Legal and GDPR arrangements
This page is for organisations working through legal and GDPR-related onboarding with FEGA Sweden. It focuses on responsibility, agreements, local review, and how policy and Data Access Agreement (DAA) information is represented in FEGA/EGA systems.
For the overall onboarding process, see Onboarding organisations. For submitter-facing guidance, see Legal prerequisites for submission.
Legal questions to clarify
The legal work in onboarding is mainly about clarifying the questions that need an organisational answer before submissions start:
- Which organisation or organisations are responsible for the data, including relevant data controller(s) and one or more research principals where applicable?
- Is a Data Processing Agreement (DPA) needed with Uppsala University?
- Does the organisation need a local legal or information security review, a Data Protection Impact Assessment (DPIA), or both?
- Which approved access policy and DAA terms should be represented as Policy metadata in the relevant systems?
The answers depend on the organisation, the data, and the local governance process. FEGA Sweden can help identify what needs to be clarified and provide information about the service, but the organisation owns its legal assessment.
Organisation review and DPIA
An organisation may need to assess whether using FEGA Sweden meets local legal, information security, and data protection requirements. This can include a DPIA or another internal review before the organisation starts submitting data.
The organisation is responsible for deciding whether a DPIA is required and for carrying out and approving that assessment. FEGA Sweden can provide information about the service, processing arrangements, agreements, and technical or operational setup to support the organisation’s review.
Policy metadata and Data Access Agreements
An organisation may use a Data Access Agreement (DAA) to define the terms that data users must accept before they can access data. In the EGA metadata model, information about the DAA is entered as part of the Policy metadata for the relevant dataset.
In FEGA Sweden, the organisation responsible for the data decides which policy and DAA terms apply, how they are approved, and how access requests are received, reviewed, and decided.
FEGA Sweden can guide the organisation on how approved policy and DAA information should be entered as Policy metadata in the relevant systems, but does not decide their content or approve them.
Data Processing Agreements with Uppsala University
When Uppsala University processes personal data on behalf of another data controller through FEGA Sweden, a DPA may be needed between that data controller and Uppsala University. FEGA Sweden has already established general DPAs with several Swedish universities (see Table 1).
If the relevant data controller has not signed a general DPA with Uppsala University, a new agreement may need to be established before data can be submitted. This is normally handled at the organisational level, not by an individual submitter alone.
| Data controller | Agreement |
|---|---|
| Chalmers University of Technology | ICM 2019/180 |
| Karolinska Institutet | ICM 2019/186 |
| KTH Royal Institute of Technology | ICM 2019/189 |
| Linköping University | ICM 2019/192 |
| Lund University | ICM 2019/195 |
| Stockholm University | ICM 2019/204 |
| Swedish University of Agricultural Sciences | ICM 2019/201 |
| Umeå University | ICM 2019/207 |
| University of Gothenburg | ICM 2019/183 |
DPA status and onboarding status
A DPA is usually part of onboarding, but it does not on its own mean that an organisation is fully onboarded for data submission.
This is why an organisation may have a DPA with Uppsala University but still need additional onboarding work before a full submission can move forward. The DPA covers the processing arrangement; onboarding also establishes the practical ways of working described in Onboarding organisations.
Data processing on behalf of FEGA Sweden
FEGA Sweden relies on services from Sunet and the Swedish Research Council that involve the processing of personal data. This data processing is governed by two separate data processing agreements:
These agreements support the processing that takes place in the technical services used by FEGA Sweden.
Learn more
- Onboarding organisations
- Legal prerequisites for submission
- For data controllers in research – by the Swedish Authority for Privacy Protection (IMY)
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR – by the European Data Protection Board (EDPB)