Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance with audit and performance metrics

preprint OA: closed
Full text JSON View at publisher

Abstract

Background: Operators of health data hubs and registries enable secondary use by implementing consent processes, privacy safeguards, access governance, data quality management, transparency, and stakeholder engagement. Ethical guidance is extensive, yet it rarely specifies operator-level practices or indicators that show whether governance performs well in routine use. This paper proposes an operator-focused framework that makes ethics implementable and assessable. Methods The framework synthesises international guidance, systematic reviews and other empirical work on governance gaps, and publicly available governance materials from major data infrastructures. Ethics practices were selected for conceptual distinctness and operator-level controllability, grouped into seven governance domains, and aligned with a PDCA (Plan–Do–Check–Act) cycle. For each practice, the framework provides illustrative audit items, descriptive metrics, and outcome indicators intended as adaptable references rather than prescriptive standards. Results Seven domains are covered: Informed Consent & Information, Privacy & Data Protection, Data Quality, Use & Access Governance, Incidental Findings, Stakeholder Engagement, and Project-Level Transparency. Each domain contains four PDCA-aligned practices with linked evaluation items. Discussion The framework shifts practical bioethics for secondary use from policy existence to demonstrable performance. It can support operator self-audit and proportionate oversight by funders, ethics committees, and stakeholder bodies, while remaining modular across legal and infrastructural contexts. It also provides a starting point for developing minimal, transparent reporting expectations to support trust-building governance.
Full text 114,414 characters · extracted from preprint-html · click to expand
Operationalising ethics in secondary health-data... | F1000Research "use strict";function _typeof(t){return(_typeof="function"==typeof Symbol&&"symbol"==typeof Symbol.iterator?function(t){return typeof t}:function(t){return t&&"function"==typeof Symbol&&t.constructor===Symbol&&t!==Symbol.prototype?"symbol":typeof t})(t)}!function(){var t=function(){var t,e,o=[],n=window,r=n;for(;r;){try{if(r.frames.__tcfapiLocator){t=r;break}}catch(t){}if(r===n.top)break;r=r.parent}t||(!function t(){var e=n.document,o=!!n.frames.__tcfapiLocator;if(!o)if(e.body){var r=e.createElement("iframe");r.style.cssText="display:none",r.name="__tcfapiLocator",e.body.appendChild(r)}else setTimeout(t,5);return!o}(),n.__tcfapi=function(){for(var t=arguments.length,n=new Array(t),r=0;r 3&&2===parseInt(n[1],10)&&"boolean"==typeof n[3]&&(e=n[3],"function"==typeof n[2]&&n[2]("set",!0)):"ping"===n[0]?"function"==typeof n[2]&&n[2]({gdprApplies:e,cmpLoaded:!1,cmpStatus:"stub"}):o.push(n)},n.addEventListener("message",(function(t){var e="string"==typeof t.data,o={};if(e)try{o=JSON.parse(t.data)}catch(t){}else o=t.data;var n="object"===_typeof(o)&&null!==o?o.__tcfapiCall:null;n&&window.__tcfapi(n.command,n.version,(function(o,r){var a={__tcfapiReturn:{returnValue:o,success:r,callId:n.callId}};t&&t.source&&t.source.postMessage&&t.source.postMessage(e?JSON.stringify(a):a,"*")}),n.parameter)}),!1))};"undefined"!=typeof module?module.exports=t:t()}(); dataLayer = dataLayer || []; // Standard GTM initialization - Google Consent Mode handles consent automatically (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl+ '>m_auth=hzk0Vc3qFsQYhCrIoHz68A>m_preview=env-1>m_cookies_win=x';f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-MWFK8L5J'); ;window.NREUM||(NREUM={});NREUM.init={distributed_tracing:{enabled:true},privacy:{cookies_enabled:true},ajax:{deny_list:["bam.nr-data.net"]}}; ;NREUM.loader_config={accountID:"438030",trustKey:"438030",agentID:"772317073",licenseKey:"97f8f67f26",applicationID:"772317073"} ;NREUM.info={beacon:"bam.nr-data.net",errorBeacon:"bam.nr-data.net",licenseKey:"97f8f67f26",applicationID:"772317073",sa:1} ;/*! For license information please see nr-loader-spa-1.236.0.min.js.LICENSE.txt */ (()=>{"use strict";var e,t,r={5763:(e,t,r)=>{r.d(t,{P_:()=>l,Mt:()=>g,C5:()=>s,DL:()=>v,OP:()=>T,lF:()=>D,Yu:()=>y,Dg:()=>h,CX:()=>c,GE:()=>b,sU:()=>_});var n=r(8632),i=r(9567);const o={beacon:n.ce.beacon,errorBeacon:n.ce.errorBeacon,licenseKey:void 0,applicationID:void 0,sa:void 0,queueTime:void 0,applicationTime:void 0,ttGuid:void 0,user:void 0,account:void 0,product:void 0,extra:void 0,jsAttributes:{},userAttributes:void 0,atts:void 0,transactionName:void 0,tNamePlain:void 0},a={};function s(e){if(!e)throw new Error("All info objects require an agent identifier!");if(!a[e])throw new Error("Info for ".concat(e," was never set"));return a[e]}function c(e,t){if(!e)throw new Error("All info objects require an agent identifier!");a[e]=(0,i.D)(t,o),(0,n.Qy)(e,a[e],"info")}var u=r(7056);const d=()=>{const e={blockSelector:"[data-nr-block]",maskInputOptions:{password:!0}};return{allow_bfcache:!0,privacy:{cookies_enabled:!0},ajax:{deny_list:void 0,enabled:!0,harvestTimeSeconds:10},distributed_tracing:{enabled:void 0,exclude_newrelic_header:void 0,cors_use_newrelic_header:void 0,cors_use_tracecontext_headers:void 0,allowed_origins:void 0},session:{domain:void 0,expiresMs:u.oD,inactiveMs:u.Hb},ssl:void 0,obfuscate:void 0,jserrors:{enabled:!0,harvestTimeSeconds:10},metrics:{enabled:!0},page_action:{enabled:!0,harvestTimeSeconds:30},page_view_event:{enabled:!0},page_view_timing:{enabled:!0,harvestTimeSeconds:30,long_task:!1},session_trace:{enabled:!0,harvestTimeSeconds:10},harvest:{tooManyRequestsDelay:60},session_replay:{enabled:!1,harvestTimeSeconds:60,sampleRate:.1,errorSampleRate:.1,maskTextSelector:"*",maskAllInputs:!0,get blockClass(){return"nr-block"},get ignoreClass(){return"nr-ignore"},get maskTextClass(){return"nr-mask"},get blockSelector(){return e.blockSelector},set blockSelector(t){e.blockSelector+=",".concat(t)},get maskInputOptions(){return e.maskInputOptions},set maskInputOptions(t){e.maskInputOptions={...t,password:!0}}},spa:{enabled:!0,harvestTimeSeconds:10}}},f={};function l(e){if(!e)throw new Error("All configuration objects require an agent identifier!");if(!f[e])throw new Error("Configuration for ".concat(e," was never set"));return f[e]}function h(e,t){if(!e)throw new Error("All configuration objects require an agent identifier!");f[e]=(0,i.D)(t,d()),(0,n.Qy)(e,f[e],"config")}function g(e,t){if(!e)throw new Error("All configuration objects require an agent identifier!");var r=l(e);if(r){for(var n=t.split("."),i=0;i {r.d(t,{D:()=>i});var n=r(50);function i(e,t){try{if(!e||"object"!=typeof e)return(0,n.Z)("Setting a Configurable requires an object as input");if(!t||"object"!=typeof t)return(0,n.Z)("Setting a Configurable requires a model to set its initial properties");const r=Object.create(Object.getPrototypeOf(t),Object.getOwnPropertyDescriptors(t)),o=0===Object.keys(r).length?e:r;for(let a in o)if(void 0!==e[a])try{"object"==typeof e[a]&&"object"==typeof t[a]?r[a]=i(e[a],t[a]):r[a]=e[a]}catch(e){(0,n.Z)("An error occurred while setting a property of a Configurable",e)}return r}catch(e){(0,n.Z)("An error occured while setting a Configurable",e)}}},6818:(e,t,r)=>{r.d(t,{Re:()=>i,gF:()=>o,q4:()=>n});const n="1.236.0",i="PROD",o="CDN"},385:(e,t,r)=>{r.d(t,{FN:()=>a,IF:()=>u,Nk:()=>f,Tt:()=>s,_A:()=>o,il:()=>n,pL:()=>c,v6:()=>i,w1:()=>d});const n="undefined"!=typeof window&&!!window.document,i="undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self.navigator instanceof WorkerNavigator||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis.navigator instanceof WorkerNavigator),o=n?window:"undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis),a=""+o?.location,s=/iPad|iPhone|iPod/.test(navigator.userAgent),c=s&&"undefined"==typeof SharedWorker,u=(()=>{const e=navigator.userAgent.match(/Firefox[/\s](\d+\.\d+)/);return Array.isArray(e)&&e.length>=2?+e[1]:0})(),d=Boolean(n&&window.document.documentMode),f=!!navigator.sendBeacon},1117:(e,t,r)=>{r.d(t,{w:()=>o});var n=r(50);const i={agentIdentifier:"",ee:void 0};class o{constructor(e){try{if("object"!=typeof e)return(0,n.Z)("shared context requires an object as input");this.sharedContext={},Object.assign(this.sharedContext,i),Object.entries(e).forEach((e=>{let[t,r]=e;Object.keys(i).includes(t)&&(this.sharedContext[t]=r)}))}catch(e){(0,n.Z)("An error occured while setting SharedContext",e)}}}},8e3:(e,t,r)=>{r.d(t,{L:()=>d,R:()=>c});var n=r(2177),i=r(1284),o=r(4322),a=r(3325);const s={};function c(e,t){const r={staged:!1,priority:a.p[t]||0};u(e),s[e].get(t)||s[e].set(t,r)}function u(e){e&&(s[e]||(s[e]=new Map))}function d(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"",t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"feature";if(u(e),!e||!s[e].get(t))return a(t);s[e].get(t).staged=!0;const r=[...s[e]];function a(t){const r=e?n.ee.get(e):n.ee,a=o.X.handlers;if(r.backlog&&a){var s=r.backlog[t],c=a[t];if(c){for(var u=0;s&&u {let[t,r]=e;return r.staged}))&&(r.sort(((e,t)=>e[1].priority-t[1].priority)),r.forEach((e=>{let[t]=e;a(t)})))}function f(e,t){var r=e[1];(0,i.D)(t[r],(function(t,r){var n=e[0];if(r[0]===n){var i=r[1],o=e[3],a=e[2];i.apply(o,a)}}))}},2177:(e,t,r)=>{r.d(t,{c:()=>f,ee:()=>u});var n=r(8632),i=r(2210),o=r(1284),a=r(5763),s="nr@context";let c=(0,n.fP)();var u;function d(){}function f(e){return(0,i.X)(e,s,l)}function l(){return new d}function h(){u.aborted=!0,u.backlog={}}c.ee?u=c.ee:(u=function e(t,r){var n={},c={},f={},g=!1;try{g=16===r.length&&(0,a.OP)(r).isolatedBacklog}catch(e){}var p={on:b,addEventListener:b,removeEventListener:y,emit:v,get:x,listeners:w,context:m,buffer:A,abort:h,aborted:!1,isBuffering:E,debugId:r,backlog:g?{}:t&&"object"==typeof t.backlog?t.backlog:{}};return p;function m(e){return e&&e instanceof d?e:e?(0,i.X)(e,s,l):l()}function v(e,r,n,i,o){if(!1!==o&&(o=!0),!u.aborted||i){t&&o&&t.emit(e,r,n);for(var a=m(n),s=w(e),d=s.length,f=0;fn,p:()=>i});var n=r(2177).ee.get("handle");function i(e,t,r,i,o){o?(o.buffer([e],i),o.emit(e,t,r)):(n.buffer([e],i),n.emit(e,t,r))}},4322:(e,t,r)=>{r.d(t,{X:()=>o});var n=r(5546);o.on=a;var i=o.handlers={};function o(e,t,r,o){a(o||n.E,i,e,t,r)}function a(e,t,r,i,o){o||(o="feature"),e||(e=n.E);var a=t[o]=t[o]||{};(a[r]=a[r]||[]).push([e,i])}},3239:(e,t,r)=>{r.d(t,{bP:()=>s,iz:()=>c,m$:()=>a});var n=r(385);let i=!1,o=!1;try{const e={get passive(){return i=!0,!1},get signal(){return o=!0,!1}};n._A.addEventListener("test",null,e),n._A.removeEventListener("test",null,e)}catch(e){}function a(e,t){return i||o?{capture:!!e,passive:i,signal:t}:!!e}function s(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2],n=arguments.length>3?arguments[3]:void 0;window.addEventListener(e,t,a(r,n))}function c(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2],n=arguments.length>3?arguments[3]:void 0;document.addEventListener(e,t,a(r,n))}},4402:(e,t,r)=>{r.d(t,{Ht:()=>u,M:()=>c,Rl:()=>a,ky:()=>s});var n=r(385);const i="xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx";function o(e,t){return e?15&e[t]:16*Math.random()|0}function a(){const e=n._A?.crypto||n._A?.msCrypto;let t,r=0;return e&&e.getRandomValues&&(t=e.getRandomValues(new Uint8Array(31))),i.split("").map((e=>"x"===e?o(t,++r).toString(16):"y"===e?(3&o()|8).toString(16):e)).join("")}function s(e){const t=n._A?.crypto||n._A?.msCrypto;let r,i=0;t&&t.getRandomValues&&(r=t.getRandomValues(new Uint8Array(31)));const a=[];for(var s=0;s {r.d(t,{Bq:()=>n,Hb:()=>o,oD:()=>i});const n="NRBA",i=144e5,o=18e5},7894:(e,t,r)=>{function n(){return Math.round(performance.now())}r.d(t,{z:()=>n})},7243:(e,t,r)=>{r.d(t,{e:()=>o});var n=r(385),i={};function o(e){if(e in i)return i[e];if(0===(e||"").indexOf("data:"))return{protocol:"data"};let t;var r=n._A?.location,o={};if(n.il)t=document.createElement("a"),t.href=e;else try{t=new URL(e,r.href)}catch(e){return o}o.port=t.port;var a=t.href.split("://");!o.port&&a[1]&&(o.port=a[1].split("/")[0].split("@").pop().split(":")[1]),o.port&&"0"!==o.port||(o.port="https"===a[0]?"443":"80"),o.hostname=t.hostname||r.hostname,o.pathname=t.pathname,o.protocol=a[0],"/"!==o.pathname.charAt(0)&&(o.pathname="/"+o.pathname);var s=!t.protocol||":"===t.protocol||t.protocol===r.protocol,c=t.hostname===r.hostname&&t.port===r.port;return o.sameOrigin=s&&(!t.hostname||c),"/"===o.pathname&&(i[e]=o),o}},50:(e,t,r)=>{function n(e,t){"function"==typeof console.warn&&(console.warn("New Relic: ".concat(e)),t&&console.warn(t))}r.d(t,{Z:()=>n})},2587:(e,t,r)=>{r.d(t,{N:()=>c,T:()=>u});var n=r(2177),i=r(5546),o=r(8e3),a=r(3325);const s={stn:[a.D.sessionTrace],err:[a.D.jserrors,a.D.metrics],ins:[a.D.pageAction],spa:[a.D.spa],sr:[a.D.sessionReplay,a.D.sessionTrace]};function c(e,t){const r=n.ee.get(t);e&&"object"==typeof e&&(Object.entries(e).forEach((e=>{let[t,n]=e;void 0===u[t]&&(s[t]?s[t].forEach((e=>{n?(0,i.p)("feat-"+t,[],void 0,e,r):(0,i.p)("block-"+t,[],void 0,e,r),(0,i.p)("rumresp-"+t,[Boolean(n)],void 0,e,r)})):n&&(0,i.p)("feat-"+t,[],void 0,void 0,r),u[t]=Boolean(n))})),Object.keys(s).forEach((e=>{void 0===u[e]&&(s[e]?.forEach((t=>(0,i.p)("rumresp-"+e,[!1],void 0,t,r))),u[e]=!1)})),(0,o.L)(t,a.D.pageViewEvent))}const u={}},2210:(e,t,r)=>{r.d(t,{X:()=>i});var n=Object.prototype.hasOwnProperty;function i(e,t,r){if(n.call(e,t))return e[t];var i=r();if(Object.defineProperty&&Object.keys)try{return Object.defineProperty(e,t,{value:i,writable:!0,enumerable:!1}),i}catch(e){}return e[t]=i,i}},1284:(e,t,r)=>{r.d(t,{D:()=>n});const n=(e,t)=>Object.entries(e||{}).map((e=>{let[r,n]=e;return t(r,n)}))},4351:(e,t,r)=>{r.d(t,{P:()=>o});var n=r(2177);const i=()=>{const e=new WeakSet;return(t,r)=>{if("object"==typeof r&&null!