11  Data protection risk assessment

Published

February 1, 2026

Modified

February 24, 2026

Note

This document was converted from Aarhus University’s official form that was a Word document into Markdown and mostly reflects the content from that document. Some content in the original form was not relevant for this website and so was removed.

11.1 Responsible parties

Data controller:

Region Midtjylland
Skottenborg 26
DK-8800 Viborg
CVR No. 2919 0925

Has the project been reported to RM’s internal register?

Person responsible for registering the project:

  • Name: Søren Gregersen
  • Department: Department of Clinical Medicine / Steno Diabetes Center Aarhus

If the person named above is not the project manager, please state the name of the project manager here: Daniel Borch Ibsen

11.3 Data processor, shared data responsibility and sharing personal data with external parties

Are you planning to use an external data processor? (Please tick relevant box)

Data processor:

LIVA Healthcare
Danneskiold Samsøes Allé 41
1434 København K
Denmark

  • Email: info@livahealth.com
  • Central business registration number: 38737368

Is the data processor within or outside the EU/EEA?

What processing will the data processor be performing? LIVA Healthcare provides an app which will allow staff and participants to communicate with each other in a secure electronic way. It will facilitate online sessions, push of information, completion of questionnaires, as well as peer support within randomisation groups. The app will hold basic personal information as well as a few pieces of health data (blood pressure, finger prick results, etc).

Data processor:

MyFood24
University of Leeds
Discovery Way
Leeds
LS2 3AA
United Kingdom

Is the data processor within or outside the EU/EEA?

What processing will the data processor be performing? MyFood24 will provide an interface which will allow participants to register in minute details everything they consume over a couple of set time periods. The company has a very large database of food products and can analyse pictures of food on a plate and suggest what the content is. They will hold basic identifying details on the participant and extensive data on what the participant consumed within the time frames where they are asked to register their intake.

Are you planning to enter into an agreement on shared data responsibility? (Please tick relevant box)

If yes, with whom?

Joint Data Controller:

Steno Diabetes Centre Copenhagen
v/ Region Hovedstaden
Borgmester Ib Juuls vej 83
2730 Herlev
Denmark
CVR: 2919 0623
(“SDCC”)

and

Steno Diabetes Center Odense
v/ Region Syddanmark
Indgang 112, Kløvervænget 10
5000 Odense C
CVR no. 2919 0909
(“SDCO”)

and

Copenhagen University Hospital Bispebjerg
v/ Region Hovedstaden
Department of Endocrinology
Bispebjerg Bakke 23
2400 København NV
CVR no. 2919 0623
(“BH”)

and

Novo Nordisk Foundation Center for Basic Metabolic Research
University of Copenhagen
Blegdamsvej 3B, Building 7 2200 København N
CVR no. 2997 9812
(“CBMR”)

and

Department of Nutrition, Exercise and Sports
Copenhagen University
Nørre Allé 51
2200 København N
CVR no. 2997 9812
(“NEXS”)

Are you planning to share (disclose) personal data with others within the EU/EEA? (Please tick relevant box)

Are you planning to share (disclose) personal data with others outside the EU/EEA? (Please tick relevant box)

Are you planning to share (disclose) biological material with others outside AU and without consent from the data subject pursuant to data protection laws? (Please tick relevant box)

Are you planning to publish personal data in a recognised scientific journal or similar without consent from the data subject pursuant to data protection laws? (Please tick relevant box)

11.4 5 Storage of personal data

How are you planning to store personal data? (Please tick relevant box)

Will there be structured pseudonymisation, deletion or full anonymisation of the data subject’s personal data?

REDCap:

No anonymisation or pseudonymisation will be undertaken with the data stored on REDCap as this is a working collection tool where staff will need access to the information concerning a named participant. We do though plan to delete data from REDCap once we are sure we have everything transferred to our safe storage area on GenomeDK.

On GenomeDK we plan to store person identifiable data in a separate file which will be store on its own with additional encryption. This data will only be decrypted when a researcher is in need of moving data to Statistics Denmark, and even then, the transfer will not be done by the individual researcher.

When? Deletion of data from REDCap will happen when data has been transferred, checked for data quality and signed off at the end of the feasibility study in the Spring of 2027.

