experiência europeia de metodologia baseada nos riscos.]]></p></abstract>
<abstract abstract-type="short" xml:lang="ca"><p><![CDATA[Resum La Llei General de Protecció de Dades preveu la protecció de les dades personals i té implicacions significatives en nombrosos àmbits, inclòs el sanitari. En aquest, a causa de la quantitat rellevant de dades sensibles que contenen informació sobre salut, es requereix precaució per part dels agents de tractament, ja que és més probable que el seu processament causi un alt risc per als drets dels titulars. En aquest sentit, l'art. 35 del Reglament General de Protecció de Dades, la legislació europea en matèria de protecció de dades personals, determina que la realització d'Avaluacions d'Impacte és obligatòria, la qual cosa no és evident en la legislació brasilera. A través d'un estudi exploratori, basat en una enquesta bibliogràfica i documental, s'investiga la importància d'aquestes Avaluacions per part de les institucions de salut en el tractament de dades sensibles, a fi de certificar no només el compliment de la legislació, sinó també de les estipulacions presents en els codis deontològics que valoren el secret, la privacitat i la confidencialitat en la relació metge-pacient. Al principi, es discuteixen aspectes generals de la llei brasilera i una perspectiva comparada respecte a l'europea. En segon lloc, exposa l'associació entre el tractament de dades sensibles i la confidencialitat en l'assistència sanitària. Conclou que és important realitzar l'Avaluació d'Impacte sobre dades sensibles, ocasió en la qual es considera l'experiència europea d'una metodologia basada en riscos.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract The General Data Protection Law provides for the protection of personal data and has significant implications in numerous areas, including in healthcare. In the health field, due to the relevant amount of sensitive data containing information on health, it is required caution from the treatment agents, since its processing is more likely to cause a high risk to the rights of the data subjects. In this regard, the art. 35 of the General Data Protection Regulation, the European legislation on the protection of personal data, determines that the carrying out of Impact Assessments is mandatory, which is not evident in the Brazilian legislation. Through exploratory research, based on a bibliographic and documentary survey, the importance of these assessments by health institutions in the treatment of sensitive data is investigated, so as to attest not only compliance with legislation, but also with stipulations present in deontological codes that value secrecy, privacy and confidentiality in doctor-patient relationship. At first, general aspects of the Brazilian law and a comparative perspective regarding the European one are discussed. Secondly, it exposes the association between treatment of sensitive data and confidentiality in healthcare. It concludes that it is important to carry out the Impact Assessment on sensitive data, an occasion in which the European experience of risk-based methodology is considered.]]></p></abstract>
<abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen La Ley General de Protección de Datos prevé la protección de los datos personales y tiene implicaciones significativas en numerosos ámbitos, incluido el sanitario. En éste, debido a la cantidad relevante de datos sensibles que contienen información sobre salud, se requiere precaución por parte de los agentes de tratamiento, ya que es más probable que su procesamiento cause un alto riesgo para los derechos de los titulares. En este sentido, el art. 35 del Reglamento General de Protección de Datos, la legislación europea en materia de protección de datos personales, determina que la realización de Evaluaciones de Impacto es obligatoria, lo que no es evidente en la legislación brasileña. A través de un estudio exploratorio, basado en una encuesta bibliográfica y documental, se investiga la importancia de estas Evaluaciones por parte de las instituciones de salud en el tratamiento de datos sensibles, a fin de certificar no sólo el cumplimiento de la legislación, sino también de las estipulaciones presentes en los códigos deontológicos que valoran el secreto, la privacidad y la confidencialidad en la relación médico-paciente. Al principio, se discuten aspectos generales de la ley brasileña y una perspectiva comparada con respecto a la europea. En segundo lugar, expone la asociación entre el tratamiento de datos sensibles y la confidencialidad en la asistencia sanitaria. Concluye que es importante realizar la Evaluación de Impacto sobre datos sensibles, ocasión en la que se considera la experiencia europea de una metodología basada en riesgos.]]></p></abstract>
<kwd-group>
<kwd lng="pt"><![CDATA[dados sensíveis]]></kwd>
<kwd lng="pt"><![CDATA[governança de dados]]></kwd>
<kwd lng="pt"><![CDATA[Lei Geral de Proteção de Dados]]></kwd>
<kwd lng="pt"><![CDATA[Regulamento Geral sobre a Proteção de Dados]]></kwd>
<kwd lng="pt"><![CDATA[Relatório de Impacto]]></kwd>
