FAQ

Short answers to common questions about PublicnEUro data access, dataset publication, governance, privacy and long-term availability.

How can I share legally under GDPR with PublicnEUro?

The General Data Protection Regulation (GDPR) is the law that regulates all processing of personal data in Europe. According to GDPR Article 4(2), processing includes a very broad range of activities such as collection, organisation, storage, alteration, retrieval, use, disclosure, alignment, restriction, or even erasure and destruction of data. GDPR Article 6(1) requires all processing of personal information to have a legal basis and be for a specified purpose, and GDPR Article 5(1)(b) states that further processing for research is not to be seen as incompatible with any initially defined purposes.

Brain imaging of patients and healthy volunteers relates to the health of a natural person, which is a special category of data given special protection by GDPR Article 9(1). Even after pseudonymisation, such data can remain personal, and processing these categories of data is prohibited except in a defined set of circumstances. One such circumstance is defined in GDPR Article 9(2), which allows research processing in accordance with national law if it pursues a substantial public interest, is proportional to the aim, and has adequate protections in place according to GDPR Article 32 and GDPR Article 89. The research institution can, according to GDPR Article 28(3), also make use of third-party services for processing personal data (cf. data processing services and the cloud below).

Following these rules, an institution can share research brain imaging data, providing the data collection and sharing is nationally lawful and users are processing data for research purposes (which should be defined in the Data User Agreement).

Data processing services and the cloud

Following GDPR Article 28(3), a third party can process data on behalf of the data controller if a data processing agreement is in place that describes what kind of processing is allowed. Such agreements can only be made with a data processor who can document that appropriate technical and organisational measures can be put in place (cf. protective measures below - GDPR Article 28(1)). The data processor may also only process information according to documented instructions from the data controller. According to GDPR Article 82(2), the data controller is liable for any damages caused by this processing, except that the data processor is liable for damage caused by any processing that has been carried out outside of these instructions.

Given the protective measures in place in PublicnEUro, EU institutions can share data using a Data Processing Agreement. EU research institutions are the data controller and remain responsible for what is happening to the data.

Read the complete policy →

Are all PublicnEUro datasets open access?

No. PublicnEUro supports both open and controlled access. Metadata and catalogue records are public, but participant-level files may require registration, institutional identification and acceptance of the dataset-specific access terms before download.

Read the complete policy →

Why must controlled-access users register?

Controlled-access users must register because EU brain-imaging research data may remain personal data even after pseudonymisation. Registration makes users identifiable, supports audit records, and allows PublicnEUro to confirm that the required DUA and any transfer safeguards have been accepted before access is granted.

Read the complete policy →

Who decides whether access is approved?

The dataset's data controller determines the permitted uses of the data. PublicnEUro grants access according to the controller's documented instructions and the dataset-specific DUA; where the DUA requires controller approval for each request, PublicnEUro waits for that approval before giving access.

Read the complete policy →

What must users outside the EU do?

Users outside the EU/EEA may need additional safeguards before access is granted. If the user is in a country without an adequate level of protection, the appropriate Standard Contractual Clauses must be signed in addition to the dataset-specific DUA.

Read the complete policy →

What is the difference between a licence, DUA and DUC?

A licence or Data User Agreement is the authoritative legal text that defines how a dataset may be used. A DUA is used for controlled-access datasets and must be accepted before access. Digital Use Conditions are a machine-readable summary of those terms for discovery and metadata purposes; they do not replace the licence or DUA.

Read the complete policy →

How do I cite a dataset?

Each published dataset version receives persistent citation information, including a DOI. Use the citation information on the dataset landing page and cite the specific version you used, especially when a dataset has been updated or superseded.

Read the complete policy →

What do active, archived, retired, withdrawn and superseded mean?

These lifecycle states explain current file availability and recommended use. Active datasets are normally available from PublicnEUro, archived datasets are in cold storage, retired datasets are no longer held by PublicnEUro, withdrawn datasets are no longer accessible, and superseded datasets have a newer version or replacement that should normally be used.

Read the complete policy →

Will metadata remain available if the files are removed?

Yes, where legally possible. PublicnEUro maintains dataset metadata and DOI landing pages independently of file availability, so users can still discover, evaluate and cite a dataset record even when the files are archived, retired, withdrawn or superseded.

Read the complete policy →

How do I deposit or update a dataset?

Data authors should arrange a service contract, prepare the dataset in BIDS or request curation, provide required metadata and any DUA, and upload the data through the route provided by PublicnEUro. New versions can be published as updates and may receive their own DOI.

Read the complete policy →

Who is responsible for the legality of data sharing?

The institution responsible for a dataset remains the data controller and is responsible for lawful collection, pseudonymisation and a lawful DUA. PublicnEUro is responsible for processing and sharing data according to documented instructions, enforcing required agreements before access, maintaining audit records and applying appropriate security measures.

Read the complete policy →

How do I report a privacy or security concern?

Contact PublicnEUro at publicneuro@nru.dk if you have a privacy or security concern, or if you want to exercise a data-protection right. If the concern relates to a dataset, PublicnEUro will handle it under the relevant data-controller instructions and incident procedures.

Read the complete policy →