scieee AI-readable full text Open interactive document viewer

Data Management Plan (DMP) – PATH2EU (MSCA PF 101206931), Version 1.0

Ortiz López, Juan Eduardo

Abstract

This record contains the Data Management Plan (DMP) of the MSCA Postdoctoral Fellowship PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in the European Union (Grant Agreement 101206931). The document presents the project’s data governance framework, including data description, standards, documentation, storage, preservation, sharing strategy, and legal/ethical compliance. It also outlines the project’s approach to FAIR principles, anonymization, and long-term archiving. This is the official public version (v1.0) of the DMP. CitationIf this document is used, referenced, or reproduced, please cite it following the “How to cite” section included in the DMP.

Full text

PROJECT Project number: 101206931 Project acronym: PATH2EU Project name: Pathways to social inclusion for unaccompanied minors in the European Union Host institution Universidad Pontificia Comillas Data Protection Office [email protected] DATA MANAGEMENT PLAN (D. 1.1) Date: 05/11/2025 Version: 1.0 2 HISTORY OF CHANGES VERSION PUBLICATION DATE CHANGE 1.0 05.11.2025 Initial version 3 Project Metadata Title: PATH2EU Creator: Juan Eduardo Ortiz López, [email protected] Affiliation: Universidad Pontificia Comillas, Instituto Universitario de Estudios sobre Migraciones (IUEM). Funder: European Commission Template: Horizon Europe Template Start date: 15-05-2025 End date: 14-05-2027 Last modified: 05-11-2025 Grant number: 101108151 Project summary (short): PATH2EU investigates pathways to social inclusion for unaccompanied minors in the European Union using qualitative, participatory and ethnographic methods (interviews, focus groups, observations, participatory workshops). The project will produce datasets composed mainly of qualitative materials (audio/video recordings, transcripts, fieldnotes, photographs, textual datasets). Keywords: Data management, DMP, FAIR data, data security, research data. Primary contact for the DMP and data questions: Data controller (institutional): Universidad Pontificia Comillas Local Data Protection Officer (DPO): [email protected] 4 Table of Contents 1. List of Abbreviations and Glossary 06 2. Introduction 07 3. Data summary 08 3.1. General overview of data 3.2. Types, formats, provenance, volume, retention, access & primary uses 3.3. Re-use of existing data: decisions & exceptions 3.4. Purpose of data generation and relation to project objectives 3.5. Origin and provenance 3.6. Data utility outside the project 3.7. Data lifecycle and operational procedures 3.8. Anonymization and Pseudonymization Procedures and Decision Documentation 3.9. Metadata, documentation and standards 3.10. Access, sharing and governance 3.11. Ethics, legal basis and DPIA 3.12. Quality assurance, versioning and provenance 3.13. Roles & responsibilities 3.14. Risks identified and principal mitigations 4. FAIR Data (Findable, Accessible, Interoperable, Re-usable) 19 3.1. Making Data Findable 3.2. Making Data Accessible 3.3. Making Data Interoperable 3.4. Increasing Data Re-use 5. Other research outputs 20 6. Allocation of resources 20 6.1. Long-term sustainability 7. Data Security and Storage 21 7.1. Storage locations and backup 7.2. Access control and authentication 7.3. Technical and organisational safeguards 7.4. Data recovery and continuity 7.5. Data Classification and Confidentiality Levels 8. Ethics and legal compliance 23 8.1. European framework 8.2. National frameworks 8.3. Consent and vulnerable participants 8.4. Data Protection Impact Assessment (DPIA) 8.5. Ethics approvals and oversight 8.6. Distinction between legal compliance and rights protection 8.7. Comparative legislative frameworks 8.7. Documentation and procedural safeguards 9. Other issues and institutional procedures 28 10. Annexes Annex I. Data Protection Impact Assessment (DPIA) – Template 29 Annex 2. Record of Processing Activities (ROPA) – Template 31 Annex 3. Data Processing Agreement (DPA) format 32 Annex 4. Data Use Agreement (DUA) format 34 5 Annex 5. Data Access Request Form 36 Annex 6. Data Breach Notification Form 38 Annex 7. Adult Informed Consent Form 40 Annex 8. Participant Minor Assent Form (Ages 14–17) 42 Annex 9. Participant Minor Assent Form (Ages 10–13) 44 Annex 10. Co-Investigator Minor Assent Form (Ages 14–17) 46 Annex 11. Guardian / Legal Representative Participant Consent Form 48 Annex 12. Guardian / Legal Representative Consent Form for Co-Investigator Role 50 Annex 13. Privacy Notice (Plain Language) 52 Annex 14. Safeguarding / Referral Protocol 54 Annex 15. Anonymization Decision Log format 59 Annex 16. Data Access Log format 61 Annex 17. Version Control & Changelog format 62 Annex 18. Encryption & Storage Protocol 63 Annex 19. Dataset README Template 65 Annex 20. DataCite Metadata Schema Template 67 Annex 21. Codebook Template 70 Annex 22. Dataset Provenance Sheet – Template 71 Annex 23. Repository Submission Checklist 73 Annex 24. Training Log 75 Annex 25. Data Access Committee (DAC) – Minutes Template 76 Annex 26. Ethics Approval Register 78 Annex 27. Protocol for Non-Participant Observation 79 Annex 28. Protocol for Semi-Structured Interviews 82 Annex 29. Protocol for Photovoice Activities 84 Annex 30. Protocol for Living Labs 87 List of Tables Table 1. List of abbreviations and glossary. 07 Table 2. Compact dataset table. 10 Table 3. Data Lifecycle Stages and Management Actions 13 Table 4. Roles and responsibilities. 17 Table 5. Risks and mitigation measures summary. 17 Table 6. Allocation of financial, human, and technical resources. 21 Table 7. Confidentiality levels. 23 Table 8. Comparative legislative frameworks 26 Table 9. Documentation and procedural safeguards 27 6 1. List of Abbreviations and Glossary The glossary and list of abbreviations below serve as a reference point for readers of this Data Management Plan (DMP). By consolidating technical terms, acronyms, and project-specific expressions, the table helps avoid ambiguity and ensures coherence in the use of language across all sections of the document. Term / Abbreviation Definition / Explanation PATH2EU Pathways to Social Inclusion for Unaccompanied Minors in the European Union (project title). UAM / MENA Unaccompanied Minor / Menor Extranjero No Acompañado – a child under 18 arriving in Europe without the presence of a parent or legal guardian. FAIR Principles of responsible data management: Findable, Accessible, Interoperable, Re-usable. DMP Data Management Plan – document describing how research data will be handled, stored, protected, shared, and preserved. DPO Data Protection Officer. For Comillas: [email protected]. GDPR General Data Protection Regulation (EU 2016/679), binding EU data protection law. DPIA Data Protection Impact Assessment – formal risk assessment for processing personal/sensitive data. DoA Description of the Action, annex to the Grant Agreement describing the work plan. HE / Horizon Europe EU Framework Programme for Research and Innovation (2021–2027). WP Work Package – a distinct unit of work within the project structure. MS Milestone – a significant project checkpoint used to monitor progress. D Deliverable – a concrete project output submitted to the EC. DAC Data Access Committee – project body reviewing requests to access restricted datasets. DPA Data Processing Agreement – legal contract with external processors (e.g., transcription vendors). DUA Data Use Agreement – legal agreement with external researchers requesting access to restricted data. PI Principal Investigator – main researcher leading the project. ERB Ethics Review Board – institutional or consortium-level committee overseeing ethics compliance. Living Labs Participatory research spaces co-designed with UAMs, NGOs, and policymakers to test solutions. Atlas.ti Qualitative data analysis software used in PATH2EU. OBIMID Observatorio Iberoamericano sobre Movilidad Humana, Migraciones y Desarrollo, collaborating research network. EU Peace EU initiative promoting peace, conflict resolution, and reconciliation, linked to project dissemination. SAMUR Social Madrid’s emergency social service, project collaborator. NGO Non-Governmental Organization. Several NGOs partner in PATH2EU fieldwork. OneDrive / Secure institutional cloud storage platforms used for project data 7 SharePoint (Comillas IT infrastructure). Zenodo Open-access repository (operated by CERN under EC mandate) used for long-term preservation and DOI assignment. DOI Digital Object Identifier – persistent identifier for datasets and publications. CC-BY / CC0 Creative Commons licenses: CC-BY (reuse with attribution); CC0 (public domain dedication). Anonymisation Irreversible process of removing all personal identifiers from data. Pseudonymisation Replacing identifiers with pseudonyms while keeping a separate reidentification key. Transcription vendor External provider contracted under a DPA to produce transcripts from audio/video recordings. Metadata Structured descriptive information about a dataset (e.g., DataCite schema). Codebook Documentation of variables, codes, and categories used in qualitative or quantitative analysis. Repository Trusted digital archive where datasets are stored and preserved for long-term access. Encryption Process of encoding data so that only authorised users can access it. 2FA Two-Factor Authentication – additional security measure for data access. Data Utility Concept of how useful datasets are to external researchers, policymakers, or other stakeholders. Data Provenance Documentation of data origin, processing steps, and transformations. Embargo period Temporary restriction on open data access to allow publications or IP protection. Sensitive Data Data that could reveal personal, vulnerable, or protected information (e.g., minor’s identity, migration status). Institutional Repository Internal archive maintained by universities or research centres for preserving research outputs. Table 1. List of abbreviations and glossary. 