Legal and GDPR arrangements
This page is for organisations working through legal and GDPR-related organisational onboarding with FEGA Sweden. It explains responsibilities, agreements, local review, and how access rules and Data Access Agreement (DAA) information are recorded in FEGA Sweden’s systems and in the European Genome-phenome Archive (EGA).
For the overall organisational onboarding process, see Organisational onboarding. For submitter-facing guidance, see Legal roles in the submission process.
Legal questions to clarify
The legal work in organisational onboarding is mainly about clarifying the questions that need an organisational answer before submissions start:
- Which organisation or organisations are responsible for the data, including the data controller(s), which decide why and how personal data are used, and any research principal(s), which are legally responsible for the research?
- Is a Data Processing Agreement (DPA) needed with Uppsala University?
- Does the organisation need a local legal or information security review, a Data Protection Impact Assessment (DPIA, an assessment of privacy risks), or both?
- Which approved access rules and DAA terms should be entered in the relevant systems?
The answers depend on the organisation, the data, and the organisation’s own decision-making process. FEGA Sweden can help identify what needs to be clarified and provide information about the service, but the organisation owns its legal assessment.
Organisation review and privacy-risk assessment (DPIA)
An organisation may need to assess whether using FEGA Sweden meets local legal, information security, and data protection requirements. This can include a Data Protection Impact Assessment (DPIA), an assessment of privacy risks, or another internal review before the organisation starts submitting data.
The organisation is responsible for deciding whether a DPIA is required and for carrying out and approving that assessment. FEGA Sweden can provide information about the service, processing arrangements, agreements, and technical or practical setup to support the organisation’s review.
For some Swedish organisations, this review is also about why they should use the Swedish FEGA service rather than send data directly to the central EGA repository. Relevant questions may include where sensitive personal data files are stored, which data processing agreements apply, how the legal status of the receiving organisation affects the assessment, and whether the organisation can accept EGA’s standard Data Processing Agreement (DPA), which is non-negotiable. In FEGA Sweden, sensitive data files are stored in Sweden, with Uppsala University as the host organisation.
Access rules (Policy metadata) and Data Access Agreements
An organisation may use a Data Access Agreement (DAA) to define the terms that data users must accept before they can access data. In EGA, this information is entered as part of the access rules, known as Policy metadata, for the relevant dataset.
In FEGA Sweden, the organisation responsible for the data decides which policy and DAA terms apply, how they are approved, and how access requests are received, reviewed, and decided.
FEGA Sweden can guide the organisation on how approved access rules and DAA information should be entered in the relevant systems, but does not decide their content or approve them.
Data Processing Agreements with Uppsala University
When Uppsala University processes personal data on behalf of another data controller through FEGA Sweden, a DPA may be needed between that data controller and Uppsala University. FEGA Sweden has already established general DPAs with several Swedish universities (see Table 1).
If the relevant data controller has not signed a general DPA with Uppsala University, a new agreement may need to be established before data can be submitted. This is normally handled at the organisational level, not by an individual submitter alone.
| Data controller | Agreement |
|---|---|
| Chalmers University of Technology | ICM 2019/180 |
| Karolinska Institutet | ICM 2019/186 |
| KTH Royal Institute of Technology | ICM 2019/189 |
| Linköping University | ICM 2019/192 |
| Lund University | ICM 2019/195 |
| Stockholm University | ICM 2019/204 |
| Swedish University of Agricultural Sciences | ICM 2019/201 |
| Umeå University | ICM 2019/207 |
| University of Gothenburg | ICM 2019/183 |
DPA status and organisational onboarding status
A DPA is usually part of organisational onboarding, but it does not on its own mean that an organisation is fully onboarded for data submission.
This is why an organisation may have a DPA with Uppsala University but still need additional organisational onboarding work before a full submission can move forward. The DPA covers how personal data are processed; organisational onboarding also establishes the practical ways of working described in Organisational onboarding.
Data processing on behalf of FEGA Sweden
FEGA Sweden relies on services from Sunet and the Swedish Research Council that involve the processing of personal data. This data processing is governed by two separate data processing agreements:
These agreements support the processing that takes place in the technical services used by FEGA Sweden.
Learn more
- Organisational onboarding
- Legal roles in the submission process
- For data controllers in research – by the Swedish Authority for Privacy Protection (IMY)
- EGA Data Protection – official EGA information about data protection, EMBL-EBI, GDPR, and the EGA Data Processing Agreement
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR – by the European Data Protection Board (EDPB)