Content Protection Safeguards
How the catalogue protects content-provider copyright, patient privacy in imaging metadata, and Human Tissue (Scotland) Act 2006 compliance.
Purpose
This document describes the technical and procedural safeguards built into the catalogue to protect three distinct kinds of interest:
- The rights of content providers and donor institutions — control over whether, and to whom, their material is shown, and a permanent record of where it came from and who holds copyright in it.
- Compliance with the Human Tissue (Scotland) Act 2006 — restricting access to human specimen material to individuals who have agreed to abide by the appropriate code of conduct, with the ability to apply or tighten that restriction at any time, including for material already in circulation.
- The privacy of patients named in source imaging metadata — for DICOM-format material specifically, removing identifying information from a file’s own internal records at the point it is collected into the catalogue, before it is ever made available to any user.
It is written for a non-technical legal and administrative audience. Technical terms (database field names) are given in parentheses only where a precise pointer may be useful for future reference.
Part 1 — Protecting copyright and provenance
1.1 The availability switch
Every slide in the catalogue carries a single yes/no flag controlling whether it can be shown at all (is_available). This is independent of every other setting described in this document — it exists specifically so that a donor or rights-holder’s wishes about visibility can be honoured directly, without having to delete or alter the underlying record.
- Defaults to available for all existing content, reflecting the fact that everything currently in the catalogue was accepted into it on that basis.
- Can be switched off for any individual slide, at any time, by a system administrator — immediately removing it from anything a user can see or search, while preserving the underlying data, metadata, and file for administrative purposes.
- Is checked independently of the Human Tissue Act controls described in Part 2 — a slide can be turned off for reasons that have nothing to do with human tissue status (e.g. a donor withdrawing consent, a rights dispute, a request to pause display while provenance is being confirmed).
1.2 Provenance and copyright records
A dedicated table (provenance_records) holds the copyright and rights information for the collections in the catalogue: which institution or department a batch of material is attributed to, who holds copyright, and free-text rights or embargo conditions. This is a linked record, not a value copied onto every slide — so a single correction or update to a collection’s rights status applies to every slide drawn from it in one step, rather than requiring each slide to be edited individually.
Currently, every slide in the catalogue is linked to one such record (the initial “University of Glasgow — MVLS Archive” batch). The table is deliberately built to support finer-grained splits later — for example, separating out a specific donor’s material, or a sub-collection under different terms, without any change to the underlying structure.
1.3 Per-slide provenance history
Independently of the shared rights record above, every slide also carries its own frozen provenance detail, recorded once when it entered the catalogue and never silently overwritten:
- How it entered the catalogue (which import process, and when).
- Where it came from — institution, collection, or donor — kept distinct from the file’s current storage location, so a future storage reorganisation cannot erase the history of where a specimen originally came from.
- When it entered the collection, distinct from when the database record itself was created (which can lag behind the real acquisition date).
- Free-text notes for anything the structured fields don’t capture — for example, a reference to donor correspondence or a specific consent record.
1.4 What the catalogue does, and does not, hold
The provenance information described above is institutional and collection-level — which archive, which batch, which import process, which dates. By its nature, the catalogue does not store personal information about the individual a specimen may relate to (name, contact details, or similar). Any such personal information that exists would be held in the original documentation created at the time a specimen was collected or donated — consent forms, clinical or departmental records, correspondence — and those original documents are not themselves stored in, or copied into, the catalogue.
What the catalogue does hold is enough of a stable reference — the specific specimen’s identity, its archive location, and which batch or collection it was drawn from — to trace any given piece of content back to that original documentation on request, held in the relevant institution’s own records. This is what makes it possible to identify and act on a removal or restriction request: the catalogue does not need to hold personal data itself in order to comply with one, only to reliably point back to where the fuller record sits, and to provide the means (§1.1, and §2.3 for human tissue specifically) to act immediately once a request is identified.
1.5 Who can act, and the audit trail
Everything described in this section is a system-administrator-only action. Every grant, change, or availability toggle is written to an administrative log recording who made the change and when. That log can, if genuinely necessary, be cleared by a system administrator — but doing so is itself logged, so an empty log is never indistinguishable from one nothing was ever written to. For the human-tissue classification decisions in Part 2, a stronger guarantee applies: see §2.3.