If you cannot specify a date, describe the procedure for deletion: We will request that the project is delete by the administrators of REDCap.

LIVA Health:

Data will be stored with personal identifiers on the LIVA Healthcare ecosystem (AWS servers and individual apps) for the duration of the study. The data will be transferred on a regular basis, and at the end of the study a final full data set will be requested. Like above the data will be transferred to GenomeDK where it will be cleaned of personal identifiers before being stored alongside the data from REDCap. Once we have ensured that we have all the data we need we will give LIVA the go-ahead to delete all study data from their systems.

When? As above.

If you cannot specify a date, describe the procedure for deletion: We have a contract with LIVA which specifies that once we request that data is deleted it will be removed from their systems without delay.

MyFood24:

The data generated in the MyFood24 ecosystem will be handled in the same way as the data from LIVA. Minimal personal information will be stored by the provider, the only difference is that there are no health data involved, only nutritional intake.

When? As above.

If you cannot specify a date, describe the procedure for deletion: We have a contract with MyFood24 which specifies that once we request that data is deleted it will be removed from their systems without delay.

11.5 Assessment of the risks of violating the rights and freedoms of the data subject

11.5.1 Confidentiality

How likely is it that others will have unintentional access to personal data? This also applies to personal data processed by a data processor (please tick relevant box)

State reason: Data will be kept in two locations that both have access control. In addition, very few members of staff will have access to the full data set. We will ensure that before new staff members understands the rules and responsibilities with regards to data handling prior to them gaining access to the system.

What will be the consequences of unintentional access to personal data for the people whose data is being processed in the project? (Please tick relevant box)

State reason: The health data we expect to collect will mainly relate to a participants diabetes diagnosis and their weight/activity levels. This data is in our opinion not as sensitive as other categories of health data (eg. mental health journal entries, STDs), adherence to a weight-loss regime is unlikely to cause problems for the participant if someone got their hands on it.

What has been done to limit the likelihood and the consequences?

Staff will be assigned to groups within REDCap which will ensure that only a few key staff members will have access to the complete data set, most staff members will only be able to access data for the participants they work directly with.

11.5.2 Integrity

How likely is it that personal data will be inadvertently changed? This also applies to personal data processed by a data processor (please tick relevant box)

State reason: Both REDCap and Liva have been set up in a way that will make it difficult to inadvertently change personal data, as there will be very few reasons for staff to access the data in a way that will allow them to change it by accident. The REDCap instruments have been designed so that were it is necessary to review/check personal data it is mirrored in the relevant instrument in a read-only way. The same applies to the Liva app.

What will be the consequences of inadvertently changing personal data for the people whose data is being processed in the project? (Please tick relevant box)

State reason: In event of changes to the personal data in REDCap there is no immediate risk to the individual in terms of exposure of data to a third party as only staff will have access to the data, we also do not expect to alter treatment of participants based on the collected data, so no immediate risk of either excess or lack of treatment.

What has been done to limit the likelihood and the consequences?

There will be access control for staff, and no access to edit data for participants. Where staff has a need to check personal data it will be displayed in a read-only format.

11.5.3 Availability

How likely is it that personal data will not be accessible, e.g. due to an IT failure or the bankruptcy of a data processor? This also applies to personal data processed by a data processor (please tick relevant box)

State reason: All main systems will be run on AU or KU infrastructure and are therefore unlikely to go down due to bankruptcy. There is a slight possibility that we may lose data and functionality if Liva Healthcare for some reason stops working, but we are at present confident that they are solvent and reliable.

IT failure is of a greater concern when it comes to the REDCap systems. It would impede work greatly if the system went down during a visit day.

What will be the consequences of lack of access to personal data for the people whose data is being processed in the project? (Please tick relevant box)

State reason: There will be no problem with temporary glitches when it comes to data stored on GenomeDK as that is all data which has been stored for reporting.

The data stored in REDCap will be more problematic if a break in service occurs when participants are due to visit on study days.

What has been done to limit the likelihood and the consequences?

Two mitigation strategies have been written up and implemented at site (SDCC) and will be implemented across all sites once we start the main study. This will take care of the situation where REDCap is down when needed for either randomisation or visit days. The strategies are kept on our SharePoint site, alongside pdf copies of the latest instruments from REDCap.