==r){if(e.has(r))return;e.add(r)}return r}};function o(e){try{return JSON.stringify(e,i())}catch(e){try{n.ee.emit("internal-error",[e])}catch(e){}}}},3960:(e,t,r)=>{r.d(t,{K:()=>a,b:()=>o});var n=r(3239);function i(){return"undefined"==typeof document||"complete"===document.readyState}function o(e,t){if(i())return e();(0,n.bP)("load",e,t)}function a(e){if(i())return e();(0,n.iz)("DOMContentLoaded",e)}},8632:(e,t,r)=>{r.d(t,{EZ:()=>u,Qy:()=>c,ce:()=>o,fP:()=>a,gG:()=>d,mF:()=>s});var n=r(7894),i=r(385);const o={beacon:"bam.nr-data.net",errorBeacon:"bam.nr-data.net"};function a(){return i._A.NREUM||(i._A.NREUM={}),void 0===i._A.newrelic&&(i._A.newrelic=i._A.NREUM),i._A.NREUM}function s(){let e=a();return e.o||(e.o={ST:i._A.setTimeout,SI:i._A.setImmediate,CT:i._A.clearTimeout,XHR:i._A.XMLHttpRequest,REQ:i._A.Request,EV:i._A.Event,PR:i._A.Promise,MO:i._A.MutationObserver,FETCH:i._A.fetch}),e}function c(e,t,r){let i=a();const o=i.initializedAgents||{},s=o[e]||{};return Object.keys(s).length||(s.initializedAt={ms:(0,n.z)(),date:new Date}),i.initializedAgents={...o,[e]:{...s,[r]:t}},i}function u(e,t){a()[e]=t}function d(){return function(){let e=a();const t=e.info||{};e.info={beacon:o.beacon,errorBeacon:o.errorBeacon,...t}}(),function(){let e=a();const t=e.init||{};e.init={...t}}(),s(),function(){let e=a();const t=e.loader_config||{};e.loader_config={...t}}(),a()}},7956:(e,t,r)=>{r.d(t,{N:()=>i});var n=r(3239);function i(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1],r=arguments.length>2?arguments[2]:void 0,i=arguments.length>3?arguments[3]:void 0;return void(0,n.iz)("visibilitychange",(function(){if(t)return void("hidden"==document.visibilityState&&e());e(document.visibilityState)}),r,i)}},1214:(e,t,r)=>{r.d(t,{em:()=>v,u5:()=>N,QU:()=>S,_L:()=>I,Gm:()=>L,Lg:()=>M,gy:()=>U,BV:()=>Q,Kf:()=>ee});var n=r(2177);const i="nr@original";var o=Object.prototype.hasOwnProperty,a=!1;function s(e,t){return e||(e=n.ee),r.inPlace=function(e,t,n,i,o){n||(n="");var a,s,c,u="-"===n.charAt(0);for(c=0;c 2?n-2:0),o=2;o {r(A[T],e,w),r(E[T],e,w)})),r(l._A,"fetch",y),t.on(y+"end",(function(e,r){var n=this;if(r){var i=r.headers.get("content-length");null!==i&&(n.rxSize=i),t.emit(y+"done",[null,r],n)}else t.emit(y+"done",[e],n)})),t}const O={},j=["pushState","replaceState"];function S(e){const t=function(e){return(e||n.ee).get("history")}(e);return!l.il||O[t.debugId]++||(O[t.debugId]=1,s(t).inPlace(window.history,j,"-")),t}var P=r(3239);const C={},R=["appendChild","insertBefore","replaceChild"];function I(e){const t=function(e){return(e||n.ee).get("jsonp")}(e);if(!l.il||C[t.debugId])return t;C[t.debugId]=!0;var r=s(t),i=/[?&](?:callback|cb)=([^&#]+)/,o=/(.*)\.([^.]+)/,a=/^(\w+)(\.|$)(.*)$/;function c(e,t){var r=e.match(a),n=r[1],i=r[3];return i?c(i,t[n]):t[n]}return r.inPlace(Node.prototype,R,"dom-"),t.on("dom-start",(function(e){!function(e){if(!e||"string"!=typeof e.nodeName||"script"!==e.nodeName.toLowerCase())return;if("function"!=typeof e.addEventListener)return;var n=(a=e.src,s=a.match(i),s?s[1]:null);var a,s;if(!n)return;var u=function(e){var t=e.match(o);if(t&&t.length>=3)return{key:t[2],parent:c(t[1],window)};return{key:e,parent:window}}(n);if("function"!=typeof u.parent[u.key])return;var d={};function f(){t.emit("jsonp-end",[],d),e.removeEventListener("load",f,(0,P.m$)(!1)),e.removeEventListener("error",l,(0,P.m$)(!1))}function l(){t.emit("jsonp-error",[],d),t.emit("jsonp-end",[],d),e.removeEventListener("load",f,(0,P.m$)(!1)),e.removeEventListener("error",l,(0,P.m$)(!1))}r.inPlace(u.parent,[u.key],"cb-",d),e.addEventListener("load",f,(0,P.m$)(!1)),e.addEventListener("error",l,(0,P.m$)(!1)),t.emit("new-jsonp",[e.src],d)}(e[0])})),t}var k=r(5763);const H={};function L(e){const t=function(e){return(e||n.ee).get("mutation")}(e);if(!l.il||H[t.debugId])return t;H[t.debugId]=!0;var r=s(t),i=k.Yu.MO;return i&&(window.MutationObserver=function(e){return this instanceof i?new i(r(e,"fn-")):i.apply(this,arguments)},MutationObserver.prototype=i.prototype),t}const z={};function M(e){const t=function(e){return(e||n.ee).get("promise")}(e);if(z[t.debugId])return t;z[t.debugId]=!0;var r=n.c,o=s(t),a=k.Yu.PR;return a&&function(){function e(r){var n=t.context(),i=o(r,"executor-",n,null,!1);const s=Reflect.construct(a,[i],e);return t.context(s).getCtx=function(){return n},s}l._A.Promise=e,Object.defineProperty(e,"name",{value:"Promise"}),e.toString=function(){return a.toString()},Object.setPrototypeOf(e,a),["all","race"].forEach((function(r){const n=a[r];e[r]=function(e){let i=!1;[...e||[]].forEach((e=>{this.resolve(e).then(a("all"===r),a(!1))}));const o=n.apply(this,arguments);return o;function a(e){return function(){t.emit("propagate",[null,!i],o,!1,!1),i=i||!e}}}})),["resolve","reject"].forEach((function(r){const n=a[r];e[r]=function(e){const r=n.apply(this,arguments);return e!==r&&t.emit("propagate",[e,!0],r,!1,!1),r}})),e.prototype=a.prototype;const n=a.prototype.then;a.prototype.then=function(){var e=this,i=r(e);i.promise=e;for(var a=arguments.length,s=new Array(a),c=0;c e())),t};function m(e,t){i.inPlace(t,["onreadystatechange"],"fn-",E)}function b(){var e=this,t=r.context(e);e.readyState>3&&!t.resolved&&(t.resolved=!0,r.emit("xhr-resolved",[],e)),i.inPlace(e,f,"fn-",E)}if(function(e,t){for(var r in e)t[r]=e[r]}(o,p),p.prototype=o.prototype,i.inPlace(p.prototype,J,"-xhr-",E),r.on("send-xhr-start",(function(e,t){m(e,t),function(e){h.push(e),a&&(y?y.then(A):u?u(A):(w=-w,x.data=w))}(t)})),r.on("open-xhr-start",m),a){var y=c&&c.resolve();if(!u&&!c){var w=1,x=document.createTextNode(w);new a(A).observe(x,{characterData:!0})}}else t.on("fn-end",(function(e){e[0]&&e[0].type===d||A()}));function A(){for(var e=0;e {r.d(t,{t:()=>n});const n=r(3325).D.ajax},6660:(e,t,r)=>{r.d(t,{A:()=>i,t:()=>n});const n=r(3325).D.jserrors,i="nr@seenError"},3081:(e,t,r)=>{r.d(t,{gF:()=>o,mY:()=>i,t9:()=>n,vz:()=>s,xS:()=>a});const n=r(3325).D.metrics,i="sm",o="cm",a="storeSupportabilityMetrics",s="storeEventMetrics"},4649:(e,t,r)=>{r.d(t,{t:()=>n});const n=r(3325).D.pageAction},7633:(e,t,r)=>{r.d(t,{Dz:()=>i,OJ:()=>a,qw:()=>o,t9:()=>n});const n=r(3325).D.pageViewEvent,i="firstbyte",o="domcontent",a="windowload"},9251:(e,t,r)=>{r.d(t,{t:()=>n});const n=r(3325).D.pageViewTiming},3614:(e,t,r)=>{r.d(t,{BST_RESOURCE:()=>i,END:()=>s,FEATURE_NAME:()=>n,FN_END:()=>u,FN_START:()=>c,PUSH_STATE:()=>d,RESOURCE:()=>o,START:()=>a});const n=r(3325).D.sessionTrace,i="bstResource",o="resource",a="-start",s="-end",c="fn"+a,u="fn"+s,d="pushState"},7836:(e,t,r)=>{r.d(t,{BODY:()=>A,CB_END:()=>E,CB_START:()=>u,END:()=>x,FEATURE_NAME:()=>i,FETCH:()=>_,FETCH_BODY:()=>v,FETCH_DONE:()=>m,FETCH_START:()=>p,FN_END:()=>c,FN_START:()=>s,INTERACTION:()=>l,INTERACTION_API:()=>d,INTERACTION_EVENTS:()=>o,JSONP_END:()=>b,JSONP_NODE:()=>g,JS_TIME:()=>T,MAX_TIMER_BUDGET:()=>a,REMAINING:()=>f,SPA_NODE:()=>h,START:()=>w,originalSetTimeout:()=>y});var n=r(5763);const i=r(3325).D.spa,o=["click","submit","keypress","keydown","keyup","change"],a=999,s="fn-start",c="fn-end",u="cb-start",d="api-ixn-",f="remaining",l="interaction",h="spaNode",g="jsonpNode",p="fetch-start",m="fetch-done",v="fetch-body-",b="jsonp-end",y=n.Yu.ST,w="-start",x="-end",A="-body",E="cb"+x,T="jsTime",_="fetch"},5938:(e,t,r)=>{r.d(t,{W:()=>o});var n=r(5763),i=r(2177);class o{constructor(e,t,r){this.agentIdentifier=e,this.aggregator=t,this.ee=i.ee.get(e,(0,n.OP)(this.agentIdentifier).isolatedBacklog),this.featureName=r,this.blocked=!1}}},9144:(e,t,r)=>{r.d(t,{j:()=>m});var n=r(3325),i=r(5763),o=r(5546),a=r(2177),s=r(7894),c=r(8e3),u=r(3960),d=r(385),f=r(50),l=r(3081),h=r(8632);function g(){const e=(0,h.gG)();["setErrorHandler","finished","addToTrace","inlineHit","addRelease","addPageAction","setCurrentRouteName","setPageViewName","setCustomAttribute","interaction","noticeError","setUserId"].forEach((t=>{e[t]=function(){for(var r=arguments.length,n=new Array(r),i=0;i 1?r-1:0),i=1;i {e.exposed&&e.api[t]&&o.push(e.api[t](...n))})),o.length>1?o:o[0]}(t,...n)}}))}var p=r(2587);function m(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{},m=arguments.length>2?arguments[2]:void 0,v=arguments.length>3?arguments[3]:void 0,{init:b,info:y,loader_config:w,runtime:x={loaderType:m},exposed:A=!0}=t;const E=(0,h.gG)();y||(b=E.init,y=E.info,w=E.loader_config),(0,i.Dg)(e,b||{}),(0,i.GE)(e,w||{}),(0,i.sU)(e,x),y.jsAttributes??={},d.v6&&(y.jsAttributes.isWorker=!0),(0,i.CX)(e,y),g();const T=function(e,t){t||(0,c.R)(e,"api");const h={};var g=a.ee.get(e),p=g.get("tracer"),m="api-",v=m+"ixn-";function b(t,r,n,o){const a=(0,i.C5)(e);return null===r?delete a.jsAttributes[t]:(0,i.CX)(e,{...a,jsAttributes:{...a.jsAttributes,[t]:r}}),x(m,n,!0,o||null===r?"session":void 0)(t,r)}function y(){}["setErrorHandler","finished","addToTrace","inlineHit","addRelease"].forEach((e=>h[e]=x(m,e,!0,"api"))),h.addPageAction=x(m,"addPageAction",!0,n.D.pageAction),h.setCurrentRouteName=x(m,"routeName",!0,n.D.spa),h.setPageViewName=function(t,r){if("string"==typeof t)return"/"!==t.charAt(0)&&(t="/"+t),(0,i.OP)(e).customTransaction=(r||"http://custom.transaction")+t,x(m,"setPageViewName",!0)()},h.setCustomAttribute=function(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2];if("string"==typeof e){if(["string","number"].includes(typeof t)||null===t)return b(e,t,"setCustomAttribute",r);(0,f.Z)("Failed to execute setCustomAttribute.\nNon-null value must be a string or number type, but a type of was provided."))}else(0,f.Z)("Failed to execute setCustomAttribute.\nName must be a string type, but a type of was provided."))},h.setUserId=function(e){if("string"==typeof e||null===e)return b("enduser.id",e,"setUserId",!0);(0,f.Z)("Failed to execute setUserId.\nNon-null value must be a string type, but a type of was provided."))},h.interaction=function(){return(new y).get()};var w=y.prototype={createTracer:function(e,t){var r={},i=this,a="function"==typeof t;return(0,o.p)(v+"tracer",[(0,s.z)(),e,r],i,n.D.spa,g),function(){if(p.emit((a?"":"no-")+"fn-start",[(0,s.z)(),i,a],r),a)try{return t.apply(this,arguments)}catch(e){throw p.emit("fn-err",[arguments,this,"string"==typeof e?new Error(e):e],r),e}finally{p.emit("fn-end",[(0,s.z)()],r)}}}};function x(e,t,r,i){return function(){return(0,o.p)(l.xS,["API/"+t+"/called"],void 0,n.D.metrics,g),i&&(0,o.p)(e+t,[(0,s.z)(),...arguments],r?null:this,i,g),r?void 0:this}}function A(){r.e(439).then(r.bind(r,7438)).then((t=>{let{setAPI:r}=t;r(e),(0,c.L)(e,"api")})).catch((()=>(0,f.Z)("Downloading runtime APIs failed...")))}return["actionText","setName","setAttribute","save","ignore","onEnd","getContext","end","get"].forEach((e=>{w[e]=x(v,e,void 0,n.D.spa)})),h.noticeError=function(e,t){"string"==typeof e&&(e=new Error(e)),(0,o.p)(l.xS,["API/noticeError/called"],void 0,n.D.metrics,g),(0,o.p)("err",[e,(0,s.z)(),!1,t],void 0,n.D.jserrors,g)},d.il?(0,u.b)((()=>A()),!0):A(),h}(e,v);return(0,h.Qy)(e,T,"api"),(0,h.Qy)(e,A,"exposed"),(0,h.EZ)("activatedFeatures",p.T),T}},3325:(e,t,r)=>{r.d(t,{D:()=>n,p:()=>i});const n={ajax:"ajax",jserrors:"jserrors",metrics:"metrics",pageAction:"page_action",pageViewEvent:"page_view_event",pageViewTiming:"page_view_timing",sessionReplay:"session_replay",sessionTrace:"session_trace",spa:"spa"},i={[n.pageViewEvent]:1,[n.pageViewTiming]:2,[n.metrics]:3,[n.jserrors]:4,[n.ajax]:5,[n.sessionTrace]:6,[n.pageAction]:7,[n.spa]:8,[n.sessionReplay]:9}}},n={};function i(e){var t=n[e];if(void 0!==t)return t.exports;var o=n[e]={exports:{}};return r[e](o,o.exports,i),o.exports}i.m=r,i.d=(e,t)=>{for(var r in t)i.o(t,r)&&!i.o(e,r)&&Object.defineProperty(e,r,{enumerable:!0,get:t[r]})},i.f={},i.e=e=>Promise.all(Object.keys(i.f).reduce(((t,r)=>(i.f[r](e,t),t)),[])),i.u=e=>(({78:"page_action-aggregate",147:"metrics-aggregate",242:"session-manager",317:"jserrors-aggregate",348:"page_view_timing-aggregate",412:"lazy-feature-loader",439:"async-api",538:"recorder",590:"session_replay-aggregate",675:"compressor",733:"session_trace-aggregate",786:"page_view_event-aggregate",873:"spa-aggregate",898:"ajax-aggregate"}[e]||e)+"."+{78:"ac76d497",147:"3dc53903",148:"1a20d5fe",242:"2a64278a",317:"49e41428",348:"bd6de33a",412:"2f55ce66",439:"30bd804e",538:"1b18459f",590:"cf0efb30",675:"ae9f91a8",733:"83105561",786:"06482edd",860:"03a8b7a5",873:"e6b09d52",898:"998ef92b"}[e]+"-1.236.0.min.js"),i.o=(e,t)=>Object.prototype.hasOwnProperty.call(e,t),e={},t="NRBA:",i.l=(r,n,o,a)=>{if(e[r])e[r].push(n);else{var s,c;if(void 0!==o)for(var u=document.getElementsByTagName("script"),d=0;d {s.onerror=s.onload=null,clearTimeout(h);var i=e[r];if(delete e[r],s.parentNode&&s.parentNode.removeChild(s),i&&i.forEach((e=>e(n))),t)return t(n)},h=setTimeout(l.bind(null,void 0,{type:"timeout",target:s}),12e4);s.onerror=l.bind(null,s.onerror),s.onload=l.bind(null,s.onload),c&&document.head.appendChild(s)}},i.r=e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},i.j=364,i.p="https://js-agent.newrelic.com/",(()=>{var e={364:0,953:0};i.f.j=(t,r)=>{var n=i.o(e,t)?e[t]:void 0;if(0!==n)if(n)r.push(n[2]);else{var o=new Promise(((r,i)=>n=e[t]=[r,i]));r.push(n[2]=o);var a=i.p+i.u(t),s=new Error;i.l(a,(r=>{if(i.o(e,t)&&(0!==(n=e[t])&&(e[t]=void 0),n)){var o=r&&("load"===r.type?"missing":r.type),a=r&&r.target&&r.target.src;s.message="Loading chunk "+t+" failed.\n("+o+": "+a+")",s.name="ChunkLoadError",s.type=o,s.request=a,n[1](s)}}),"chunk-"+t,t)}};var t=(t,r)=>{var n,o,[a,s,c]=r,u=0;if(a.some((t=>0!==e[t]))){for(n in s)i.o(s,n)&&(i.m[n]=s[n]);if(c)c(i)}for(t&&t(r);u {i.r(o);var e=i(3325),t=i(5763);const r=Object.values(e.D);function n(e){const n={};return r.forEach((r=>{n[r]=function(e,r){return!1!==(0,t.Mt)(r,"".concat(e,".enabled"))}(r,e)})),n}var a=i(9144);var s=i(5546),c=i(385),u=i(8e3),d=i(5938),f=i(3960),l=i(50);class h extends d.W{constructor(e,t,r){let n=!(arguments.length>3&&void 0!==arguments[3])||arguments[3];super(e,t,r),this.auto=n,this.abortHandler,this.featAggregate,this.onAggregateImported,n&&(0,u.R)(e,r)}importAggregator(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(this.featAggregate||!this.auto)return;const r=c.il&&!0===(0,t.Mt)(this.agentIdentifier,"privacy.cookies_enabled");let n;this.onAggregateImported=new Promise((e=>{n=e}));const o=async()=>{let t;try{if(r){const{setupAgentSession:e}=await Promise.all([i.e(860),i.e(242)]).then(i.bind(i,3228));t=e(this.agentIdentifier)}}catch(e){(0,l.Z)("A problem occurred when starting up session manager. This page will not start or extend any session.",e)}try{if(!this.shouldImportAgg(this.featureName,t))return void(0,u.L)(this.agentIdentifier,this.featureName);const{lazyFeatureLoader:r}=await i.e(412).then(i.bind(i,8582)),{Aggregate:o}=await r(this.featureName,"aggregate");this.featAggregate=new o(this.agentIdentifier,this.aggregator,e),n(!0)}catch(e){(0,l.Z)("Downloading and initializing ".concat(this.featureName," failed..."),e),this.abortHandler?.