Must be at least 8 characters and not entirely numeric.

Institution & Role
Data Classification Declaration

Data Classification Declaration for Repository Uploads

Before uploading any CT imaging or related metadata to the RHYTHM Repository, each participating institution must declare the legal and data-protection status of the data it will contribute.

The RHYTHM Repository supports the secure storage, management and authorized use of both pseudonymized and anonymized CT imaging data and associated metadata contributed by participating healthcare institutions. The selected classification is important because it determines the applicable data-protection responsibilities of the Data Provider and the Repository Operator, including processing obligations, access governance, retention rules and the handling of future data-use requests.

The classification selected for Repository Data must be consistent with the applicable Data Transfer Agreement (DTA) and any associated institutional, ethical and data protection documentation. The Data Provider is responsible that the selected classification accurately reflects the legal and data-protection status of the Data it contributes.

Mandatory defacing and de-identification requirement

For all uploads, regardless of whether the data are classified as anonymized or pseudonymized, the submitted CT imaging data must be de-identified before transfer and must comply with the Repository's technical specifications. In addition, all submitted imaging data must be defaced (where applicable) before upload, to reduce the risk of facial or anatomical re-identification from CT image data.

The Repository Operator must not receive, possess or have access to any information, linkage file or re-identification key capable of identifying individual data subjects. Any pseudonymization keys or other means of re-identification must remain exclusively under the control of the relevant Data Provider.

Mandatory institutional declaration

Please select the classification applicable to the Data contributed by your institution. The selected classification must be consistent with the applicable DTA and relevant institutional, ethical and data protection requirements.

Option A — Anonymized data. Our institution declares that the data uploaded to the RHYTHM Repository are anonymized data. Our institution confirms that the CT imaging data, dose information, protocol information and related metadata have been irreversibly anonymized before transfer and no longer constitute personal data within the meaning of the GDPR.

Option B — Pseudonymized data. Our institution declares that the data uploaded to the RHYTHM Repository are pseudonymized personal data. This means that direct identifiers have been removed or replaced before transfer, but the data may still be linked back to individuals by the Data Provider using additional information or pseudonymization keys retained only by the Data Provider. Such additional information or keys shall not be transferred or made available to the Repository Operator.

Confirmation

I confirm that I am authorized by my institution to make this declaration and that the selected classification is consistent with the applicable DTA and relevant institutional, ethical and data protection requirements.

I have read and understood the above information and confirm that the selected classification applies to the data uploaded by my institution to the RHYTHM Repository.

Terms of Use

RHYTHM Repository Policy and Terms of Use

By creating an account, I confirm that I am authorized by my institution to use the RHYTHM Repository Upload Platform and, where applicable, to submit CT/DICOM imaging data, associated dose and technical metadata information under the signed Data Transfer Agreement (DTA). The data provider remains responsible for ensuring that all data have been anonymized or pseudonymized before transfer, that no direct patient identifiers or re-identification keys are uploaded, and that all necessary ethics approvals, institutional authorizations, and legal bases under GDPR and applicable national law are in place.

All repository actions, including uploads, access and analysis queries, may be logged for security, auditability and oversight by the RHYTHM governance bodies.

Use of the repository must comply with the DTA, the RHYTHM Data Management Plan, GDPR, EHDS-aligned governance principles, and the instructions of the Data Management Board and ELSIB.

Having trouble signing in or registering? Please contact the RHYTHM Repository support team.