Skip to content

Search result

    Showing results 1391 - 1400 of 1989

    Sanction rules

    It is important that you familiarise yourself with and comply with Statistics Denmark’s transfer and data security rules. If you do not comply with the rules, you risk suspension of you or your entire institution with Statistics Denmark. Read about our sanction rules and case processing in case of data breach., Users of Statistics Denmark’s researcher machines are responsible for complying with our transfer and data security rules. This means that you, as a user, are responsible for: , Your work on the researcher machines being compliant with Statistics Denmark’s data security rules. , Read more under Rules for working with microdata,  , Transferring analysis results and materials in compliance with Statistics Denmark’s transfer rules. , Read more under Rules on transfer of analysis results,  , Notifying , Denmark’s Data Portal immediately if you realise that you have failed to comply with Statistics Denmark’s data security or transfer rules., For more details, read Statistics Denmark’s guideline material:, Rules for data safety under the microdata schemes (pdf), Breach of the rules? This is how you handle it, If you have broken Statistics Denmark’s rules or suspect that you have, you have a duty of notification. Complying with the duty of notification in relation to breach will be considered a mitigating circumstance., Please notify both the person responsible for authorisation in your institution and Denmark’s Data Portal; the latter by sending an email to , FSEHjemtag@dst.dk, with the following: , Your ident and the authorisation number of the institution you are associated with, Project number, if any, A description of the breach or where you suspect a breach, Date and time of the breach , If the breach involves files, for example files you have transferred, image files on your computer, in your mail box or similar, you must delete them immediately from your PC, DDP App, mail folders etc. and inform about this in your email to Denmark’s Data Portal.,  , Statistics Denmark’s sanction rules, If there is a breach of Statistics Denmark’s transfer rules or data security rules, Statistics Denmark can sanction users and, worst-case-scenario, entire institutions. Statistics Denmark’s sanction rules will be deployed if: , A user breaks the rules for working with microdata on Statistics Denmark’s researcher machines, for example by taking a screendump or transcribing from the researcher machine, , or, A user has transferred data with microdata, for example transferred a file with pseudonymised key variables from BOPIKOM, Note, : An isolated breach of the rules of statistical disclosure control will not result in sanctions. In case of repeated non-compliance, however, it can result in sanctions for the institution., Sanctions in case of breach - Assessment of severity and scope, Statistics Denmark makes decisions about sanctions. We distinguish between less severe and severe breaches: , Less severe breaches, : Thoughtless action or accident – for example identification in connection with troubleshooting, Severe breaches, : Conscious action – for example conscious attempt to identify individuals or enterprises in data , Statistics Denmark decides whether a breach is categorised as less severe or severe. In the assessment of the severity of a breach, we take the following into account:, Was it a thoughtless or conscious action?, Has the user detected the breach himself, and if so, observed his duty of notification?, In connection with transfer, : How large a volume of microdata has the user transferred?, In connection with transfer, : Has the transfer tool in DDP App been used for the transfer, and if so, has the user ignored the transfer module’s warning? , In case of isolated, less severe breaches, the sanction will target the user and the project where the breach has happened. This means that the project where the breach took place will be temporarily closed for everybody and the user’s access temporarily closed, so that he or she cannot access his or her projects. In case of severe or repeated breaches, i.e. where breaches have previously been registered on the institution number, the sanctions will be more rigorous. See the overview of sanctions below., Note, : If Statistics Denmark has previously registered a breach for an institution, breaches dating back more than 2 years will not be taken into consideration. This means that any new breaches will be handled as first-time-breaches., Overview of sanctions , Sanction system for the researcher scheme,  , Sanction against user and project, Access is closed for user and access to the project is closed , Sanction against institution, Access is closed for all users and access to all projects is closed , Occurrence, First time, Second time, in 2 years, Third time, in 2 years, Fourth time, in 2 years, Less severe , breach, Until report can be approved*, 1-month suspension*, 3-month suspension*, Concrete, assessment*, Potential termination of the institution’s authorisation agreement, Severe breach, 3-month suspension*, 3-month suspension*, Potential termination of the institution’s authorisation agreement and/or specific user agreement, 6-month suspension*, Concrete evaluation of the institution’s authorisation agreement and potential termination of the institution’s authorisation agreement*, Sanction system for the authority scheme,  , Sanction against user , Access is closed for user , Sanction against scheme, Access is closed for users of the scheme, Occurrence, First time, Second time , in 2 years, Third time , in 2 years, Fourth time , in 2 years, Less severe , breach, Until report can be approved*, 1-month suspension, 1-month suspension, Concrete assessment, Potential termination of authorisation agreement, Severe breach, 3-month suspension, 