Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
473 changes: 124 additions & 349 deletions DataPreparation.md

Large diffs are not rendered by default.

457 changes: 67 additions & 390 deletions DataSharingAnnex.md

Large diffs are not rendered by default.

380 changes: 52 additions & 328 deletions DataTransferAnnex.md

Large diffs are not rendered by default.

66 changes: 37 additions & 29 deletions Federated.md

Large diffs are not rendered by default.

12 changes: 6 additions & 6 deletions Governance.md
Original file line number Diff line number Diff line change
@@ -1,21 +1,21 @@
# 2\. Governance {#2.-governance}
# 2. Governance

## 2.1. Data governance {#2.1.-data-governance}
## 2.1. Data governance

Data provision in EUCAIM follows a structured process led by its operational boards, each playing a key role in ensuring that incoming datasets meet the platform’s scientific, technical and legal standards.

When a Data Holder submits an application to join the federation using the **Expression of Interest**, the **Access Committee** initiates the review process. It coordinates with the **Technical Board** (TB) which evaluates whether the proposed infrastructure, anonymisation protocols, risk analysis and data quality controls are in line with EUCAIM’s technical requirements. At the same time, the **Ethical and Legal Board** assesses the legal documentation submitted as evidence for the technical aspects reviewed by TB, verifying its compliance with data protection and ethical norms.

Once all evaluations are completed, the Access Committee prepares a consolidated report which is sent to the **Management Board** and **Steering Committee** to make the final decision. Throughout the process, Data Holders are expected to collaborate closely with the involved boards, provide documentation, and requests for clarification. [Figure 1](#fig_dataprov) shows a graphical representation of this process.

<img src="figures/image1.png" alt="Data provision workflow" width="600" height="400">
### <a id="fig_dataprov"></a>

<a id="fig_dataprov"></a>Figure 1: Data provision workflow.
<figure><img src="figures/image1.png" width="500"><figcaption><p>Figure 1: Data provision workflow.</p></figcaption></figure>

Once the data is registered and available through the EUCAIM Platform, the access for the Data Users will be submitted through the negotiator component and will be subject to the evaluation of the Access Committee. The AC evaluates the applications and informs the Management board and the DH, when needed. Federated DHs will be involved in the negotiation process for the agreement on the data access conditions. [Figure 2](#fig_dureq) shows a graphical schema of the process.

<img src="figures/image2.png" alt="Data access request workflow." width="900" height="300">
### <a id="fig_dureq"></a>

<a id="fig_dureq"></a>Figure 2: Data access request workflow.
![Figure 2: Data access request workflow.](figures/image2.png)

The Data Holders must provide a contact point, in case of a federated node, and should endorse the EUCAIM AC to request the signature of the access conditions in the case of transferring the data to a reference node. This is explained in more detail in the next section.
2 changes: 1 addition & 1 deletion Introduction.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# 1\. Introduction {#1.-introduction}
# 1. Introduction

This handbook is designed to guide **Data Holders** through the onboarding process for sharing or transferring data to the EUCAIM infrastructure. It outlines the roles, responsibilities, legal and technical requirements, and procedural steps to ensure compliance and facilitate smooth integration into the EUCAIM Federation.

Expand Down
36 changes: 20 additions & 16 deletions Onboarding.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# 3\. Onboarding Process {#3.-onboarding-process}
# 3. Onboarding Process

EUCAIM defines a federated infrastructure in which nodes provide with data and services[^3].

## 3.1. Initial requirements and commitments {#3.1.-initial-requirements-and-commitments}
## 3.1. Initial requirements and commitments

**Before you start, pre-onboarding workflow**:

Expand All @@ -29,21 +29,23 @@ EUCAIM defines a federated infrastructure in which nodes provide with data and s
- GDPR-compliant documentation to be reviewed and approved by the institutional ethics committee.
- DTA/DSA signature + other documentation, please go to section 3.2 Legal Documents of this Handbook.
- Technical requirements: [Technical_requirements_Data_Holders](https://docs.google.com/document/d/1u0IPiPNcPivfECYzVvU6zXzh77jNrLojPeHIdLPjEhc/edit?usp=sharing)
4. Imaging and data preparation according to the EUCAIM [Common Data Model](https://eucaim-cdm.ics.forth.gr/) and [Hyperontology](https://eucaim-cdm.ics.forth.gr/).
4. Imaging and data preparation according to the EUCAIM [Common Data Model](https://eucaim-cdm.ics.forth.gr/) and [Hyperontology](https://hyperontology.eucaim.cancerimage.eu/).
5. Participation in monitoring, validation and quality assurance activities. Each step is supported by __tools, documentation, and expert teams__ from EUCAIM, ensuring Data Holders receive technical, legal, and procedural guidance throughout the process.