Part 2 — Human Tissue (Scotland) Act 2006 compliance
The legal basis, and the catalogue’s role
The 2006 Act governs the removal, retention and use of parts of the body of a deceased person in Scotland. Section 3(1) permits such use for the purposes of transplantation, research, education or training, or audit — but only where it has been appropriately authorised under the Act. Education and training is the purpose under which this catalogue’s teaching material falls.
Two boundaries of that framework matter for this document:
- The 100-year disapplication. Under section 4(1)(d), the Act’s authorisation requirements do not apply to the removal, retention or use of any part of a body of a deceased person where both of two conditions are met: the person died before 1 September 2006 (the day section 3 came into force), and at least 100 years have elapsed since the date of death. This is a two-limbed test, not simply “died more than 100 years ago”: material from a person who died after 1 September 2006 can never become exempt through the passage of time. (A parallel provision, section 25, makes the same disapplication for the Act’s post-mortem examination requirements; where material derives from post-mortem examination, Parts 2 and 3 of the Act may also be relevant to the underlying determination.)
- Tissue versus images. The Act regulates human tissue itself — bodies, organs, blocks, and the material on glass slides. The digitised images that make up this catalogue are not themselves parts of a body. The controls in this Part are therefore the University’s own governance of images derived from regulated material, deliberately adopting the framework and standards of the 2006 Act as the appropriate benchmark — in places going beyond what the Act would strictly require (see §2.3). (The Human Tissue Act 2004, and licensing by the Human Tissue Authority, apply to England, Wales and Northern Ireland only; Scotland is governed by the 2006 Act.)
2.1 The problem this addresses
Collections in the catalogue routinely contain a mix of human and non-human specimens, and — critically — a mix of human specimens under genuinely different circumstances (for example, material believed to be more than 100 years old alongside recently acquired teaching material) within the same collection. A single, collection-wide access rule cannot correctly express this. The catalogue therefore controls access to human specimen material at the level of the individual specimen, never at the level of the folder or collection it happens to sit in.
2.2 Per-specimen classification
Every slide carries one of four classification states (hta_status):
| State | Meaning |
|---|---|
| Not applicable | Not a human specimen. |
| Exempt | A human specimen a curator has actively reviewed and confirmed is not subject to the Act’s authorisation requirements — most commonly on the statutory basis in section 4(1)(d): the person died before 1 September 2006 and at least 100 years have elapsed since the date of death. An exemption note should record both limbs of that test. |
| Restricted | A human specimen requiring code-of-conduct acceptance (§2.4) to view. |
| Pending review | A human specimen that has not yet been reviewed by a curator. |
An honest caveat on the first of these: a specimen can only be flagged as human once its species is recorded, so the Not applicable state today necessarily contains a mixture of specimens confirmed as non-human and specimens whose species has simply never been recorded. The catalogue’s own recent experience shows why this matters — the entire currently-Restricted set (§2.7) had no species information at all until it was actively reviewed, and so had passed every earlier process unnoticed. Species verification of the Not applicable population is therefore treated as part of the ongoing curatorial review described in §2.8, not as a closed question: a specimen without recorded species information is a queue item, not a cleared one.
The default is fail-safe. Any specimen whose recorded species indicates a human origin is automatically set to Pending review the moment that fact is recorded — never Exempt and never openly visible by default. A specimen only becomes viewable to a wider audience once a curator has actively reviewed it and made an explicit decision; nothing becomes open purely by the passage of time or by default inaction. For the purposes of who can view a specimen, Pending review and Restricted are conceptually treated as the same underlying concern — a specimen requiring caution — though, as §2.8 explains, they are not yet enforced identically today.
Every classification decision is timestamped and attributed to whoever made it — a system administrator, or an expert acting within their own collection (§2.3) — with an optional free-text note recording the reasoning (for example, evidence of date of death, or a documented family request) — never a mandatory field, so a decision is never blocked on paperwork, but a reason can always be recorded when one exists.
2.3 Retroactive restriction — the ability to act on request, at any time
A specimen’s classification is not a one-way, one-time decision. A system administrator, or an expert with recognised standing over the specific collection a specimen belongs to, can move any specimen to Restricted at any moment:
- A specimen currently believed exempt (for example, on the section 4(1)(d) basis) can be moved to Restricted immediately if, for instance, a family member comes forward with a request — regardless of whether the Act’s own minimum legal requirement would technically still permit it to remain visible. This is treated as an institutional choice the catalogue supports, not merely a legal minimum the catalogue enforces.
