We recommend that you always use the latest version of your browser.

Privacy Notification Procedure / Research Section

All processing of personal data, including de-identified data, at Sørlandet Hospital (SSHF) must be recorded in the overview of the hospital’s processing of personal data, ref. Article 30 of the Personal Data Act.

The establishment of new data processing activities for clinical and administrative purposes that involve the recording of personal data must be approved by a manager and have a designated system owner. This applies both when establishing an application/service on the hospital network and with another data processor, including services available via the Internet.
 
Research, studies and quality assurance carried out at SSHF, including disclosure to external studies, must always be endorsed by management before they start. This applies both to health research that must be approved by REK and to other research, quality assurance, and broad research and quality registries that require a recommendation from the Data Protection Officer.
 
The processing of anonymous data is not subject to the notification requirement to the Data Protection Officer, but this presupposes that the data has been collected lawfully.
 
 

New notification system as of 2.2.2026

UsePEIK - Privacy and Internal Control (PEIK guidance)

It is no longer necessary to complete an endorsement form, as endorsement is now part of the notification process.

The distinction between quality assurance and research can be difficult. If you are unsure which category the project falls under, we recommend contacting SSHF’s Data Protection Officer (PVO) and/or REK for clarification. A quality project may identify issues that will later be studied in a research project. If the project’s status changes, an application must be submitted to REK for approval as soon as possible.
 

Research

Research aims to establish new knowledge, not to evaluate existing treatment. As a general rule, research projects must be approved by REK and require the research participant’s consent, cf. Informed consent.
 
Characteristics indicating that the project is a research project:
 
  1. There is a project protocol describing a research question to be investigated or a hypothesis to be tested using scientific methods.
  2. The project involves risks to participants beyond those normally associated with diagnosis and treatment.
  3. The project involves something qualitatively new being done with participants that would not otherwise have been done as part of routine follow-up/subsequent examination.
  4. The project may generate new knowledge about health and disease.
  5. New diagnostic or therapeutic methods are to be tested.
  6. Randomization will be performed.
  7. Use of a control group consisting of healthy individuals.
  8. The project is “other research” and requires an exemption from the consent requirement to access personally identifiable health information.
 

Quality assurance

While research is about acquiring new knowledge about what is, or should become, best practice, a quality study is about finding out whether best practice is being followed.
 
Quality assurance can be defined as projects, surveys, evaluations, etc. whose purpose is to check that diagnosis and treatment actually produce the expected results. For example, the aim may be to improve the efficiency and/or quality of treatment.
 
The National Committee for Medical and Health Research Ethics (NEM) has prepared a checklist that may be helpful in the assessment:
 
  1. Is the purpose of the proposed project to improve the quality of patient care locally?
  2. Will the project measure practice against established standards?
  3. Will the project involve the patient in any way beyond what is routine in their treatment?
If the answer to 1 and 2 is “yes”, and to 3 is “no”, then the project is probably a quality study. Otherwise, it is probably research.


Diagram

 

The project manager or the project’s contact person must complete the notification form:
 
 
Select the option "Health research"
 
The following documentation must be uploaded when completing the notification:
  • Copy of the REK application with all attachments
  • REK approval (all approvals, if there have been multiple rounds with REK)
  • Protocol / project description
  • Information and consent form

Diagram
Disclosure for health research
Before health and personal data can be disclosed to an externally managed health research project, a notification must be sent to the Data Protection Officer at SSHF. The Data Protection Officer is responsible for assessing the basis for disclosure. The Information Security Manager must also ensure that information security is maintained during collection and disclosure.
 
The project’s contact person must complete the notification form:
Notification to the Data Protection Officer and Research Section - SSHF - Nettskjema
Select the option "Disclosure for health research"
 
Upload the following documentation in the form:

Diagram
Quality studies, health services research and other research
Research that falls outside REK’s remit must be reported to the Data Protection Officer.
 
This also includes quality studies that are not governed by the provisions on internal quality assurance.
 
The project manager or the project contact person must complete the notification form:
​ 
Upload the following documentation in the form:
  • Protocol / project description
  • Information and consent form
  • Other relevant documentation, such as participant questionnaires
  • The project must not start until the Data Protection Officer has issued a recommendation.
 