2. Introduction This DMP establishes the framework for managing research data within the PATH2EU project (Pathways to Social Inclusion for Unaccompanied Minors in the European Union). It has been prepared in accordance with Horizon Europe requirements and reflects recognised best practices in research data management. The DMP is designed to ensure compliance with ethical and legal obligations, to safeguard participants’ rights, and to maximise the scientific and societal value of the project’s outcomes. The plan covers all categories of data that the project will generate or process. These include qualitative data such as interviews, ethnographic field notes, photovoice materials, and outputs from living labs; derived and anonymized datasets; metadata and documentation; as well as informed consent and assent records. In addition, it extends to protocols, coding schemes, analytical outputs, and other research materials that support transparency, replicability, and re-use. The purpose of this plan is twofold: to guarantee the secure handling of personal and sensitive data, and to ensure that project outputs can be disseminated and re-used under 8 conditions that respect both legal requirements and the FAIR principles (Findable, Accessible, Interoperable, Re-usable). By integrating storage, back-up, anonymization, licensing, and longterm preservation strategies, the DMP provides a coherent and sustainable approach to the management of project data. The document is structured into thematic sections aligned with the Horizon Europe template. It begins with a summary of the data to be collected and produced, followed by the measures to ensure FAIR compliance. It then addresses other research outputs beyond datasets, the allocation of resources and responsibilities, and the provisions for secure storage and access control. Dedicated sections cover ethics and legal compliance, while institutional and national procedures are also taken into account. The annexes provide practical transparency by including participant-facing documents (consent and assent forms, privacy notices) and methodological protocols (interviews, photovoice, and living labs). The DMP is a living document. It will be reviewed periodically and updated whenever necessary to reflect changes in project activities, ethical or legal requirements, or repository arrangements. Updated versions will be submitted through the Grant Management System as required by the European Commission. In this way, the plan ensures that the management of research data remains consistent, transparent, and fully aligned with both project objectives and regulatory standards. 3. Data summary PATH2EU produces primarily original, qualitative research material collected through fieldwork with unaccompanied minors (UAMs) and with professionals and organisations who work with them. The Data Summary below describes what will be collected, why, how much, where it comes from, and for whom it will be useful. It also explains the operational measures that convert sensitive raw material into responsibly managed and (where appropriate) reusable outputs. 5.1 General overview of data PATH2EU does not plan to systematically re-use individual-level datasets from other projects because existing datasets generally do not meet the project’s methodological and ethical requirements (participatory protocols, age-appropriate consent/assent, living-lab outputs, and language/context specificity). The project will, however, compile and curate publicly available policy and legal documents (national reception protocols, municipal guidelines, legislative texts) into a comparative corpus where licensing permits; this will be treated as a legal-text dataset for cross-site analysis. Primary data will be collected directly from participants in the field: UAMs (with guardian/representative consent or local authority arrangements as required), staff and volunteers from partner NGOs and institutions (e.g., SAMUR Social, Comunità di Sant’Egidio, Minor-Ndako, Rode Kruis Vlaanderen), social workers, caseworkers, and officials involved in reception and protection. Methods include semi-structured interviews, ethnographic field notes, photovoice activities, and participatory living labs. All audio/video recordings and transcripts will be processed under the data protection measures described below. The expected raw volume for the whole project is up to 1 TB (mainly audio/video files). After transcription, anonymization, selection and curation, the datasets intended for deposit and external re-use will be much smaller (largely transcripts, metadata and codebooks). The DMP sets out the lifecycle of each data type, the anonymization/pseudonymization methods, retention schedules, repository recommendations, licensing preferences, and controlled access procedures for restricted datasets. 9 3.2 Types, formats, provenance, volume, retention, access & primary uses To ensure clarity and transparency in data management, the following table provides a structured overview of the main categories of data that PATH2EU will generate or compile. For each category, the table specifies formats, sources of provenance, estimated volumes, retention policy, access conditions, and intended uses. This synthesis enables both project officers and external reviewers to understand at a glance the scope and lifecycle of the data handled in PATH2EU. Data type Typical formats Provenance / source Estimated raw volume (project) Retention policy (project) Access category (shareability) Primary intended uses Audio recordings (interviews, photovoice narratives) .mp4, .m4a, .wav Recorded directly in interviews with UAMs, professionals ~600–800 GB Kept temporarily for transcription (max 6 months unless otherwise approved). Raw audio deleted or securely archived only with explicit consent and DPO approval. Restricted (contains direct identifiers/voice) Transcription → qualitative coding; internal verification of transcripts Video recordings (selected interviews, photovoice narratives, living labs) .mp4, .avi Recorded in participatory sessions when ethically approved ~100–150 GB raw Retained only with explicit consent; face/video blurring or extraction of anonymised clips for reuse. Raw video retained minimally for verification; otherwise deleted per DPO rules. Restricted / Controlled Contextual analysis; participatory dissemination (with consent) Transcripts (selected interviews, photovoice narratives, living labs) .docx, .txt, .pdf Produced from audio/video (human or secure automated transcription) ~5–10 GB Anonymised/pseudonymised transcripts archived long term (up to 10 years) in encrypted institutional storage; a curated anonymised version for public deposit where allowed. Open (anonymised)/ Restricted (raw transcripts) Qualitative coding (Atlas.ti), publications, secondary reuse Fieldnotes & observation logs .docx, .txt Researchers’ ethnographic notes ~2–5 GB Stored in institutional SharePoint/OneDrive; personal identifiers removed or stored separately; archived up to 10 years. Restricted / internal Contextual triangulation, method notes Photographs (photovoice outputs, events, field contexts) .jpeg, .png Participant activities; photographic prompts ~0.5–1 GB Only with explicit consent, identifiable images either redacted/blinded or not published; stored up to 10 years or deleted if requested. Restricted / Controlled Visual narratives for analysis of social inclusion; illustrative anonymised excerpts in publications/ policy briefs: visual outputs for reports, exhibitions (consent dependent) 16 trusted repositories. This prevents accidental overwriting while ensuring that subsequent users can cite specific dataset versions with confidence. Provenance documentation accompanies each dataset in the form of a provenance sheet (see Annex 21). This record captures essential contextual details: the date and location of data collection (generalised when necessary to protect confidentiality), the instrument employed, the identity of the transcriber, the anonymization or pseudonymization steps taken, and the custodian responsible for long-term stewardship. In this way, every dataset is embedded within a transparent chain of custody that demonstrates its authenticity, processing history and accountability. Together, these measures establish a framework of quality, traceability and trustworthiness, aligning PATH2EU with best practices in research data management and strengthening the reliability of outputs destined for both academic and policy audiences. 