Skip to content

GDPR Position Statement

Effective date: 2026-08-17.

This page explains how NEMAR (Neuroelectromagnetic Data Archive and Tools Resource) relates to the European Union’s General Data Protection Regulation (GDPR). It is an operational position statement, not legal advice. Questions: [email protected].

The GDPR governs personal data. Data that is anonymous, meaning the data subject is no longer identifiable by any means reasonably likely to be used, is outside the scope of the GDPR entirely (Recital 26).

Every NEMAR dataset is de-identified before deposit under the Data Contributor Terms, and the depositor declares the status of the re-identification key:

  • Key destroyed: the dataset is anonymous under Recital 26, and the GDPR does not apply to it, for NEMAR or for anyone else.
  • Key retained by the depositor: the dataset is pseudonymized under Article 4(5), which remains personal data in the hands of the key holder. The depositing institution is the controller for that data. NEMAR never receives the key, holds no means of re-identification, and hosts data that is effectively anonymous in its hands.

For datasets originating in the European Union or European Economic Area, the depositor warrants a legal basis for public deposit, typically the explicit informed consent of participants, which also satisfies the transfer derogation of Article 49(1)(a) where transfer rules apply at all. The Open Brain Consent GDPR edition provides participant consent language reviewed for this scenario.

The GDPR does not require personal data to remain in the European Union, and it places no location constraints on anonymous data. What it regulates is the transfer of personal data to third countries (Chapter V). Lawful transfer mechanisms relevant to NEMAR:

NEMAR data is therefore hosted in the United States lawfully, and a European mirror is a performance question, not a compliance one.

The personal data NEMAR itself controls is its user account records: name, email address, and the profile fields described in the Privacy Policy. For users in the European Union, we honor the GDPR data subject rights (access, rectification, erasure, objection) as described there. Requests go to [email protected].