(),n(!1)}};c.il?(0,f.b)((()=>o()),!0):o()}shouldImportAgg(r,n){return r!==e.D.sessionReplay||!1!==(0,t.Mt)(this.agentIdentifier,"session_trace.enabled")&&(!!n?.isNew||!!n?.state.sessionReplay)}}var g=i(7633),p=i(7894);class m extends h{static featureName=g.t9;constructor(r,n){let i=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];if(super(r,n,g.t9,i),("undefined"==typeof PerformanceNavigationTiming||c.Tt)&&"undefined"!=typeof PerformanceTiming){const n=(0,t.OP)(r);n[g.Dz]=Math.max(Date.now()-n.offset,0),(0,f.K)((()=>n[g.qw]=Math.max((0,p.z)()-n[g.Dz],0))),(0,f.b)((()=>{const t=(0,p.z)();n[g.OJ]=Math.max(t-n[g.Dz],0),(0,s.p)("timing",["load",t],void 0,e.D.pageViewTiming,this.ee)}))}this.importAggregator()}}var v=i(1117),b=i(1284);class y extends v.w{constructor(e){super(e),this.aggregatedData={}}store(e,t,r,n,i){var o=this.getBucket(e,t,r,i);return o.metrics=function(e,t){t||(t={count:0});return t.count+=1,(0,b.D)(e,(function(e,r){t[e]=w(r,t[e])})),t}(n,o.metrics),o}merge(e,t,r,n,i){var o=this.getBucket(e,t,n,i);if(o.metrics){var a=o.metrics;a.count+=r.count,(0,b.D)(r,(function(e,t){if("count"!==e){var n=a[e],i=r[e];i&&!i.c?a[e]=w(i.t,n):a[e]=function(e,t){if(!t)return e;t.c||(t=x(t.t));return t.min=Math.min(e.min,t.min),t.max=Math.max(e.max,t.max),t.t+=e.t,t.sos+=e.sos,t.c+=e.c,t}(i,a[e])}}))}else o.metrics=r}storeMetric(e,t,r,n){var i=this.getBucket(e,t,r);return i.stats=w(n,i.stats),i}getBucket(e,t,r,n){this.aggregatedData[e]||(this.aggregatedData[e]={});var i=this.aggregatedData[e][t];return i||(i=this.aggregatedData[e][t]={params:r||{}},n&&(i.custom=n)),i}get(e,t){return t?this.aggregatedData[e]&&this.aggregatedData[e][t]:this.aggregatedData[e]}take(e){for(var t={},r="",n=!1,i=0;i t.max&&(t.max=e),e 2&&void 0!==arguments[2])||arguments[2];super(e,r,j.t,n),c.il&&((0,t.OP)(e).initHidden=Boolean("hidden"===document.visibilityState),(0,N.N)((()=>(0,s.p)("docHidden",[(0,p.z)()],void 0,j.t,this.ee)),!0),(0,O.bP)("pagehide",(()=>(0,s.p)("winPagehide",[(0,p.z)()],void 0,j.t,this.ee))),this.importAggregator())}}var P=i(3081);class C extends h{static featureName=P.t9;constructor(e,t){let r=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];super(e,t,P.t9,r),this.importAggregator()}}var R,I=i(2210),k=i(1214),H=i(2177),L={};try{R=localStorage.getItem("__nr_flags").split(","),console&&"function"==typeof console.log&&(L.console=!0,-1!==R.indexOf("dev")&&(L.dev=!0),-1!==R.indexOf("nr_dev")&&(L.nrDev=!0))}catch(e){}function z(e){try{L.console&&z(e)}catch(e){}}L.nrDev&&H.ee.on("internal-error",(function(e){z(e.stack)})),L.dev&&H.ee.on("fn-err",(function(e,t,r){z(r.stack)})),L.dev&&(z("NR AGENT IN DEVELOPMENT MODE"),z("flags: "+(0,b.D)(L,(function(e,t){return e})).join(", ")));var M=i(6660);class B extends h{static featureName=M.t;constructor(r,n){let i=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];super(r,n,M.t,i),this.skipNext=0;try{this.removeOnAbort=new AbortController}catch(e){}const o=this;o.ee.on("fn-start",(function(e,t,r){o.abortHandler&&(o.skipNext+=1)})),o.ee.on("fn-err",(function(t,r,n){o.abortHandler&&!n[M.A]&&((0,I.X)(n,M.A,(function(){return!0})),this.thrown=!0,(0,s.p)("err",[n,(0,p.z)()],void 0,e.D.jserrors,o.ee))})),o.ee.on("fn-end",(function(){o.abortHandler&&!this.thrown&&o.skipNext>0&&(o.skipNext-=1)})),o.ee.on("internal-error",(function(t){(0,s.p)("ierr",[t,(0,p.z)(),!0],void 0,e.D.jserrors,o.ee)})),this.origOnerror=c._A.onerror,c._A.onerror=this.onerrorHandler.bind(this),c._A.addEventListener("unhandledrejection",(t=>{const r=function(e){let t="Unhandled Promise Rejection: ";if(e instanceof Error)try{return e.message=t+e.message,e}catch(t){return e}if(void 0===e)return new Error(t);try{return new Error(t+(0,D.P)(e))}catch(e){return new Error(t)}}(t.reason);(0,s.p)("err",[r,(0,p.z)(),!1,{unhandledPromiseRejection:1}],void 0,e.D.jserrors,this.ee)}),(0,O.m$)(!1,this.removeOnAbort?.signal)),(0,k.gy)(this.ee),(0,k.BV)(this.ee),(0,k.em)(this.ee),(0,t.OP)(r).xhrWrappable&&(0,k.Kf)(this.ee),this.abortHandler=this.#e,this.importAggregator()}#e(){this.removeOnAbort?.abort(),this.abortHandler=void 0}onerrorHandler(t,r,n,i,o){"function"==typeof this.origOnerror&&this.origOnerror(...arguments);try{this.skipNext?this.skipNext-=1:(0,s.p)("err",[o||new F(t,r,n),(0,p.z)()],void 0,e.D.jserrors,this.ee)}catch(t){try{(0,s.p)("ierr",[t,(0,p.z)(),!0],void 0,e.D.jserrors,this.ee)}catch(e){}}return!1}}function F(e,t,r){this.message=e||"Uncaught error with no additional information",this.sourceURL=t,this.line=r}let U=1;const q="nr@id";function G(e){const t=typeof e;return!e||"object"!==t&&"function"!==t?-1:e===c._A?0:(0,I.X)(e,q,(function(){return U++}))}function V(e){if("string"==typeof e&&e.length)return e.length;if("object"==typeof e){if("undefined"!=typeof ArrayBuffer&&e instanceof ArrayBuffer&&e.byteLength)return e.byteLength;if("undefined"!=typeof Blob&&e instanceof Blob&&e.size)return e.size;if(!("undefined"!=typeof FormData&&e instanceof FormData))try{return(0,D.P)(e).length}catch(e){return}}}var X=i(7243);class W{constructor(e){this.agentIdentifier=e,this.generateTracePayload=this.generateTracePayload.bind(this),this.shouldGenerateTrace=this.shouldGenerateTrace.bind(this)}generateTracePayload(e){if(!this.shouldGenerateTrace(e))return null;var r=(0,t.DL)(this.agentIdentifier);if(!r)return null;var n=(r.accountID||"").toString()||null,i=(r.agentID||"").toString()||null,o=(r.trustKey||"").toString()||null;if(!n||!i)return null;var a=(0,_.M)(),s=(0,_.Ht)(),c=Date.now(),u={spanId:a,traceId:s,timestamp:c};return(e.sameOrigin||this.isAllowedOrigin(e)&&this.useTraceContextHeadersForCors())&&(u.traceContextParentHeader=this.generateTraceContextParentHeader(a,s),u.traceContextStateHeader=this.generateTraceContextStateHeader(a,c,n,i,o)),(e.sameOrigin&&!this.excludeNewrelicHeader()||!e.sameOrigin&&this.isAllowedOrigin(e)&&this.useNewrelicHeaderForCors())&&(u.newrelicHeader=this.generateTraceHeader(a,s,c,n,i,o)),u}generateTraceContextParentHeader(e,t){return"00-"+t+"-"+e+"-01"}generateTraceContextStateHeader(e,t,r,n,i){return i+"@nr=0-1-"+r+"-"+n+"-"+e+"----"+t}generateTraceHeader(e,t,r,n,i,o){if(!("function"==typeof c._A?.btoa))return null;var a={v:[0,1],d:{ty:"Browser",ac:n,ap:i,id:e,tr:t,ti:r}};return o&&n!==o&&(a.d.tk=o),btoa((0,D.P)(a))}shouldGenerateTrace(e){return this.isDtEnabled()&&this.isAllowedOrigin(e)}isAllowedOrigin(e){var r=!1,n={};if((0,t.Mt)(this.agentIdentifier,"distributed_tracing")&&(n=(0,t.P_)(this.agentIdentifier).distributed_tracing),e.sameOrigin)r=!0;else if(n.allowed_origins instanceof Array)for(var i=0;i 2&&void 0!==arguments[2])||arguments[2];super(r,n,Z.t,i),(0,t.OP)(r).xhrWrappable&&(this.dt=new W(r),this.handler=(e,t,r,n)=>(0,s.p)(e,t,r,n,this.ee),(0,k.u5)(this.ee),(0,k.Kf)(this.ee),function(r,n,i,o){function a(e){var t=this;t.totalCbs=0,t.called=0,t.cbTime=0,t.end=E,t.ended=!1,t.xhrGuids={},t.lastSize=null,t.loadCaptureCalled=!1,t.params=this.params||{},t.metrics=this.metrics||{},e.addEventListener("load",(function(r){_(t,e)}),(0,O.m$)(!1)),c.IF||e.addEventListener("progress",(function(e){t.lastSize=e.loaded}),(0,O.m$)(!1))}function s(e){this.params={method:e[0]},T(this,e[1]),this.metrics={}}function u(e,n){var i=(0,t.DL)(r);i.xpid&&this.sameOrigin&&n.setRequestHeader("X-NewRelic-ID",i.xpid);var a=o.generateTracePayload(this.parsedOrigin);if(a){var s=!1;a.newrelicHeader&&(n.setRequestHeader("newrelic",a.newrelicHeader),s=!0),a.traceContextParentHeader&&(n.setRequestHeader("traceparent",a.traceContextParentHeader),a.traceContextStateHeader&&n.setRequestHeader("tracestate",a.traceContextStateHeader),s=!0),s&&(this.dt=a)}}function d(e,t){var r=this.metrics,i=e[0],o=this;if(r&&i){var a=V(i);a&&(r.txSize=a)}this.startTime=(0,p.z)(),this.listener=function(e){try{"abort"!==e.type||o.loadCaptureCalled||(o.params.aborted=!0),("load"!==e.type||o.called===o.totalCbs&&(o.onloadCalled||"function"!=typeof t.onload)&&"function"==typeof o.end)&&o.end(t)}catch(e){try{n.emit("internal-error",[e])}catch(e){}}};for(var s=0;s 1?e[1]=i:e.push(i)}else e[0]&&e[0].headers&&s(e[0].headers,n)&&(this.dt=n);function s(e,t){var r=!1;return t.newrelicHeader&&(e.set("newrelic",t.newrelicHeader),r=!0),t.traceContextParentHeader&&(e.set("traceparent",t.traceContextParentHeader),t.traceContextStateHeader&&e.set("tracestate",t.traceContextStateHeader),r=!0),r}}function x(e,t){this.params={},this.metrics={},this.startTime=(0,p.z)(),this.dt=t,e.length>=1&&(this.target=e[0]),e.length>=2&&(this.opts=e[1]);var r,n=this.opts||{},i=this.target;"string"==typeof i?r=i:"object"==typeof i&&i instanceof Y?r=i.url:c._A?.URL&&"object"==typeof i&&i instanceof URL&&(r=i.href),T(this,r);var o=(""+(i&&i instanceof Y&&i.method||n.method||"GET")).toUpperCase();this.params.method=o,this.txSize=V(n.body)||0}function A(t,r){var n;this.endTime=(0,p.z)(),this.params||(this.params={}),this.params.status=r?r.status:0,"string"==typeof this.rxSize&&this.rxSize.length>0&&(n=+this.rxSize);var o={txSize:this.txSize,rxSize:n,duration:(0,p.z)()-this.startTime};i("xhr",[this.params,o,this.startTime,this.endTime,"fetch"],this,e.D.ajax)}function E(t){var r=this.params,n=this.metrics;if(!this.ended){this.ended=!0;for(var o=0;o 2&&void 0!==arguments[2])||arguments[2];super(e,t,we.t,r),this.importAggregator()}}new class{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:(0,_.ky)(16);c._A?(this.agentIdentifier=t,this.sharedAggregator=new y({agentIdentifier:this.agentIdentifier}),this.features={},this.desiredFeatures=new Set(e.features||[]),this.desiredFeatures.add(m),Object.assign(this,(0,a.j)(this.agentIdentifier,e,e.loaderType||"agent")),this.start()):(0,l.Z)("Failed to initial the agent. Could not determine the runtime environment.")}get config(){return{info:(0,t.C5)(this.agentIdentifier),init:(0,t.P_)(this.agentIdentifier),loader_config:(0,t.DL)(this.agentIdentifier),runtime:(0,t.OP)(this.agentIdentifier)}}start(){const t="features";try{const r=n(this.agentIdentifier),i=[...this.desiredFeatures];i.sort(((t,r)=>e.p[t.featureName]-e.p[r.featureName])),i.forEach((t=>{if(r[t.featureName]||t.featureName===e.D.pageViewEvent){const n=function(t){switch(t){case e.D.ajax:return[e.D.jserrors];case e.D.sessionTrace:return[e.D.ajax,e.D.pageViewEvent];case e.D.sessionReplay:return[e.D.sessionTrace];case e.D.pageViewTiming:return[e.D.pageViewEvent];default:return[]}}(t.featureName);n.every((e=>r[e]))||(0,l.Z)("".concat(t.featureName," is enabled but one or more dependent features has been disabled (").concat((0,D.P)(n),"). This may cause unintended consequences or missing data...")),this.features[t.featureName]=new t(this.agentIdentifier,this.sharedAggregator)}})),(0,T.Qy)(this.agentIdentifier,this.features,t)}catch(e){(0,l.Z)("Failed to initialize all enabled instrument classes (agent aborted) -",e);for(const e in this.features)this.features[e].abortHandler?.();const r=(0,T.fP)();return delete r.initializedAgents[this.agentIdentifier]?.api,delete r.initializedAgents[this.agentIdentifier]?.[t],delete this.sharedAggregator,r.ee?.abort(),delete r.ee?.get(this.agentIdentifier),!1}}}({features:[J,m,S,class extends h{static featureName=oe;constructor(t,r){if(super(t,r,oe,!(arguments.length>2&&void 0!==arguments[2])||arguments[2]),!c.il)return;const n=this.ee;let i;(0,k.QU)(n),this.eventsEE=(0,k.em)(n),this.eventsEE.on(se,(function(e,t){this.bstStart=(0,p.z)()})),this.eventsEE.on(ae,(function(t,r){(0,s.p)("bst",[t[0],r,this.bstStart,(0,p.z)()],void 0,e.D.sessionTrace,n)})),n.on(ce+ne,(function(e){this.time=(0,p.z)(),this.startPath=location.pathname+location.hash})),n.on(ce+ie,(function(t){(0,s.p)("bstHist",[location.pathname+location.hash,this.startPath,this.time],void 0,e.D.sessionTrace,n)}));try{i=new PerformanceObserver((t=>{const r=t.getEntries();(0,s.p)(te,[r],void 0,e.D.sessionTrace,n)})),i.observe({type:re,buffered:!0})}catch(e){}this.importAggregator({resourceObserver:i})}},C,xe,B,class extends h{static featureName=de;constructor(e,r){if(super(e,r,de,!(arguments.length>2&&void 0!==arguments[2])||arguments[2]),!c.il)return;if(!(0,t.OP)(e).xhrWrappable)return;try{this.removeOnAbort=new AbortController}catch(e){}let n,i=0;const o=this.ee.get("tracer"),a=(0,k._L)(this.ee),s=(0,k.Lg)(this.ee),u=(0,k.BV)(this.ee),d=(0,k.Kf)(this.ee),f=this.ee.get("events"),l=(0,k.u5)(this.ee),h=(0,k.QU)(this.ee),g=(0,k.Gm)(this.ee);function m(e,t){h.emit("newURL",[""+window.location,t])}function v(){i++,n=window.location.hash,this[ve]=(0,p.z)()}function b(){i--,window.location.hash!==n&&m(0,!0);var e=(0,p.z)();this[pe]=~~this[pe]+e-this[ve],this[ye]=e}function y(e,t){e.on(t,(function(){this[t]=(0,p.z)()}))}this.ee.on(ve,v),s.on(be,v),a.on(be,v),this.ee.on(ye,b),s.on(ge,b),a.on(ge,b),this.ee.buffer([ve,ye,"xhr-resolved"],this.featureName),f.buffer([ve],this.featureName),u.buffer(["setTimeout"+le,"clearTimeout"+fe,ve],this.featureName),d.buffer([ve,"new-xhr","send-xhr"+fe],this.featureName),l.buffer([me+fe,me+"-done",me+he+fe,me+he+le],this.featureName),h.buffer(["newURL"],this.featureName),g.buffer([ve],this.featureName),s.buffer(["propagate",be,ge,"executor-err","resolve"+fe],this.featureName),o.buffer([ve,"no-"+ve],this.featureName),a.buffer(["new-jsonp","cb-start","jsonp-error","jsonp-end"],this.featureName),y(l,me+fe),y(l,me+"-done"),y(a,"new-jsonp"),y(a,"jsonp-end"),y(a,"cb-start"),h.on("pushState-end",m),h.on("replaceState-end",m),window.addEventListener("hashchange",m,(0,O.m$)(!0,this.removeOnAbort?.signal)),window.addEventListener("load",m,(0,O.m$)(!0,this.removeOnAbort?.signal)),window.addEventListener("popstate",(function(){m(0,i>1)}),(0,O.m$)(!0,this.removeOnAbort?.signal)),this.abortHandler=this.