- Requests from families are handled bona fide. A request from a family member is acted on in good faith, as it stands: the specimen is restricted first, and any questions are resolved afterwards. A family is never asked to prove legal standing, produce documentation, or cite a provision of the Act before material is hidden — the design makes this affordable precisely because restriction is immediate, reversible, and preserves the underlying record.
- This applies uniformly to any specimen in any collection, including one that has been visible for some time — there is no notion of a specimen becoming “locked in” to an earlier decision.
- A day-to-day discovery route, not just a formal request. A reviewer — someone with recognised standing to review material in a collection, short of the further standing needed to restrict a specimen directly — can flag a specimen for a decision, recording why. An expert with standing over that collection can act on the flag immediately by restricting the specimen; otherwise it is picked up through the administrative queue below. Either route automatically clears the flag once acted on, so nothing sits open and unresolved once a decision has genuinely been made.
- The reverse — moving a specimen back out of Restricted, or confirming one Exempt — remains a system-administrator-only decision, made through the administrative queue below. Loosening a restriction always requires that additional level of sign-off; tightening one, whether by an administrator or an expert, does not.
A dedicated administrative screen (the HTA classification queue) lists every specimen by its current status, including a specific view of everything currently flagged and awaiting a decision. Together with an expert’s direct restriction described above, this is the only route by which a specimen’s classification changes — there is no way for this to happen as a side effect of an unrelated action. Every such change, however it is made, is written to a dedicated record of who changed what, from which status to which, and when. Unlike the general administrative log described in §1.5, this record cannot be edited or cleared by anyone, including a system administrator, through any interface the catalogue provides — it is enforced at the database level, not merely by application logic.
2.4 Code-of-conduct acceptance
Viewing a Restricted specimen (and, once §2.8’s rollout completes, Pending review too) additionally requires the viewing user to hold a specific, separate acceptance flag on their account, confirming they have agreed to the Human Tissue Act code of conduct. This is deliberately independent of ordinary catalogue login and of collection access (§2.5) — holding either does not imply the other.
Access to restricted material is therefore an individual matter, never something that comes bundled with a role or a collection grant: a user who wishes to view Restricted material makes an individual request, subscribes to the Human Tissue Act code of conduct through the institutional process, and only then has acceptance recorded against their account.
The code-of-conduct document and the process of agreeing to it are handled entirely outside this system. The catalogue’s role is limited to recording, on a system administrator’s explicit action, that a given user has been confirmed as having agreed to it — the acceptance workflow itself is an institutional process, not a self-service checkbox inside the application. This can be revoked by an administrator at any time, with the same immediate effect as any other access change described in this document.
2.5 Collection-level view access
Separately from specimen-level classification, access to browse a given collection at all requires an explicit grant. Every new account is automatically granted access to browse the general teaching archive (the “MVLS Archive” collection) — judged safe as a baseline for any legitimate catalogue user — while access to other collections requires a specific grant from a system administrator.
2.6 Visibility of a specimen’s status
Where a specimen is actively classified Restricted, the catalogue displays a clear on-screen indicator on that specimen’s page — but, consistent with everything above, only to a user who would actually be permitted to see it (i.e. someone holding both the relevant collection access and code-of-conduct acceptance, or a system administrator). A user without that access sees no indication one way or the other that the restriction exists.
2.7 Current status (as of 2026-08-18)
| Specimens classified Restricted | 31 |
| Specimens Pending review (fail-safe default, human, not yet reviewed) | 1,328 |
| Specimens Not applicable (non-human, or species not yet recorded — see the caveat in §2.2) | 2,115 |
| Users with code-of-conduct acceptance recorded | 2 |
The 31 currently Restricted specimens are the “Oral Pathology” teaching collection — a set of specimens (including material such as a labelled osteoma resection) that had no species information recorded at all prior to this review, and so had not previously been identified as human material by any earlier process.
2.8 What is enforced now, and what is staged
Enforcement is being switched on in two stages that mirror the classification split in §2.2:
- Confirmed Restricted material is gated now, ahead of the wider rollout. As of this document, viewing a Restricted specimen — on its own page or in search results — requires the same collection access and code-of-conduct acceptance described in §2.4/§2.5, enforced directly: a user without both is refused access outright, and the specimen is excluded from their search results entirely, not merely hidden from display. There is no backlog rationale for deferring this: these are precisely the specimens the mechanism exists for.