## 3.2. Legal documents. {#3.2.-legal-documents.}
## 3.2. Legal documents

This section summarises the legal documentation that is required to become a Data Holder in EUCAIM. This information is much more detailed (and potentially more up-to-date) in the Legal Handbook of the project, available in this [link](https://docs.google.com/document/d/1U-RpFycjXEVP-4-l9ppveT654x78Dhlw/edit). We recommend going through the Legal Handbook when requesting and preparing the information and use the information below as a general guidance.
A set of legal agreements must be prepared and signed to clearly state the obligations and responsibilities of the parties involved. The process is simpler in the case of Data Transfer Data Holders, as documents related to security and Service Level Agreements are provided by the reference nodes where the data will be deposited. Federated nodes have to provide a guarantee that they can fulfill the security and performance requirements[^5]. [Figure 3](#fig_legaldiagram) graphically shows the information and steps required for the legal framework of EUCAIM.

![Figure 3: Information and steps required to complete the legal framework of EUCAIM.](figures/image3.png) Figure 3: Information and steps required to complete the legal framework of EUCAIM.
### <a id="fig_legaldiagram"></a>

![Figure 3: Information and steps required to complete the legal framework of EUCAIM.](figures/image3.png)

It is essential that the data holder provides a contact person of its legal team to be in close communication with the legal team of EUCAIM. A contact point will be assigned during the onboarding process.

The first step will be to Complete the ethical training via the Moodle platform ([https://training.eucaim.cancerimage.eu/](https://training.eucaim.cancerimage.eu/))[^6]. Then, the ethical and legal requirements for data holders are different depending on the collaboration model chosen:
The first step will be to Complete the ethical training[^6] via the Moodle platform ([https://training.eucaim.cancerimage.eu/](https://training.eucaim.cancerimage.eu/)). Then, the ethical and legal requirements for data holders are different depending on the collaboration model chosen:

* **Data holders who agree to transfer data to a reference node**:

Expand Down Expand Up @@ -84,27 +86,29 @@ The first step will be to Complete the ethical training via the Moodle platform

In both cases it is compulsory that the DPO and/or the legal representative of the Data Holder confirm that they are aware about the transfer or sharing the data within EUCAIM and the security measures that must be taken.

[Table 1](#tab_DTA-1) summarises the actions for the Data Holders opting for the Data Transfer model and [Table 2](#tab_DSA-1) for the Data Holders who will set up a federated node.
[Table 1](#tab_dta1) summarises the actions for the Data Holders opting for the Data Transfer model and [Table 2](#tab_dsa1) for the Data Holders who will set up a federated node.