3-month suspension, Potential termination of authorisation agreement and/or user agreement, 3-month suspension, 6-month suspension, Potential termination of authorisation agreement, * When Statistics Denmark detects a breach that comes under the sanction rules, the user and the project where the breach occurred will be temporarily suspended, until Statistics Denmark has processed the case and made a decision. This applies regardless if it is an isolated breach or repeated breaches within two years. , Statistics Denmark makes a decision based on a report and a plan that must be presented to Statistics Denmark by the institution with which the user is associated. Statistics Denmark will not commence the processing of the case, until we have received an adequate report and plan. Statistics Denmark estimates whether the report and plan of an institution is adequate or should be rewritten.  , You can read more about Statistics Denmark’s case processing and the requirements to the report and the plan under ”Statistics Denmark’s case processing in connection with breach of rules - guide”.,  , Statistics Denmark’s case processing in connection with breach of rules - guide, When Statistics Denmark receives a notification, or we find out ourselves that a user has not complied with Statistics Denmark’s data security and transfer rules, the user in question and the project where the breach has taken place will be temporarily suspended. The suspension lasts until Statistics Denmark has received an adequate report about the incident and a plan for prevention of similar breaches in future, and Statistics Denmark has processed and decided the case., The case processing step-by-step , The process takes place in the following steps:, Step: Presentation and demand for report and plan, When Denmark’s Data Portal receives a notification, or find out themselves that a user has not complied with Statistics Denmark’s rules, the user in question and the person responsible for authorisation in the institution will be notified by email., Denmark’s Data Portal informs about the date of the suspension of the project and of the user in question, and they will request an adequate report about the incident and the scope of the breach as well as an adequate plan for preventing similar breaches in future. Both the report and the plan must be completed in the standard template provided by Denmark’s Data Portal., The person responsible for authorisation in the institution is responsible for the report and the plan being prepared and sent to Denmark’s Data Portal., Presentation and plan – demand for “adequacy”, With the demand for adequacy, Denmark’s Data Portal asks for an adequate report about the incident and the scope of the breach. By an adequate plan is meant a report and any documentation for appropriate technical, organisational and/or staff-related measures the institution has implemented in the light of the breach. The plan can consist of e.g.:, A brief account of the current rules and practice in the institution that may be relevant for the case, A presentation of what the institution has done in connection with the breach, for example, which consequences it has had for the user, A plan for what the institution is going to do to prevent similar breaches in future, It is important that it is not statements of intent. This means that the institution must account for the initiatives that they have already implemented or will implement, and describe the process behind it. Examples could be:, Has the person responsible for authorisation held a meeting with relevant stakeholders in the institution about the breach? (Indicate: Who? When? Which proposals/decisions were made?). Attach any resolution minutes., Has the person responsible for authorisation made proposals or suggested solutions to a relevant committee, the executive board, the governing body or similar? (Indicate: Who? When? What is/was on the agenda? What was decided?). Attach the agenda and/or resolution minutes., Has a decision been made in the institution to enhance for example the communication, instructional materials, code of conduct or similar? (What? How? When? Who is the target group?)., Has the institution adopted or made any other efforts to prevent similar breaches in future? (What? How? When? Who is the target group?)., If Denmark’s Data Portal estimates that the report, plan or both are inadequate, Statistics Denmark will notify you about it and request a new one., Step: The case processing in Statistics Denmark, When Statistics Denmark estimates that the report and plan we have received are adequate, Denmark’s Data Portal will prepare the case for Statistics Denmark’s Supervisory Board and Director General. You can expect the case processing to take approximately 8 working days from we receive the adequate report until we send our decision., Step: Decision, When Statistics Denmark has made a decision of the case, we send a decision letter by email to the person responsible for authorisation. The letter contains the final decision from Statistics Denmark’s Director General, including the reason for the decision and information on whether the temporary suspension of the project and the user is lifted or whether further sanctions are imposed on the user or the institution., Guides, agreements and documents in relation to data security and responsibility, Statistics Denmark’s data security rules under the Microdata schemes, Rules for data safety under the microdata schemes (pdf), Statistics Denmark’s information security and data confidentiality policy , Information security and data confidentiality policy – Statistics Denmark, Agreements (in Danish), Autorisationsaftale (pdf), Databehandleraftale (pdf), Tilknytningsaftale (pdf), Brugeraftale (pdf)

    https://www.dst.dk/en/TilSalg/data-til-forskning/regler-og-datasikkerhed/sanktionsregler