3.13 Roles & responsibilities Effective data governance in PATH2EU relies on a clear distribution of responsibilities across the project team, institutional services, and external partners. This ensures that all stages of the data lifecycle—from collection to preservation—are managed consistently and in compliance with both ethical standards and legal requirements. By assigning explicit roles, the project establishes accountability and guarantees that no critical function is overlooked. The PI carries overall responsibility for data practices and makes final decisions regarding data deposit and external access. The DPO provides oversight on GDPR compliance, particularly in relation to high-risk processing and the DPIA. Day-to-day management of data structures, metadata creation and repository submission falls to the Project Data Manager, who also liaises with the institutional IT services. These IT services safeguard the infrastructure, provide secure backups, manage access control, and support encryption. Ethical oversight is ensured by the Ethics Review Boards of the host and partner institutions, which review and approve research protocols and consent procedures. For access to restricted datasets, a dedicated DAC—composed of the PI, the DPO, and an external ethics advisor—evaluates requests, reviews supporting documentation, and approves DUAs. Finally, specific operational partners such as transcription vendors contribute under formal Data Processing Agreements (DPAs) that bind them to secure handling, deletion of raw files, and delivery of pseudonymised transcripts. The table below summarises these roles and their respective responsibilities: Role Name / Description Key Responsibilities Principal Investigator (PI) Project PI (lead researcher) Overall responsibility for data practices; final decisions on data deposit and access. Data Protection Officer (DPO) DPO (Universidad Pontificia Comillas) GDPR compliance; DPIA oversight; cross-border issues; consent and retention guidance. Data Manager (project) Assigned researcher / project manager Day-to-day handling; folder structure; backups; repository submissions; metadata creation. IT / Institutional services Comillas IT Institutional backups; server security; access provisioning; encryption support. Ethics Review Board Institutional ethics committees Review and approval of field protocols and consent procedures. Data Access Committee (DAC) PI + DPO + external ethics advisor Evaluation of access requests; approval of DUAs and access conditions. 17 Transcription vendor Contracted provider (under DPA) Secure transcription; deletion of audio; return of pseudonymised transcripts. Table 4. Roles and responsibilities. 3.14 Risks identified and principal mitigations Because PATH2EU works with vulnerable participants and highly sensitive qualitative data, risk management is not a secondary concern but a central pillar of the project’s data governance strategy. Anticipating risks in advance allows PATH2EU to establish safeguards that protect both participants and the research process itself. Four principal categories of risk have been identified: the risk of re-identification, the possibility of data breaches, the challenge of ensuring valid consent in the case of children, and the vulnerabilities introduced by third-party service providers. Each of these risks is paired with a set of mitigation strategies designed to reduce their likelihood and limit their potential impact. The table below summarises these risks and the corresponding mitigations: Risk Description Mitigation measures Reidentification Possibility that participants could be re-identified through direct or indirect identifiers in qualitative data. Pseudonymization at intake; strict anonymization before external sharing; anonymization decision log; restricted access; DUAs specifying prohibitions on reidentification; short retention of raw media. Data breach Unauthorised disclosure or loss of sensitive information due to cyberattack, device loss, or system failure. Strong encryption at rest and in transit; twofactor authentication (2FA); institutional backups with versioning; vendor DPAs requiring security; access logging; incident response plan including supervisory authority notification where required. Consent gaps (children) Incomplete or invalid consent processes due to complex guardianship situations with unaccompanied children. Use of age-appropriate assent materials; documented guardian or legal representative consent; clear fallback procedures when no guardian is available (appointed guardian/public authority); oversight by ethics committee. Third-party processor risk Risks arising from external providers (e.g., transcription vendors) who handle sensitive data. Vendor due diligence prior to contract; mandatory DPAs; verification of processing location within EU/EEA or adequacy-approved country; contractual safeguards on confidentiality, deletion, and incident reporting. Table 5. Risks and mitigation measures summary. This risk framework is closely linked to the broader project Risk Management Plan (see project documentation). By integrating technical, organisational and ethical safeguards, PATH2EU ensures that identified risks are systematically mitigated while maintaining proportionality and feasibility in practice. 4. FAIR data (Findable, Accessible, Interoperable, Re-usable) PATH2EU fully aligns with the Horizon Europe mandate to manage data according to the FAIR principles. This means that all datasets will be structured to maximise discoverability, 18 accessibility, interoperability and reusability, while applying the principle “as open as possible, as closed as necessary” to safeguard unaccompanied children. 6.1 Making data findable Datasets will be systematically described using the DataCite metadata schema, including all required fields (title, creators, abstract, keywords, funder, project number [101206931], licence, DOI, and repository). Metadata will be deposited in Zenodo that guarantees harvesting by services such as OpenAIRE, declaring visibility across the European Research Area. Each dataset will include a README file with methodological notes, instruments employed, sampling frame, anonymization procedures, and provenance information. This guarantees that secondary users understand not only the content but also the context of data creation. To ensure persistence, non-sensitive datasets will receive DOIs from Zenodo. 6.2 Making data accessible PATH2EU has designed a balanced strategy for data accessibility that combines open science commitments with the obligation to protect vulnerable participants. In practice, this means distinguishing clearly between datasets that can be openly disseminated and those that must remain under controlled access. Non-sensitive materials, such as the curated legal and policy corpus or fully anonymised comparative summaries, will be deposited in Zenodo under a CC-BY 4.0 licence. These datasets will receive DOIs, ensuring long-term persistence, citability and open availability to the research community and the public. By contrast, datasets containing sensitive personal data—such as audio or video recordings and transcripts with residual identifiers—will not be openly released. Instead, they will be made available only under restricted access procedures. A dedicated DAC will review all requests, evaluating the researcher’s credentials, institutional affiliation and ethics clearance. Where approval is granted, the researcher will sign a DUA setting out the permitted uses, conditions for publication, and obligations for secure deletion of files. For particularly sensitive cases, data will only be accessible within a secure environment (either virtual or on-site), so that raw data cannot be exported. To maintain discoverability while protecting participants, metadata for all datasets will be published under CC0 licences, unless disclosure could indirectly expose participants to harm. This ensures that the existence of datasets is visible and citable, while respecting the ethical requirement of proportionality in data sharing. 6.3 Making data interoperable Interoperability in PATH2EU will be guaranteed by systematically prioritising open, machine-readable formats that remain accessible over the long term. For instance, tabular datasets will be produced in CSV, qualitative transcripts will be stored in UTF-8 encoded TXT, and long textual documents will be preserved as PDF/A, a standard designed for long-term readability. These formats allow secondary users to work with the data without dependency on specific proprietary software. In cases where proprietary formats are unavoidable—such as project files from Atlas.ti, which is used for qualitative coding—PATH2EU will provide detailed documentation and export instructions. This ensures that even when a file originates in a proprietary environment, users will still be able to interpret or convert the data into open formats for reuse. 19 To further strengthen interoperability, the project will apply standard vocabularies and identifiers wherever possible. Multilingual materials will be tagged with ISO language codes, while metadata records will include DataCite subject keywords to ensure consistency across repositories. Project-specific codebooks will also be prepared, defining thematic codes and categories to guarantee that others can understand the analytical framework applied. Finally, metadata will be machine-actionable, for example through DataCite JSON schemas, enabling repositories to expose the datasets via APIs. This ensures that PATH2EU data can be harvested automatically by discovery services, enhancing integration with other datasets in migration studies, sociology of childhood and social policy. 6.4 Increasing data re-use The reusability of PATH2EU datasets will be guaranteed through a combination of transparent licensing, comprehensive documentation and robust long-term preservation. These measures ensure that the data will not only fulfil the immediate objectives of the project but also remain a valuable resource for future comparative research in migration studies, child protection and social policy. Licensing will make explicit what kinds of reuse are permitted. Publicly shared datasets will be released under a CC-BY 4.0 licence, granting users the right to reuse the material provided they give appropriate credit. Metadata will be published under CC0, so as to allow catalogue entries and descriptive records circulate freely. For restricted datasets, permissions and obligations will be clearly specified in DUAs, which will set out the scope of reuse, publication rules and conditions for secure data destruction. To make reuse meaningful rather than merely nominal, each dataset will be accompanied by extensive documentation. This includes detailed codebooks that explain the thematic coding, anonymization logs that describe the steps taken to protect participants, data-cleaning notes that document processing decisions, and analytic memos that situate the dataset within the broader research framework. Together, these materials provide the transparency needed for other researchers to evaluate the quality of the data and, where appropriate, replicate analyses. Finally, long-term preservation ensures that these datasets remain accessible to future generations of scholars and practitioners. All deposits will be stored for a minimum of ten years in Zenodo, as well as in the institutional archive at Universidad Pontificia Comillas. The institutional archive provides redundant backups and archival snapshots, protecting against both accidental loss and technological obsolescence. 