### <a id="tab_dta1"></a>

| Data Transfer | | |
| :---- | :---- | :---- |
| **Action** | **Description** | **Documents** |
| Provide documentation | - Proof of legal representative, and legal basis if necessary.<br> - A copy of a favorable ethical approval (if applicable).<br> - A report from the DPO confirming legal compliance.<br> - Security compliance.<br> - GDPR compliance.<br> - Data Protection Impact Assessment (if applicable).<br> - Any documents required under the national legislation.<br> - Evidence of an adequate anonymization/pseudonymization process that has been carried out | For more information see primarily the [Legal Handbook](https://docs.google.com/document/d/1U-RpFycjXEVP-4-l9ppveT654x78Dhlw/edit?tab=t.0), [D4.4 Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy) (See Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders)
Find also here the template for the DPO report: [faq_DPO_template.docx - Google Docs](https://docs.google.com/document/d/1KHf1nlCxFB1BjhhQXHVo4zVSoOBorL_X/edit) |
| Data Transfer Agreement | Fill-in and sign the DTA | [DTA](https://drive.google.com/file/d/1TTuaFo4cWwomLJBtQbs_lkrBNFVSLH_L/view?usp=drive_link) |
[Table 1](#table_DTA-1): Summary of steps to be completed for Data Transfer case.
| Provide documentation | - Proof of legal representative, and legal basis if necessary.<br> - A copy of a favorable ethical approval (if applicable).<br> - A report from the DPO confirming legal compliance.<br> - Security compliance.<br> - GDPR compliance.<br> - Data Protection Impact Assessment (if applicable).<br> - Any documents required under the national legislation.<br> - Evidence of an adequate anonymization/pseudonymization process that has been carried out | For more information see primarily the [Legal Handbook](https://docs.google.com/document/d/1U-RpFycjXEVP-4-l9ppveT654x78Dhlw/edit?tab=t.0), [D4.4 Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy) (See Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders)) <br> - Find also here the template for the DPO report: [faq_DPO_template.docx - Google Docs](https://docs.google.com/document/d/1KHf1nlCxFB1BjhhQXHVo4zVSoOBorL_X/edit) |
| Data Transfer Agreement | Fill-in and sign the DTA once all the legal documentation have been provided | [DTA](https://drive.google.com/file/d/1TTuaFo4cWwomLJBtQbs_lkrBNFVSLH_L/view?usp=drive_link) |

[Table 1](#tab_dta1): Summary of steps to be completed for Data Transfer case.

### <a id="tab_dsa1"></a>

| Data Sharing | | |
| :---- | :---- | :---- |
| **Action** | **Description** | **Documents** |
| Provide documentation | - Proof of legal representative, and legal basis if necessary.<br>- A copy of a favourable ethical approval (if applicable).<br>- A report from the DPO confirming legal compliance.<br>- GDPR compliance.<br>- Data Protection Impact Assessment (if applicable).<br>- Evidence of an adequate anonymization/pseudonymization process that has been carried out.<br>- Documents demonstrating the security of the information system.<br>- Any documents required under your national legislation.<br>| For more information see primarily the [Legal Handbook](https://docs.google.com/document/d/1U-RpFycjXEVP-4-l9ppveT654x78Dhlw/edit?tab=t.0), [D4.4 Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy) (See Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders)
Find also here the template for the DPO report: [faq_DPO_template.docx - Google Docs](https://docs.google.com/document/d/1KHf1nlCxFB1BjhhQXHVo4zVSoOBorL_X/edit) |
| Provide documentation | - Proof of legal representative, and legal basis if necessary.<br>- A copy of a favourable ethical approval (if applicable).<br>- A report from the DPO confirming legal compliance.<br>- GDPR compliance.<br>- Data Protection Impact Assessment (if applicable).<br>- Evidence of an adequate anonymization/pseudonymization process that has been carried out.<br>- Documents demonstrating the security of the information system.<br>- Any documents required under your national legislation.<br>| For more information see primarily the [Legal Handbook](https://docs.google.com/document/d/1U-RpFycjXEVP-4-l9ppveT654x78Dhlw/edit?tab=t.0), [D4.4 Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy) (See Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders)) <br> - Find also here the template for the DPO report: [faq_DPO_template.docx - Google Docs](https://docs.google.com/document/d/1KHf1nlCxFB1BjhhQXHVo4zVSoOBorL_X/edit) |
| Data Sharing Agreement | Fill-in and sign the DSA | [DSA](https://drive.google.com/file/d/1-UyQ02w0-shmRgQgp8L1ATWs1JEco3_Y/view?usp=drive_link) |
| Define especial Access Conditions | A Document to be signed by the Data User that indicates the conditions under the Data User can access the data. | [Draft Template](https://drive.google.com/file/d/1UMdDF52mXGHNIL0GegzfyuSBVfKCIl7d/view?usp=sharing) |
| Contact point for the negotiation (Only in federated nodes) | The LS-AAI details of the data holder delegate who will interact with the Data User through the negotiator. | [Registration of users in EUCAIM](https://drive.google.com/file/d/1EsFYxbzqpyYKggyeKrKKw3FkVecDby8P/view) LS-AAI. |