    FAQ

    We have gathered the most frequently asked questions about the DDP App on this page. If you cannot find an answer to your question, you are welcome to contact Denmark’s Data Portal at , danmarksdatavindue@dst.dk, or by telephone +45 39 17 31 30. , We respond to emails within 2 working days, and our telephone hours are Monday through Friday from 10 a.m. until 12 noon.,  , See video guides on how to use DDP App (in Danish),  , Login to the DDP App, I have entered my password incorrectly and have been locked out - how long will I be locked out?, Wait for 30 minutes and then try again., I have technical issues in the DDP App - who should I contact?, If you have technical issues or encounter errors in the DDP App, we would appreciate hearing about it, so that we can take corrective action. You can write directly to , DDVsupport@dst.dk, . Indicate your user, the relevant institution number and project number, if any, and describe the problem – preferably with a brief step-by-step explanation and matching screendumps. Then DDP App Support will deal with the problem as soon as possible., I have problems logging in via remote.dst.dk - who should I contact?, If you have problems logging in via www.remote.dst.dk, please contact IT support in Statistics Denmark at , servicedesk@dst.dk, or telephone +45 39 17 38 00., Which browsers support the DDP App?, Google Chrome: Version 98 and upwards, Microsoft Edge: Version 97 and upwards, Firefox: Version 97 and upwards, IOS_Safari: 14 and upwards, Safari: Version 14 and upwards, Internet Explorer is not supported., Read more about Login in DDP App, User roles, Allocation of project owner in Statistics Denmark, When you submit a new project to Denmark’s Data Portal, a project owner will be allocated to you with whom you will have direct contact. We do our best to answer your enquiry as soon as possible., See the average response times,  , Who can edit user information in the DDP App?, The individual users can update their own user information in the DDP App. This could be relevant, e.g. if a user changes workplace and therefore needs to update his or her email address., If an association agreement must be terminated, this must be done either by the user, the institution administrator, the person responsible for authorisation or his or her substitute., Read more about user roles, Project proposal and data ordering, How do you make a project proposal in the DDP App?, Read how to make a project proposal in the DDP App, and find out which information should be included in a project proposal under , How to create a project proposal, ., Should I add all users to the project one by one?, Yes, all new users must be added one at a time., Where do I sign the project proposal?, Read how to sign a project proposal under , Signing the project proposal, ., Can I make changes in the project proposal after it has been sent to the administrator/Statistics Denmark?, No, once you have sent the project proposal to your administrator or to Statistics Denmark, you can no longer edit it. If your project owner in Statistics Denmark has questions or comments for the proposal, you have the opportunity to edit it, before you re-submit it., Can I associate users when the proposal has been sent to the administrator/Statistics Denmark?, No, once you have sent the project proposal to your administrator or to Statistics Denmark, you can no longer associate users. When the project proposal has been returned to you, either as approved or for revision, you can associate users again., Where can I get an overview of registers and see when they are updated?, In the DDP App, under ’Data content’ or at , danmarksdatavindue.dk, (does not require login), you can see all the registers that are part of the databank of basic data in Statistics Denmark. Here you can see when the registers were created (and will be closed, if relevant), and how often they are updated. Moreover, you can see which variables the register includes and find links to the variables documentation., Can I order not yet released data in the DDP app?, It is only possible to order not yet released data for project databases and the main and sub-projects of authority schemes., How do I get our own data added to my project?, Data that does not come from Statistics Denmark’s Database of basic data must be described broadly under ‘External data’ in the project proposal. Furthermore, a variable description is uploaded with an indication of the variables that must be pseudonymised. Read more about the requirements data must meet and how you upload data in practice under , Linking of external data, ., Where in the process is my project proposal?, A project proposal changes status depending on where in the process the proposal is. Note that your project owner or the customer team in Statistics Denmark is not notified of your proposal until the administrator has sent it to Statistics Denmark., A proposal can have the following statuses:, Created, A project proposal has been created and is being prepared., Sent to administrator, The project proposal is ready for the administrator to read it., Sent to Statistics Denmark, The project proposal is ready and the administrator has sent it to Denmark’s Data Portal. At this stage, a project owner is allocated, if a new project is concerned or a project with a previous employee in Denmark’s Data Portal., Under review, The administrator or the project owner in Denmark’s Data Portal has questions or comments to the submitted proposal and has therefore returned