#e,this.importAggregator()}#e(){this.removeOnAbort?.abort(),this.abortHandler=void 0}}],loaderType:"spa"})})(),window.NRBA=o})(); window.jQuery || document.write(' ') CKEDITOR_BASEPATH='https://f1000research.com/js/vendor/ckeditor/' window.reactTheme = 'research'; window.MathJax = { CommonHTML: { linebreaks: { automatic: true } }, 'HTML-CSS': { linebreaks: { automatic: true } }, SVG: { linebreaks: { automatic: true } }, AuthorInit: function() { MathJax.Hub.Register.MessageHook('End Process', function () { let timeout = false; // holder for timeout id const delay = 250; // delay after event is "complete" to run callback const reflowMath = function() { const dispFormulas = document.querySelectorAll('.disp-formula.panel'); if (!dispFormulas) { return; } for (const dispFormula of dispFormulas) { const child = dispFormula.querySelector('.MathJax_Preview').nextSibling.firstChild; const isMultiline = MathJax.Hub.getAllJax(dispFormula)[0].root.isMultiline; if (dispFormula.offsetWidth < child.offsetWidth || isMultiline) { MathJax.Hub.Queue(['Rerender', MathJax.Hub, dispFormula]); } } }; window.addEventListener('resize', function() { clearTimeout(timeout); // clear the timeout timeout = setTimeout(reflowMath, delay); // start timing for event "completion" }); }); }, }; if (window.location.hash == '#_=_'){ window.location = window.location.href.split('#')[0] } !function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function() {n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)} ;if(!f._fbq)f._fbq=n; n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0; t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window, document,'script','https://connect.facebook.net/en_US/fbevents.js'); fbq('init', '1641728616063202'); fbq('track', "PixelInitialized", {}); (function(h,o,t,j,a,r){ h.hj=h.hj||function(){(h.hj.q=h.hj.q||[]).push(arguments)}; h._hjSettings={hjid:2318163,hjsv:6}; a=o.getElementsByTagName('head')[0]; r=o.createElement('script');r.async=1; r.src=t+h._hjSettings.hjid+j+h._hjSettings.hjsv; a.appendChild(r); })(window,document,'https://static.hotjar.com/c/hotjar-','.js?sv='); search file_upload Submit your research search menu close search Browse Gateways & Collections How to Publish Submit your Research My Submissions Article Guidelines Article Guidelines (New Versions) Open Data, Software and Code Guidelines Open Data and Accessible Source Materials Guidelines (HSS) Open Data, Software and Code Guidelines (PSE) Prepublication Checks Production Process Posters and Slides Guidelines Document Guidelines Article Processing Charges Peer Review Finding Article Reviewers About How it Works For Reviewers Our Advisors Policies Glossary FAQs For Developers Newsroom Contact My Research Submissions Content and Tracking Alerts My Details Sign In file_upload Submit your research { "@context": "https://schema.org", "@type": "ScholarlyArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://f1000research.com/articles/15-508" }, "headline": "Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance...", "datePublished": "2026-04-13T12:40:46", "dateModified": "2026-04-13T12:40:46", "author": [ { "@type": "Person", "name": "Daniel Strech" } ], "publisher": { "@type": "Organization", "name": "F1000Research", "logo": { "@type": "ImageObject", "url": "https://f1000research.com/img/AMP/F1000Research_image.png", "height": 480, "width": 60 } }, "image": { "@type": "ImageObject", "url": "https://f1000research.com/img/AMP/F1000Research_image.png", "height": 1200, "width": 150 }, "description": " Background Operators of health data hubs and registries enable secondary use by implementing consent processes, privacy safeguards, access governance, data quality management, transparency, and stakeholder engagement. Ethical guidance is extensive, yet it rarely specifies operator-level practices or indicators that show whether governance performs well in routine use. This paper proposes an operator-focused framework that makes ethics implementable and assessable. Methods The framework synthesises international guidance, systematic reviews and other empirical work on governance gaps, and publicly available governance materials from major data infrastructures. Ethics practices were selected for conceptual distinctness and operator-level controllability, grouped into seven governance domains, and aligned with a PDCA (Plan–Do–Check–Act) cycle. For each practice, the framework provides illustrative audit items, descriptive metrics, and outcome indicators intended as adaptable references rather than prescriptive standards. Results Seven domains are covered: Informed Consent & Information, Privacy & Data Protection, Data Quality, Use & Access Governance, Incidental Findings, Stakeholder Engagement, and Project-Level Transparency. Each domain contains four PDCA-aligned practices with linked evaluation items. Discussion The framework shifts practical bioethics for secondary use from policy existence to demonstrable performance. It can support operator self-audit and proportionate oversight by funders, ethics committees, and stakeholder bodies, while remaining modular across legal and infrastructural contexts. It also provides a starting point for developing minimal, transparent reporting expectations to support trust-building governance. " } { "@context": "http://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": "1", "item": { "@id": "https://f1000research.com/", "name": "Home" } }, { "@type": "ListItem", "position": "2", "item": { "@id": "https://f1000research.com/browse/articles", "name": "Browse" } }, { "@type": "ListItem", "position": "3", "item": { "@id": "https://f1000research.com/articles/15-508/v1", "name": "Operationalising ethics in secondary health-data use: an operator-focused..." } } ] } Home Browse Operationalising ethics in secondary health-data use: an operator-focused... ALL Metrics - Views Downloads Get PDF Get XML Cite How to cite this article Strech D. Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance with audit and performance metrics [version 1; peer review: awaiting peer review] . F1000Research 2026, 15 :508 ( https://doi.org/10.12688/f1000research.179326.1 ) NOTE: If applicable, it is important to ensure the information in square brackets after the title is included in all citations of this article. Close Copy Citation Details Export Export Citation Sciwheel EndNote Ref. Manager Bibtex ProCite Sente EXPORT Select a format first Track Share ▬ ✚ Opinion Article Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance with audit and performance metrics [version 1; peer review: awaiting peer review] Daniel Strech https://orcid.org/0000-0002-9153-079X Daniel Strech https://orcid.org/0000-0002-9153-079X PUBLISHED 13 Apr 2026 Author details Author details QUEST Center for Responsible Research, Berlin Institute of Health at Charite, Berlin, Germany Daniel Strech Roles: Conceptualization, Formal Analysis, Methodology, Project Administration, Writing – Original Draft Preparation OPEN PEER REVIEW REVIEWER STATUS AWAITING PEER REVIEW This article is included in the Health Services gateway. Abstract Background Operators of health data hubs and registries enable secondary use by implementing consent processes, privacy safeguards, access governance, data quality management, transparency, and stakeholder engagement. Ethical guidance is extensive, yet it rarely specifies operator-level practices or indicators that show whether governance performs well in routine use. This paper proposes an operator-focused framework that makes ethics implementable and assessable. Methods The framework synthesises international guidance, systematic reviews and other empirical work on governance gaps, and publicly available governance materials from major data infrastructures. Ethics practices were selected for conceptual distinctness and operator-level controllability, grouped into seven governance domains, and aligned with a PDCA (Plan–Do–Check–Act) cycle. For each practice, the framework provides illustrative audit items, descriptive metrics, and outcome indicators intended as adaptable references rather than prescriptive standards. Results Seven domains are covered: Informed Consent & Information, Privacy & Data Protection, Data Quality, Use & Access Governance, Incidental Findings, Stakeholder Engagement, and Project-Level Transparency. Each domain contains four PDCA-aligned practices with linked evaluation items. Discussion The framework shifts practical bioethics for secondary use from policy existence to demonstrable performance. It can support operator self-audit and proportionate oversight by funders, ethics committees, and stakeholder bodies, while remaining modular across legal and infrastructural contexts. It also provides a starting point for developing minimal, transparent reporting expectations to support trust-building governance. READ ALL READ LESS Keywords secondary use; health data governance; ethics implementation; data access governance; audit and performance metrics; health data hubs Corresponding Author(s) Daniel Strech ( [email protected] ) Close Corresponding author: Daniel Strech Competing interests: The author served as spokesperson and remains a member of the German working group ‘Consent,’ which developed the broad consent model for the German Medical Informatics Initiative (MII). The author receives research funding related to the topics of this paper from MII consortia (HiGHmed, CAEHR) and from the EU-funded project More-EUROPA. The author was also part of an expert group that authored a report for the German Federal Ministry of Health outlining technical, legal, and ethical preconditions for responsible secondary use of health data. In addition, the author served as a member of two WHO working/review groups relevant to this topic: ‘Guidance for Ethical Review of Health Systems Research’ and ‘Ethics of Public Health Surveillance.’ Grant information: This work was supported by intramural funds from the Berlin Institute of Health at Charité – Universitätsmedizin Berlin, Germany. The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript. Copyright: © 2026 Strech D. This is an open access article distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. How to cite: Strech D. Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance with audit and performance metrics [version 1; peer review: awaiting peer review] . F1000Research 2026, 15 :508 ( https://doi.org/10.12688/f1000research.179326.1 ) First published: 13 Apr 2026, 15 :508 ( https://doi.org/10.12688/f1000research.179326.1 ) Latest published: 13 Apr 2026, 15 :508 ( https://doi.org/10.12688/f1000research.179326.1 ) Introduction Over the past decade, the secondary use of health data has evolved into a highly heterogeneous field, spanning retrospective analyses of electronic health records, prospective cohort studies, real-time surveillance infrastructures, and large-scale national platforms. This diversity reflects not only differences in data types and access models, but also varying regulatory traditions, governance capacities, and stakeholder expectations. 1 Examples of long-standing infrastructures include the Clinical Practice Research Datalink (CPRD, UK), 2 claims data repositories in the US (e.g., OptumLabs), and hospital-based disease registries operated by academic institutions. Earlier national flagships such as the UK Biobank paved the way, while more recent large-scale programmes, e.g. All of Us in the United States or the German Medical Informatics Initiative (MII), explicitly aim to serve multiple user groups, including academic research, public health and policy. Regardless of label, these infrastructures depend on operators who shoulder a long list of governance duties: maintaining system availability, enforcing privacy safeguards, implementing interoperability standards, curating data quality, selecting a consent model if needed, planning access procedures, engaging stakeholders and more. While all of these tasks have normative relevance, they differ in how directly they implement ethical values. Highly technical or operational activities (e.g., uptime, load balancing, budgeting) are guided primarily by IT and finance frameworks and express values only indirectly. By contrast, tasks such as protecting privacy, obtaining informed consent, ensuring data quality, or involving patients in governance processes directly translate aspirational norms into operator-controlled rules, procedures, and verifiable actions. This paper refers to such tasks as ethics practices. Taken together, they define the domain of normative governance : the set of responsibilities through which infrastructure operators concretely implement core ethical principles. For example, “respect for persons” is expressed through consent mechanisms and privacy safeguards, while “public value” is operationalized via data quality management and transparency regarding approved secondary uses and their results reporting. Normative governance: an underdefined field The maturity of ethics practices varies considerably. Some areas, such as privacy or data quality, are guided by extensive privacy standards (GDPR, HIPAA, ISO 27701) and by well-established data-quality frameworks (FAIR principles, Kahn et al. dimensions). 3 , 4 Others, such as consent models, access governance, or stakeholder engagement, remain heterogeneous, under-institutionalized, and difficult to evaluate. Although central to trust and accountability in data infrastructures, these practices are rarely treated as a coherent field with shared structures, expectations, or evaluative tools. The missing piece: a framework for mapping and evaluation What is still lacking is a structured approach to describe, organize, and assess these ethics practices. Unlike technical domains such as data architecture or cost allocation, which are supported by specialized toolkits and professional norms, normative governance remains fragmented. No widely accepted model captures the full range of ethics practices, their connection to ethical values, or the means by which their implementation can be evaluated. This paper proposes a framework that addresses this gap in two ways: first, by categorizing ethics practices across key governance domains (e.g. consent, data protection, access control); second, by linking each domain to relevant audit questions and evaluation criteria. The framework is not a prescriptive checklist but an orientation tool, intended to support operators in adapting, combining, or omitting elements based on their institutional context. Positioning within the landscape of existing ethics guidance Numerous bioethics contributions, international statements and best-practice guidelines have laid out the ethical principles for secondary data use. A systematic review of principles and norms in this area by Kalkman et al. synthesized four stable value clusters: (i) societal benefit & public value, (ii) respect for persons, (iii) fairness & data justice, and (iv) public trust & engagement. 