5. Other research outputs PATH2EU may produce additional outputs such as qualitative coding frameworks, anonymized interview excerpts used in publications, policy briefs, training materials, and software scripts for anonymization or data handling. Where possible, research outputs such as documentation, codebooks and non-sensitive scripts will be published alongside datasets or in dedicated repositories (Zenodo). In addition to the core qualitative datasets, PATH2EU will generate a range of secondary research outputs that, while not datasets in the strict sense, are essential for ensuring transparency, methodological robustness, and reusability of knowledge. These materials include, for instance, ethical and methodological protocols, data management templates, consent and assent forms (in anonymized versions), interview guides, training materials, policy briefs, and safeguarding procedures. Such outputs do not contain individual-level data, but they document the research process, making it reproducible and open to scrutiny by other scholars and practitioners. They also facilitate the transfer of best 20 practices to institutions and NGOs working with unaccompanied minors. Whenever feasible, these outputs will be shared through Zenodo, under open licenses (e.g., CC BY 4.0), ensuring that PATH2EU contributes not only data but also methodological and ethical infrastructure to the broader research community. One important category of outputs will be qualitative coding frameworks and thematic codebooks developed during the analysis of interviews and participatory materials. These will be anonymized and published alongside datasets so that secondary users can understand the analytical categories and replicate or adapt them for comparative work. In some cases, anonymized excerpts from interviews may also be shared when used in publications, provided that participants’ identities are fully protected. The project will also produce policy briefs and practice-oriented guidelines, codeveloped with NGOs and municipal stakeholders. While these documents are not raw data, they represent a critical form of knowledge translation and will be made openly available through Zenodo and the institutional repository, to account for citability and long-term accessibility. To support training and capacity-building, PATH2EU will develop training materials (e.g., workshop guides, teaching slides, handouts on ethical fieldwork with children and adolescents) that will also be shared under open licences whenever possible. These materials will strengthen the uptake of project methods among both academic and practitioner audiences. Finally, the project may produce software scripts or small tools for anonymization and data handling, especially where automation supports consistent application of protocols. By treating these diverse outputs as part of the research record and applying the same standards of documentation, licensing and preservation as for datasets, PATH2EU expects to extend contributions beyond immediate empirical results, leaving a durable and reusable corpus for future research, teaching, and policy engagement. 6. Allocation of resources Effective data management in PATH2EU is supported by both dedicated budget lines and institutional co-funding, ensuring that the procedures described in this DMP are realistic and sustainable. Resources are allocated not only to cover immediate operational needs (e.g., transcription, secure storage), but also to ensure long-term preservation, open access dissemination, and compliance with ethical and legal frameworks. The table below summarises the allocation of financial, human, and technical resources, showing the responsible actor and funding source for each category: Resource type Covered by Responsible actor Notes / Procedures Transcription services Project budget PI + Data Manager Outsourced under Data Processing Agreement (DPA); vendor deletes raw audio upon delivery. Secure storage & backup Institutional IT services (Comillas) IT Department OneDrive/SharePoint with MFA, encryption, institutional backups. Hardware (fieldwork) Project budget (contingency) Data Manager Encrypted external drives for local storage if secure transfer not immediately possible. Archiving & DOIs Project budget + repository Data Manager Deposits in Zenodo and GitHub; DOI assignment; minimum 10-year 21 services retention. Open access publications (APCs) Project budget PI Costs covered when required to ensure compliance with HE open access rules. Compliance oversight Institutional cofunding DPO GDPR, DPIA monitoring, cross-border transfer checks. Table 6. Allocation of financial, human, and technical resources. 6.1. Long-term sustainability In accordance with Horizon Europe requirements, all public datasets will be preserved for a minimum of 10 years in trusted repositories (Zenodo) and mirrored in the institutional archive at Universidad Pontificia Comillas. Confidential data retained for audit or verification will also be kept securely for at least 10 years in encrypted institutional archives. These infrastructures comply with redundant backups, access control, and secure deletion protocols where required by law, providing durable preservation well beyond the project’s active phase. 7. Data security and storage The security of sensitive data is a central concern in PATH2EU, given the project’s focus on unaccompanied children and adolescents, and the high ethical and legal obligations associated with their participation. Data will therefore be stored, processed and transferred exclusively under conditions that guarantee confidentiality, integrity and resilience against accidental or unlawful access. 7.1 Storage locations and backup Primary storage is provided by the institutional OneDrive/SharePoint infrastructure of Universidad Pontificia Comillas, which operates under access-controlled conditions and follows institutional backup policies. This ensures daily backups, redundancy, and recovery in the event of accidental loss. Temporary local storage may occur only when strictly necessary during fieldwork; in such cases, researchers will use password-protected laptops with fulldisk encryption. When external drives are employed, they must be encrypted hardware devices, and only for short-term transfer purposes. External transcription services, where used, will be contracted under strict DPAs. Vendors are required to delete all identifiable audio files immediately after secure transfer and return only pseudonymized transcripts, thereby minimising exposure outside institutional systems. 7.2 Access control and authentication Access to sensitive personal data is restricted to authorised project members through institutional accounts only. Two-factor authentication (2FA) is required wherever available, and files are organised into password-protected folders with role-based permissions. All access to sensitive data is logged, ensuring traceability and accountability in line with GDPR requirements. 7.3 Technical and organisational safeguards The project applies a layered set of technical and organisational measures to protect data throughout its lifecycle. Pseudonymization is carried out as early as possible so that direct identifiers are separated from analytical materials; the link between codes and real identities is 22 stored in a dedicated encrypted file, accessible only to the PI and data manager, and destroyed at the end of the retention period. Encryption is mandatory not only for institutional storage but also for any transfer of files, which must use secure protocols such as SFTP or encrypted password-protected links. Devices employed in fieldwork or analysis are required to comply fully with institutional IT policies: this includes up-to-date operating system patches, antivirus and anti-malware protections, and restricted administrative privileges. Together, these safeguards significantly reduce the risks of unauthorised access, accidental disclosure or data loss. 7.4 Data recovery and continuity Beyond protection, PATH2EU also ensures that data can be recovered quickly in case of disruption. Institutional cloud infrastructures provide redundant daily backups and archival snapshots, allowing both recent work and older versions to be restored if necessary. In practice, this means that no dataset depends on a single device or user: master files are always stored in the institutional cloud, while local copies are strictly temporary working files. The institutional IT services are responsible for implementing recovery protocols, while researchers are required to document where working copies are stored and ensure timely synchronisation with the institutional servers. This approach guarantees continuity even in adverse scenarios such as hardware failure, accidental deletion or loss of equipment during fieldwork. 