Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Data Protection Impact Assessment (DPIA) Framework

This document defines anDREa B.V.’s (anDREa) platform-level Data Protection Impact Assessment (DPIA) for the myDRE ecosystem. It ensures structured alignment with the GDPR, the Dutch Algemene verordening gegevensbescherming (AVG), ISO 27001:2023 (A.05.34), and NIS 2.

This framework undergoes mandatory review annually or immediately following significant architecture or data flow changes.


1. Project Objective & Processing Necessity

Project Scope

The myDRE Shared Tenant model permits client organizations (Tenants) to securely link their Microsoft Azure Subscriptions to anDREa’s centralized Entra ID (formerly Azure Active Directory). This architecture allows the systematic deployment of isolated research environments (Workspaces).

Workspace Governance

Each Workspace is bound to at least one Tenant-mandated individual designated as the Accountable. Workspaces enable multi-institutional research teams to ingress, process, analyze, and egress sensitive intellectual property and personal data within a validated boundary.

Processing Trigger

To provision user accounts and maintain unalterable compliance logging, anDREa must collect and process basic identity telemetry (names and business emails).


2. Data Flow & Processing Lifecycle

Collection & Sourcing

  • Consent Boundary: Prior to account provisioning, every user must explicitly accept the myDRE Terms of Service and Privacy Policy.
  • Data Origin: Identity telemetry (name and email) is provided directly by the Tenant or via peer invitations initiated by authorized platform users.

Distribution & Protection

  • Third-Party Policy: anDREa does not share user data with third parties.
  • Technical Safeguards: All platform telemetry and Workspace data assets are strictly encrypted at-rest and in-transit. System access is strictly gated by Role-Based Access Control (RBAC).

Scope and Context of Processing

  • Platform Processing: Restricted solely to name and email. No special category data (e.g., medical, criminal) is collected or processed at the platform level.
  • Volume & Demographics: Limited strictly to active platform participants globally. Retention metrics follow the formal Data Retention Policy.
  • User Demographics: Platform users are restricted to individuals aged 16 or older who are not considered part of a vulnerable group.
  • Compliance Benchmarks: Certified under ISO 27001:2023. Operations are engineered to align with ISO 9001 and NIS 2 frameworks. (NEN-7510 compliance has been reviewed and determined not applicable to anDREa as a platform provider).
important

The Workspace Boundary: anDREa maintains a zero-knowledge posture regarding the data stored within individual research Workspaces. It is assumed that Workspaces contain highly sensitive personal data. Consequently, Workspace Accountables hold exclusive legal and operational responsibility for executing standalone DPIAs for their specific Workspaces, in coordination with their organization's Data Protection Officer (DPO).

Purpose of Processing

  • For anDREa: Ensuring stable platform performance and compiling demonstrable, unalterable compliance logs.
  • For Tenants & Accountables: Facilitating verifiable risk management, secure collaborative research, and audit tracking for their respective home organizations.

3. Consultation & Proportionality

Stakeholder Consultation Matrix

Continuous validation of this DPIA involves structured collaboration across the following sectors:

  • Tenants: CISOs and Core Support Teams.
  • Governance Bodies: The anDREa Advisory Board (including Chief Scientific Information Officers and Heads of Nodes).
  • End-Users: Community representatives, Accountables, and Privileged Members.
  • Technical Teams: Core anDREa developers.

Proportionality & Function Creep Prevention

  • Lawful Basis: Processing is strictly limited to data necessary for platform security, access control, and compliance verification.
  • Mitigating Function Creep: Maintaining, storing, and monitoring data incurs overhead. Because cost optimization is a core business metric for anDREa, the platform inherently minimizes data retention to limit operational liabilities.
  • Tenant Obligations: Tenant organizations must establish their own lawful basis for research data processing, including executing necessary Data Transfer Agreements (DTAs) for cross-border data flows.

4. Risk Assessment & Mitigation Matrix

A. Platform-Level Risks (anDREa Governance)

IDThreat Vector / Risk SourceInitial RiskImplemented Technical & Organizational ControlsResidual Risk
1Orphaned Offboarding Accounts: Former personnel retain legacy access to codebases, SharePoint, email, Teams, or Google Workspace.HighStrictly enforced identity revocation policies based on least-privilege. Complete de-provisioning occurs within 5 business days of offboarding.Low
2Unauthorized Resource Access: Malicious actor accesses compute, storage, or admin infrastructure.High
  • Continuous monitoring for behavioral anomalies.
  • Enforced MFA, strong password policies, passwordless authentication, and optional hardware keys.
  • Just-in-Time (JIT) access-on-demand via Privileged Identity Management (PIM) for core infrastructure (RDP, Entra ID).
  • Mandatory periodic access reviews.
Low
3Physical Media Compromise: Physical theft or unauthorized access to endpoint storage devices.HighMandatory annual Information Security and Data Protection training. Enforcement of strict Mobile Device and Teleworking guidelines.Low
4Azure Admin Exploitation: Compromise of administrative "skeleton" master keys.HighEnforced multi-factor authentication (MFA) and continuous administrative behavior monitoring.Low
5Platform Denial of Service (DoS): Volumetric or application-layer attacks rendering myDRE unavailable.High24/7/365 Azure telemetry alerting, health heartbeats, strict SLA metrics, and annual external penetration testing.Low

B. Environment-Level Risks (Accountable / Tenant Governance)

IDThreat Vector / Risk SourceInitial RiskImplemented Technical & Organizational ControlsResidual Risk
6Workspace Stale Access: Personnel who leave a project retain active Workspace permissions.HighAccountables and Privileged Members manage membership via self-service identity tools. Mandatory periodic access reviews automatically revoke permissions if deadlines are missed.Low
7Virtual Machine Brute-Force: Automated RDP brute-force attacks against active researcher VMs.High
  • VM access requires authenticating through the secure User Portal.
  • External connections tunnel through Azure Bastion.
  • Default automated de-allocation of VMs at 19:00 CET (re-allocation generates a new ephemeral public IP).
  • 24/7/365 infrastructure monitoring.
Low
8Physical Data Center Breach: Physical intrusion into the hosting infrastructure.HighOut-of-scope physical security controls fully managed by Microsoft Data Center security frameworks.Low
9Unmonitored Internet Egress: Data exfiltration via unmonitored outbound internet channels.HighWorkspaces enforce a default outbound deny-all policy. Outbound traffic is restricted to pre-approved allowlisted subdomains. Adjustments require explicit opt-in confirmation warnings and can only be executed by Accountables or Privileged Members.Low
10Workspace Denial of Service: Workspace disruption via malicious configuration choices.HighStandard Workspaces deploy through rigid authorization workflows. Customizations (e.g., opening outbound ports) require explicit risk acceptance from the Accountable before activation.Low
info

Security Manifesto Disclaimer: While anDREa implements robust monitoring to identify anomalous behaviors and protect against unauthorized actors, the platform is not designed to restrict or block actions taken by explicitly authorized personnel acting with malicious intent.