DiagramInternal quality assurance
The Patient Records Act Section 6 and the Health Personnel Act Section 26 provide a legal basis for projects and registries established by a manager to carry out internal control and quality assurance of healthcare. A management decision and a recommendation from the Data Protection Officer are required.
 
The project aims to improve patient treatment at the hospital, for example through improved diagnostic or treatment methods. This is an internal purpose intended to ensure continuous improvement and, where relevant, to support adjustments to treatment so that changes to treatment regimens achieve at least the same or better results.
 
Neither patients nor their next of kin are directly involved. No new information is collected from patients or other external sources; only information already collected as part of healthcare and recorded in the organisation’s consolidated patient record is used.
 
The purpose is limited to internal activities and needs. It does not include publication of results. Any need to publish results must be specified as an additional purpose. A decision to publish results will require an assessment of the rationale for establishing the quality registry, its purpose, and the assumption that it serves an internal purpose.
 
The department’s contact person must complete the notification form:
 
 
The Data Protection Officer’s recommendation is conditional on the legal basis for accessing patient records having been clarified.
 
The Data Protection Officer’s recommendation must be in place before registration can begin.
 
For a more detailed definition of an internal quality registry, see the document:Quality assurance - Approval of internal quality registries.
 

Diagram
Research/quality registry with a broad purpose
The establishment of a health registry with a broad thematic purpose related to research, including nationwide quality registries, must be reported to the Data Protection Officer. Such registries will generally require a documented Data Protection Impact Assessment (DPIA).
 
The Data Protection Officer can be contacted for advice on preparing this assessment.
 
The project manager or the project contact person must complete the notification form:
 
 
Select the option “Broad registry”.
 
Upload the following documentation in the form:
The Data Protection Officer’s recommendation must be in place before registration can begin.
 
 

Diagram
Disclosure for other research and quality assurance
Before health and personal data can be disclosed to an externally managed project or registry, whether for quality assurance or other research outside REK’s remit, a notification must be sent to the Data Protection Officer at SSHF. This applies even if the external party has received a recommendation from its own Data Protection Officer. The Data Protection Officer must assess the basis for disclosure. The Information Security Manager must also ensure that information security is maintained during collection and disclosure.
 
The project contact person must complete the notification form:
Notification to the Data Protection Officer
Select either “Research outside REK’s remit” if data are to be disclosed to a project, or “Registry with a broad purpose” if data are to be disclosed to a registry.
 
Upload the following documentation in the form:
  • Recommendation from another Data Protection Officer
  • Protocol / project description
  • Information and consent form, or a copy of the exemption
  • If data are to be disclosed to a registry: the registry’s bylaws
The recommendation for disclosure from the Data Protection Officer at OUS must be in place before the project starts and data are disclosed.
 

SSHF has its own procedure for master’s projects; seeData collection - master’s students (sshf.no) 
 
Use of the hospital’s time and resources must be approved by the relevant managers.
 
Contact Vivi Haavik TønnessenVivi.Tonnessen@sshf.nofor guidance.
 
 

Diagram
Case study
Before accessing patient records for the purpose of presenting a patient history (in a journal, at a conference, etc.), a notification must be sent to the Data Protection Officer at SSHF. Only SSHF employees are eligible to apply.
 
The project contact person must complete the notification form:
 
PEIK - Data Protection and Internal Controland select "Other research/project"
 
Upload the following documentation to the form:
 

Bilde></picture>
<figcaption class=Amendment notification
Notifications of changes to previously approved data registrations must be sent to the body/bodies that approved the registrations.
 
If the change affects information security, for example an electronic data collection solution, storage, analysis tools or disclosure, approval from the PVO/Information Security Manager at SSHF must be obtained.
 

Health research

An amendment notification is only required if the change concerns the storage location and/or disclosure of data. In such cases, the notification form must be completed:
 
Project registered after 2.2.2026:
PEIK - Data Protection and Internal Control
 
Project registered before 2.2.2026:
Select the option "Amendment notification"
 
All other changes to health research projects must only be reported to REK.
 

Other research, quality studies and internal quality assurance

Project registered after 2.2.2026:
 
Project registered before 2.2.2026:
Select the option "Amendment notification"
 
The change cannot be implemented until feedback on the amendment notification has been provided by the Data Protection Officer and/or the Information Security Manager.
 

Last updated 03.02.2026
TEST VERSION
Machine-translated copy of sshf.no for testing only. Not official information.