GDPR Position Statement
Effective date: 2026-08-17.
This page explains how NEMAR (Neuroelectromagnetic Data Archive and Tools Resource) relates to the European Union’s General Data Protection Regulation (GDPR). It is an operational position statement, not legal advice. Questions: [email protected].
The datasets
Section titled “The datasets”The GDPR governs personal data. Data that is anonymous, meaning the data subject is no longer identifiable by any means reasonably likely to be used, is outside the scope of the GDPR entirely (Recital 26).
Every NEMAR dataset is de-identified before deposit under the Data Contributor Terms, and the depositor declares the status of the re-identification key:
- Key destroyed: the dataset is anonymous under Recital 26, and the GDPR does not apply to it, for NEMAR or for anyone else.
- Key retained by the depositor: the dataset is pseudonymized under Article 4(5), which remains personal data in the hands of the key holder. The depositing institution is the controller for that data. NEMAR never receives the key, holds no means of re-identification, and hosts data that is effectively anonymous in its hands.
For datasets originating in the European Union or European Economic Area, the depositor warrants a legal basis for public deposit, typically the explicit informed consent of participants, which also satisfies the transfer derogation of Article 49(1)(a) where transfer rules apply at all. The Open Brain Consent GDPR edition provides participant consent language reviewed for this scenario.
Data residency
Section titled “Data residency”The GDPR does not require personal data to remain in the European Union, and it places no location constraints on anonymous data. What it regulates is the transfer of personal data to third countries (Chapter V). Lawful transfer mechanisms relevant to NEMAR:
- the EU-US Data Privacy Framework adequacy decision, under which Amazon Web Services and other NEMAR service providers are certified;
- Standard Contractual Clauses, which are built into the AWS Data Processing Addendum available to all AWS customers;
- explicit consent under Article 49 for research deposits, as above.
NEMAR data is therefore hosted in the United States lawfully, and a European mirror is a performance question, not a compliance one.
User accounts
Section titled “User accounts”The personal data NEMAR itself controls is its user account records: name, email address, and the profile fields described in the Privacy Policy. For users in the European Union, we honor the GDPR data subject rights (access, rectification, erasure, objection) as described there. Requests go to [email protected].
References
Section titled “References”- GDPR full text (unofficial consolidated version)
- Recital 26: anonymous data
- Article 4: definitions of personal data and pseudonymisation
- Chapter V: transfers to third countries
- Article 49: derogations for specific situations
- European Data Protection Board guidelines
- EU-US Data Privacy Framework
- AWS GDPR Center
- Open Brain Consent, GDPR edition