Legal prerequisites for submission

Before a submission can move forward, FEGA Sweden needs enough information to identify which organisation or organisations are responsible for the data that will be submitted. This includes clarifying the research principal(s) (forskningshuvudman/forskningshuvudmän), who controls the processing of personal data, whether the relevant organisation is onboarded, and whether the necessary ethics documentation is in place.

This page is intended as practical guidance for submitters. It is not legal advice. If you are unsure about your project’s legal setup, check with your organisation’s legal function, data protection officer (DPO), research support, or other relevant local contact.

What to clarify before you submit

Before submitting data to FEGA Sweden, try to clarify:

  • which organisation or organisations are the research principal(s) (forskningshuvudman/forskningshuvudmän) for the research behind the data
  • which organisation or organisations are data controller(s) under GDPR for the data that will be submitted
  • whether the relevant organisation is onboarded for submission to FEGA Sweden
  • whether your ethics documentation is complete and available

It is still useful to submit a submission request even if some of these points are unclear. The request helps FEGA Sweden assess the case and advise on what needs to be clarified before the submission can move forward.

Research principal(s)

A research principal (forskningshuvudman) is a role defined in Swedish ethics legislation. In broad terms, it is an organisation in whose activities the research is carried out. This may be a university, healthcare region, biobank, company, authority, or another legal entity.

A research project may have one or more research principals. Identifying the research principal(s) is important because the role is connected to responsibility for the research project and to the ethical approval. In collaborations, it is important to check how responsibility is described in the ethics documentation and in local project records.

A research principal is not the same thing as the GDPR data controller, although the same organisation may often have both roles.

Data controller

The data controller is the organisation that determines why and how personal data are processed. For research at a Swedish university or higher education institution, the data controller is usually the organisation rather than the individual researcher. In some collaborations, there may be more than one data controller.

Before submitting data, identify which organisation or organisations are data controller(s) for the data that will be submitted. This is important because it affects which organisational arrangements and agreements may be needed before FEGA Sweden can receive the data.

If you are unsure, contact your organisation’s DPO, legal function, research support, or equivalent local contact.

Onboarding status

Submission to FEGA Sweden normally requires that the relevant organisation is onboarded. Onboarding establishes the legal, administrative, and operational arrangements needed for data submission and access handling.

Check whether the relevant organisation is onboarded before you start preparing a full submission. A Data Processing Agreement (DPA) may be part of onboarding, but a DPA does not by itself mean that submission processes are in place.

If the relevant organisation is not yet onboarded, you can still submit a submission request. That allows FEGA Sweden to assess your case and advise on next steps.

Ethics documentation

For Swedish research involving sensitive personal data or human biological material, ethical approval is often required before the research can be carried out. FEGA Sweden requests the relevant ethics documentation so that we can understand the project, assess whether the data are suitable for FEGA Sweden, and identify any issues that may need to be clarified.

See Ethical approval for more guidance.

Learn more