5 These value clusters are echoed in reviews of patient and public attitudes 6 , 7 and in principle-oriented guidance such as the WMA Declaration of Taipei, 8 the OECD Recommendation on Health Data Governance 9 and the CIOMS International Ethical Guidelines. 10 Practice-oriented documents go a step further. The ISBER Best Practices 11 or the WHO policy and implementation guide on health-data reuse 12 provide detailed operational recommendations on biospecimen handling, data security, access procedures and quality control. Similarly, frameworks such as the UK Biobank Ethics & Governance Framework, 13 , 14 the All of Us Data-Access Framework 15 and the GA4GH Framework for Responsible Sharing of Genomic and Health-Related Data 16 set concrete standards for consent, privacy or tiered access. However, each addresses only selected ethics-practice domains and rarely embeds evaluation metrics. As a result, even the more detailed best-practice documents offer valuable guidance but do not yet provide an integrative, evaluable framework for ethics practices as a field in its own right. Methods Conceptual orientation The goal was to construct an operator-focused framework that couples widely accepted ethical values to actionable practices and a lean but meaningful evaluation tier. Knowledge inputs and scope Six knowledge streams informed the design: 1. International guidance or frameworks for secondary data use or its specific ethics practices 8 , 10 , 12 – 22 2. Systematic reviews on values and public attitudes anchoring the four aspirational norms 5 – 7 , 23 3. Governance-gap studies that document heterogeneous or missing practices 1 , 24 – 29 4. Practice-focused case literature on the implementation of specific ethics practices for secondary use 30 – 37 5. An expert report for the German Federal Ministry of Health that described technical, legal and ethical preconditions and success requirements for responsible secondary use. 38 6. Conceptual work on ethics implementation that stresses measurability. 39 – 41 Practice selection Source documents were scanned for recurring but distinct ethics practices such as consent, data protection or stakeholder engagement. Candidate practices were retained if they met two filters: 1) Conceptual distinctness – no thematic overlap with other candidates, and 2) Operator controllability – the platform can implement, mandate, or audit the activity. Each governance domain was then structured into four PDCA (Plan–Do–Check–Act)-aligned activities to reflect the dual goal of implementation and evaluation 42 : • Norm-Setting (Plan): Define and justify the ethics practice; • Operational (Do): Implement the practice and capture primary data; • Assurance (Check): Monitor implementation with metrics and judge effectiveness and quality; • Improvement (Act): Revise standards or processes when assurance findings or new requirements demand change. The list of ethics practices across the PDCA structure is deliberately illustrative, not comprehensive. An all-inclusive catalogue would be unmanageable, ignore context-specific tailoring and age rapidly. The framework therefore provides anchor practices in each domain—enough to guide gap analysis and stakeholder dialogue, while leaving space for operators to add, refine or merge practices as required. Evaluation layer For every ethics practice, the framework specifies: • an audit item verifying the presence and currency of policies or logs, and • descriptive and/or outcome metrics that feed the Assurance tier (e.g. completeness of key variables, consent-decline rate, access-review turnaround, follow-up completion for incidental findings). Plausibility check To verify the completeness and real-world applicability of the resulting list of ethics practices, the following plausibility checks were conducted. In a practice-guideline triangulation the list was cross-matched with five benchmark guidelines for secondary health-data use, namely. 8 – 12 In a real-world implementation scan the practices were mapped to governance artefacts from five well-documented platforms (UK Biobank, All of Us, PCORnet, German MII, GA4GH) and to 51 European patient registries reviewed by van den Akker et al. 25 Results Overview of the three-layer framework The framework translates four aspirational norms into illustrative ethics practices across seven governance domains ( Table 1 ) and couples each practice to evaluation items ( Table 2 ). Practices are organised along the Plan–Do–Check–Act (PDCA) logic, labelled Norm-Setting, Operational, Assurance and, where applicable, Improvement. Table 1. Seven governance domains with illustrative ethics practices aligned to the PDCA cycle. Domain Norm-setting practice (Plan) 1 Operational practice (Do) Assurance practice (Check) Improvement practice (Act) 2 Informed Consent & Information Select and justify the consent model (broad, waiver/opt-out); draft and approve participant information, consent documents, and guidance e.g. for consent procedures Collect consent and withdrawals; publish (version-controlled) documents Monitor consent/decline/withdrawal rates; test comprehension of participant information on a representative sample Revise materials and procedures Privacy & Data Protection Adopt a privacy & data-protection policy compliant with GDPR (or equivalent) and complete a DPIA/PIA Implement pseudonymisation, encryption and audit-log controls; maintain breach-response plan Audit logs monthly; conduct an annual penetration test Revise privacy and data protection measures Data Quality Adopt a data-quality framework aligned with Kahn et al. dimensions (completeness, plausibility, uniqueness, temporal consistency, bias) and FAIR metadata principles Run automated profiling & quality checks on each load; publish quarterly quality dashboard Benchmark key indicators; trigger bias review if coverage or completeness falls below threshold Remediate quality gaps (re-extract data or update curation rules) Use & Access Governance Specify eligibility, fairness and rejection criteria in a use&access policy, publish a data-transfer agreement template, adopt a conflicts-of-interest (COI) policy Execute a structured access checklist and sign data-transfer agreements, maintain an up-to-date COI register Track turnaround; analyse rejection reasons, review the COI register annually Revise policy and template Incidental-Finding Management Establish clinical-significance thresholds and minimum communication and follow-up guidances Run the IF workflow; record detection, disclosure and follow-up Calculate % actionable IFs communicated and follow-up completion Update thresholds and guidances Patient & Stakeholder Engagement Specify engagement measures (e.g. seats for patient representatives in U&A committee, annual consultation forums, user satisfaction surveys) Hold consultation forums and post summaries of feedback received Survey user/stakeholder satisfaction Update engagement measures Project-Level Transparency Define transparency rules for approved secondary-use projects such as prospective registration, public result reporting, and code sharing Maintain or cooperate with a public project register; collect result summaries and code uploads Measure % projects registered prospectively, % results posted, % code shared Revise transparency rules 1 Abbreviations: COI = conflict of interest; DPIA/PIA = (Data) Privacy Impact Assessment; IF = incidental finding; FAIR = Findable, Accessible, Interoperable, Reusable; 2 Executed when assurance results or legal/ethical updates indicate a need for change Table 2. Evaluation layer: Illustrative examples for audit, descriptive and outcome metrics for each ethics practice. Domain Audit items 1 Descriptive metrics 2 Quality/outcome metrics 3 Informed Consent & Information Consent-model file approved; latest info sheet online; staff training records Consent/decline/withdrawal rates; median dialogue duration Comprehension score ≥ 80% correct Privacy & Data Protection DPIA on file & reviewed annually; data-processing-agreement template current Number of log-exception alerts per month; encryption key rotations per year No critical pen-test findings open >30 days Data Quality Data-quality framework document available; latest dashboard ≤3 months old Completeness rate of key variables; number of plausibility fails Completeness ≥95% and plausibility error < 1% Use & Access Governance Use-and-access policy online; DTA template online Median turnaround days; number of requests & rejections 100% of veto-based rejections independently reviewed and documented quarterly Incidental-Finding Management Guidelines for IF communication and follow-up available Actionable IFs detected/disclosed; follow-ups initiated Follow-up completion ≥90% Patient & Stakeholder Engagement List of patient/stakeholder representatives online; engagement plan posted; forum minutes archived Attendance count at consultation forum Mean user-satisfaction score ≥ 3 Transparency Public project register operational; result-summary template available; code-sharing policy published Percent projects registered prospectively; percent results posted ≤12 m Percent projects with linked code/data (threshold set by operator) 1 Audit metrics verify policy existence or a documented “not-applicable” rationale, 2 Descriptive metrics characterise workload or process features without value judgement, 3 Outcome metrics enable normative assessment by comparing results with predefined thresholds Seven domains proved sufficient when tested against the contents of multiple international guidance documents and governance artefacts from five major data platforms and 33 registries. No further domain emerged, indicating a breadth that is “complete enough to start a gap analysis” yet concise. Ethics practices Each domain includes four action-oriented, conceptually distinct practices (one per PDCA step). The domains and examples are as follows: • Informed Consent & Information distinguishes: (i) choosing and justifying an opt-in or opt-out (or no-consent) model; (ii) maintaining participant-facing documents; (iii) monitoring decline and comprehension; (iv) revising materials when thresholds are missed. • Privacy & Data Protection lists DPIA completion, implementation of pseudonymisation/encryption, annual pen-test review and remediation of critical findings. • Data Quality includes adoption of a Kahn/FAIR framework, automated profiling with quality dashboards, bias review if thresholds are missed and data recuration as needed. • Use & Access Governance covers eligibility criteria, a structured review checklist with data-transfer agreements, analysis of veto-based rejections and criterion adjustment when bottlenecks appear. • Incidental-Finding Management moves from threshold policy, through workflow logging, to follow-up auditing and policy update if completion falls below a certain threshold. • Patient & Stakeholder Engagement progresses from formal inclusion, to consultation forums, satisfaction surveying and redesign if scores drop below a certain threshold. • Project-Level Transparency includes prospective registration, timely result reporting, and reproducibility through code and data sharing. The practices are illustrative, not exhaustive. They are intended to provide a shared vocabulary and structure, while enabling tailoring or merging in line with platform scope, objectives and resources. Special context for Privacy & Data Protection and Data Quality For Privacy & Data Protection and Data Quality these examples are deliberately concise, because detailed operational playbooks already exist e.g. GDPR and ISO 27701 for privacy safeguards; the Kahn data-quality dimensions together with FAIR and further guides for profiling and validation. In the other five domains, Informed Consent & Information, Use & Access Governance, Incidental-Finding Management, Patient & Stakeholder Engagement, and Project-Level Transparency, no universally adopted standards are available. The framework therefore offers additional illustrative examples to help operators translate abstract norms into actionable and auditable tasks. Division of labour between operators and data users Not all practices must be executed by the operator’s internal staff. In domains such as incidental findings or project-level transparency, tasks may be i) handled centrally by the operator, ii) delegated to researchers, or iii) executed via a hybrid model, where researchers must follow operator-defined standards and report back. The framework includes practices that the operator can mandate, monitor or audit, even when operational execution is partly decentralised. Whether platforms opt for centralised, decentralised or hybrid models will depend on legal, scientific and logistical context. In all cases, operators should retain oversight to ensure that the aspirational norms are met. Evaluation items Table 2 links each ethics practice to three evaluation items: 1. Audit items verify whether each practice is formally addressed and up to date, either through an operative artefact (policy, SOP, dashboard, log) or through a documented justification that the practice is not applicable (e.g. no consent required, no incidental findings expected). These can often be assessed externally by funders, reviewers or patient representatives. 2. Descriptive metrics characterise workloads and basic process features (e.g. consent-decline rate, number of log exceptions, median turnaround time for access requests). They enable trend analysis without value judgement. 