Privacy, Governance & Responsible Healthcare Data Handling
SCILabel designs its healthcare data workflows to support applicable data-protection, privacy and security requirements, including the Kenya Data Protection Act, GDPR and HIPAA requirements where they apply to the particular organisation, dataset, processing relationship and project.
Data protection requirements are considered throughout the project
The appropriate legal and operational controls depend on factors including geography, data type, identifiability, lawful basis, contractual roles and intended use.
Purpose & Scope
Define the project purpose, required data fields and permitted processing activities.
Data Rights
Dataset sourcing should consider provenance, licensing, consent or other appropriate authorization.
Minimization
Limit unnecessary personal or sensitive information where the project allows.
De-identification
Apply appropriate de-identification or pseudonymization requirements when required by the engagement.
Controlled Access
Restrict access according to roles and project requirements.
Retention & Delivery
Project-specific retention, delivery and deletion requirements can be defined contractually and operationally.
Compliance depends on the specific processing relationship
References to regulatory frameworks do not mean that every dataset or project is governed by every framework. SCILabel works with clients and data partners to identify the requirements relevant to the specific engagement.
Kenya
Projects involving Kenyan personal data may require consideration of the Kenya Data Protection Act and applicable regulatory requirements.
European Context
Projects involving relevant European personal data may require GDPR-aligned contractual and operational controls.
United States Healthcare
HIPAA-related requirements depend on the data, entities involved and the applicable processing relationship.
Build your healthcare AI data workflow with SCILabel
Talk to our team about your healthcare data, annotation or AI evaluation requirements.