7.5 Data Classification and Confidentiality Levels To ensure full compliance with GDPR and Horizon Europe data governance principles, PATH2EU classifies all project documentation and datasets according to their confidentiality level and access conditions. This classification supports proportional data protection, enabling open access where possible while safeguarding sensitive information and internal governance records. The table below summarises the confidentiality status, access permissions, and rationale for each document or data type referenced in this DMP: Document / Dataset / Annex Confidentiality Level Access Permissions Rationale / Description Data Protection Impact Assessment (DPIA) Restricted / Confidential PI, DPO, Ethics Board Contains risk assessments, internal mitigation plans, and sensitive data mapping. Record of Processing Activities (ROPA) Restricted / Confidential PI, DPO Required under GDPR; tracks all processing of personal data. Data Processing Agreements (DPA) Restricted / Legal/Internal PI, DPO, Legal Office Contractual clauses with vendors (transcription, storage). Data Use Agreements (DUA) Restricted / Legal/Internal DAC, PI, Requesting Institution Sets conditions for secondary data access. Data Breach Notification Form Restricted / Emergency Use Only DPO, PI, Supervisory Authority (if required) Used only in case of incident notification. Access Request Forms Internal / DAC, Ethics Board Used for evaluating third- 23 Controlled Access party access to restricted datasets. Logs (Access, Anonymisation, Training) Internal / Auditable PI, DPO, Auditors Provide accountability and traceability for GDPR compliance. Protocols (Interviews, Photovoice, Living Labs) Internal / Ethics Review Only PI, Ethics Board, Evaluators Contain sensitive methodological details but no personal data. Consent & Assent Templates (anonymised) Public / Open Access Public repositories (Zenodo, institutional) For transparency and reuse by future researchers; no identifying data. Privacy Notice (GDPR, plain language) Public / Open Access Participants, Public, Repository Required under GDPR; provides participants with rights information. Methodological instruments (Interview guides, codebooks) Public / Open Access Public, academic community Facilitate replicability and capacity building. Legal & Policy Corpus (summaries and comparative tables) Public / Open Access Public, policymakers Non-personal data derived from public sources. Table 7. Confidentiality levels. 8. Ethics and legal compliance The ethical and legal framework underpinning PATH2EU ensures that the project not only complies with binding regulations but also safeguards the rights and dignity of children and adolescents. This section is organised into six parts: first, the overarching European legal framework is presented; second, the relevant national frameworks in Spain, Italy and Belgium are detailed; third, project-specific procedures for consent with vulnerable participants are outlined; fourth, the DPIA is described; fifth, the mechanisms for ethics approvals and oversight are explained; and finally, the distinction between legal compliance and rights protection is clarified. A comparative legislation table and a summary of required documentation are provided to ensure traceability. 8.1 European framework PATH2EU aligns fully with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). Processing of personal data will rely on Article 6(1)(a) GDPR (informed consent) and, where special categories of data are concerned, Article 9(2)(a) GDPR (explicit consent). Horizon Europe’s rules on data management and open science are also binding. Beyond data protection, the project is guided by the EU Charter of Fundamental Rights (Articles 7–8) and the UN Convention on the Rights of the Child (CRC, Articles 3, 12, 16), which affirm privacy, protection and participation rights for minors. 8.2 National frameworks In Spain, PATH2EU operates under the Organic Law 3/2018 on the Protection of Personal Data and Digital Rights (LOPDGDD), which adapts and complements the GDPR at the national level. The project is equally bound by the Organic Law 1/1996 on the Legal Protection of Minors, further reinforced by Organic Law 26/2015, which strengthened child protection systems. Regional frameworks also play an important role: in Madrid, for example, 24 the Law 6/1995 on Childhood Rights regulates guardianship procedures and establishes specific safeguards for minors, ensuring that participation in research respects their rights and welfare. In Italy, the relevant legal framework combines data protection and child protection provisions. The Italian Data Protection Code (Legislative Decree 196/2003, as amended by Decree 101/2018) sets the standards for personal data processing, while Law 47/2017 on the protection of unaccompanied foreign minors provides a specialised regime for UAMs. This law establishes procedures for guardianship, recognises rights to education and healthcare, and mandates safeguards that ensure that minors’ participation in projects such as PATH2EU occurs in a safe and legally compliant manner. In Belgium, national data protection is governed by the Law of 30 July 2018 on the Protection of Natural Persons with regard to the Processing of Personal Data, which implements the GDPR domestically. Child protection is framed by the Youth Protection Law of 1965 (as amended), but practical implementation is shared across regional authorities. The Flemish Decree on Youth Assistance (2004) and the French Community Decree on Youth Aid (1991) provide the legal and procedural frameworks that shape how guardianship, consent, and participation rights are managed in each community. 8.3 Consent and vulnerable participants Special safeguards are in place given that PATH2EU works with UAMs. Guardian consent will be sought wherever an official guardian or appointed representative exists. In parallel, ageappropriate assent will always be obtained from the child, in line with the CRC. Where no guardian is available, local legal procedures (e.g., court-appointed guardians in Italy or youth protection authorities in Spain/Belgium) will be followed and documented. For adult participants (professionals, NGO staff, authorities), written informed consent will be collected. 8.4 Data Protection Impact Assessment (DPIA) A DPIA has been initiated at Universidad Pontificia Comillas. It covers high-risk processing such as audiovisual recordings and collection of sensitive contextual data. Risks identified include re-identification, data breach, and psychological harm. Mitigation includes early pseudonymization, minimal retention of raw media, encryption, DPAs with vendors, rolebased access, and staff training. The DPIA will be updated whenever there is a change in scope or methodology. 8.5 Ethics approvals and oversight Ethics approvals will be secured at the host institutions (Comillas) before fieldwork begins. Oversight will be continuous: the Institutional Ethics Review Board, the DPO, and the DAC will all play roles in monitoring compliance. Documentation of approvals, consent templates and DPIA updates will be stored centrally for audit. 8.6 Distinction between legal compliance and rights protection PATH2EU makes a deliberate distinction between legal compliance and the broader goal of rights protection, recognising that adherence to law is necessary but not sufficient when working with unaccompanied children and adolescents. On the one hand, legal compliance refers to the fulfilment of binding data protection obligations. This includes alignment with the GDPR and its national implementations, the conduct and regular updating of a DPIA, the establishment of a lawful basis for processing (consent or explicit consent in the case of special categories), and the application of security, 25 retention, and access controls as prescribed by law. Compliance ensures that the project operates within the minimum legal standards of the European Union and the Member States where research is conducted. It is the baseline that guarantees accountability and protects the project against unlawful or arbitrary data use. On the other hand, rights protection goes beyond compliance, drawing directly on the principles of the UN Convention on the Rights of the Child (CRC) and the EU Charter of Fundamental Rights. While legal compliance safeguards personal data, rights protection safeguards that the participation of children and adolescents respects their dignity, agency, and best interests. This means not only asking for consent but also reassuring that information is provided in age-appropriate and culturally accessible formats, that participation is genuinely voluntary, and that procedures exist to prevent or mitigate harm. The distinction matters because a project may be legally compliant while still failing to respect the broader rights of children. For instance, GDPR alignment might allow data to be processed with consent, but without careful attention to the child’s ability to understand, that consent might not be meaningful. Similarly, lawful storage of data does not by itself ensure that children feel safe or empowered in their participation. PATH2EU therefore integrates rightsbased approaches into every stage of data management and fieldwork, so that ethical obligations complement legal ones, and the project sets a higher standard than law alone would require. 