<kwd lng="ca"><![CDATA[dades sensibles]]></kwd>
<kwd lng="ca"><![CDATA[governança de dades]]></kwd>
<kwd lng="ca"><![CDATA[Llei General de Protecció de Dades]]></kwd>
<kwd lng="ca"><![CDATA[Reglament General de Protecció de Dades]]></kwd>
<kwd lng="ca"><![CDATA[Avaluació d'Impacte]]></kwd>
<kwd lng="en"><![CDATA[Sensitive data]]></kwd>
<kwd lng="en"><![CDATA[data governance]]></kwd>
<kwd lng="en"><![CDATA[General Data Protection Law]]></kwd>
<kwd lng="en"><![CDATA[General Data Protection Regulation]]></kwd>
<kwd lng="en"><![CDATA[Impact Assessment]]></kwd>
<kwd lng="es"><![CDATA[datos sensibles]]></kwd>
<kwd lng="es"><![CDATA[gobernanza de datos]]></kwd>
<kwd lng="es"><![CDATA[Ley General de Protección de Datos]]></kwd>
<kwd lng="es"><![CDATA[Reglamento General de Protección de Datos]]></kwd>
<kwd lng="es"><![CDATA[Evaluación de Impacto]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<label>1</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Abouelmehdi]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[Beni-Hessane]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Khaloufi]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Big healthcare data: preserving security and privacy]]></article-title>
<source><![CDATA[Journal of Big Data, El Jadida]]></source>
<year>2018</year>
<volume>5</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>1-18</page-range></nlm-citation>
</ref>
<ref id="B2">
<label>2</label><nlm-citation citation-type="">
<collab>Anahp</collab>
<source><![CDATA[Lei Geral de Proteção de Dados: Recomendações Anahp para os hospitais]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B3">
<label>3</label><nlm-citation citation-type="journal">
<article-title xml:lang=""><![CDATA[Manual Melhores Práticas LGPD]]></article-title>
<source><![CDATA[Anahp]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B4">
<label>4</label><nlm-citation citation-type="journal">
<article-title xml:lang=""><![CDATA[Article 29 Data Protection Working Party]]></article-title>
<source><![CDATA[Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679, WP248]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B5">
<label>5</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ashford]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Facebook is ready for GDPR, says Zuckerberg]]></article-title>
<source><![CDATA[Computer Weekly]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B6">
<label>6</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Baracat]]></surname>
<given-names><![CDATA[MK]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A gestão de riscos e a LGPD]]></article-title>
<source><![CDATA[Estadão]]></source>
<year>2019</year>
</nlm-citation>
</ref>
<ref id="B7">
<label>7</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bauman]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
</person-group>
<source><![CDATA[Vigilância Líquida. Diálogos com David Lyon]]></source>
<year>2013</year>
<publisher-loc><![CDATA[Rio de Janeiro ]]></publisher-loc>
<publisher-name><![CDATA[Zahar]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B8">
<label>8</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bertoni]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[O novo vazamento de dados na Saúde. E suas consequências]]></article-title>
<source><![CDATA[Nexo]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B9">
<label>9</label><nlm-citation citation-type="">
<collab>Brasil</collab>
<source><![CDATA[ABNT NBR ISO 31000. Gestão de riscos - princípios e diretrizes]]></source>
<year>2009</year>
</nlm-citation>
</ref>
<ref id="B10">
<label>10</label><nlm-citation citation-type="journal">
<collab>Brasil</collab>
<article-title xml:lang=""><![CDATA[Lei Federal nº 13.709, de 14 de agosto de 2018. Lei Geral de Proteção de Dados Pessoais (LGPD)]]></article-title>
<source><![CDATA[Diário Oficial da União, Poder Executivo, Brasília, DF]]></source>
<year>2018</year>
<page-range>3</page-range></nlm-citation>
</ref>
<ref id="B11">
<label>11</label><nlm-citation citation-type="">
<collab>Brasil</collab>
<source><![CDATA[Lei Geral de Proteção de Dados (LGPD): Guia de Boas Práticas Para Implementação na Administração Pública Federal]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B12">
<label>12</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dash]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Big data in healthcare: management, analysis and future prospects]]></article-title>
<source><![CDATA[Journal of Big Data]]></source>
<year>2019</year>
<volume>6</volume>
<page-range>54</page-range><publisher-loc><![CDATA[Guimarães ]]></publisher-loc>
</nlm-citation>
</ref>
<ref id="B13">
<label>13</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Fontes]]></surname>
<given-names><![CDATA[E]]></given-names>
</name>
</person-group>
<source><![CDATA[Políticas e normas para segurança da informação]]></source>
<year>2012</year>
<publisher-loc><![CDATA[Rio de Janeiro ]]></publisher-loc>
<publisher-name><![CDATA[Brasport]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B14">