[Table 2](#table_DSA-1): Summary of steps to be completed for Data Sharing case

[Table 2](#tab_dsa1): Summary of steps to be completed for Data Sharing case


[^3]: *See [D5.6 Minimum Data Federation and Interoperability Framework](https://drive.google.com/file/d/1URY8jtofLQpokTh7Hzag2wFFV9r1d_fs/view?usp=sharing)* *section 3 and [https://eucaim.gitbook.io/architecture-of-eucaim/4.-detailed-architecture](https://eucaim.gitbook.io/architecture-of-eucaim/4.-detailed-architecture)*
Expand All @@ -115,4 +119,4 @@ Find also here the template for the DPO report: [faq_DPO_template.docx - Google

[^6]: *See D2.4 [Training Evaluation: Guidelines, Best Practices, Lessons Learned](https://drive.google.com/file/d/1hNCkrP8UutNiPexzAzpsdt3WDOwdVh66/view?usp=drive_link).*

[^7]: See D4.4 [Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy), Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders).
[^7]: *See D4.4 [Final rules for participation report](https://drive.google.com/drive/folders/1dn1xQB9K7Fn3WzzqN5HRiQ7NiVwYt0yy), Sections 4.4.1 (Legal requirements) and 4.4.2 (Ethical requirements for Data Holders)*.
45 changes: 22 additions & 23 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

**Project title:** European Federation for Cancer Images

![image](figures/image0.png)
<figure><img src="figures/image0.png" width="700"></figure>

**Disclaimer**

Expand All @@ -24,56 +24,55 @@ Table of contents



[**1\. Introduction**](https://eucaim.gitbook.io/handbook/introduction){:target="_blank"}
[**1\. Introduction**](Introduction.md)


[**2\. Governance**](https://eucaim.gitbook.io/handbook/governance)
[**2\. Governance**](Governance.md)

&nbsp;&nbsp;&nbsp;&nbsp;[2.1. Data governance](Governance.md#data-governance)
&nbsp;&nbsp;&nbsp;&nbsp;[2.1. Data governance](Governance.md#id-2.1.-data-governance)

[**3\. Onboarding Process**](https://eucaim.gitbook.io/handbook/onboarding)
[**3\. Onboarding Process**](Onboarding.md)

&nbsp;&nbsp;&nbsp;&nbsp;[3.1. Initial requirements and commitments](Onboarding.md#initial-requirements-and-commitments)
&nbsp;&nbsp;&nbsp;&nbsp;[3.1. Initial requirements and commitments](Onboarding.md#id-3.1.-initial-requirements-and-commitments)

&nbsp;&nbsp;&nbsp;&nbsp;[3.2. Legal documents.](Onboarding.md#legal-documents.)
&nbsp;&nbsp;&nbsp;&nbsp;[3.2. Legal documents](Onboarding.md#id-3.2.-legal-documents)

[**4\. Support and communication**](Support.md)

&nbsp;&nbsp;&nbsp;&nbsp;[4.1. Engagement Team](Support.md#engagement-team)
&nbsp;&nbsp;&nbsp;&nbsp;[4.1. Engagement Team](Support.md#id-4.1.-engagement-team)

&nbsp;&nbsp;&nbsp;&nbsp;[4.2. Helpdesk](Support.md#helpdesk)
&nbsp;&nbsp;&nbsp;&nbsp;[4.2. Helpdesk](Support.md#id-4.2.-helpdesk)

&nbsp;&nbsp;&nbsp;&nbsp;[4.3. EUCAIM training platform: Overview of courses and access](Support.md#eucaim-training-platform)
&nbsp;&nbsp;&nbsp;&nbsp;[4.3. EUCAIM training platform: Overview of courses and access](Support.md#id-4.3.-eucaim-training-platform-overview-of-courses-and-access)

[**5\. Data Preparation process**](DataPreparation.md)

&nbsp;&nbsp;&nbsp;&nbsp;[5.1. Data Preparation tools](DataPreparation.md#data-preparation-tools)
&nbsp;&nbsp;&nbsp;&nbsp;[5.1. Data Preparation tools](DataPreparation.md#id-5.1.-data-preparation-and-related-tools-from-the-eucaim-catalogue)