3. Quality/outcome metrics enable normative assessment, for instance: comprehension of consent materials ≥80%, data completeness ≥95%, no critical pen-test findings unresolved after 30 days, or independent review of all veto-based access rejections, Currently, most platforms satisfy only the audit item: they can point to a policy or SOP, but descriptive and especially outcome metrics are still uncommon. Consent materials are seldom comprehension-tested, IF workflows rarely audited, and stakeholder engagement rarely evaluated for satisfaction or perceived impact. The proposed structure aims to shift normative governance culture from “existence” to “performance.” Plausibility results The list of ethics practices was cross-matched with five benchmark guidelines (ISBER 2023, WHO 2022, OECD 2022, CIOMS 2016, WMA 2016). All seven governance domains appeared at least once across the set, no additional domain emerged. Coverage, however, was uneven: domains such as Informed Consent & Information and Privacy & Data Protection were present (and often detailed) in every guideline, whereas Stakeholder Engagement and Incidental-Finding Management were mentioned in only two or three, typically at a high level. A real-world scan linked the seven domains to governance artefacts from UK Biobank, All of Us, PCORnet, GA4GH, and the German MII. Each domain had at least one concrete implementation artefact (policy, template, SOP), demonstrating that every practice on the list is in active use somewhere in the field. The registry review by van den Akker et al. (2024) analysed 51 European patient registries. Again, every domain surfaced at least once, yet implementation was highly variable. For example, only 1 of 20 consent/information forms (5%) described a procedure for incidental findings, and fewer than one-third of registries detailed how data were anonymised or pseudonymised. These findings confirm the framework’s completeness while illustrating the heterogeneity it is meant to address. Discussion This paper advances the governance debate on secondary use of health data by moving beyond aspirational value statements toward a system in which ethics practices are made explicit and linked to verifiable evaluation items. In doing so, it complements earlier work that catalogued norms 5 or surveyed public attitudes 7 and extends implementation-science proposals to the ethics domain. 39 The framework enables registry operators to conduct quick self-audits, select context-relevant metrics, and monitor progress over time. Researchers, funders, patient representatives, and policymakers can use the same structure as a reference for what constitutes good normative governance in this area and what types of evidence should be requested or scrutinized. From value to verifiability Current guidance for biobanks and data platforms, such as the WMA Declaration of Taipei, 8 typically stops at high-level imperatives such as “ensure consent” or “justify data access,” without indicating which concrete ethics practices are required or how performance should be judged. Checklists such as the ISBER Best Practices go further, 11 but they rarely span all seven domains identified here and seldom distinguish between the mere existence of a document and the effectiveness of its implementation. By pairing each practice with audit items and performance metrics, the present framework fills this gap. Its breadth is intentional but lean: complete enough to initiate internal gap analysis, yet not so prescriptive that initiatives are paralyzed by dozens of indicators. The framework moves governance from a trust-based logic of presumed compliance to an audit-informed logic that demands not only written policies but also evidence of their real-world performance. Contextual adaptability and scalable use A key feature of the framework is its modularity. It allows differentiated use across stakeholder groups, from self-assessment by operators to oversight by funders or advocacy by civil society actors. Equally important, it is scalable: the domains and practices are structured in a way that applies to small-scale registries as well as national or multi-jurisdictional platforms. Its illustrative nature enables context-sensitive specification. Operators are not expected to implement every practice identically, but to transparently justify how they adapt the framework to their operational, legal, and social environment. Such justification may take two forms: a positive specification (e.g. “we implement X by doing Y”) or an explicit non-adoption with rationale (e.g. “this domain is not relevant because our data are fully anonymised” or “this metric is currently infeasible but under development”). This practice of context-based declaration makes the framework practical and normatively accountable at once. From policies to performance As the plausibility check showed, most large data platforms (e.g. UK Biobank, All of Us, PCORnet,) and many patient registries already satisfy the audit layer by publishing policies or SOPs that cover at least some of the seven ethics-practice domains. Publicly disclosed descriptive or outcome metrics, however, remain rare. The framework draws attention to this blind spot. Tracking consent comprehension, veto-based access rejections, or IF follow-up adds workload, but these data are essential for demonstrating respect, fairness, and public value in practice. Future work should therefore develop lightweight tooling for routine metric collection and explore how external stakeholders (ethics committees, funders, patient groups) can access and interpret such data without over-burdening operators. Although systematic evaluation remains the exception, published case studies show that it is feasible. Zenker et al. report on broad consent uptake across 27 university hospitals participating in the German Medical Informatics Initiative (MII), providing implementation-level insights into consent processes at scale. 43 While substantial variation in consent rates across sites was observed, the authors emphasize that interpretation remains difficult due to inconsistent definitions and documentation standards. Fischer-Rosinsky et al. complement these findings with detailed uptake data from four emergency departments 44 : among 1,138 approached patients, only 28% ultimately consented, while over 40% declined or could not complete the process, often due to contextual or situational factors. These studies illustrate that capturing consent dynamics is feasible, but depends on clear procedural standards and routine monitoring. Bossert et al. used participatory feedback and cognitive interviews to iteratively revise a broad consent form. 45 While no quantitative comprehension testing was reported, patient feedback led to substantial revisions across three document versions. These case examples for the domain “Consent&Information” show that descriptive and outcome metrics can be embedded into routine operations or implemented by independent third parties. Beyond consent, recent audits illustrate how further ethics practices can be assessed in practice. A pan-European survey of 41 health-data hubs showed that 83% apply some form of data-quality control and 65% report anonymisation procedures, but only about half publish Data-Access or Data-Processing Agreements, and fewer still enforce minimum quality thresholds before ingesting data. 1 The cross-sectional audit of 51 European patient registries showed that although 31 (61%) claimed to have a use-and-access policy, only 17 made the full document publicly available and just four explicitly prohibited re-identification. 25 Relation to adjacent ethics domains While this framework centers on operator-level governance of health data infrastructures, it intersects with adjacent ethics discourses that warrant distinction. One such discourse concerns Learning Health Care Systems (LHCS). These systems depend on many of the same infrastructures and may presuppose several of the ethics practices addressed here. However, LHCS ethics typically focus on downstream questions at the point of care or project level, such as minimal-risk research without explicit consent, point-of-care randomisation, or obligations to implement findings. 46 , 47 In contrast, the present framework addresses upstream responsibilities: the governance of data access, protection, and provisioning that enables such learning activities in the first place. A parallel situation arises with AI ethics. Much AI development, especially in medical contexts, relies on access to large, well-governed datasets managed by health data platforms. Yet AI ethics debates often focus on downstream issues such as algorithmic explainability, fairness, or accountability. 48 , 49 These are important but distinct from the operator-level responsibilities that determine whether and how data become available for AI development at all. While this framework does not seek to resolve domain-specific concerns in LHCS or AI ethics, it may help clarify what responsible infrastructure entails in practice, especially where operator decisions shape the scope, quality, and legitimacy of downstream research and innovation. Strengths, limitations, and future directions A strength of the framework lies in its integrative structure: it brings together ethical concepts, normative considerations, and insights from existing governance materials across multiple health data platforms. Rather than proposing a fixed model, it offers adaptable components that can be aligned with different institutional contexts and levels of maturity. At the same time, several limitations apply. First, the proposed metrics are illustrative: they have not been broadly discussed or endorsed across the data governance community, and no shared standards exist regarding their use, relevance, or thresholds. Routine data collection for many domains, such as consent comprehension, veto-based access rejections, or incidental finding follow-up, remains rare. Implementation will therefore require context-sensitive prioritization and negotiation of feasibility. Second, while the framework is grounded in a broad range of conceptual and documentary sources, it does not result from a systematic or exhaustive scan of all existing platforms and policies. Rather, it reflects a structured synthesis of operator-level responsibilities, developed through iterative comparison with international ethics guidance and governance practices. While the seven domains are intended to offer a comprehensive account of ethically relevant tasks at the infrastructure level, future work may test their completeness and applicability across additional settings. Building on these limitations, two lines of inquiry suggest themselves. First, adaptation studies at platform level could explore how the framework is interpreted and specified in different legal, infrastructural, and ethical environments, and what rationales are offered for adaptation, postponement, or omission. Second, indicator research should refine and test proposed metrics, distinguishing between norm-referenced targets and descriptive monitors. Consensus-building methods may help establish minimal reporting standards, including metadata on evidentiary strength and resource requirements. Conclusion Governing secondary use of health data requires both normative robustness and empirical accountability. By coupling widely accepted values to a compact but comprehensive set of ethics practices and evaluation items, this framework offers a practical starting point. Its value will grow as communities iterate on the illustrative metrics, refine implementation across diverse contexts, and share comparative results—helping the field evolve from principled aspiration to demonstrable responsibility. Ethics approval Ethics approval was not required, as this conceptual work draws exclusively on publicly available information. Data availability No data are associated with this article. References 1. Alvarez-Romero C, Martinez-Garcia A, Bernabeu-Wittel M, et al. : Health data hubs: an analysis of existing data governance features for research. Health Res Policy Syst. 2023; 21 (1): 70. PubMed Abstract | Publisher Full Text | Free Full Text 2. CPRD: Clinical Practice Research Datalink, Data Governance Operating Framework. Reference Source 2022. 3. Wilkinson MD, Dumontier M, Aalbersberg IJ, et al. : The FAIR Guiding Principles for scientific data management and stewardship. Sci. Data. 2016; 3 : 160018. PubMed Abstract | Publisher Full Text | Free Full Text 4. Kahn MG, Callahan TJ, Barnard J, et al. : A Harmonized Data Quality Assessment Terminology and Framework for the Secondary Use of Electronic Health Record Data. EGEMS (Wash DC). 2016; 4 (1): 1244. PubMed Abstract | Publisher Full Text 5. Kalkman S, Mostert M, Gerlinger C, et al. : Responsible data sharing in international health research: a systematic review of principles and norms. BMC Med. Ethics. 2019; 20 (1): 21. PubMed Abstract | Publisher Full Text | Free Full Text 6. Kalkman S, van Delden J , Banerjee A, et al. : Patients' and public views and attitudes towards the sharing of health data for research: a narrative review of the empirical evidence. J. Med. Ethics. 2022; 48 (1): 3–13. PubMed Abstract | Publisher Full Text | Free Full Text 7. Hutchings E, Loomes M, Butow P, et al. : A systematic literature review of attitudes towards secondary use and sharing of health administrative and clinical trial data: a focus on consent. Syst. Rev. 2021; 10 (1): 132. PubMed Abstract | Publisher Full Text | Free Full Text 8. WMA: World Medical Association, Declaration of Taipei on ethical considerations regarding health databases and biobanks.2016. Reference Source 9. OECD: Health Data Governance for the Digital Age: Implementing the OECD Recommendation on Health Data Governance. Paris: 2022. Publisher Full Text 10. CIOMS: International Ethical Guidelines for Health-Related Research Involving Human Subjects. Geneva: Council for International Organizations of Medical Sciences; 2016. 11. ISBER: International Society for Biological and Environmental Repositories. ISBER best practices: Recommendations for repositories (5th ed.). Reference Source 2023. 12. WHO: World Health Organization. Policy and Implementation Guidance on Data Sharing and Use of Health-Related Data for Research Purposes. Geneva: Reference Source 13. UK Biobank: UK Biobank Ethics and Governance Framework. Reference Source 2007. 