Legal and GDPR arrangements

This page is for organisations working through legal and GDPR-related onboarding with FEGA Sweden. It focuses on responsibility, agreements, local review, and how policy and Data Access Agreement (DAA) information is represented in FEGA/EGA systems.

For the overall onboarding process, see Onboarding organisations. For submitter-facing guidance, see Legal prerequisites for submission.

Organisation review and DPIA

An organisation may need to assess whether using FEGA Sweden meets local legal, information security, and data protection requirements. This can include a DPIA or another internal review before the organisation starts submitting data.

The organisation is responsible for deciding whether a DPIA is required and for carrying out and approving that assessment. FEGA Sweden can provide information about the service, processing arrangements, agreements, and technical or operational setup to support the organisation’s review.

Policy metadata and Data Access Agreements

An organisation may use a Data Access Agreement (DAA) to define the terms that data users must accept before they can access data. In the EGA metadata model, information about the DAA is entered as part of the Policy metadata for the relevant dataset.

In FEGA Sweden, the organisation responsible for the data decides which policy and DAA terms apply, how they are approved, and how access requests are received, reviewed, and decided.

FEGA Sweden can guide the organisation on how approved policy and DAA information should be entered as Policy metadata in the relevant systems, but does not decide their content or approve them.

Data Processing Agreements with Uppsala University

When Uppsala University processes personal data on behalf of another data controller through FEGA Sweden, a DPA may be needed between that data controller and Uppsala University. FEGA Sweden has already established general DPAs with several Swedish universities (see Table 1).

If the relevant data controller has not signed a general DPA with Uppsala University, a new agreement may need to be established before data can be submitted. This is normally handled at the organisational level, not by an individual submitter alone.

Table 1: General Data Processing Agreements with Uppsala University
Data controller Agreement
Chalmers University of Technology ICM 2019/180
Karolinska Institutet ICM 2019/186
KTH Royal Institute of Technology ICM 2019/189
Linköping University ICM 2019/192
Lund University ICM 2019/195
Stockholm University ICM 2019/204
Swedish University of Agricultural Sciences ICM 2019/201
Umeå University ICM 2019/207
University of Gothenburg ICM 2019/183

DPA status and onboarding status

A DPA is usually part of onboarding, but it does not on its own mean that an organisation is fully onboarded for data submission.

This is why an organisation may have a DPA with Uppsala University but still need additional onboarding work before a full submission can move forward. The DPA covers the processing arrangement; onboarding also establishes the practical ways of working described in Onboarding organisations.

Data processing on behalf of FEGA Sweden

FEGA Sweden relies on services from Sunet and the Swedish Research Council that involve the processing of personal data. This data processing is governed by two separate data processing agreements:

These agreements support the processing that takes place in the technical services used by FEGA Sweden.

Learn more