Privacy Notice for EGA Public Website
This privacy notice explains what personal data EMBL collects, for what purposes, how it is processed, and how we keep it secure, in the context of:
1. Who is responsible for the processing
The EMBL data controller (and joint-controller if applicable) contact details are:
- EMBL-EBI Hinxton
- Wellcome Genome Campus Hinxton, Cambridgeshire CB10 1SD United Kingdom
- +44 (0)1223 494 444
- info@ebi.ac.uk
You may contact CRG, whose EGA team is represented by Dr. Jordi Rambla de Argila, by:
- email at jordi.rambla@crg.eu, or
- post at Fundació Centre de Regulació Genòmica - Centre for Genomic Regulation (CRG), Dr.Aiguader 88, PRBB Building, 08003 Barcelona, Spain.
CRG Data Protection Officer may be contacted by:
- email at dpo@crg.eu
- post at Fundació Centre de Regulació Genòmica - Centre for Genomic Regulation (CRG), C/ Dr. Aiguader, 88, PRBB Building, 08003 Barcelona, Spain.
2. What personal data do we process
The following categories of personal data may be processed:
Account & Technical Data:
- Digital identifiers (username, IP address, ORCID)
- Login credentials
- System access logs
- Usage data and cookies
Custom value:
- IP addresses, Date and time of a visit to the service website, Operating system, Amount of data transmitted, Browser, Cookies, Email address (only when support is requested by the user)
If applicable, the following categories of sensitive data may be processed:
- None
3. For what purposes do we process your personal data
Your personal data will be processed for the following purposes:
-
Service Delivery:
- Provide and manage service access
- Technical support and maintenance
- User authentication and security
-
Compliance & Security:
- Data protection compliance
- Security monitoring
To provide the user access to the service, to better understand the needs of the users and guide future improvements of the service, to monitor website activities according to and in compliance with the Terms of Use, to better understand the needs of the website visitors and guide future improvements of the service, to conduct and monitor website security activities, to create anonymous usage statistics.
4. What is the legal basis for processing
We rely on the following legal basis(es) to process your personal data:
Personal data is processed based on Article 6(1) of EMBL Internal Policy No 68 (hereinafter, “IP68”): for the achievement of the aims laid down in the 1973 agreement establishing EMBL, such as the promotion of cooperation in fundamental research, in the development of advanced instrumentation and in advanced teaching in molecular biology and dissemination of information.
5. Who can access your personal data
The following categories of recipients may access your personal data:
EMBL internal recipients
-
EMBL-EBI Hinxton:
- Human Genomics team
EMBL external recipients
-
External recipient categories:
- Data processors processing data on EMBL’s behalf
- Entity processing data on their own behalf
-
Data Processor 1:
- Cookies management tool
-
Processing Entities:
- CRG
-
Location of Processor, External Recipient or International Organisation:
- Within the European Economic Area (EEA)
6. How long do we keep your personal data
Your personal data will be kept for the following period of time:
Retention envisaged time limits:
Personal data will be retained even if users no longer use the service, in order to ensure legal compliance and allow for internal and external audits.
Retention period rationale:
Any personal data directly obtained from you will be retained for as long as the service remains live. This retention period supports scientific research, ensures legal compliance, and facilitates internal and external audits where required.
By contrast, log files relating to anonymous usage statistics (raw web service logs) are retained for only 30 days and are deleted thereafter erased.
7. How do we protect your personal data
We have adopted the following measures to protect your personal data:
1. Risk Management & Controls: Regular risk assessments of information assets, Implementation of control measures, Periodic review of access rights
2. Training & Access: Mandatory security awareness and data protection training, Access granted based on job roles, Strict management of privileged accounts, Cryptographic key management
3. Incident Response & Recovery: Cyber security incident management process, Regular penetration testing, Disaster recovery planning, Business continuity measures
4. Compliance & Privacy: Protection of personal data in adherence with IP68 and other contractual obligations, Biometric data security, Rigorous due diligence of third-party data hosting such as cloud services, Regular compliance monitoring
8. Data subjects’ rights and oversight mechanism
Under Article 16 of the EMBL Internal Policy No 68 , data subjects have the following rights:
• a right not to be subject to a decision made by automated means (i.e. without any human intervention)
• a right to request access to your personal data
• a right to request information on the reasoning underlying data processing
• a right to object to the processing of personal data
• a right to request erasure or rectification of your personal data.
When the legal basis to process personal data is consent, please note that you have the right to withdraw your consent at any time.
Please note that those rights can be subject to limitations, as described in Article 16 (2) of the EMBL Internal Policy No 68 .
If you wish to exercise your rights or wish to contact the data controller regarding any other data protection-related matters, you can contact us by sending an e-mail to: info@embl.de or by sending a letter to: Meyerhofstraße 1 69117 Heidelberg Germany.
Advice on data protection matters can also be obtained from the EMBL Data Protection Officer (DPO), under Article 20 (2) of the EMBL Internal Policy No 68 . The DPO can be reached by email at dpo@embl.org or by letter at: EMBL Data Protection Officer, EMBL Heidelberg, Meyerhofstraße 1, 69117 Heidelberg, Germany.
If you wish to complain under Article 25(1) of the EMBL Internal Policy No 68 , you may do so with the DPO by email at dpo@embl.org.
If you believe that the response of the DPO is unsatisfactory or if the DPO has failed to respond within three months from receipt of the complaint, you may complain in writing to the Data Protection Committee. It can be reached by email at dpc@embl.org or by post at: EMBL Heidelberg, Data Protection Committee, Meyerhofstraße 1, 69117 Heidelberg, Germany.
Last update: 24 February 2026
