Consortium and grant agreements
Work on a funded project is compliance and rarely dispute. What counts are two points in time before the project starts and three sets of rules, of which the consortium agreement covers only one.
The grant has been awarded, the project start is fixed, and the consortium agreement is still circulating as a draft. What is negotiated are work packages and budgets, while the questions on data, ethics and authorisations are deferred to the time after the kick-off.
Little speaks against that as long as nothing goes wrong, which is also why it seldom goes otherwise. Two duties, however, have already fallen due by then.
Two points in time lie before the project start
What has to be settled before acceding to the grant agreement follows from the Regulation itself and not from the model consortium agreement.
Point 1: Before acceding to the grant agreement
The beneficiaries inform each other of limitations on access to their background, Article 41(3) of Regulation (EU) 2021/695. Declaring a limitation later means access has already been opened.
Point 2: Before the relevant activity begins
All authorisations from the competent ethics committees and data protection authorities must be in hand and on file, Article 19(4) of the Regulation.
Point 3: Up to one year after completion
A request for access for exploitation remains possible unless the beneficiaries agreed a different period, Article 41(8) of the Regulation. That period belongs in the consortium agreement.
Access to results is free of charge where a partner needs them to carry out its own tasks in the action. The same holds for background, as long as nothing else was agreed before accession. That is the practical value of the first deadline.
The ethics requirements are a condition of funding
How far the ethics requirements reach is usually underestimated, because the self-assessment looks like a form. Article 19(1) of the Regulation binds all actions to the principles of ethics and names the protection of privacy and of personal data expressly.
- The ethics self-assessment names all foreseeable ethics issues and not only the obvious ones
- Compliance with the European Code of Conduct for Research Integrity is confirmed
- For activities outside the Union it is confirmed that they would have been permitted in a member state
- Every required authorisation is in hand before the relevant activity begins and is on file
- The consortium agreement names who keeps the ethics records and who produces them on request
The consequence of a gap is no ancillary matter. Under Article 19(6) of the Regulation an action that does not meet the requirements is rejected or terminated as soon as that has been established.
The consortium agreement does not settle data protection between the partners
Who is responsible for what between the partners in data protection terms is as a rule written down nowhere. The consortium agreement allocates tasks, results and access rights. Once the partners jointly determine the analysis design, however, the test in Article 26(1) GDPR is met, and from that follows the duty to conclude a separate arrangement.
Added to this are the safeguards under Article 89(1) GDPR, that is technical and organisational measures ensuring in particular data minimisation. Both belong alongside the consortium agreement rather than inside it, because the parties differ and the essence of the arrangement has to be made available to data subjects.
The AI Act research exemption ends at testing in real-world conditions
Whether the AI Act applies to a project is often denied too quickly. Two exclusions do apply, and both are narrow.
Outside the Regulation
- Systems developed for the sole purpose of scientific research and development
- Research, testing and development activity prior to placing on the market
- The output of such systems
Not outside it
- Testing in real-world conditions, expressly under Article 2(8) AI Act
- Putting a result into service in a partner’s own operations
- Exploitation after the project ends
- Data protection law, which continues to apply alongside
How we help
- As a consortium partnerWe take on the work package covering data protection, AI and ethics and deliver the associated reports.
- Before accessionWe settle the limitations on background and the authorisations required, while both can still be shaped.
- Alongside the consortium agreementWe draft the Article 26 GDPR arrangement and align it with the consortium agreement.
Not covered here are national funding programmes, whose ancillary provisions follow their own rules, and the exploitation of results after the project ends.
A proposal is funded, and the consortium agreement is pending?
We establish what has to be settled before accession and take on the work package.
Discuss the projectFrequently asked questions
When does the consortium agreement have to be in place?
Before acceding to the grant agreement, and not for formal reasons. Article 41(3) of Regulation (EU) 2021/695 requires the beneficiaries to inform each other of any limitations on granting access to their background by that point. Declaring a limitation later means access has already been opened without charge, because paragraph 6 ties the absence of a fee to an agreement reached before accession.
Is the ethics self-assessment from the proposal enough?
As a self-assessment yes, as evidence no. Under Article 19(4) of Regulation (EU) 2021/695 all authorisations required by competent national and local ethics committees or by bodies such as data protection authorities must be in hand before the relevant activities begin, and they have to be kept on file. Where one is missing, it is not the documentation that is deficient but the activity that started too early.
Do we also need an arrangement under Article 26 GDPR?
Once the partners jointly determine the purposes and means, yes. The consortium agreement settles results, access rights and tasks, but not the allocation of data protection roles. The two documents stand side by side and frequently contradict each other, for instance where the consortium agreement provides for a transfer for which no legal basis is named. More under joint controllership.
Does the AI Act apply to our project?
As long as the work is purely research, as a rule not. Article 2(6) AI Act excludes systems developed and put into service for the sole purpose of scientific research and development, and Article 2(8) AI Act excludes research, testing and development activity prior to placing on the market. Testing in real-world conditions is expressly outside that exclusion, and that is where the exemption ends.
What applies to partners outside the Union?
Two further examinations arise. Under Article 19(2)(c) of Regulation (EU) 2021/695 it has to be confirmed that the activities would have been permitted in a member state. In data protection terms the transfer to a third country requires its own basis. Both belong in the planning and not in the reporting phase.