Privacy Notice for EGA User Account
This privacy notice explains what personal data EMBL collects, for what purposes, how it is processed, and how we keep it secure, in the context of:
EGA services for Data Access Committee Account
1. Who is responsible for the processing
The EMBL data controller (and joint-controller if applicable) contact details are:
- EMBL-EBI Hinxton
- Wellcome Genome Campus Hinxton, Cambridgeshire CB10 1SD United Kingdom
- +44 (0)1223 494 444
- info@ebi.ac.uk
You may contact CRG, whose EGA team is represented by Dr. Jordi Rambla de Argila, by:
- email at jordi.rambla@crg.eu, or
- post at Fundació Centre de Regulació Genòmica - Centre for Genomic Regulation (CRG), Dr.Aiguader 88, PRBB Building, 08003 Barcelona, Spain.
CRG Data Protection Officer may be contacted by:
- email at dpo@crg.eu
- post at Fundació Centre de Regulació Genòmica - Centre for Genomic Regulation (CRG), C/ Dr. Aiguader, 88, PRBB Building, 08003 Barcelona, Spain.
2. What personal data do we process
The following categories of personal data may be processed:
Account & Technical Data:
- Digital identifiers (username, IP address, ORCID)
- Login credentials
- System access logs
- Usage data and cookies
Custom value:
Name, Email address, Title/Position, Organisation, Organisational affiliation, Business address, Telephone number, IP addresses, Date and time of a visit to the service website, Operating system, Amount of data transmitted, Browser, Username, Password.
If applicable, the following categories of sensitive data may be processed:
- None
3. For what purposes do we process your personal data
Your personal data will be processed for the following purposes:
-
Service Delivery:
- Provide and manage service access
- Technical support and maintenance
- User authentication and security
-
Compliance & Security:
- Data protection compliance
- Security monitoring
To provide DAC user account and authenticated access to the service, to publicly publish some information to facilitate scientific research, to better understand the needs of the data subjects and guide future improvements of the service, to create anonymous usage statistics (from number of DACs, datasets per DAC), to monitor the activities on the website.
4. What is the legal basis for processing
We rely on the following legal basis(es) to process your personal data:
Personal data is processed based on Article 6(1) of EMBL Internal Policy No 68 (hereinafter, "IP68"): for the achievement of the aims laid down in the 1973 agreement establishing EMBL, such as the promotion of cooperation in fundamental research, in the development of advanced instrumentation and in advanced teaching in molecular biology and dissemination of information.
5. Who can access your personal data
The following categories of recipients may access your personal data:
EMBL internal recipients
-
EMBL-EBI Hinxton:
- Human Genomics team
EMBL external recipients
-
External recipient categories:
- Entity processing data on their own behalf
- The general public (e.g. social media)
-
Data Processor 1:
- Cookies management tool.
-
Processing Entities:
- CRG
-
Located in:
-
Location of Processor, External Recipient or International
Organisation:
- Within the European Economic Area (EEA)
-
Location of Processor, External Recipient or International
Organisation:
6. How long do we keep your personal data
Your personal data will be kept for the following period of time:
Retention envisaged time limits:
Personal data will be retained even if users no longer use the service, but will still be available to ensure legal compliance and the possibility to undergo internal and external audits.
Retention period rationale:
Any personal data directly obtained from the user will be retained as long as the service is live. Such duration serves the purpose of enabling scientific research and ensures legal compliance and facilitates internal and external audits if they arise. By contrast, the log files for the data categories related to anonymous usage statistics (raw web service logs) are processed only for 30 days and thereafter erased.
7. How do we protect your personal data
We have adopted the following measures to protect your personal data:
1. Risk Management & Controls: Regular risk assessments of information assets, Implementation of control measures, Periodic review of access rights
2. Training & Access: Mandatory security awareness and data protection training, Access granted based on job roles, Strict management of privileged accounts, Cryptographic key management
3. Incident Response & Recovery: Cyber security incident management process, Regular penetration testing, Disaster recovery planning, Business continuity measures
4. Compliance & Privacy: Protection of personal data in adherence with IP68 and other contractual obligations, Biometric data security, Rigorous due diligence of third party data hosting such as cloud services, Regular compliance monitoring
8. Data subjects’ rights and oversight mechanism
Under Article 16 of the EMBL Internal Policy No 68 , data subjects have the following rights:
• a right not to be subject to a decision made by automated means (i.e. without any human intervention)
• a right to request access to your personal data
• a right to request information on the reasoning underlying data processing
• a right to object to the processing of personal data
• a right to request erasure or rectification of your personal data.
When the legal basis to process personal data is consent, please note that you have the right to withdraw your consent at any time.
Please note that those rights can be subject to limitations, as described in Article 16 (2) of the EMBL Internal Policy No 68 .
If you wish to exercise your rights or wish to contact the data controller regarding any other data protection related matters, you can contact us using, by sending an e-mail to: info@embl.de or by sending a letter to: Meyerhofstraße 1 69117 Heidelberg Germany.
Advice on data protection matters can also be obtained from the EMBL Data Protection Officer (DPO), under Article 20 (2) of the EMBL Internal Policy No 68 . The DPO can be reached by email at dpo@embl.org or by letter at: EMBL Data Protection Officer, EMBL Heidelberg, Meyerhofstraße 1, 69117 Heidelberg, Germany.
If you wish to complain under Article 25(1) of the EMBL Internal Policy No 68 , you may do so with the DPO by email at dpo@embl.org.
If you believe that the response of the DPO is unsatisfactory or if the DPO has failed to respond within three months from receipt of the complaint, you may complain in writing to the Data Protection Committee. It can be reached by email at dpc@embl.org or by post at: EMBL Heidelberg, Data Protection Committee, Meyerhofstraße 1, 69117 Heidelberg, Germany.
Last update: February 24, 2026