8.7 Comparative legislative frameworks To ensure clarity in a multi-country project, PATH2EU maps the relevant legal and childprotection frameworks in Spain, Italy and Belgium. The purpose of this comparative overview is to demonstrate that the project is aware of its obligations in each jurisdiction, that compliance will be ensured not only with the GDPR but also with domestic adaptations and child-protection laws, and that differences between countries are explicitly accounted for in procedures. The table below synthesises the core areas of relevance: data protection law, child protection legislation, consent practices and supervisory authorities. Area Spain Italy Belgium National data protection law Organic Law 3/2018 (LOPDGDD) – adapts GDPR to the Spanish legal order, with specific rules on children’s data. Italian Data Protection Code (Legislative Decree 196/2003, amended by Decree 101/2018) – harmonises GDPR with Italian privacy law. Law of 30 July 2018 – implements GDPR, regulating personal data processing for natural persons. Child protection law Organic Law 1/1996 on the Legal Protection of Minors and Organic Law 26/2015, plus Madrid Law 6/1995 on Childhood Rights – provide specific safeguards for minors and guardianship. Law 47/2017 on unaccompanied foreign minors – regulates guardianship, access to services, and protection measures. Youth Protection Law (1965, amended), complemented by Flemish Decree on Youth Assistance (2004) and French Community Decree on Youth Aid (1991) – govern guardianship and youth services. Consent Guardian/legal Guardian appointment Guardian or youth 32 Annex 2. Record of Processing Activities (ROPA) – Template 2 Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Record of Processing Activities (ROPA) Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Restricted 2 This document represents a simplified institutional format corresponding to the templates used in the PATH2EU Data Management Plan. The official and extended versions of the Data Protection Impact Assessment (DPIA), Record of Processing Activities (ROPA), and Data Processing Agreements (DPAs) are maintained within the institutional data protection management system, operated and supervised by the Data Protection Office of Universidad Pontificia Comillas. The system is based on the software ECIX® which provides full compliance tracking, automated risk scoring, and secure documentation under the supervision of the institutional Data Protection Officer (DPO). Processing Activity Purpose of Processing Data Subjects Categories of Data Legal Basis Data Source Storage Location Retention Period Recipients / Transfers Safeguards Responsible Person In-depth interviews & oral histories To reconstruct migration and reception trajectories Unaccompa nied minors (14–18), guardians Audio/video , transcripts, fieldnotes Consent (Art. 6(1)(a)), Explicit Consent (Art. 9(2)(a)) Direct from participants Institutional OneDrive (encrypted), secure local backup Raw audio/video: max 2 years; anonymised transcripts: 10 years PI, transcriptio n vendor (under DPA) Encryption, pseudonymi sation, anonymisati on log PI + Data Manager Photovoice activities To coproduce materials and narratives with minors UAMs (with guardian consent + minor assent) Photographs , written narratives Consent Direct from participants Institutional cloud, encrypted external drives Raw images: max 2 years; anonymised set: 10 years PI, DAC (restricted reuse) Image blurring, consent managemen t, restricted storage PI + DPO Living labs To generate participator y, practiceoriented outputs UAMs and professional s Notes, audio (if consented), photos (if consented) Consent Direct from participants Institutional servers 10 years (anonymise d records) PI, DAC if reuse Pseudonymi sation, storage protocols PI Collection of legal/policy texts To build a comparative corpus of institutional frameworks None (public data) Laws, protocols, reports (PDFs, docs) Public task / legitimate interest Institutional /public sources Institutional repository, Zenodo Permanent Open access (CC-BY) Provenance metadata Legal WP Lead Administrati ve and managemen t documents Project managemen t, deliverables, reporting Consortium partners Deliverables , reports, presentation s Legitimate interest (Art. 6(1)(f)) Partners Institutional servers 10 years EC, reviewers Institutional IT policies Project Manager Webinars & training events To disseminate and exchange knowledge Academics, NGOs, policy stakeholders Video recordings, participant lists, slides Consent (recording); legitimate interest (attendance records) Direct from participants Institutional servers, Zoom/Team s (EU storage) Raw recordings: 2 years; anonymised clips: 10 years Openly shared (selected clips), repository (Zenodo) Consent forms, selective anonymisati on PI + Communicat ion Lead 33 Annex 3. Data Processing Agreement (DPA) format 3 Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Data Processing Agreement (DPA) (pursuant to Article 28 GDPR) Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Restricted Between: Data Controller: Universidad Pontificia Comillas, Calle Alberto Aguilera 23, 28015 Madrid, Spain. Represented by the Principal Investigator of PATH2EU. Data Processor: [Name of Vendor / Company], [Address], [Country]. Project reference: Horizon Europe MSCA PF 101206931 – PATH2EU 1. Subject Matter and Duration The Processor will provide [e.g., transcription services / secure storage / IT support] for data collected under the PATH2EU project. This agreement remains valid for the duration of the services provided and as long as the Processor retains personal data on behalf of the Controller. 2. Nature and Purpose of Processing The Processor is authorised to process personal data solely for the purposes of transcription, secure storage, and transfer of anonymised datasets, in line with PATH2EU research activities. Processing shall not extend to any secondary use beyond the contract. 3. Types of Data and Categories of Data Subjects Types of data: audio and/or video recordings, transcripts, qualitative notes, demographic information. Data subjects: unaccompanied minors, caregivers/legal guardians, child protection professionals, NGO staff, policymakers. 4. Obligations of the Processor The Processor shall:  Act only on documented instructions from the Controller.  Ensure confidentiality of staff authorised to process data.  Implement appropriate technical and organisational measures (encryption, access control, backups).  Not engage another sub-processor without prior written consent from the Controller. 3 This document represents a simplified institutional format corresponding to the templates used in the PATH2EU Data Management Plan. The official and extended versions of the Data Protection Impact Assessment (DPIA), Record of Processing Activities (ROPA), and Data Processing Agreements (DPAs) are maintained within the institutional data protection management system, operated and supervised by the Data Protection Office of Universidad Pontificia Comillas. The system is based on the software ECIX® which provides full compliance tracking, automated risk scoring, and secure documentation under the supervision of the institutional Data Protection Officer (DPO). 34  Assist the Controller in responding to data subject rights (access, rectification, erasure).  Notify the Controller without undue delay in case of a data breach.  At the end of the contract, delete or return all personal data, unless EU or national law requires retention.  Make available all information necessary to demonstrate compliance and allow audits by the Controller or an appointed auditor. 5. Security Measures The Processor commits to:  Use encrypted transfer protocols (SFTP, secure portals).  Store data on servers located within the EU/EEA.  Apply two-factor authentication for access to sensitive files.  Maintain logs of access and changes to datasets.  Regularly update anti-malware and system security patches. 6. Sub-processing Sub-contracting is only allowed with prior written authorisation from the Controller. Any authorised sub-processor must be bound by a contract with equivalent data protection obligations. 7. Liability The Processor shall be liable for damages caused by processing where it has acted outside or contrary to lawful instructions. Both parties recognise the supervisory authority (AEPD in Spain) as the competent body for oversight. 8. Signatures For the Controller (Universidad Pontificia Comillas): Name: ________________________ Position: _____________________ Date: ____ / ____ / ______ Signature: ___________________ For the Processor ([Vendor]): Name: ________________________ Position: _____________________ Date: ____ / ____ / ______ Signature: ___________________ 35 Annex 4. Data Use Agreement (DUA) format Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Data Use Agreement (DUA) (for restricted access to PATH2EU datasets) Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Restricted Between: Data Controller: Universidad Pontificia Comillas, Calle Alberto Aguilera 23, 28015 Madrid, Spain. Represented by the Principal Investigator (PATH2EU). Data Requestor: [Full name, institution, address, country]. Project reference: Horizon Europe MSCA PF 101206931 – PATH2EU 1. Purpose of the Agreement This Agreement governs access to and use of restricted PATH2EU datasets. Access is granted for research, teaching, or policy analysis purposes only, and under strict compliance with GDPR, national laws, and project safeguarding protocols. 2. Description of the Data The datasets covered may include:  Anonymised transcripts of interviews and focus groups with unaccompanied minors, caregivers, and professionals.  Audio/video extracts (where specifically authorised and ethically approved).  Metadata and codebooks associated with qualitative data. Sensitive raw data (unedited recordings, identifiable documents) will not be shared. 3. Access Conditions Access is granted only after review and approval by the PATH2EU Data Access Committee (DAC). Requestor must provide:  Research proposal or justification of use.  Institutional affiliation and supervisor (if student).  Evidence of ethics approval from their institution. Access will be limited to:  Secure on-site environment, OR  Virtual secure environment (no raw download allowed). 4. Permitted Uses Data may be used only for the purposes stated in the approved request. Data may not be re-shared, re-identified, or combined with other datasets without prior approval. Publications must acknowledge the PATH2EU project and cite dataset DOI. 36 5. Prohibited Uses  No attempt to identify participants.  No transfer of data to unauthorised third parties.  No use of data for commercial purposes, legal proceedings, or immigration enforcement. 6. Security and Confidentiality The Requestor must:  Use data only within secure environments.  