BS EN 14484 provides guidance on a High-Level Security Policy for third country organizations and is restricted to aspects relevant to personal health data transferred from a compliant country to a third country.
BS EN 14484 provides guidance on the High-Level Security Policy which should be adopted by third country organizations involved in international informatics applications which entail the transmission of a person’s health data from an EU Member State to a non-EU Member State whose data protection is inadequate in the context of the EU Data Protection Directive. Its purpose is to assist in the application of the EU Directive.
Note: The European Standard does not provide definitive legal advice but comprises guidance. When applying the guidance to a particular application legal advice appropriate to that application should be sought.
BS EN 14484 on high-level security policy of personal health data covered by the EU data protection directive is useful for:
High-Level Security Policy is for organizations in third countries which process personal health data from the EU Member States.
BS EN 14484 enables you to identify an individual quickly and uniquely, for example, by using a combination of name, address, age, sex, and identification number, to confirm that two data sets belong to the same person without having to identify the person himself, for example, for record linkage and/or longitudinal statistics, and for statistical purposes, but with the end goal of positively preventing any individual identification. BS EN 14484 addresses these aspects and provides guidance on the policy that an organization in a non-EU country should adopt to demonstrate compliance with the measures necessary to make permissible the transfer of personal health data to it from an EU country in the context of the EU Directive.
EN 14484:2003