Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

GDPR Compliance Assessment

This assessment defines how anDREa B.V. (anDREa) complies with the General Data Protection Regulation (GDPR / AVG) and outlines how the myDRE platform unburdens Tenants and Workspace Accountables in achieving demonstrable compliance. This document is mapped against A.05.34 - Privacy and protection of personal identifiable information (PII) and NIS 2 guidelines, and undergoes mandatory annual reviews.


1. Shared Responsibility Compliance Model

To satisfy GDPR Article 30 (Record of Processing Activities) and transparency obligations, compliance responsibilities are divided between the platform provider (anDREa) and the Client Organization (Tenant / Accountable):

Platform Exclusions (Tenant/Accountable Responsibility)

The myDRE platform does not natively store or provide evidence for the following research-level items. These must be maintained externally (e.g., via a Data Management Plan (DMP), Study Registry, or Ethical Commission Approval):

  • Full registry of hosted active studies.
  • Explicit legal purposes and justifications for individual research workflows.
  • Granular classification of the specific types of data processed inside a Workspace.
  • Precise physical locations and legal agreements for third-party research data sharing.
  • Fixed study-specific data retention and erasure schedules.

Platform Inclusions (anDREa Verifiable Evidence)

The myDRE platform does natively enforce and provide evidence for the following infrastructure-level controls:

  • Access Control Logs: Complete, auditable historical records of who has or had access to a Workspace.
  • Identity Protection: Enforced strong passwords and Multi-Factor Authentication (MFA) with number matching for all authorized users.
  • Technical Safeguards: Universal encryption for data at-rest and in-transit.
  • Geographic Sovereignty: Data storage and processing are rigidly restricted to the specific Microsoft Azure Region designated by the Tenant.
  • Secure Deletion: Deleting a Workspace permanently purges its associated data assets. (Microsoft provides a non-guaranteed 14-day soft-delete restoration window for storage accounts).

2. Lawful Basis & Transparency Boundaries

Legal Justification (GDPR Article 6)

  • User Account Data: anDREa establishes and logs explicit user consent during the platform onboarding flow before any profile is generated.
  • Workspace Research Data: anDREa provides no legal justification or lawfulness validation for data stored within a Workspace. The Tenant/Accountable must independently secure and document their lawful processing basis (e.g., Informed Consent or Ethical Commission approval).

Privacy Notifications & Data Security (GDPR Articles 5, 12)

  • Platform Level: anDREa directly provides concise, clear, and intelligible Privacy and Cookie Policies covering User Account data. Users must be 16 years or older.
  • Workspace Level: The Accountable is responsible for issuing compliant privacy notices to research data subjects.
  • Data Protection by Design & Default: myDRE provides full auditable visibility into technical events. Platform audit trails log workspace membership changes, data ingress/egress requests, approval actions, and infrastructure adjustments (retained for at least 90 days). Data access reviews are conducted at least twice a year.

3. Detailed Compliance & Governance Matrix (Articles 30–49)

GDPR CategoryPlatform Implementation (anDREa)Tenant / Accountable Responsibility
Record Keeping
(Art. 30)
Automatically maintains system logs of Workspace memberships and Data Portal transfer activities.Mandated to maintain corporate records of Data Protection Officers (DPOs) and research data classifications.
Data Protection Officer
(Art. 37)
Not legally required to retain a dedicated DPO; the Director directly oversees corporate data protection.Must appoint and publish contact details of their own designated organizational DPO.
Training & Policies
(Art. 5)
Enforces an internal Data Handling Policy; maintains Data Retention, Subject Access Rights, and Data Breach procedures.Must ensure all Workspace members are adequately trained in core GDPR principles and handling protocols.
Fair Processing & Profiling
(Art. 6 & 21)
No algorithmic user profiling or automated decision-making is performed. Onboarding captures direct consent.Must ensure valid informed consent is maintained and conduct individual study-level DPIAs.
Subject Rights
(Art. 15–21)
Processes platform-level account deletion or access requests within 1 month. Identity interactions are retained in unalterable logs for compliance. Usernames are blocked upon deletion to prevent reuse.Responsible for managing all data subject rights requests (Access, Erasure, Portability) for data stored inside Workspaces.
Privacy by Design / Default
(Art. 25)
Enforces strict RBAC and multi-factor gates. Minimizes platform data collection to basic identity parameters (name, email, phone number) and operational event logs.Retains exclusive legal status as the Data Controller for all information ingressed into a Workspace.
International Data Exports
(Art. 28, 44–49)
Restricts its own infrastructure processing to three verified vendors: Microsoft (Entra ID), Google (Workspace Docs), and Zoho (Desk). Platform data transfers outside the EEA occur only on explicit Tenant instruction.Responsible for establishing standard contractual clauses (SCCs) and Data Transfer Agreements (DTAs) if configuring Workspaces outside the EEA.

4. Technical Security & Breach Protocols

Appropriate Security Measures (GDPR Article 32)

  • Encryption Baselines: Universal encryption at-rest and in-transit across all platform layers.
  • Resiliency & Recovery: Automated 30-day rolling snapshots of Workspace fileshares enable self-service restoration. Platform codebase lifecycles follow a strict, documented change procedure.
  • Classification Standards: The myDRE ecosystem is formally classified as MEDIUM for Data Integrity and MEDIUM for Availability, making it suitable for standard institutional research. Custom pseudonymization or higher-tier availability requirements are the responsibility of the Principal Investigator (PI) or Tenant.

Data Breach Procedures (GDPR Articles 33 & 34)


┌───────────────────────────────┐
│  Security Incident Detected   │
└───────────────┬───────────────┘
                ▼
┌───────── ──────────────────────┐
│     anDREa Triage & Core      │
│   Breach Procedure Enforced   │
└───────────────┬───────────────┘
                │
                ├────────────────────────────────────────┐
                ▼                                        ▼
┌───────────────────────────────┐        ┌───────────────────────────────┐
│  Platform-Level Compromise    │        │   Workspace-Level Compromise  │
└───────────────┬───────────────┘        └───────────────┬───────────────┘
                ▼                                        ▼
┌───────────────────────────────┐        ┌───────────────────────────────┐
│ Report to AP (Regulator) &    │        │ Immediate Notification Routed │
│ Impacted Users within 72 Hours│        │  to Designated Tenant Contact │
└───────────────────────────────┘        └───────────────┬───────────────┘
                                                         ▼
                                       ┌───────────────────────────────┐
                                       │ Tenant (Data Controller) Logs │
                                       │  Official Regulatory Report   │
                                       └───────────────────────────────┘

  • Within 72 Hours: If a platform breach is confirmed, anDREa initiates its Data Breach Procedure, reporting the event to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and impacted individuals when mandatory notification thresholds are met.
  • Workspace Breaches: Because the Tenant remains the legal Data Controller for information residing inside individual Workspaces, anDREa will immediately notify the Tenant's designated security contact upon discovering a potential Workspace breach, enabling the Tenant to fulfill their statutory regulatory reporting obligations.