Protect login credentials and not share access.  Delete any temporary working files after completion of analysis.  Report any suspected breach to the Controller immediately. 7. Data Retention and Disposal Data must not be retained beyond the approved project duration. Upon completion, Requestor must confirm destruction of any local working copies and provide a signed Certificate of Data Destruction. 8. Monitoring and Compliance The DAC reserves the right to audit compliance. Breach of this Agreement may result in withdrawal of access, reporting to the Requestor’s institution, and notification of relevant supervisory authorities. 9. Liability The Requestor accepts full responsibility for compliance with this Agreement. The Controller is not liable for damages resulting from unauthorised or unlawful use of the data. 10. Signatures For the Controller (Universidad Pontificia Comillas): Name: ________________________ Position: _____________________ Date: ____ / ____ / ______ Signature: ___________________ For the Data Requestor: Name: ________________________ Institution: __________________ Date: ____ / ____ / ______ Signature: ___________________ 37 Annex 5. Data Access Request Form Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Data Access Request Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Restricted 1. Applicant details Full Name: ___________________________________________________ Position / Role: ______________________________________________ Institution: ___________________________________________________ Department / Unit: __________________________________________ Address: ______________________________________________________ Email: _________________________________________________________ Telephone: ___________________________________________________ 2. Research project details Project title: _____________________________________ Short summary of objectives (max. 300 words):  Purpose of requested data use (tick all that apply): ☐ Academic research ☐ Teaching / training ☐ Policy analysis ☐ Other (specify): _________________________ Expected outputs (e.g., publications, reports): Proposed duration of access: from ____ / ____ / ______ to ____ / ____ / ______ 3. Dataset(s) requested (Please indicate which restricted dataset(s) you are applying for) ☐ Anonymised transcripts of interviews/focus groups ☐ Anonymised codebooks / thematic analyses ☐ Audio/video extracts (if ethically approved) ☐ Other (please specify): _________________________ 4. Ethical and legal compliance  Has this project received ethics approval from your institution? ☐ Yes (attach copy) ☐ Pending (provide expected approval date) ☐ No 38  Will the project involve processing of special category data? ☐ Yes (explain safeguards) ☐ No  Data protection officer (DPO) or legal contact at your institution: Name: __________________________ Email: __________________________ 5. Security and confidentiality measures Please describe how you will ensure secure handling of the data: Secure storage location(s): ________________________ Encryption / access control: ________________________ Responsible staff / team members: ________________________ 6. Access modality requested ☐ Controlled download (after DAC approval + DUA signed) ☐ Secure on-site access at Universidad Pontificia Comillas ☐ Secure remote environment (if provided by PATH2EU) 7. Declarations By signing this form, I declare that:  I will use the data only for the purposes described above.  I will not attempt to re-identify participants.  I will not share the data with unauthorised parties.  I will comply with GDPR, national data laws, and the PATH2EU Data Use Agreement. Applicant name: _______________________________ Signature: ______________________________________ Date: ____ / ____ / ______ 8. DAC decision (to be completed by PATH2EU) ☐ Approved ☐ Conditionally approved (specify conditions): _________________________ ☐ Rejected (reason): _________________________ Reviewer name: _________________________ Role: _________________________ Date: ____ / ____ / ______ Signature: _________________________ 39 Annex 6. Data Breach Notification Form Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Data Breach Notification Version: 1.0 – 06/10/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal 1. Incident details Date & time of breach detection: _____________________________________________ Location/system affected: ____________________________________________________ Reported by (name, role): ____________________________________________________ Contact details: ________________________________________________________________ 2. Description of the breach  Nature of breach (tick all that apply): ☐ Loss of device (laptop, external drive) ☐ Accidental deletion or alteration of data ☐ Unauthorised access (hacking, phishing, password leak) ☐ Physical theft of documents/media ☐ Other (specify): __________________________  Description of incident (what happened, how detected): 3. Categories and volume of data affected  Type(s) of data: ☐ Personal identifiers (names, contact details) ☐ Sensitive data (migration history, health, religion, etc.) ☐ Audio/video recordings ☐ Anonymised transcripts ☐ Administrative/project data ☐ Other: __________________________  Approximate number of records/data subjects affected: __________________________ 4. Impact assessment  Potential consequences for data subjects (tick all that apply): ☐ Risk of identification ☐ Risk of discrimination or stigma 40 ☐ Psychological harm ☐ Loss of confidentiality ☐ Financial loss ☐ Other: __________________________  Risk level (initial assessment): ☐ Low ☐ Medium ☐ High 5. Immediate containment measures  Actions taken to stop or limit the breach:  Date & time containment completed: __________________________ 6. Notifications  Data Protection Officer (DPO) informed? ☐ Yes ☐ No  Supervisory Authority informed? ☐ Yes ☐ No o If yes: Date/time of notification: __________________________ o Reference number (if issued): __________________________  Data subjects informed? ☐ Yes ☐ No o If yes: Method of notification (email, phone, letter, in-person): __________________________ o Date/time of notification: __________________________ 7. Corrective actions & lessons learned  Measures taken to prevent recurrence (technical/organisational):  Training or procedural changes required: __________________________ 8. Sign-off Completed by (name, role): __________________________ Signature: __________________________ Date: ____ / ____ / ______ Reviewed by DPO: __________________________ Signature: __________________________ Date: ____ / ____ / ______ 41 Annex 7. Adult Informed Consent Form Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Adult Informed Consent Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public 1. Purpose of the Research You are invited to participate in the PATH2EU project, which investigates the trajectories, reception contexts, and pathways to social inclusion of unaccompanied minors in Spain, Italy, and Belgium. The aim is to produce knowledge that supports evidence-based policy, strengthens protection systems, and amplifies the voices of young migrants. 2. What Participation Involves If you agree to participate, you may be asked to:  Take part in an individual interview (audio-recorded, approx. 60–90 minutes).  Contribute to workshops with other professionals and/or youth.  Provide access to non-confidential policy or administrative documents for analysis.  Participate in dissemination activities (if you wish). 3. Risks and Safeguards Minimal risks: Some questions may involve sensitive topics (migration, family, integration). You may refuse to answer any question and stop the interview at any time. Confidentiality: All identifying details will be removed from transcripts and reports. Audio files will be pseudonymised and stored securely. Safeguards: If any issue of child protection or well-being arises, researchers will follow institutional safeguarding protocols and refer the matter to appropriate services. 4. Benefits  Contribution to improving child protection systems and integration policies.  Opportunity to share your professional perspective and experiences.  Participation in shaping policy recommendations and training materials. 5. Voluntary Participation and Withdrawal Your participation is completely voluntary. You may withdraw at any time without giving a reason. If you withdraw, your data will be deleted unless you explicitly authorise its continued use. 6. Data Protection and Privacy (GDPR Compliance) Data controller: Universidad Pontificia Comillas (Madrid, Spain). Legal basis for processing: Article 6(1)(a) GDPR – explicit informed consent. Data collected: audio/video recordings, transcripts, notes, professional documents (nonconfidential). 48 Relevant data protection information:  Data controller: Universidad Pontificia Comillas (Madrid, Spain).  Legal basis for processing: Article 6(1)(a) GDPR – explicit informed consent.  Data collected: audio/video recordings, transcripts, notes, professional documents (nonconfidential).  Storage: encrypted institutional servers (OneDrive/SharePoint). Temporary local copies only on encrypted devices.  Retention: raw audio/video deleted within 6 months after transcription; anonymised transcripts and metadata preserved for at least 10 years in trusted repositories.  Access: only the research team, Data Protection Officer, and authorised auditors.  Transfers: no data will be transferred outside the EU/EEA without GDPR-compliant safeguards.  Your rights: access, rectification, erasure, restriction of processing, withdrawal of consent, (for this purpose, please contact us in [email protected]) and lodging a complaint with your national Data Protection Authority. 