EDBT 2026 Demo / reviewers in the wild / expert
Paul Quinn
dblp:154/6792
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2024
0000-0002-6243-765XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The European Health Data Space: An expanded right to data portability?abstractThe European Commission recently released its proposal for a Regulation giving rise to a European Health Data Space (EHDS), as the first domain-specific common European data space under the European Union's data strategy. The proposed EHDS aims to improve access to and control by individuals of their personal electronic health data in primary use and increase data availability for secondary use purposes. This article is primarily concerned with the ambition to enhance the right of natural persons to data portability and promote interoperability in the health sector. This article seeks to delineate to what extent they represent a new and expanded right alongside the right to data portability provided in the General Data Protection Regulation (GDPR). In comparing this new expanded right to the original right outlined in Article 20 of the GDPR, the authors argue that Article 3(8) of the EHDS proposal represents an important expansion with the potential to allow individuals more possibility to control and mobilise their electronic health data, especially those elements located within Electronic Health Records (EHRs). This will also be facilitated by the strengthened interoperability requirements foreseen by the EHDS proposal. However, this paper also identifies several limitations and inconsistencies in the new data portability right which could potentially hinder its functioning. This notably includes the proposal's failure to take into account the need for data portability for secondary use purposes, and the unclear relationship of Article 3(8) of the proposal with Article 9 of the GDPR. It is recommended that these points should be considered carefully in future versions of the EHDS proposal. Paul Quinn |
Comput. Law Secur. Rev. | 2 |
| 2024 | Will the GDPR Restrain Health Data Access Bodies Under the European Health Data Space (EHDS)?abstractThe plans for a European Health Data Space (EHDS) envisage an ambitious and radical platform that will inter alia make the sharing of secondary health data easier. It will encourage the systematic sharing of health data and provide a legal framework for it to be shared by Health Data Access Bodies (HDABs) based in each of the Member States. Whilst this promises to bring about major benefits for research and innovation, it also raises serious questions given the intrinsic sensitivity of health data. Fears concerning privacy harms on the individual level and detrimental effects on the societal level have been raised. This article discusses two of the main protective pillars designed to allay such concerns. The first is that the proposal clearly outlines several contexts for which a Health Data Access Permit (HDAP) should and should not be granted. The second is that a request for an HDAP must also be compliant with the GDPR (inter alia requiring a valid legal basis and respecting data processing principles such as ‘minimization’ and ‘storage limitation’). As this article discusses, in some instances the need to have a valid legal basis under the GDPR may make it difficult to obtain a data access permit, in particular for some of the commercially orientated grounds outlined within the EHDS proposal. A further important issue concerns the ability of HDABs to analyse the compatibility permit requests under the GDPR and relevant national law at both speed and scale. Paul Quinn, Erika Ellyne, Cong Yao |
Comput. Law Secur. Rev. | 1 |
| 2019 | Data Protection by Design for cybersecurity systems in a Smart Home environmentabstractThe present paper deals with the elucidation and implementation of the Data Protection by Design (DPbD) principle as recently introduced in the European Union data protection law, specifically with regards to cybersecurity systems in a Smart Home environment, both from a legal and a technical perspective. Starting point constitutes the research conducted in the Cyber-Trust project, which endeavours the development of an innovative and customisable cybersecurity platform for cyber-threat intelligence gathering, detection and mitigation within the Internet of Things ecosystem. During the course of the paper, the requirements of DPbD with regards to the conceptualisation, design and actual development of the system are introduced as prescribed in law. These requirements are then translated into technical solutions, as envisaged in the Cyber-Trust system. For trade-offs are not foreign to the DPbD context, technical limitations and legal challenges are also discussed in this interdisciplinary dialogue. Olga Gkotsopoulou, Elisavet Charalambous, Konstantinos Limniotis, Paul Quinn, Dimitris Kavallieros, Gohar Sargsyan, Stavros Shiaeles, Nicholas Kolokotronis |
NetSoft | 4 |
| 2018 | Big genetic data and its big data protection challenges
Paul Quinn, Liam Quinn |
Comput. Law Secur. Rev. | 1 |
| 2017 | The EU commission's risky choice for a non-risk based strategy on assessment of medical devices
Paul Quinn |
Comput. Law Secur. Rev. | 1 |
| 2011 | The Patients' Rights Directive (2011/24/EU) - Providing (some) rights to EU residents seeking healthcare in other Member States
Paul Quinn, Paul de Hert |
Comput. Law Secur. Rev. | 1 |