Data Protection Impact Assessment (DPIA) Framework
This document defines anDREa B.V.’s (anDREa) platform-level Data Protection Impact Assessment (DPIA) for the myDRE ecosystem. It ensures structured alignment with the GDPR, the Dutch Algemene verordening gegevensbescherming (AVG), ISO 27001:2023 (A.05.34), and NIS 2.
This framework undergoes mandatory review annually or immediately following significant architecture or data flow changes.
1. Project Objective & Processing Necessity
Project Scope
The myDRE Shared Tenant model permits client organizations (Tenants) to securely link their Microsoft Azure Subscriptions to anDREa’s centralized Entra ID (formerly Azure Active Directory). This architecture allows the systematic deployment of isolated research environments (Workspaces).
Workspace Governance
Each Workspace is bound to at least one Tenant-mandated individual designated as the Accountable. Workspaces enable multi-institutional research teams to ingress, process, analyze, and egress sensitive intellectual property and personal data within a validated boundary.
Processing Trigger
To provision user accounts and maintain unalterable compliance logging, anDREa must collect and process basic identity telemetry (names and business emails).
2. Data Flow & Processing Lifecycle
Collection & Sourcing
- Consent Boundary: Prior to account provisioning, every user must explicitly accept the myDRE Terms of Service and Privacy Policy.
- Data Origin: Identity telemetry (name and email) is provided directly by the Tenant or via peer invitations initiated by authorized platform users.
Distribution & Protection
- Third-Party Policy: anDREa does not share user data with third parties.
- Technical Safeguards: All platform telemetry and Workspace data assets are strictly encrypted at-rest and in-transit. System access is strictly gated by Role-Based Access Control (RBAC).
Scope and Context of Processing
- Platform Processing: Restricted solely to name and email. No special category data (e.g., medical, criminal) is collected or processed at the platform level.
- Volume & Demographics: Limited strictly to active platform participants globally. Retention metrics follow the formal Data Retention Policy.
- User Demographics: Platform users are restricted to individuals aged 16 or older who are not considered part of a vulnerable group.
- Compliance Benchmarks: Certified under ISO 27001:2023. Operations are engineered to align with ISO 9001 and NIS 2 frameworks. (NEN-7510 compliance has been reviewed and determined not applicable to anDREa as a platform provider).
The Workspace Boundary: anDREa maintains a zero-knowledge posture regarding the data stored within individual research Workspaces. It is assumed that Workspaces contain highly sensitive personal data. Consequently, Workspace Accountables hold exclusive legal and operational responsibility for executing standalone DPIAs for their specific Workspaces, in coordination with their organization's Data Protection Officer (DPO).
Purpose of Processing
- For anDREa: Ensuring stable platform performance and compiling demonstrable, unalterable compliance logs.
- For Tenants & Accountables: Facilitating verifiable risk management, secure collaborative research, and audit tracking for their respective home organizations.
3. Consultation & Proportionality
Stakeholder Consultation Matrix
Continuous validation of this DPIA involves structured collaboration across the following sectors:
- Tenants: CISOs and Core Support Teams.
- Governance Bodies: The anDREa Advisory Board (including Chief Scientific Information Officers and Heads of Nodes).
- End-Users: Community representatives, Accountables, and Privileged Members.
- Technical Teams: Core anDREa developers.
Proportionality & Function Creep Prevention
- Lawful Basis: Processing is strictly limited to data necessary for platform security, access control, and compliance verification.
- Mitigating Function Creep: Maintaining, storing, and monitoring data incurs overhead. Because cost optimization is a core business metric for anDREa, the platform inherently minimizes data retention to limit operational liabilities.
- Tenant Obligations: Tenant organizations must establish their own lawful basis for research data processing, including executing necessary Data Transfer Agreements (DTAs) for cross-border data flows.
4. Risk Assessment & Mitigation Matrix
A. Platform-Level Risks (anDREa Governance)
| ID | Threat Vector / Risk Source | Initial Risk | Implemented Technical & Organizational Controls | Residual Risk |
|---|---|---|---|---|
| 1 | Orphaned Offboarding Accounts: Former personnel retain legacy access to codebases, SharePoint, email, Teams, or Google Workspace. | High | Strictly enforced identity revocation policies based on least-privilege. Complete de-provisioning occurs within 5 business days of offboarding. | Low |
| 2 | Unauthorized Resource Access: Malicious actor accesses compute, storage, or admin infrastructure. | High |
| Low |
| 3 | Physical Media Compromise: Physical theft or unauthorized access to endpoint storage devices. | High | Mandatory annual Information Security and Data Protection training. Enforcement of strict Mobile Device and Teleworking guidelines. | Low |
| 4 | Azure Admin Exploitation: Compromise of administrative "skeleton" master keys. | High | Enforced multi-factor authentication (MFA) and continuous administrative behavior monitoring. | Low |
| 5 | Platform Denial of Service (DoS): Volumetric or application-layer attacks rendering myDRE unavailable. | High | 24/7/365 Azure telemetry alerting, health heartbeats, strict SLA metrics, and annual external penetration testing. | Low |
B. Environment-Level Risks (Accountable / Tenant Governance)
| ID | Threat Vector / Risk Source | Initial Risk | Implemented Technical & Organizational Controls | Residual Risk |
|---|---|---|---|---|
| 6 | Workspace Stale Access: Personnel who leave a project retain active Workspace permissions. | High | Accountables and Privileged Members manage membership via self-service identity tools. Mandatory periodic access reviews automatically revoke permissions if deadlines are missed. | Low |
| 7 | Virtual Machine Brute-Force: Automated RDP brute-force attacks against active researcher VMs. | High |
| Low |
| 8 | Physical Data Center Breach: Physical intrusion into the hosting infrastructure. | High | Out-of-scope physical security controls fully managed by Microsoft Data Center security frameworks. | Low |
| 9 | Unmonitored Internet Egress: Data exfiltration via unmonitored outbound internet channels. | High | Workspaces enforce a default outbound deny-all policy. Outbound traffic is restricted to pre-approved allowlisted subdomains. Adjustments require explicit opt-in confirmation warnings and can only be executed by Accountables or Privileged Members. | Low |
| 10 | Workspace Denial of Service: Workspace disruption via malicious configuration choices. | High | Standard Workspaces deploy through rigid authorization workflows. Customizations (e.g., opening outbound ports) require explicit risk acceptance from the Accountable before activation. | Low |
Security Manifesto Disclaimer: While anDREa implements robust monitoring to identify anomalous behaviors and protect against unauthorized actors, the platform is not designed to restrict or block actions taken by explicitly authorized personnel acting with malicious intent.