ciTIzen-centric DAta pLatform (TIDAL): Sharing distributed personal data in a privacy-preserving manner for health research

Developing personal data sharing tools and standards in conformity with data protection regulations is essential to empower citizens to control and share their health data with authorized parties for any purpose they approve. This can be, among others, for primary use in healthcare, or secondary use for research to improve human health and well-being. Ensuring that citizens are able to make fine-grained decisions about how their personal health data can be used and shared will significantly encourage citizens to participate in more health-related research. In this paper, we propose a ciTIzen-centric DatA pLatform (TIDAL) to give individuals ownership of their own data, and connect them with researchers to donate the use of their personal data for research while being in control of the entire data life cycle, including data access, storage and analysis. We recognize that most existing technologies focus on one particular aspect such as personal data storage, or suffer from executing data analysis over a large number of participants, or face challenges of low data quality and insufficient data interoperability. To address these challenges, the TIDAL platform integrates a set of components for requesting subsets of RDF (Resource Description Framework) data stored in personal data vaults based on SOcial LInked Data (Solid) technology and analyzing them in a privacy-preserving manner. We demonstrate the feasibility and efficiency of the TIDAL platform by conducting a set of simulation experiments using three different pod providers (Inrupt, Solidcommunity, Self-hosted Server). On each pod provider, we evaluated the performance of TIDAL by querying and analyzing personal health data with varying scales of participants and configurations. The reasonable total time consumption and a linear correlation between the number of pods and variables on all pod providers show the feasibility and potential to implement and use the TIDAL platform in practice. TIDAL facilitates individuals to access their personal data in a fine-grained manner and to make their own decision on their data. Researchers are able to reach out to individuals and send them digital consent directly for using personal data for health-related research. TIDAL can play an important role to connect citizens, researchers, and data organizations to increase the trust placed by citizens in the processing of personal data.

[1]  V. Rodríguez-Doncel,et al.  Analysis of ontologies and policy languages to represent information flows in GDPR , 2022, Semantic Web.

[2]  Tek Raj Chhetri,et al.  Consent through the lens of semantics: State of the art survey and best practices , 2021, Semantic Web.

[3]  John Domingue,et al.  Decentralised Verification Technologies and the Web , 2021, Media, Technology and Education in a Post-Truth Society.

[4]  Cas J. F. Cremers,et al.  The Provable Security of Ed25519: Theory and Practice , 2021, 2021 IEEE Symposium on Security and Privacy (SP).

[5]  Jatinder Singh,et al.  Decentralized data processing: personal data stores and the GDPR , 2021 .

[6]  Tim Hulsen Sharing Is Caring—Data Sharing Initiatives in Healthcare , 2020, International journal of environmental research and public health.

[7]  John Domingue,et al.  COVID-19 Antibody Test/Vaccination Certification: There's an App for That , 2020, IEEE Open Journal of Engineering in Medicine and Biology.

[8]  Jiazhou Wang,et al.  Distributed learning on 20 000+ lung cancer patients - The Personal Health Train. , 2020, Radiotherapy and oncology : journal of the European Society for Therapeutic Radiology and Oncology.

[9]  Luiz Olavo Bonino da Silva Santos,et al.  Distributed Analytics on Sensitive Medical Data: The Personal Health Train , 2020, Data Intelligence.

[10]  Ruben Verborgh,et al.  LDflex: A Read/Write Linked Data Abstraction for Front-End Web Developers , 2020, SEMWEB.

[11]  H. Aerts,et al.  Distributed radiomics as a signature validation study using the Personal Health Train infrastructure , 2019, Scientific Data.

[12]  David Manset,et al.  Enabling trust in healthcare data exchange with a federated blockchain-based architecture , 2019, WI.

[13]  Michel Dumontier,et al.  A Privacy-Preserving Infrastructure for Analyzing Personal Health Data in a Vertically Partitioned Scenario , 2019, MedInfo.

[14]  George Danezis,et al.  Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed Ledgers , 2018, NDSS.

[15]  Axel Polleres,et al.  Creating A Vocabulary for Data Privacy , 2019 .

[16]  Sherif Sakr,et al.  Processing of RDF Stream Data , 2018 .

[17]  Michel Dumontier,et al.  Using the Personal Health Train for Automated and Privacy-Preserving Analytics on Vertically Partitioned Data , 2018, MIE.

[18]  Theo Bass,et al.  Me, my data and I: the future of the personal data economy , 2017 .

[19]  Simon Josefsson,et al.  Edwards-Curve Digital Signature Algorithm (EdDSA) , 2017, RFC.

[20]  P. Lambin,et al.  Distributed learning: Developing a predictive model based on data from multiple hospitals without data leaving the hospital - A real life proof of concept. , 2016, Radiotherapy and oncology : journal of the European Society for Therapeutic Radiology and Oncology.

[21]  Tim Berners-Lee,et al.  A Demonstration of the Solid Platform for Social Web Applications , 2016, WWW.

[22]  Jie Chen,et al.  Personalized Strategies to Activate and Empower Patients in Health Care and Reduce Health Disparities , 2016, Health education & behavior : the official publication of the Society for Public Health Education.

[23]  Nicola Greco,et al.  Solid : A Platform for Decentralized Social Applications Based on Linked Data , 2016 .

[24]  Tanja Lange,et al.  EdDSA for more curves , 2015, IACR Cryptol. ePrint Arch..

[25]  Erez Shmueli,et al.  openPDS: Protecting the Privacy of Metadata through SafeAnswers , 2014, PloS one.

[26]  Tanja Lange,et al.  High-speed high-security signatures , 2011, Journal of Cryptographic Engineering.

[27]  Christopher G. Chute,et al.  BioPortal: ontologies and integrated data resources at the click of a mouse , 2009, Nucleic Acids Res..

[28]  Fausto Giunchiglia,et al.  Ontology Driven Community Access Control , 2008, SPOT@ESWC.

[29]  Kevin Donnelly,et al.  SNOMED-CT: The advanced terminology and coding system for eHealth. , 2006, Studies in health technology and informatics.

[30]  Burton H. Bloom,et al.  Space/time trade-offs in hash coding with allowable errors , 1970, CACM.

[31]  J. Olsen,et al.  The European Commission , 2020, The European Union.