Guidelines: GDPR and Standard Contractual Clauses (SCC) Roles
This framework defines the legal allocation of responsibilities under the General Data Protection Regulation (GDPR) and EU Standard Contractual Clauses (SCC) for entities using the myDRE platform. It serves as an audit-ready supportive reference for A.05.34 - Privacy and protection of personal identifiable information (PII) and NIS 2.
Legal Disclaimer: This matrix outlines the baseline architectural responsibilities prepared in consultation with legal counsel (UMC Utrecht). Because specific cross-border data flows vary, Tenants must always consult their own Data Protection Officer (DPO) and Legal Department to validate explicit SCC implementations. See: Standard Contractual Clauses (SCC)
Crucial SCC Enforcement Rule
anDREa B.V. is only subject to SCC rules if it actively initiates an independent data transfer. If researchers use myDRE functionality to transfer or access data across borders, the Workspace Accountable and their home Institute hold sole legal responsibility for executing the required SCCs.
Legal Responsibility & Licensing Matrix
| ID | Party | GDPR Role | SCC Role & Cross-Border Obligations | Licensing Boundary |
|---|---|---|---|---|
| A.1 | anDREa B.V. (Platform Software Delivery) | Processor to the License Holder (the Institute). | If anDREa actively transfers data outside the EEA, anDREa acts as the Data Exporter and must sign SCC Module 3 (P2P) or Module 4 (P2C) as agreed in the DPA. | Under the primary software licenses purchased from anDREa. |
| A.2 | anDREa B.V. (Internal Corporate Operations) | Controller for standard business relationships (contacts, agreements, meetings). | If anDREa transfers its own corporate data outside the EEA, it acts as the Data Exporter and must sign SCC Module 1 (C2C) or Module 2 (C2P). | Not Applicable. |
| B | anDREa's Sub-processors (Microsoft, Google, Zoho) | Sub-processor to the Institute. | For data transfers from anDREa to its sub-processors outside the EEA, anDREa must execute SCC Module 3 (P2P) within its vendor DPAs. | Not Applicable. |
| C | The Institute (Tenant Institution) | Controller | If the Institute transfers data outside the EEA (including allowing platform access from outside the EEA), it acts as the Data Exporter and must execute SCC Module 1 (C2C) or Module 2 (C2P) with the importing party. | Direct license purchaser from anDREa. |
| D | Research & Collaboration Partners (Accessing via the Institute) | Controller or Joint Controller (per GDPR criteria). |
| Covered under the Institute's license, provided the Institute remains the primary Controller and is accountable for the overall data management of the study. |
| E | Subcontractors / Third Parties / Data Providers (Contracted directly by the Institute) | Controller, Joint Controller, or Processor depending on specific local privacy laws and service configurations. |
| Covered under the Institute's license, provided the Institute remains the primary Controller and holds legal accountability for the work package. |
| F.1 | Subcontractors of Partners (Subcontracted by a partner, but granted myDRE access by the Institute) | Controller, Joint Controller, or Processor depending on localized privacy statutes. |
| Covered under the Institute's license, provided the Institute remains the primary Controller and holds legal accountability for the work package. |
| F.2 | Subcontractors of Partners (Where the Institute acts strictly as a Processor for third-party Controllers) | Institute: Processor Other Parties: Controllers / Joint Controllers anDREa B.V.: Sub-processor | If these entities transfer data outside the EEA, they act as the Data Exporter. SCC requirements depend completely on the actual data flows. (Note: Because the Institute cannot legally sign as a Controller here, this scenario is typically structurally flawed). | Out of Scope: If the Institute acts purely as a Processor under the GDPR, this setup violates the Institute's license. The external Controllers or partners must purchase independent licenses from Protinus or anDREa. |
Summary Checklist for DPOs and Auditors
- EEA Internal Access: No SCC execution is required for standard operations where all participating entities and users reside within the EEA.
- External Ingress (Remote Access from outside the EEA): The Institute must initiate Module 2 (C2P) or Module 1 (C2C) agreements targeting the foreign user's institution before granting access.
- Zero-Knowledge Posture: anDREa B.V. never signs SCCs regarding research datasets inside a Workspace, as it lacks administrative visibility into the data and holds no legal status as a Data Exporter for research projects.