Contact person for the personal data processing in the service is Unit head Kati Donner, email:
Contact details for Data Protection Officer:
Why do we process your personal data and what is the legal basis for processing?
Personal data are processed for the provision of genetic analysis services.
FIMM Genomics processes samples and the data generated from them within its service on behalf of customers of the infrastructure. The research projects and their home organisations using the service are the controllers for the personal data and thus responsible for taking care of study participants' data protection rights (privacy notice, informing, etc). The legal basis is also defined by the customers, the most common being research carried out in public interests.
FIMM Genomics receives samples from its customers in pseudonymized form so the data subjects cannot be directly identified. Customers are instructed not to include any identifying information in the metadata associated with the samples. The analysis of the samples generates genetic data. As a result, the output data produced from the analysis may contain genetic information that could be used to identify individuals.
The analyses performed within the service include e.g.:
• Next Generation Sequencing
• Third Generation Sequencing
• Sanger Sequencing
• Targeted Amplicon Sequencing
• Transcriptomics
• Targeted protein and RNA assays
• Genotyping
These analyses generate various types of genetic data from the samples. However, the resulting data do not contain any strong personal identifiers such as names or national personal identity codes.
What personal data is processed?
We process data generated from the genetic analysis of human-derived samples.
The processing includes genetic and health data that is regarded special category data in the light of data protection regulation.
Do we disclose personal data to third parties?
The result datasets are delivered to the designated contact person of the customers commissioning the genetic analyses. The data is for research use only.
For how long do we process and retain personal data?
The results and sample information shall be stored at the FIMM Genomics database for two (2) months after the completion of the analysis project marked by the data release message via iLab. After this period the data is deleted.
Transfers of personal data to countries outside the EU/European Economic Area
Data is not transferred outside the European Economic Area, it is only processed within the EU.
Data subject rights
The research projects and their home organisations as controllers are responsible for implementing and enforcing the data subject rights. Your rights are affected, for example, by the legal basis on which your personal data is processed. As far as possible FIMM Genomics role as a service provider and personal data processor is to assist the controllers in the fulfilment of their obligations to respond to requests from the data subjects.
More information about your rights in different situations can be found on the website of the Office of the Data Protection Ombudsman:
Protection of personal data
The personal data and materials processed within the scope of FIMM Genomic services are handled and stored in a secure manner. Data is stored in a high capacity storage array and it's accessible only through authentication and authorization by Microsoft Active Directory located on-premises. The high-availability storage protects also against accidental deletion and possible data corruption.
Connections outside FIMM network require using restricted VPN access to Helsinki university network and then two-factor authentication through the FIMM access point.
Some of the data is analyzed in ePouta environment, which is secure, isolated private cloud service provided by CSC - IT Center for Science for sensitive data. FIMM has a dedicated MPLS VPN connection to ePouta, so the data is protected both during the transfer and analysis.