Data governance and ethics
How imaging is de-identified, who decides which requests are approved, and what a data use agreement commits you to. This is the framework the repository rests on.
Principles
- Consent and approval come first. Nothing enters the repository without a documented basis for its collection and its secondary use.
- De-identify at ingest, not on the way out. Identifiers are removed before data lands, so no downstream mistake can leak what was never stored.
- Least access that answers the question. Requests are granted at the narrowest tier and smallest cohort that supports the stated aim.
- Every access should be attributable. Governed access without an audit trail is an honour system. Stated as the principle it is, because the platform does not yet meet it in full: authorisation is enforced on every request, but a per-case access log is not kept. See the privacy notice.
- The collection is a shared asset. Contributors are credited; users give back findings and corrections.
De-identification standard
Ingest applies a documented profile derived from the DICOM confidentiality profile, with the retentions the department needs for research value.
Removed
- Patient name, medical record number, and all other direct identifiers in the header.
- Referring and performing physician names, institution and device serial numbers where they narrow the population.
- Private tags not on the retain list, and any free-text comment field.
- Burned-in pixel annotation — screened automatically, then confirmed by a reviewer before release.
Retained or transformed
- Acquisition parameters needed to interpret the study: modality, sequence, slice thickness, field strength, contrast phase.
- Age at study, retained in years; ages above 89 are grouped rather than stated.
- Sex, and clinical context needed for teaching value.
- Dates shifted per subject by a consistent random offset, so intervals between studies survive but calendar dates do not identify an admission.
Automated burned-in text detection is good, not perfect — it misses annotations rotated with the image, and it over-flags anatomy that resembles glyphs. A reviewer confirming the flagged set costs little compared with releasing a study carrying a name in the corner.
Ethics approval
Contributing a study requires approval from Komisi Etik Penelitian Kedokteran dan Kesehatan (KEPK) FK-KMK UGM, or a documented determination that the collection falls under an existing approval. Approval references are recorded against every case and are visible to the access committee.
Researchers requesting a cohort supply their own protocol approval. The repository does not substitute for that approval — it is a source of data, not a licence to use it.
Access tiers
Requests are granted at one of the following. The tier determines what leaves the platform, not what you can look at.
- Teaching
- Curated teaching sets, viewable in the browser. No bulk export. Open to residents and supervised students.
- Research — in platform
- Cohort assembly and pipeline runs inside GAMA-RADS. Results and derived measures export; source imaging does not.
- Research — export
- Defined cohort released under a data use agreement. Requires protocol approval and a named custodian at the receiving institution.
- Contributor
- Upload rights into the ingest pipeline, scoped to the studies covered by your approval.
Access committee
A standing committee reviews requests above the teaching tier. It meets monthly and records for every decision the requester, the cohort definition, the stated purpose, the tier granted, and the reasoning — including for refusals.
Decisions are expected within five working days of a complete request. Incomplete requests are returned with what is missing rather than refused.
Data use agreement
Any release beyond the platform is covered by a data use agreement signed by the requester and their institution. It records:
- The exact cohort released and the date of release.
- The approved purpose, and that use outside it requires a new request.
- A prohibition on re-identification and on onward transfer to anyone not named.
- Storage and security expectations at the receiving institution.
- A retention period and a destruction obligation at the end of it.
- Citation and acknowledgement obligations.
- An audit right, and the consequences of breach.
Publication and citation
Cite the repository in any output that used it:
GAMA-RADS Imaging Repository. Departemen Radiologi FK-KMK, Universitas Gadjah Mada. Cohort [cohort identifier], accessed [date].
Where a data use agreement names contributing investigators, follow its authorship terms. Send the department the reference on publication.
Do not publish images that could identify a subject through an unusual finding, implant or external marker, even after de-identification. If a case is visually distinctive enough to be recognisable, ask before it appears in a figure.
Incidental findings
If you notice a finding in repository imaging that appears clinically significant and unreported, tell the department. Do not attempt to trace the patient yourself. The department holds the route back to the clinical record and will decide what, if anything, can be acted on — that decision is theirs to make, not the data user's.
Breach handling
Suspected exposure is reported immediately to the department and the data protection officer. The response is: contain, assess whether re-identification is plausible, notify the ethics committee, and notify the supervisory authority and affected individuals where UU PDP requires it. Findings and corrective actions are recorded and fed back into this framework.
Review
This framework is reviewed annually, and sooner if the law changes, an incident exposes a gap, or the platform's scope shifts. Version history is retained so it is possible to establish which rules applied when a given cohort was released.
