Glossary

GDPR compliance

In short

The GDPR is the EU's general regulation on personal data protection, and it applies to a project regardless of the participant's country whenever data on people in the EU is processed. In a proposal it forms a separate category of ethics issues, and undeclared data processing leads to requirements before the grant is signed.

The regulation applies not by where your organisation sits but by whose data you process. A Ukrainian institution in a European consortium almost always falls within it.

Where it appears in the proposal

Personal data is one of the nine categories in the ethics issues table everyone completes. Ticking "yes" does not complicate your life: it is undeclared processing, surfaced at ethics screening, that produces requirements to be met before signature – and therefore delay.

What to think through

The legal basis for processing and how you obtain informed consent from research participants.

Minimisation – collecting only what the project's purposes genuinely require.

Anonymisation or pseudonymisation – and distinguishing them honestly: anonymised data falls outside the regulation, pseudonymised data remains personal because re-identification is possible.

Transfers outside the EU – a separate question with its own rules, relevant to any consortium with non-EU participants.

Retention periods and how data is destroyed after the project.

Relation to open data

The open science requirement does not override data protection, and there is no contradiction: the principle expressly allows closing what must be closed. Personal data is a classic legitimate ground for restricting access, provided it is justified in the data management plan.

Updated 27.07.2026 · Reviewed by: GetGrant editorial team

Share TelegramXLinkedInFacebook

← All terms