14. UK Biobank: Access Procedures. Application and review procedures for access to the UK Biobank Resource. Reference Source 2022. 15. All of Us: Framework for Access to All of Us Data Resources v1.1.2021. Reference Source 16. GA4GH: Global Alliance for Genomics and Health. Framework for Responsible Sharing of Genomic and Health-Related Data. Version 1.0. Reference Source 17. ISBER: International Society for Biological and Environmental Repositories (ISBER). Best Practices: Recommendations for Repositories. 5th edition.2023. Reference Source 18. OECD: Recommendation of the Council on Health Data Governance. OECD/LEGAL/0433. Reference Source 2017. 19. Presidential Commission for the Study of Bioethical Issues: Anticipate and Communicate: Ethical Management of Incidental and Secondary Findings in the Clinical, Research, and Direct-to-Consumer Contexts. Washington, DC: 2013. 20. CIOMS: International guidelines on good governance practice for research institutions. Geneva: Council for International Organizations of Medical Sciences; 2023. 21. Nuffield Council on Bioethics: The collection, linking and use of data in biomedical research and health care: ethical issues. London: 2015. Reference Source 22. European Network for Health Technology Assessment: Registry Evaluation and Quality Standards Tool (REQueST).2019. Reference Source 23. Stockdale J, Cassell J, Ford E: "Giving something back": A systematic review and ethical enquiry into public views on the use of patient data for research in the United Kingdom and the Republic of Ireland. Wellcome Open Res. 2018; 3 : 6. Publisher Full Text 24. Pavlenko E, Strech D, Langhof H: Implementation of data access and use procedures in clinical data warehouses. A systematic review of literature and publicly available policies. BMC Med. Inform. Decis. Mak. 2020; 20 (1): 157. Publisher Full Text 25. van den Akker OR , Stark S, Strech D: Ethics practices associated with reusing health data: an assessment of patient registries. BMC Med. 2024; 22 (1): 577. PubMed Abstract | Publisher Full Text | Free Full Text 26. van den Akker OR , Thibault RT, Ioannidis JPA, et al. : Transparency in the secondary use of health data: assessing the status quo of guidance and best practices. R. Soc. Open Sci. 2025; 12 (3): 241364. PubMed Abstract | Publisher Full Text | Free Full Text 27. Langhof H, Kahrass H, Illig T, et al. : Current practices for access, compensation, and prioritization in biobanks. Results from an interview study. Eur. J. Hum. Genet. 2018; 26 (11): 1572–1581. PubMed Abstract | Publisher Full Text | Free Full Text 28. Lamer A, Popoff B, Delange B, et al. : Barriers encountered with clinical data warehouses: Recommendations from a focus group. Comput. Methods Prog. Biomed. 2024; 256 : 108404. PubMed Abstract | Publisher Full Text 29. Qualls LG, Phillips TA, Hammill BG, et al. : Evaluating Foundational Data Quality in the National Patient-Centered Clinical Research Network (PCORnet(R)). EGEMS (Wash DC). 2018; 6 (1): 3. PubMed Abstract | Publisher Full Text 30. Barazzetti G, Bosisio F, Koutaissoff D, et al. : Broad consent in practice: lessons learned from a hospital-based biobank for prospective research on genomic and medical data. Eur. J. Hum. Genet. 2020; 28 (7): 915–924. PubMed Abstract | Publisher Full Text | Free Full Text 31. Zenker S, Strech D, Ihrig K, et al. : Data protection-compliant broad consent for secondary use of health care data and human biosamples for (bio) medical research: Towards a new German national standard. J. Biomed. Inform. 2022; 131 : 104096. Publisher Full Text 32. Doutreligne M, Degremont A, Jachiet PA, et al. : Good practices for clinical data warehouse implementation: A case study in France. PLOS Digit Health. 2023; 2 (7): e0000298. PubMed Abstract | Publisher Full Text | Free Full Text 33. Danciu I, Cowan JD, Basford M, et al. : Secondary use of clinical data: the Vanderbilt approach. J. Biomed. Inform. 2014; 52 : 28–35. PubMed Abstract | Publisher Full Text | Free Full Text 34. Tai CG, Harris-Wai J, Schaefer C, et al. : Multiple Stakeholder Views on Data Sharing in a Biobank in an Integrated Healthcare Delivery System: Implications for Biobank Governance. Public Health Genomics. 2018; 21 (5–6): 207–216. Publisher Full Text 35. Des Jardins TR: The keys to governance and stakeholder engagement: the southeast michigan beacon community case study. EGEMS (Wash DC). 2014; 2 (3): 1068. PubMed Abstract | Publisher Full Text 36. Nab L, Schaffer AL, Hulme W, et al. : OpenSAFELY: A platform for analysing electronic health records designed for reproducible research. Pharmacoepidemiol. Drug Saf. 2024; 33 (6): e5815. PubMed Abstract | Publisher Full Text | Free Full Text 37. Waitman LR, Bailey LC, Becich MJ, et al. : Avenues for Strengthening PCORnet's Capacity to Advance Patient-Centered Economic Outcomes in Patient-Centered Outcomes Research (PCOR). Med. Care. 2023; 61 (12 Suppl 2): S153–S160. PubMed Abstract | Publisher Full Text | Free Full Text 38. Strech D, von Kielmansegg S , Zenker S, et al. : "Data Donation" – Research Needs, Ethical Assessment, and Legal, IT, and Organizational Frameworks; Scientific Expert Report. Commissioned by the Federal Ministry of Health; 2020. (German language). Reference Source 39. Sisk BA, Mozersky J, Antes AL, et al. : The "Ought-Is" Problem: An Implementation Science Framework for Translating Ethical Norms Into Practice. Am. J. Bioeth. 2020; 20 (4): 62–70. PubMed Abstract | Publisher Full Text | Free Full Text 40. Huxtable R, Ives J: Mapping, framing, shaping: a framework for empirical bioethics research projects. BMC Med. Ethics. 2019; 20 (1): 86. PubMed Abstract | Publisher Full Text | Free Full Text 41. Schwietering J, Langhof H, Strech D: Empirical studies on how ethical recommendations are translated into practice: a cross-section study on scope and study objectives. BMC Med. Ethics. 2023; 24 (1): 2. PubMed Abstract | Publisher Full Text | Free Full Text 42. ISO: International Organization for Standardization, ISO/IEC 27701:2019 – Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines. Geneva: 2019. 43. Zenker S, Strech D, Jahns R, et al. : Nationally standardized broad consent in practice: initial experiences, current developments, and critical assessment. Bundesgesundheitsblatt Gesundheitsforschung Gesundheitsschutz. 2024; 67 (6): 637–647. PubMed Abstract | Publisher Full Text | Free Full Text 44. Fischer-Rosinsky A, Eienbroker L, Mockel M, et al. : Broad consent in the emergency department: a cross sectional study. Arch. Public Health. 2025; 83 (1): 44. PubMed Abstract | Publisher Full Text | Free Full Text 45. Bossert S, Kahrass H, Heinemeyer U, et al. : Participatory improvement of a template for informed consent documents in biobank research - study results and methodological reflections. BMC Med. Ethics. 2017; 18 (1): 78. PubMed Abstract | Publisher Full Text | Free Full Text 46. Faden RR, Kass NE, Goodman SN, et al. : An Ethics Framework for a Learning Health Care System: A Departure from Traditional Research Ethics and Clinical Ethics. Hastings Cent. Rep. 2013; 43 : S16–S27. Publisher Full Text 47. IOM: Best Care at Lower Cost: The Path to Continuously Learning Health Care in America. Washington D.C.: National Academies Press, Institute of Medicine (IOM); 2012. 48. European Commission: Directorate-General for Communications Networks, Content and Technology. (2019). Ethics guidelines for trustworthy AI. Publications Office of the European Union; 2019. Reference Source 49. Floridi L, Cowls J, Beltrametti M, et al. : AI4People-An Ethical Framework for a Good AI Society: Opportunities, Risks, Principles, and Recommendations. Minds Mach (Dordr). 2018; 28 (4): 689–707. PubMed Abstract | Publisher Full Text | Free Full Text Comments on this article Comments (0) Version 1 VERSION 1 PUBLISHED 13 Apr 2026 ADD YOUR COMMENT Comment Author details Author details QUEST Center for Responsible Research, Berlin Institute of Health at Charite, Berlin, Germany Daniel Strech Roles: Conceptualization, Formal Analysis, Methodology, Project Administration, Writing – Original Draft Preparation Competing interests The author served as spokesperson and remains a member of the German working group ‘Consent,’ which developed the broad consent model for the German Medical Informatics Initiative (MII). The author receives research funding related to the topics of this paper from MII consortia (HiGHmed, CAEHR) and from the EU-funded project More-EUROPA. The author was also part of an expert group that authored a report for the German Federal Ministry of Health outlining technical, legal, and ethical preconditions for responsible secondary use of health data. In addition, the author served as a member of two WHO working/review groups relevant to this topic: ‘Guidance for Ethical Review of Health Systems Research’ and ‘Ethics of Public Health Surveillance.’ Grant information This work was supported by intramural funds from the Berlin Institute of Health at Charité – Universitätsmedizin Berlin, Germany. The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript. Article Versions (1) version 1 Published: 13 Apr 2026, 15:508 https://doi.org/10.12688/f1000research.179326.1 Copyright © 2026 Strech D. This is an open access article distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. Download Export To Sciwheel Bibtex EndNote ProCite Ref. Manager (RIS) Sente metrics Views Downloads F1000Research - - PubMed Central info_outline Data from PMC are received and updated monthly. - - Citations open_in_new 0 open_in_new 0 open_in_new SEE MORE DETAILS CITE how to cite this article Strech D. Operationalising ethics in secondary health-data use: an operator-focused framework for normative governance with audit and performance metrics [version 1; peer review: awaiting peer review] . F1000Research 2026, 15 :508 ( https://doi.org/10.12688/f1000research.179326.1 ) NOTE: If applicable, it is important to ensure the information in square brackets after the title is included in all citations of this article. COPY CITATION DETAILS track receive updates on this article Track an article to receive email alerts on any updates to this article. TRACK THIS ARTICLE Share Open Peer Review Current Reviewer Status: AWAITING PEER REVIEW AWAITING PEER REVIEW ? Key to Reviewer Statuses VIEW HIDE Approved The paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved Fundamental flaws in the paper seriously undermine the findings and conclusions Comments on this article Comments (0) Version 1 VERSION 1 PUBLISHED 13 Apr 2026 ADD YOUR COMMENT Comment keyboard_arrow_left keyboard_arrow_right Open Peer Review Reviewer Status AWAITING PEER REVIEW Comments on this article All Comments (0) Add a comment Sign up for content alerts Sign Up You are now signed up to receive this alert Browse by related subjects Alongside their report, reviewers assign a status to the article: Approved - the paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations - A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved - fundamental flaws in the paper seriously undermine the findings and conclusions Adjust parameters to alter display View on desktop for interactive features Includes Interactive Elements View on desktop for interactive features Competing Interests Policy Provide sufficient details of any financial or non-financial competing interests to enable users to assess whether your comments might lead a reasonable person to question your impartiality. Consider the following examples, but note that this is not an exhaustive list: Examples of 'Non-Financial Competing Interests' Within the past 4 years, you have held joint grants, published or collaborated with any of the authors of the selected paper. You have a close personal relationship (e.g. parent, spouse, sibling, or domestic partner) with any of the authors. You are a close professional associate of any of the authors (e.g. scientific mentor, recent student). You work at the same institute as any of the authors. You hope/expect to benefit (e.g. favour or employment) as a result of your submission. You are an Editor for the journal in which the article is published. Examples of 'Financial Competing Interests' You expect to receive, or in the past 4 years have received, any of the following from any commercial organisation that may gain financially from your submission: a salary, fees, funding, reimbursements. You expect to receive, or in the past 4 years have received, shared grant support or other funding with any of the authors. You hold, or are currently applying for, any patents or significant stocks/shares relating to the subject matter of the paper you are commenting on. Stay Updated Sign up for content alerts and receive a weekly or monthly email with all newly published articles Register with F1000Research Already registered? Sign in Not now, thanks close PLEASE NOTE If you are an AUTHOR of this article, please check that you signed in with the account associated with this article otherwise we cannot automatically identify your role as an author and your comment will be labelled as a “User Comment”. If you are a REVIEWER of this article, please check that you have signed in with the account associated with this article and then go to your account to submit your report, please do not post your review here. If you do not have access to your original account, please contact us . All commenters must hold a formal affiliation as per our Policies . The information that you give us will be displayed next to your comment. User comments must be in English, comprehensible and relevant to the article under discussion. We reserve the right to remove any comments that we consider to be inappropriate, offensive or otherwise in breach of the User Comment Terms and Conditions . Commenters must not use a comment for personal attacks. When criticisms of the article are based on unpublished data, the data should be made available. I accept the User Comment Terms and Conditions Please confirm that you accept the User Comment Terms and Conditions. Affiliation ✕ refresh Please enter your institution. Note: To add your institution or organisation, start typing the name and then select the correct name from the list. Where applicable, the name will appear