it to the users of the project. Questions and comments are shown in the proposal or sent via email., Sent for signature, The project owner in Denmark’s Data Portal has sent the project proposal to the signatory group., Approved, The project proposal is approved by the Head of Division for Denmark’s Data Portal, and it is now possible to move on with the order (for example drafting of contract, data delivery)., Data delivered, The assignment is completed and will subsequently be invoiced., My project proposal has not been approved - what can I do?, Your project owner in Denmark’s Data Portal may have comments or questions for the project’s contact person, and this is why your project proposal is returned for revision. , When you have edited the project proposal, you can re-submit it via the DDP App., How do you make a re-proposal in the DDP App?, Read how you make a re-proposal of a project under , Specifically about re-proposals, ., My project was approved before the DDP App was created. Should I add the previously approved registers and variables when I make a re-proposal?, Yes, you should. Only one project proposal will be valid, and all data must be documented on the valid project proposal. This is why you must enter all details in the re-proposal., Do I have to create a new population whenever I make a re-proposal of my project?, You only need to create a new population segment if the population changes significantly, for example if it is created based on changed criteria, or if a submitted population is defined differently from the previous one. If you need to extend the population and the population must have the same register extraction as the original population, you can add this as an appendix to the description of the original population. You can do the same under ‘External data’, if external data from other sources than Statistics Denmark must be added., How do I change the deletion date of my project?, If you are the administrator, you can change the deletion date of projects. When you have clicked into the relevant project, you must click the three dots to the right of the project title. Now you are able to indicate a new deletion date for the project by clicking ‘Edit project’. You should not approve the deletion date, as this means that you cannot create re-proposals in future., I have created a project under the researcher scheme, but is should have been created under the project database scheme. What can I do?, Create a new project under the project database scheme with the same information. Then the administrator for your institution can approve the deletion of the ‘incorrectly’ created project under the researcher scheme., How do I approve the deletion of a project?, If you are the administrator, you can initiate the deletion process for a project. Click the project, click the three dots to the right of the project title and select ‘Edit project’. You are now able to approve deletion of the project., The project owners in Denmark’s Data Portal do not have rights to approve a deletion., Project owner, delivery times and price, When will a project owner be allocated to my newly created project?, A project owner will be allocated to you when your administrator sends the project proposal for approval with Denmark’s Data Portal. If you have questions at an earlier stage in the process, you can send an email to , danmarksdatavindue@dst.dk, , indicating the project number in the subject field. In your email, you can ask the questions you may have. , How long can I expect it to take for me to get my data?, See the average delivery time under , Contact Denmark’s Data Portal., You are always welcome to ask the project owner in Denmark’s Data Portal how long he or she expects that it will take. The delivery time depends on the individual project., How do I see the price of my data order before I order?, When the administrator has sent the project proposal and data order to Denmark’s Data Portal via the DDP App, the project owner in Denmark’s Data Portal will be able to prepare a price quote. This quote is sent via email to the contact person for the project. It is not possible to see the price in the DDP App. You are welcome to ask for a price estimate at any time., Physical token, A token is a physical unit used for two-factor login. With two-factor login, you first log in to www.remote.dst.dk with your three/four character IDENT (without figures) and PIN code. Then you are required to confirm your identity by means of the unique security code shown on your token. When you request a physical token, you must indicate a delivery address (e.g. the institution address) and full name of the person to which it must be sent (att.)., Note that we do not send it to addresses abroad., If you choose a physical token, you are not associated with the project until you have received your token in the mail., Guidelines for using physical token versus SMS token, Users without a Danish mobile number can get a physical token mailed to them., Users who are travelling to a foreign destination where it takes a long time for a Danish SMS to get through (for example African countries or New Zealand), can get a physical token., Users travelling to a European country or USA with a Danish mobile phone can still use SMS token., Users who would like a physical token simply as a matter of convenience, generally have to use SMS token instead. The costs of a physical token are far higher than the costs of SMS token.

    https://www.dst.dk/en/TilSalg/data-til-forskning/ddv-app/faq