At first glance a funding dossier looks like a project description. In reality it almost always contains far more: CVs of the team, details of employment arrangements, bank details, occasionally reference letters or medical reports where scholarships or social funding are involved. That puts funding platforms in the same category as a personnel file — except that here the data is also read by external committees.

Who is allowed to see what?

The question that matters most in practice is not hosting, it is access rights. In many programmes the jury includes people who work in the same market as the applicants. Blanket read access to every dossier is problematic in that situation, even where a confidentiality agreement has been signed.

A rights structure that follows the procedure makes more sense:

  • Assessors see only the dossiers assigned to them, and only in their round.
  • Financial details become visible only from the due diligence phase onwards.
  • Conflicts of interest are recorded when dossiers are assigned, not minuted in the meeting.
  • Every access remains traceable in an audit log.

Retention is a decision, not an accident

In practice, rejected applications often stay in the system for years because nobody decided when they should be deleted. Data protection law requires a reason and a deadline for that. For most programmes a differentiated rule is workable: funded projects for the entire reporting period plus the retention period, rejected applications for considerably less, with the option of explicit consent for resubmission in the next round.

The most uncomfortable question from a supervisory authority is rarely «Where is the data stored?» but «Who had access to it, and for how long?»

Why location still matters

Swiss funding programmes and public bodies work with data that often belongs neither abroad nor within reach of foreign authorities. Hosting in an ISO 27001-certified data centre in Switzerland does not answer every question, but it takes the debate about third-country transfers out of the project — which in a procurement process can save several weeks.

Tenant separation belongs in the same category: a dedicated instance per organisation rather than a shared database. That simplifies deletion concepts, exports and the evidence that data from different programmes is not mixed.

Checklist before the call opens: Which fields are genuinely needed? Who sees which phase? How long do rejected applications stay stored? Who receives an export at the end — and in what format? Four questions that take an hour to settle before the start, and weeks afterwards.

This article is not legal advice. For the specific design of your record of processing activities, data processing agreement and deletion concept, it is worth consulting your own legal advisors.