&nbsp;&nbsp;&nbsp;&nbsp;[5.2. Tier 1 datasets](DataPreparation.md#tier-1-datasets)
&nbsp;&nbsp;&nbsp;&nbsp;[5.2. Tier 1 datasets](DataPreparation.md#id-5.2.-tier-1-datasets)

&nbsp;&nbsp;&nbsp;&nbsp;[5.3. Tier 2 and 3 datasets](DataPreparation.md#tier-2-and-3-datasets)
&nbsp;&nbsp;&nbsp;&nbsp;[5.3. Tier 2 and 3 datasets](DataPreparation.md#id-5.3.-tiers-2-and-3-datasets)

[**6\. Option 1: Transfer to Reference Node**](Transfer.md)

&nbsp;&nbsp;&nbsp;&nbsp;[6.1. Reference Nodes](Transfer.md#reference-nodes)
&nbsp;&nbsp;&nbsp;&nbsp;[6.1. Reference Nodes](Transfer.md#id-6.1.-reference-nodes)

&nbsp;&nbsp;&nbsp;&nbsp;[6.2. Transferring data to the nodes](Transfer.md#transferring-data-to-the-nodes)
&nbsp;&nbsp;&nbsp;&nbsp;[6.2. Transferring data to the nodes](Transfer.md#id-6.2.-transferring-data-to-the-nodes)

[**7\. Option 2: Setting up a Federated Node**](Federated.md)

&nbsp;&nbsp;&nbsp;&nbsp;[7.1. Setting up the node](Federated.md#setting-up-the-node)
&nbsp;&nbsp;&nbsp;&nbsp;[7.1. Setting up the node](Federated.md#id-7.1.-setting-up-the-node)

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.1.1. Security and privacy considerations](Federated.md#security-and-privacy-considerations)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.1.1. Security and privacy considerations](Federated.md#id-7.1.1.-security-and-privacy-considerations)

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.1.2. Service Level Agreement](Federated.md#service-level-agreement)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.1.2. Service Level Agreement](Federated.md#id-7.1.2.-service-level-agreement)

&nbsp;&nbsp;&nbsp;&nbsp;[7.2. Tier 1 compliance](Federated.md#tier-1-compliance)
&nbsp;&nbsp;&nbsp;&nbsp;[7.2. Tier 1 compliance](Federated.md#id-7.2.-tier-1-compliance)

&nbsp;&nbsp;&nbsp;&nbsp;[7.3. Tier 2 compliance](Federated.md#tier-2-compliance)
&nbsp;&nbsp;&nbsp;&nbsp;[7.3. Tier 2 compliance](Federated.md#id-7.3.-tier-2-compliance)

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.3.1. Node Registration and Deployment](Federated.md#7.3.1.-node-registration-and-deployment)
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[7.3.1. Node Registration and Deployment](Federated.md#id-7.3.1.-node-registration-and-deployment)

&nbsp;&nbsp;&nbsp;&nbsp;[7.4. Tier 3 compliance](Federated.md#7.4.-tier-3-compliance)
&nbsp;&nbsp;&nbsp;&nbsp;[7.4. Tier 3 compliance](Federated.md#id-7.4.-tier-3-compliance)

[**8\. References**](References.md)

Expand Down
2 changes: 1 addition & 1 deletion References.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@

\[5\] Registration of users in EUCAIM LS-AAI. [https://drive.google.com/file/d/1EsFYxbzqpyYKggyeKrKKw3FkVecDby8P/view](https://drive.google.com/file/d/1EsFYxbzqpyYKggyeKrKKw3FkVecDby8P/view)

\[6\] EUCAIM Dashboard Manual. [https://eucaim.gitbook.io/eucaim-dashboard](https://eucaim.gitbook.io/eucaim-dashboard)
\[6\] EUCAIM Dashboard Page. [https://dashboard.eucaim.cancerimage.eu/documentation](https://dashboard.eucaim.cancerimage.eu/documentation)

\[7\] End user Guide of the Platform Services for the different profiles [https://eucaim.gitbook.io/end-user-guide](https://eucaim.gitbook.io/end-user-guide)

Expand Down
Loading