01
What is MyDNABank?
MyDNABank provides consent and access infrastructure for genomic data. Individuals manage research choices, laboratories contribute services and eligible datasets, and research partners seek approved access. Participating laboratories perform sequencing and laboratory testing.
02
Who is MyDNABank for?
Individuals managing their genomic information, laboratories and biobanks holding genomic datasets, and pharma, biotech and contract research organisations (CROs) seeking approved research access.
03
Who controls the genomic data?
Individuals manage their research permissions. Laboratories and biobanks retain their agreed approval roles for the datasets they hold. MyDNABank connects recorded permissions with access decisions. Each request must respect participant rights, institutional authority and restrictions attached to the data.
04
How does research access work?
A research partner submits a defined request. The approval process checks its purpose against recorded permissions, applicable legal requirements and institutional restrictions. Approved analysis takes place within a Trusted Research Environment, a controlled space for working with sensitive data. Only reviewed, permitted outputs are released.
05
Which research needs does MyDNABank support?
MyDNABank supports pharma, biotech and CRO teams assessing genomic cohorts for biomarker research, drug-target research, patient stratification and pharmacogenomic studies.
We connect the research question with cohort feasibility, available clinical context and documented permissions. Suitability depends on the datasets available and the approved study scope. Feasibility findings support study planning. Participant recruitment requires a separate agreed workflow.
06
How do you assess whether a cohort meets our research requirements?
Assessment starts with your research question, target population and required genomic and clinical information.
We review available cohort descriptions for relevant variants, phenotype, treatment history and outcomes. The assessment identifies missing information, quality limitations and preparation requirements, including compatibility with your analysis methods.
The supplying institution confirms dataset characteristics. Preliminary matches require scientific validation and permission review before inclusion in a study. Clinical completeness and suitability for combined analysis are assessed for each source.
07
How do you establish permission for research and commercial use?
The supplying institution must establish its authority to make a dataset available for the proposed purpose. The review covers participant permissions, applicable legal grounds, contractual restrictions and required ethical approvals. Academic research permission does not automatically authorise commercial research.
Research permission and the legal basis for processing personal data are assessed separately. MyDNABank's consent layer connects validated permissions and research-use restrictions with access decisions. The institution retains its agreed approval role. Unclear or insufficient authority requires resolution before access proceeds.
08
Where does analysis take place, and which platforms support the work?
MyDNABank's research-access model brings approved computation to the data within an agreed Trusted Research Environment. Established analysis platforms and specialist tools are assessed against the project's methods, data location and institutional requirements.
Where the selected deployment supports federation, analysis is coordinated across participating environments while source datasets stay with their custodians. GA4GH standards inform the architecture for dataset descriptions, researcher credentials and research-use permissions.
MyDNABank manages the permission workflow. The research environment enforces technical access and output controls. The project review covers software compatibility, researcher locations and international-transfer requirements, including remote access. Only reviewed, permitted outputs are released.
09
What security and privacy safeguards apply?
Research access requires verified researcher identities, access limited to approved users and purposes, encryption during transfer and storage, activity logging and output review.
MyDNABank, the supplying institution and the analysis provider verify the safeguards for their respective functions before access begins. The review covers the selected deployment, incident response and data residency. Any ISO/IEC 27001 certification or other independent assurance evidence is assessed for its scope and coverage of the services used.
Project governance addresses General Data Protection Regulation (GDPR) obligations and, where applicable, Health Insurance Portability and Accountability Act (HIPAA) requirements. Agreements record data-protection responsibilities, permitted use, onward-sharing limits and incident notification procedures. They prohibit unauthorised re-identification.
10
How are data provenance and the audit trail maintained?
Each project requires documented dataset provenance, including the supplying institution, source information, relevant processing history and known quality limitations.
MyDNABank's consent layer links permission history and approved research purposes to access decisions. The research environment records analysis activity, workflow versions and output release within its responsibilities.
Together, these records support review of who performed an action, when and under which approval. Project agreements define retention, availability of audit evidence and responsibility for investigating discrepancies.
11
What happens when a participant withdraws research permission?
The consent layer records withdrawal and blocks new research access covered by the withdrawn permission. Account holders submit changes through their consent settings. Institutional partners communicate permission changes through the agreed process.
For active studies, processing dependent on withdrawn consent must stop. Any continued use of previously collected personal data requires an independently valid legal basis and the applicable genetic-data safeguards. The relevant basis and withdrawal limits must be established and explained before participation.
The responsible organisations implement required access changes and assess retention or deletion obligations. The audit trail records the withdrawal and resulting actions.
12
How do we start a research project?
Share your research question, target population, required genomic and clinical data, analysis needs and timeline. Please exclude participant identifiers and genomic files from the initial message.
The initial assessment sets out whether suitable cohorts are available, the relevant permission constraints, material data gaps and preparation requirements. The proposed scope defines deliverables, the analysis environment, responsibilities and next steps.
Research access begins once the required agreements, approvals and safeguards are in place.