Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

Guidelines: GDPR and Standard Contractual Clauses (SCC) Roles

This framework defines the legal allocation of responsibilities under the General Data Protection Regulation (GDPR) and EU Standard Contractual Clauses (SCC) for entities using the myDRE platform. It serves as an audit-ready supportive reference for A.05.34 - Privacy and protection of personal identifiable information (PII) and NIS 2.

warning

Legal Disclaimer: This matrix outlines the baseline architectural responsibilities prepared in consultation with legal counsel (UMC Utrecht). Because specific cross-border data flows vary, Tenants must always consult their own Data Protection Officer (DPO) and Legal Department to validate explicit SCC implementations. See: Standard Contractual Clauses (SCC)

Crucial SCC Enforcement Rule

anDREa B.V. is only subject to SCC rules if it actively initiates an independent data transfer. If researchers use myDRE functionality to transfer or access data across borders, the Workspace Accountable and their home Institute hold sole legal responsibility for executing the required SCCs.


IDPartyGDPR RoleSCC Role & Cross-Border ObligationsLicensing Boundary
A.1anDREa B.V.
(Platform Software Delivery)
Processor to the License Holder (the Institute).If anDREa actively transfers data outside the EEA, anDREa acts as the Data Exporter and must sign SCC Module 3 (P2P) or Module 4 (P2C) as agreed in the DPA.Under the primary software licenses purchased from anDREa.
A.2anDREa B.V.
(Internal Corporate Operations)
Controller for standard business relationships (contacts, agreements, meetings).If anDREa transfers its own corporate data outside the EEA, it acts as the Data Exporter and must sign SCC Module 1 (C2C) or Module 2 (C2P).Not Applicable.
BanDREa's Sub-processors
(Microsoft, Google, Zoho)
Sub-processor to the Institute.For data transfers from anDREa to its sub-processors outside the EEA, anDREa must execute SCC Module 3 (P2P) within its vendor DPAs.Not Applicable.
CThe Institute
(Tenant Institution)
ControllerIf the Institute transfers data outside the EEA (including allowing platform access from outside the EEA), it acts as the Data Exporter and must execute SCC Module 1 (C2C) or Module 2 (C2P) with the importing party.Direct license purchaser from anDREa.
DResearch & Collaboration Partners
(Accessing via the Institute)
Controller or Joint Controller (per GDPR criteria).
  • Transferring data out of EEA: Partner acts as Data Exporter and must sign SCCs with the recipient.
  • Accessing myDRE from outside EEA: Partner acts as Data Importer and must sign SCCs directly with the Institute (Data Exporter), not with anDREa B.V.
Covered under the Institute's license, provided the Institute remains the primary Controller and is accountable for the overall data management of the study.
ESubcontractors / Third Parties / Data Providers
(Contracted directly by the Institute)
Controller, Joint Controller, or Processor depending on specific local privacy laws and service configurations.
  • Transferring data out of EEA: Acts as Data Exporter and must sign SCCs with the importer.
  • Accessing myDRE from outside EEA: Acts as Data Importer and must sign SCCs with the Institute (Data Exporter), not with anDREa B.V.
Covered under the Institute's license, provided the Institute remains the primary Controller and holds legal accountability for the work package.
F.1Subcontractors of Partners
(Subcontracted by a partner, but granted myDRE access by the Institute)
Controller, Joint Controller, or Processor depending on localized privacy statutes.
  • Transferring data out of EEA: Acts as Data Exporter and must sign SCCs with the recipient.
  • Accessing myDRE from outside EEA: Acts as Data Importer and must sign SCCs with the Institute (Data Exporter), not with anDREa B.V.
Covered under the Institute's license, provided the Institute remains the primary Controller and holds legal accountability for the work package.
F.2Subcontractors of Partners
(Where the Institute acts strictly as a Processor for third-party Controllers)
Institute: Processor
Other Parties: Controllers / Joint Controllers
anDREa B.V.: Sub-processor
If these entities transfer data outside the EEA, they act as the Data Exporter. SCC requirements depend completely on the actual data flows. (Note: Because the Institute cannot legally sign as a Controller here, this scenario is typically structurally flawed).Out of Scope: If the Institute acts purely as a Processor under the GDPR, this setup violates the Institute's license. The external Controllers or partners must purchase independent licenses from Protinus or anDREa.

Summary Checklist for DPOs and Auditors

  • EEA Internal Access: No SCC execution is required for standard operations where all participating entities and users reside within the EEA.
  • External Ingress (Remote Access from outside the EEA): The Institute must initiate Module 2 (C2P) or Module 1 (C2C) agreements targeting the foreign user's institution before granting access.
  • Zero-Knowledge Posture: anDREa B.V. never signs SCCs regarding research datasets inside a Workspace, as it lacks administrative visibility into the data and holds no legal status as a Data Exporter for research projects.