University of Illinois System
Last item for navigation

Research and International Privacy

If you intend to conduct research in a foreign country, your research needs to comply with any applicable laws in that country, including applicable privacy laws.

The EU GDPR, the UK GDPR, and/or PIPL may affect to your research if:

  • Your research involves the personal information of persons physically present in the European Economic Area (EEA), the UK, and/or Mainland China;
  • You want to re-use personal information you previously collected from persons in the EEA, the UK, and/or Mainland China (e.g., for a previous research project) or you want to obtain existing personal information about persons in the EEA, the UK, and/or Mainland China from other persons or units at the U of I (e.g., admissions data) to use in your research;
  • A person or entity physically present in the EEA, the UK, or Mainland China is providing you with the personal information of research subjects located anywhere in the world;
  • You intend to conduct data scraping involving the accounts or websites of persons or entities physically present in the EEA, the UK, and/or Mainland China; or,
  • You are collaborating with researchers or entities physically present in the EEA, the UK, and/or Mainland China.

In addition to requiring adequate security over the personal information of research subjects and collaborating partners, the EU and UK GDPRs and PIPL impose certain notice and consent requirements you will need to consider when designing your research protocol. The notice and consent requirements can be complex if the research involves certain special categories of personal data identified in Article 9 of the EU GDPR and the UK GDPR or certain sensitive personal information as defined in Article 28 of PIPL.

The EU and UK GDPRs also prohibit processing criminal conviction and offense information in Article 10 (see the EU and the UK versions of Article 10), except in very limited circumstances (none of which currently apply to the U of I).

As a further GDPR security measure, data processing agreements (GDPR) and/or data handling agreements (PIPL) are generally required when persons or entities other than the U of I process personal information for your research. The EU and UK GDPRs and PIPL define processing very broadly so that it covers essentially any operation performed on personal information or sets of personal information, whether or not by automated means. Processing includes, but is not limited to, collecting, recording, organizing, structuring, storing, adapting, altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning, combining, restricting, erasing or destroying personal information. Processing under PIPL is also referred to as “handling”.

If you are planning or conducting research that may be covered by the EU or UK GDPR or China’s PIPL, or if you have questions regarding whether PIPL or either GDPR applies to your research, the U of I has online tools to assist you (you will need your NetID and password to access the tools):

You may also contact the following offices for guidance:

Resources