Need Help?

Privacy Notice for EGA User Account

This privacy notice explains what personal data EMBL collects, for what purposes, how it is processed, and how we keep it secure, in the context of:

EGA services for Data Access Committee Account

1. Who is responsible for the processing

The EMBL data controller (and joint-controller if applicable) contact details are:

You may contact CRG, whose EGA team is represented by Dr. Jordi Rambla de Argila, by:

CRG Data Protection Officer may be contacted by:

2. What personal data do we process

The following categories of personal data may be processed:

Account & Technical Data:

Custom value:

Name, Email address, Title/Position, Organisation, Organisational affiliation, Business address, Telephone number, IP addresses, Date and time of a visit to the service website, Operating system, Amount of data transmitted, Browser, Username, Password.

If applicable, the following categories of sensitive data may be processed:

3. For what purposes do we process your personal data

Your personal data will be processed for the following purposes:

To provide DAC user account and authenticated access to the service, to publicly publish some information to facilitate scientific research, to better understand the needs of the data subjects and guide future improvements of the service, to create anonymous usage statistics (from number of DACs, datasets per DAC), to monitor the activities on the website.

4. What is the legal basis for processing

We rely on the following legal basis(es) to process your personal data:

Personal data is processed based on Article 6(1) of EMBL Internal Policy No 68 (hereinafter, "IP68"): for the achievement of the aims laid down in the 1973 agreement establishing EMBL, such as the promotion of cooperation in fundamental research, in the development of advanced instrumentation and in advanced teaching in molecular biology and dissemination of information.

5. Who can access your personal data

The following categories of recipients may access your personal data:

EMBL internal recipients

EMBL external recipients

6. How long do we keep your personal data

Your personal data will be kept for the following period of time:

Retention envisaged time limits:

Personal data will be retained even if users no longer use the service, but will still be available to ensure legal compliance and the possibility to undergo internal and external audits.

Retention period rationale:

Any personal data directly obtained from the user will be retained as long as the service is live. Such duration serves the purpose of enabling scientific research and ensures legal compliance and facilitates internal and external audits if they arise. By contrast, the log files for the data categories related to anonymous usage statistics (raw web service logs) are processed only for 30 days and thereafter erased.

7. How do we protect your personal data

We have adopted the following measures to protect your personal data:

1. Risk Management & Controls: Regular risk assessments of information assets, Implementation of control measures, Periodic review of access rights

2. Training & Access: Mandatory security awareness and data protection training, Access granted based on job roles, Strict management of privileged accounts, Cryptographic key management

3. Incident Response & Recovery: Cyber security incident management process, Regular penetration testing, Disaster recovery planning, Business continuity measures

4. Compliance & Privacy: Protection of personal data in adherence with IP68 and other contractual obligations, Biometric data security, Rigorous due diligence of third party data hosting such as cloud services, Regular compliance monitoring

8. Data subjects’ rights and oversight mechanism

Under Article 16 of the EMBL Internal Policy No 68 , data subjects have the following rights:

• a right not to be subject to a decision made by automated means (i.e. without any human intervention)

• a right to request access to your personal data

• a right to request information on the reasoning underlying data processing

• a right to object to the processing of personal data

• a right to request erasure or rectification of your personal data.

When the legal basis to process personal data is consent, please note that you have the right to withdraw your consent at any time.

Please note that those rights can be subject to limitations, as described in Article 16 (2) of the EMBL Internal Policy No 68 .

If you wish to exercise your rights or wish to contact the data controller regarding any other data protection related matters, you can contact us using, by sending an e-mail to: info@embl.de or by sending a letter to: Meyerhofstraße 1 69117 Heidelberg Germany.

Advice on data protection matters can also be obtained from the EMBL Data Protection Officer (DPO), under Article 20 (2) of the EMBL Internal Policy No 68 . The DPO can be reached by email at dpo@embl.org or by letter at: EMBL Data Protection Officer, EMBL Heidelberg, Meyerhofstraße 1, 69117 Heidelberg, Germany.

If you wish to complain under Article 25(1) of the EMBL Internal Policy No 68 , you may do so with the DPO by email at dpo@embl.org.

If you believe that the response of the DPO is unsatisfactory or if the DPO has failed to respond within three months from receipt of the complaint, you may complain in writing to the Data Protection Committee. It can be reached by email at dpc@embl.org or by post at: EMBL Heidelberg, Data Protection Committee, Meyerhofstraße 1, 69117 Heidelberg, Germany.

Last update: February 24, 2026