- Pending review material remains visible to logged-in institutional users while the review backlog is worked through. Switching full gating on for 1,328 not-yet-reviewed specimens overnight would suddenly hide a large volume of legitimate teaching content from staff who currently and appropriately use it — the risk being one of disruption, not of exposure, since the catalogue is not yet in public view and access is already limited to logged-in institutional accounts. As each specimen is reviewed it moves either to Exempt (and opens) or to Restricted (and is gated immediately, the moment a curator makes that decision).
This is a deliberate, staged rollout, not an oversight: classification, acceptance recording, restricted-specimen enforcement, and the display safeguards are all live and in active use now, and the Pending review population shrinks toward zero as the curatorial review proceeds — at which point the distinction between the two stages disappears.
Part 3 — De-identifying DICOM imaging at the point of collection
Some of the catalogue’s source material arrives in the DICOM format used by clinical imaging equipment, which — unlike the scanned-slide formats making up most of the catalogue — carries patient-identifying information directly inside the file’s own internal records (name, date of birth, referring clinician, institution, and similar). Where this format is used, that information is stripped out as part of collecting the file into the catalogue, before it is stored or made available to anyone.
3.1 Two de-identification modes
Whoever runs the collection process chooses one of two modes, applied per file:
- Full (the system default) — removes every direct patient/institution identifier, and additionally removes every descriptive field that could narrow down who the patient is even indirectly (age, size, weight, free-text descriptions). What remains is only the technical imaging information needed to display and study the image, with no clinical or patient context at all.
- Non-identifying — removes the same direct identifiers, but deliberately retains non-identifying descriptive fields that carry real teaching value (patient sex, age, body part examined, modality, study description, imaging parameters).
Both modes also regenerate the file’s internal cross-reference identifiers (study/series/image UIDs), so a de-identified file cannot be linked back to the source clinical system’s own records for that patient.
3.2 An honest limitation, and the safeguard for it
This process only inspects the file’s internal header records — it does not, and cannot, inspect the image itself. Some scanners burn identifying text directly onto the visible image (for example, a patient name printed in the corner of the picture); no header-stripping process can detect or remove that. Where a source file’s own metadata claims this has happened, the catalogue records a specific warning flag against it, so that file can be routed for manual visual review before it is made available — rather than relying on the automated process alone for that specific risk.
This process is deliberately described as a practical, conservative approach rather than a certified implementation of any formal de-identification standard, and its output is expected to be spot-checked, particularly on free-text fields, before being treated as safe to publish.
3.3 Current status
This capability exists and has been tested, but no DICOM-format material has been collected into this particular catalogue yet — every slide in the system today is in one of the other supported scanned-slide formats. The safeguard is in place ahead of that content type being used, not retrofitted after the fact.
Summary
| Protects against | Mechanism | Scope |
|---|---|---|
| Showing content a rights-holder wants hidden | Availability switch | Per specimen |
| Losing the record of who holds copyright / where material came from | Linked provenance & copyright records + frozen per-specimen history | Per collection batch + per specimen |
| Holding personal data the catalogue doesn’t need, while staying able to trace and act on a removal request | Institutional/collection-level provenance only; original documentation stays outside the catalogue, referenced not copied | Per specimen |
| Showing human specimen material without appropriate authorisation under the 2006 Act | Per-specimen classification (§2.2), fail-safe default, individual request + code-of-conduct acceptance (§2.4), enforced for Restricted specimens now (§2.8) | Per specimen, per user |
| A family’s wishes about a specimen | Bona fide, restrict-first handling of any family request (§2.3) | Per specimen, immediate |
| A specimen “locking in” an earlier access decision | Reclassification available at any time, in either direction, by a system administrator | Per specimen, unlimited |
| Untraceable access-control decisions | Administrative log of every grant, revoke, and availability change (§1.5); a separate, database-enforced append-only record of every human-tissue classification change that cannot be edited or cleared by anyone (§2.3) | System-wide |
| Patient-identifying information in source DICOM imaging metadata | Header de-identification at point of collection, with manual-review routing for suspected burned-in identifiers | Per file, at intake |