<label>14</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gomes]]></surname>
<given-names><![CDATA[MCO]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Para além de uma "obrigação legal": o que a metodologia de benefícios e riscos nos ensina sobre o relatório de impacto à proteção de dados]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[Lima]]></surname>
<given-names><![CDATA[AP]]></given-names>
</name>
<name>
<surname><![CDATA[Hissa]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Saldanha]]></surname>
<given-names><![CDATA[PM]]></given-names>
</name>
</person-group>
<source><![CDATA[Direito Digital: Debates Contemporâneos]]></source>
<year>2019</year>
<page-range>141-53</page-range><publisher-loc><![CDATA[São Paulo ]]></publisher-loc>
<publisher-name><![CDATA[Revista dos Tribunais]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<label>15</label><nlm-citation citation-type="">
<collab>Hipaa</collab>
<source><![CDATA[Healthcare Data Breach Statistics]]></source>
<year>2021</year>
</nlm-citation>
</ref>
<ref id="B16">
<label>16</label><nlm-citation citation-type="book">
<collab>Institute of Medicine</collab>
<article-title xml:lang=""><![CDATA[Confidentiality and Privacy of Personal Data]]></article-title>
<person-group person-group-type="author">
<name>
<surname><![CDATA[Donaldson]]></surname>
<given-names><![CDATA[MS]]></given-names>
</name>
<name>
<surname><![CDATA[Lohr]]></surname>
<given-names><![CDATA[KN]]></given-names>
</name>
</person-group>
<source><![CDATA[Health Data in the Information Age: Use, Disclosure, and Privacy]]></source>
<year>1994</year>
<page-range>136-224</page-range><publisher-loc><![CDATA[Washington, DC ]]></publisher-loc>
<publisher-name><![CDATA[The National Academies Press]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B17">
<label>17</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Lourau]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Lapassade]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
</person-group>
<source><![CDATA[Chaves da sociologia]]></source>
<year>1972</year>
<publisher-loc><![CDATA[Rio de Janeiro ]]></publisher-loc>
<publisher-name><![CDATA[Civilização Brasileira]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B18">
<label>18</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mendelson]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Rees]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Medical confidentiality and patient privacy]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[White]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
<name>
<surname><![CDATA[Mcdonald]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
<name>
<surname><![CDATA[Willmott]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[Health Law in Australia]]></source>
<year>2014</year>
<page-range>396-433</page-range><publisher-loc><![CDATA[Pyrmont ]]></publisher-loc>
<publisher-name><![CDATA[Thomson Reuters]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B19">
<label>19</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mendes]]></surname>
<given-names><![CDATA[PAB]]></given-names>
</name>
</person-group>
<source><![CDATA[Análise de Risco no GDPR]]></source>
<year>2018</year>
<publisher-loc><![CDATA[Lisboa ]]></publisher-loc>
<publisher-name><![CDATA[Faculdade de Ciências, Universidade de Lisboa]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B20">
<label>20</label><nlm-citation citation-type="">
<collab>Secretaria de Governo Digital</collab>
<source><![CDATA[Oficina Dirigida: Relatório de Impacto à Proteção de Dados Pessoais - RIPD]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B21">
<label>21</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Siqueira]]></surname>
<given-names><![CDATA[LS]]></given-names>
</name>
<name>
<surname><![CDATA[Hoch]]></surname>
<given-names><![CDATA[PA]]></given-names>
</name>
</person-group>
<source><![CDATA[Os dados pessoais e a proteção de dados de saúde: análise a partir das iniciativas de e-Saúde]]></source>
<year>2019</year>
<conf-name><![CDATA[ Congresso Internacional de Direito e Contemporaneidade, 5º]]></conf-name>
<conf-date>2 e 3 set. 2019</conf-date>
<conf-loc>Santa Maria </conf-loc>
</nlm-citation>
</ref>
<ref id="B22">
<label>22</label><nlm-citation citation-type="">
<collab>União Europeia</collab>
<source><![CDATA[Regulation (EU) 2016/679 (General Data Protection Regulation)]]></source>
<year>2016</year>
</nlm-citation>
</ref>
<ref id="B23">
<label>23</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Vainzof]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[O que é o relatório de impacto à proteção de dados pessoais (RIPD)]]></article-title>
<source><![CDATA[Opice Blum Academy]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B24">
<label>24</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ventura]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Exclusivo: vazamento que expôs 220 milhões de brasileiros é pior do que se pensaba]]></article-title>
<source><![CDATA[Tecnoblog]]></source>
<year>2021</year>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
