Skip to content
All articles
Blog

The citizen service number ban and the EHDS

· Antoinette

The prohibition on using the civil service number hinders medical-scientific research. Dr. Vlieger analyzes the legal knot and explains why the EHDS offers the opportunity to resolve this.

Who does that ban actually apply to?

The ban on using the Dutch national identification number is a curious matter. The general perception is that this citizen service number (BSN) may not be used for scientific research, save for a handful of exceptions. Whether that is legally correct is open to question. The Dutch GDPR Implementation Act (Uitvoeringswet AVG, UAVG) provides that the number may only be used where a statute permits it. The Dutch General Provisions on the Citizen Service Number Act (Wet algemene bepalingen burgerservicenummer) then provides that all parts of government may use the BSN in performing the tasks assigned to them. On the basis of that statutory provision, the Dutch National Institute for Public Health and the Environment (RIVM) therefore simply uses the BSN. But the academic hospitals are government too, and their statutory tasks include conducting medical scientific research. They nevertheless believe that they may not do so, while no one can explain why the rules should be different for them than for the RIVM.

Privacy Enhancing Technology became "sensitive"

More importantly: the entire medical-scientific field is calling, in various forms, for the ban on the BSN to be lifted. There are no clear counter-arguments, yet it is still not being arranged. And this too appears to be a matter of perception. The 2004 White Paper on Privacy Enhancing Technologies, until recently available on the website of the Dutch Data Protection Authority (AP), stated that the purposes of the BSN were: "to improve service provision to clients, to combat identity fraud and to increase the transparency of government, with the aim of improving privacy." The use of the number was thus intended to improve privacy, because such a number was more anonymous than the use of name, address and residence details. Oddly enough, over the years the perception has arisen that the BSN is in fact sensitive. The AP now writes: "The BSN is a sensitive personal data item. The BSN makes it easy to link information from different files. Careless use of the BSN therefore gives rise to privacy risks." Strangely, then, the number that was designed in part to protect privacy is, twenty years later, regarded as a privacy risk.

Sensitive because you can link data — but linking is the whole point!

From "sensitive personal data" many people infer that this is a "special category of personal data" as defined in the GDPR. That is not the case. The AP states that it is sensitive because it allows files to be linked. In doing so, however, the authority overlooks the fact that in certain cases we positively do want to link files. Researchers link files for the purposes of their research. Recently, for example, the Amsterdam UMC published a study showing that general practitioners can, with the help of AI, detect lung cancer up to four months earlier. Research of that kind is only possible by linking hospital files to general practitioners' files. That requires data present in both sets of files; this may be name, address and residence details, but it may equally be the BSN. If the BSN may not be used, linking can therefore only be done by using more privacy-sensitive data. The third option is of course not to conduct such research at all, but almost no one regards that as an option.

1779479277490 reverse side of ID card Aug 2021

The BSN is safer than name and address data, if not linking is not an option

So if researchers are allowed to link files because of the importance of their research, then a choice has to be made between either linking by means of name, address and residence details or linking by means of the BSN. One may respond that pseudonymisation is also possible, but the BSN is precisely a form of pseudonymisation; one that is always applied in the same way, so that data can still be linked and retrieved where that is in fact necessary. The BSN is therefore indeed, as the AP writes, sensitive in the sense that it enables files to be linked where we do not want that. But in those cases where we positively do want files to be linked, use of the BSN is safer from a privacy perspective than the use of name, address and residence details. Moreover, the BSN is also intended to prevent the risk of persons being confused with one another, and researchers too are keen to reduce that risk, for a more accurate outcome of their research.

Which Ministry is up next?

There are of course public authorities that understand all this perfectly well. The Ministry of Health, Welfare and Sport (VWS) regularly writes that "something" must be done about the ban on the BSN. That this is not happening appears to be connected with uncertainty as to which statute the matter should be resolved in, and hence which ministry is up next. Article 46 UAVG, where the ban is laid down, seems the most logical place, but VWS is not responsible for that Act; the Ministry of Justice is. That ministry does recognise the problem, but writes that the matter should be resolved in "sectoral legislation." The Ministry of Justice thus appears to think that another ministry should solve it, but that is not logical. After all, we want the same arrangement for all researchers and statisticians, not only on grounds of equality before the law, but also so that health data can be linked to other data, for example. That is why it still seems the most logical solution for the Ministry of Justice to amend Article 46 UAVG.

Trusted data holders and the BSN

Now, with the introduction of the EHDS, it is moreover a good moment to resolve the BSN problem. The HDAB will be a government body, and will have the power to link files in the performance of its tasks. But the EHDS also provides for the role of trusted data holders. These are parties which, on the basis of their expertise, are permitted to prepare the HDAB's decisions administratively. They can draft data permits themselves. Trusted data holders are, however, required to have a secure processing environment. They can then work with EHDS data there, in their own secure processing environment. All this saves the HDAB a great deal of work, but part of that benefit is lost if trusted data holders are not allowed to link data files using the BSN themselves and therefore still have to call in the HDAB to do so. That is why, if the role of trusted data holder under the EHDS is to come into its own, the ban on the BSN must now be amended.

Consulting the National Control Register

Incidentally, such a provision should not state that the BSN may be used by researchers "in order to link data." That would once again be too restrictive. Patients will shortly be able to object to the reuse of their data in the National Control Register (Nationaal Zeggenschapsregister). When a trusted data holder consults that register, it too must be able to make use of the BSN. If the Ministry of Justice continues to insist that the matter must be resolved in sectoral legislation, then the matter can equally be resolved by VWS in the national implementing legislation for the EHDS; so as to ensure that (i) trusted data holders can do their work, as envisaged in the EHDS, without too much help from the HDAB, and (ii) the National Control Register can be consulted using the BSN rather than name, address and residence details, because this is better for privacy. In the discussions surrounding this, it is important to draw a sharp distinction between the question of whether we want particular files to be linked, and the follow-up question of how, if we do indeed want that, this can best be done.