in both the original language and in English. Do not paste in the name. If the name does not appear in the drop-down list, we will display the information you have entered. ✕ refresh Country/Region * USA UK Canada China France Germany Afghanistan Aland Islands Albania Algeria American Samoa Andorra Angola Anguilla Antarctica Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bosnia and Herzegovina Botswana Bouvet Island Brazil British Indian Ocean Territory British Virgin Islands Brunei Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Christmas Island Cocos (Keeling) Islands Colombia Comoros Congo Cook Islands Costa Rica Cote d'Ivoire Croatia Cuba Cyprus Czech Republic Democratic Republic of the Congo Denmark Djibouti Dominica Dominican Republic Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Federated States of Micronesia Fiji Finland France French Guiana French Polynesia French Southern Territories Gabon Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guernsey Guinea Guinea-Bissau Guyana Haiti Heard Island and Mcdonald Islands Holy See (Vatican City State) Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Israel Italy Jamaica Japan Jersey Jordan Kazakhstan Kenya Kiribati Kosovo (Serbia and Montenegro) Kuwait Kyrgyzstan Lao People's Democratic Republic Latvia Lebanon Lesotho Liberia Libya Liechtenstein Lithuania Luxembourg Macao Madagascar Malawi Malaysia Maldives Mali Malta Marshall Islands Martinique Mauritania Mauritius Mayotte Mexico Minor Outlying Islands of the United States Moldova Monaco Mongolia Montenegro Montserrat Morocco Mozambique Myanmar Namibia Nauru Nepal Netherlands Antilles New Caledonia New Zealand Nicaragua Niger Nigeria Niue Norfolk Island North Korea North Macedonia Northern Mariana Islands Norway Oman Pakistan Palau Palestinian Territory Panama Papua New Guinea Paraguay Peru Philippines Pitcairn Poland Portugal Puerto Rico Qatar Reunion Romania Russian Federation Rwanda Saint Helena Saint Kitts and Nevis Saint Lucia Saint Pierre and Miquelon Saint Vincent and the Grenadines Samoa San Marino Sao Tome and Principe Saudi Arabia Senegal Serbia Seychelles Sierra Leone Singapore Slovakia Slovenia Solomon Islands Somalia South Africa South Georgia and the South Sandwich Is South Korea South Sudan Spain Sri Lanka Sudan Suriname Svalbard and Jan Mayen Swaziland Sweden Switzerland Syria Taiwan Tajikistan Tanzania Thailand The Gambia The Netherlands Timor-Leste Togo Tokelau Tonga Trinidad and Tobago Tunisia Turkey Turkmenistan Turks and Caicos Islands Tuvalu UK USA Uganda Ukraine United Arab Emirates United States Virgin Islands Uruguay Uzbekistan Vanuatu Venezuela Vietnam Wallis and Futuna West Bank and Gaza Strip Western Sahara Yemen Zambia Zimbabwe Please select your country/region. You must enter a comment. Competing Interests Please disclose any competing interests that might be construed to influence your judgment of the article's or peer review report's validity or importance. Competing Interests Policy Provide sufficient details of any financial or non-financial competing interests to enable users to assess whether your comments might lead a reasonable person to question your impartiality. Consider the following examples, but note that this is not an exhaustive list: Examples of 'Non-Financial Competing Interests' Within the past 4 years, you have held joint grants, published or collaborated with any of the authors of the selected paper. You have a close personal relationship (e.g. parent, spouse, sibling, or domestic partner) with any of the authors. You are a close professional associate of any of the authors (e.g. scientific mentor, recent student). You work at the same institute as any of the authors. You hope/expect to benefit (e.g. favour or employment) as a result of your submission. You are an Editor for the journal in which the article is published. Examples of 'Financial Competing Interests' You expect to receive, or in the past 4 years have received, any of the following from any commercial organisation that may gain financially from your submission: a salary, fees, funding, reimbursements. You expect to receive, or in the past 4 years have received, shared grant support or other funding with any of the authors. You hold, or are currently applying for, any patents or significant stocks/shares relating to the subject matter of the paper you are commenting on. Please state your competing interests The comment has been saved. An error has occurred. Please try again. Cancel Post var lTitle = "Operationalising ethics in secondary health-data...".replace("'", ''); var linkedInUrl = "http://www.linkedin.com/shareArticle?url=https://f1000research.com/articles/15-508/v1" + "&title=" + encodeURIComponent(lTitle) + "&summary=" + encodeURIComponent('Read the article by '); var deliciousUrl = "https://del.icio.us/post?url=https://f1000research.com/articles/15-508/v1&title=" + encodeURIComponent(lTitle); var redditUrl = "http://reddit.com/submit?url=https://f1000research.com/articles/15-508/v1" + "&title=" + encodeURIComponent(lTitle); linkedInUrl += encodeURIComponent('Strech D'); var offsetTop = /chrome/i.test( navigator.userAgent ) ? 4 : -10; var addthis_config = { ui_offset_top: offsetTop, services_compact : "facebook,twitter,www.linkedin.com,www.mendeley.com,reddit.com", services_expanded : "facebook,twitter,www.linkedin.com,www.mendeley.com,reddit.com", services_custom : [ { name: "LinkedIn", url: linkedInUrl, icon:"/img/icon/at_linkedin.svg" }, { name: "Mendeley", url: "http://www.mendeley.com/import/?url=https://f1000research.com/articles/15-508/v1/mendeley", icon:"/img/icon/at_mendeley.svg" }, { name: "Reddit", url: redditUrl, icon:"/img/icon/at_reddit.svg" }, ] }; var addthis_share = { url: "https://f1000research.com/articles/15-508", templates : { twitter : "Operationalising ethics in secondary health-data use: an operator-focused.... Strech D, published by " + "@F1000Research" + ", https://f1000research.com/articles/15-508/v1" } }; if (typeof(addthis) != "undefined"){ addthis.addEventListener('addthis.ready', checkCount); addthis.addEventListener('addthis.menu.share', checkCount); } $(".f1r-shares-twitter").attr("href", "https://twitter.com/intent/tweet?text=" + addthis_share.templates.twitter); $(".f1r-shares-facebook").attr("href", "https://www.facebook.com/sharer/sharer.php?u=" + addthis_share.url); $(".f1r-shares-linkedin").attr("href", addthis_config.services_custom[0].url); $(".f1r-shares-reddit").attr("href", addthis_config.services_custom[2].url); $(".f1r-shares-mendelay").attr("href", addthis_config.services_custom[1].url); function checkCount(){ setTimeout(function(){ $(".addthis_button_expanded").each(function(){ var count = $(this).text(); if (count !== "" && count != "0") $(this).removeClass("is-hidden"); else $(this).addClass("is-hidden"); }); }, 1000); } close How to cite this report {{reportCitation}} Cancel Copy Citation Details $(function(){R.ui.buttonDropdowns('.dropdown-for-downloads');}); $(function(){R.ui.toolbarDropdowns('.toolbar-dropdown-for-downloads');}); $.get("/articles/acj/179326/197830") new F1000.Clipboard(); new F1000.ThesaurusTermsDisplay("articles", "article", "197830"); $(document).ready(function() { $( "#frame1" ).on('load', function() { var mydiv = $(this).contents().find("div"); var h = mydiv.height(); console.log(h) }); var tooltipLivingFigure = jQuery(".interactive-living-figure-label .icon-more-info"), titleLivingFigure = tooltipLivingFigure.attr("title"); tooltipLivingFigure.simpletip({ fixed: true, position: ["-115", "30"], baseClass: 'small-tooltip', content:titleLivingFigure + " " }); tooltipLivingFigure.removeAttr("title"); $("body").on("click", ".cite-living-figure", function(e) { e.preventDefault(); var ref = $(this).attr("data-ref"); $(this).closest(".living-figure-list-container").find("#" + ref).fadeIn(200); }); $("body").on("click", ".close-cite-living-figure", function(e) { e.preventDefault(); $(this).closest(".popup-window-wrapper").fadeOut(200); }); $(document).on("mouseup", function(e) { var metricsContainer = $(".article-metrics-popover-wrapper"); if (!metricsContainer.is(e.target) && metricsContainer.has(e.target).length === 0) { $(".article-metrics-close-button").click(); } }); var articleId = $('#articleId').val(); if($("#main-article-count-box").attachArticleMetrics) { $("#main-article-count-box").attachArticleMetrics(articleId, { articleMetricsView: true }); } }); var figshareWidget = $(".new_figshare_widget"); if (figshareWidget.length > 0) { window.figshare.load("f1000", function(Widget) { // Select a tag/tags defined in your page. In this tag we will place the widget. _.map(figshareWidget, function(el){ var widget = new Widget({ articleId: $(el).attr("figshare_articleId") //height:300 // this is the height of the viewer part. [Default: 550] }); widget.initialize(); // initialize the widget widget.mount(el); // mount it in a tag that's on your page // this will save the widget on the global scope for later use from // your JS scripts. This line is optional. //window.widget = widget; }); }); } close Error Close Add Reset F1000.MICROSERVICES.AFFILIATION = ''; $(document).ready(function () { $('.js-affiliations-form').each((index, form) => { new AffiliationForm({ formId: form.id, institutionErrorSelector: '.comment-enter-institution', departmentErrorSelector: '.comment-enter-department', placeSelector: '.js-add-comment-place', stateSelector: '.js-add-comment-state', zipCodeSelector: '.js-add-comment-zipcode', countrySelector: '.js-add-comment-country', countryErrorSelector: '.comment-enter-country', }); }); }); $(document).ready(function () { var reportIds = { "486151": 0, "486150": 0, "486149": 0, "475407": 0, "486158": 0, "475406": 0, "486157": 0, "475405": 0, "486156": 0, "475404": 0, "486155": 0, "475403": 0, "486154": 0, "486153": 0, "486152": 0, "475412": 0, "475411": 0, "475410": 0, "475409": 0, "475408": 0, "480543": 0, "480542": 0, "480541": 0, "480540": 0, "480539": 0, "480538": 0, "480537": 0, "480546": 0, "480545": 0, "480544": 0, "477551": 0, "477550": 0, "477549": 0, "477548": 0, "477547": 0, "482423": 0, "482422": 0, "477556": 0, "477555": 0, "477554": 0, "477553": 0, "477552": 0, "482431": 0, "482430": 0, "482429": 0, "482428": 0, "482427": 0, "482426": 0, "482425": 0, "482424": 0, }; $(".referee-response-container,.js-referee-report").each(function(index, el) { var reportId = $(el).attr("data-reportid"), reportCount = reportIds[reportId] || 0; $(el).find(".comments-count-container,.js-referee-report-views").html(reportCount); }); var uuidInput = $("#article_uuid"), oldUUId = uuidInput.val(), newUUId = "ad6f182f-1861-4d68-8e48-940f567b8562"; uuidInput.val(newUUId); $("a[href*='article_uuid=']").each(function(index, el) { var newHref = $(el).attr("href").replace(oldUUId, newUUId); $(el).attr("href", newHref); }); }); An innovative open access publishing platform offering rapid publication and open peer review, whilst supporting data deposition and sharing. Browse Gateways Collections How it Works Contact For Developers Cookie Notice Privacy Notice RSS Submit Your Research Follow us © 2012-2026 F1000 Research Ltd. ISSN 2046-1402 | Legal | Partner of Research4Life • CrossRef • ORCID • FAIRSharing R.templateTests.simpleTemplate = R.template(' $text $text $text $text $text '); R.templateTests.runTests(); var F1000platform = new F1000.Platform({ name: "f1000research", displayName: "F1000Research", hostName: "f1000research.com", id: "1", editorialEmail: "[email protected]", infoEmail: "[email protected]", usePmcStats: true }); $(function(){R.ui.dropdowns('.dropdown-for-authors, .dropdown-for-about, .dropdown-for-myresearch');}); // $(function(){R.ui.dropdowns('.dropdown-for-referees');}); $(document).ready(function () { if ($(".cookie-warning").is(":visible")) { $(".sticky").css("margin-bottom", "35px"); $(".devices").addClass("devices-and-cookie-warning"); } $(".cookie-warning .close-button").click(function (e) { $(".devices").removeClass("devices-and-cookie-warning"); $(".sticky").css("margin-bottom", "0"); }); $("#tweeter-feed .tweet-message").each(function (i, message) { var self = $(message); self.html(linkify(self.html())); }); $(".partner").on("mouseenter mouseleave", function() { $(this).find(".gray-scale, .colour").toggleClass("is-hidden"); }); }); Sign In Remember me Forgotten your password? Sign In Cancel Email or password not correct. Please try again Please wait... $(function(){ // Note: All the setup needs to run against a name attribute and *not* the id due the clonish // nature of facebox... $("a[id=googleSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("GOOGLE"); $("form[id=oAuthForm]").submit(); }); $("a[id=facebookSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("FACEBOOK"); $("form[id=oAuthForm]").submit(); }); $("a[id=orcidSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("ORCID"); $("form[id=oAuthForm]").submit(); }); }); If you've forgotten your password, please enter your email address below and we'll send you instructions on how to reset your password. The email address should be the one you originally registered with F1000. Email address not valid, please try again You registered with F1000 via Google, so we cannot reset your password. To sign in, please click here . If you still need help with your Google account password, please click here . You registered with F1000 via Facebook, so we cannot reset your password. To sign in, please click here . If you still need help with your Facebook account password, please click here . Code not correct, please try again Reset password Cancel Email us for further assistance. Server error, please try again. If your email address is registered with us, we will email you instructions to reset your password. If you think you should have received this email but it has not arrived, please check your spam filters and/or contact for further assistance. Please wait... Register $(document).ready(function () { signIn.createSignInAsRow($("#sign-in-form-gfb-popup")); $(".target-field").each(function () { var uris = $(this).val().split("/"); if (uris.pop() === "login") { $(this).val(uris.toString().replace(",","/")); } }); });

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00