7. Consent choices (please tick) ☐ I agree to take part as a co-investigator in this project. ☐ I agree to audio recording during meetings (if applicable). ☐ I agree to video recording during meetings (if applicable). ☐ I agree that my anonymised ideas and contributions may be used in reports/articles. ☐ I would like my name to appear as a contributor or co-author if appropriate. ☐ I prefer to remain anonymous in all project outputs. 8. Signatures Young person’s name: ________________________ Signature: ________________________ Date: ____ / ____ / ______ Researcher’s name: ________________________ Signature: ________________________ Date: ____ / ____ / ______ 49 Annex 11. Guardian / Legal Representative Participant Consent Form Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Guardian / Legal Representative Participant Consent Form Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public 1. Purpose of the Study The PATH2EU project aims to understand the experiences of unaccompanied minors in Europe, focusing on their journeys, reception conditions, and pathways to social inclusion. The study will gather interviews, group discussions, and creative activities (e.g., photovoice) to support better child protection systems and policy recommendations. 2. Why we need your consent As the legal guardian or authorised representative, your permission is required for the child to take part in this research. In addition to your consent, the child will also be asked for their own assent. Both must agree for participation to proceed. 3. What participation involves  Interviews or group discussions: approx. 45–90 minutes.  Optional creative activities such as drawings or photos (child decides).  Audio or video recordings (only with permission).  No payment is offered, but refreshments may be provided during activities. 4. Risks and safeguards  Talking about migration and personal experiences may sometimes be upsetting. Participation is voluntary, and the child may stop at any time.  All researchers are trained in child safeguarding protocols. If any concern arises about the child’s well-being, appropriate services will be informed following legal requirements. 5. Benefits  Opportunity for the child to share their story and have their voice heard.  Contribution to improving services and policies for unaccompanied minors. 6. Rights of the child  Participation is voluntary.  The child may stop at any time without consequences.  Data can be deleted upon request unless anonymised and already used in publications. 7. Data protection and GDPR Data controller: Universidad Pontificia Comillas. Legal basis: Article 6(1)(a) GDPR – explicit consent; Article 9(2)(a) for special categories. Data collected: audio/video, transcripts, creative materials, demographic details. 50 Storage: secure encrypted servers (OneDrive/SharePoint); temporary encrypted devices only if necessary. Retention: raw audio/video deleted within 6 months of transcription; anonymised data stored for minimum 10 years in trusted repositories. Access: only the PATH2EU research team, DPO, and authorised auditors. Transfers: no data outside EU/EEA unless GDPR adequacy or Standard Contractual Clauses apply. Rights: access, rectification, erasure, withdrawal of consent, restriction, objection, complaint to a supervisory authority. 8. Checklist for researcher (to be completed before signature) ☐ Legal guardian or appointed representative has provided official proof (ID or appointment letter). ☐ Privacy Notice was explained and handed over in a language understood by the guardian. ☐ Minor’s assent form has also been explained and provided. 9. Consent options (please tick) ☐ I consent for the child under my guardianship to participate in the PATH2EU project. ☐ I consent to audio recording of the child’s participation. ☐ I consent to video recording of the child’s participation. ☐ I consent to the use of anonymised quotations in reports/publications. ☐ I consent to anonymised data being stored in secure research repositories. ☐ I understand that the child can withdraw at any time without consequences. 10. Signatures Child’s name: _______________________________________ Guardian’s name: ___________________________________ Signature: ________________________ Date: ____ / ____ / ______ Researcher’s name: _________________________________ Signature: ________________________ Date: ____ / ____ / ______ 51 Annex 12. Guardian / Legal Representative Consent Form for Co-Investigator Role Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Guardian / Legal Representative Consent Form for Co-Investigator Role Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public 1. Purpose of the study This project seeks to understand the experiences of unaccompanied minors in Europe. In this specific case, the child under your guardianship is invited to join not only as a participant, but also as a youth co-investigator, helping in the design and analysis of the study. 2. What participation involves If both you and the child agree, they may:  Contribute ideas for interviews, group activities, or analysis.  Join workshops or meetings with the research team.  Decide whether to be named as contributor or co-author in outputs.  Withdraw at any moment without negative consequences. 3. Risks and safeguards  Some discussions may involve sensitive issues. The child may stop at any time.  All activities will follow strict child safeguarding protocols.  Researchers will ensure the child’s contributions are voluntary, safe, and respected. 4. Benefits  Empowerment through participation as co-researcher.  Learning skills and contributing to policy and research outcomes.  Possibility of being recognised in project outputs. 5. Data protection and GDPR Data controller: Universidad Pontificia Comillas. Legal basis: Article 6(1)(a) GDPR (explicit consent), Article 9(2)(a) for sensitive data. Data collected: audio/video, notes, creative or analytical contributions. Storage: encrypted servers; temporary encrypted devices only if needed. Retention: raw files deleted within 6 months; anonymised data stored up to 10 years. Access: only the PATH2EU team, DPO, and authorised auditors. Transfers: no data outside EU/EEA unless with GDPR adequacy safeguards. Rights: access, rectification, erasure, withdrawal of consent, complaint to DPA. Please contact [email protected] 6. Consent options (please tick) ☐ I consent for the child under my guardianship to take part as a co-investigator. 52 ☐ I consent to audio recording of their participation. ☐ I consent to video recording of their participation. ☐ I consent to anonymised contributions being included in reports/publications. ☐ I consent to the child being named as contributor or co-author if they wish. ☐ I understand the child can withdraw at any time without consequences. 7. Signatures Child’s name: __________________________________ Guardian’s name: _______________________________ Signature: ________________________ Date: ____ / ____ / ______ Researcher’s name: ______________________________ Signature: ________________________ Date: ____ / ____ / ______ 53 Annex 13. Privacy Notice (Plain Language) Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Privacy Notice (Plain Language) Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public Who we are We are researchers from Universidad Pontificia Comillas (Spain), with partners in Italy and Belgium. Our project studies the experiences of unaccompanied migrant children and adolescents to improve protection, services, and policies. What information we collect Depending on the activity, we may collect:  Interviews or group discussions (audio or video, if you agree).  Written notes or observations by researchers.  Drawings, photos, or creative work (if the child wants to share).  Basic personal information (age, gender, country of origin).  Sensitive information (for example, health, religion, or family situation) may appear in your answers. We will treat this with extra protection. Why we collect this data  To understand the pathways and challenges of unaccompanied migrant children and adolescents in Europe.  To support better laws, services, and protection practices.  To share findings in scientific articles, reports for the European Commission, policy briefs, and training materials. Legal basis for using your data Consent (Article 6(1)(a) GDPR): You agree to take part. Special category data (Article 9 GDPR): We only use sensitive information if you give explicit permission. For minors, both guardian consent and child assent are required. How we protect your data  We replace names with codes (pseudonymisation).  Personal details and codes are stored separately in encrypted files.  Only the PATH2EU team can access the identifiable data.  Data is stored in secure institutional servers (OneDrive/SharePoint), with backups.  Raw audio/video is deleted within 6 months of transcription.  Anonymised transcripts and notes are preserved for at least 10 years in trusted repositories. 54 What will never happen with your data  Data will never be sold or used for commercial purposes.  Data will not be shared with immigration authorities or any service that could harm participants.  No decisions about your legal status, benefits, or services will be made based on this research. Your rights You may at any time:  See the data we have about you.  Ask us to correct mistakes.  Ask us to delete your data (unless already anonymised and used).  Withdraw your consent.  Complain to your national Data Protection Authority if you think your rights are not respected. Contacts  Principal Investigator: Juan Eduardo Ortiz López – j[email protected]u  Data Protection Office: [email protected]  Supervisory Authority (Spain): Agencia Española de Protección de Datos (AEPD) – https://www.aepd.es ✅ This notice is for you to keep. It explains how your data is used and protected. 55 Annex 14 – Safeguarding / Referral Protocol Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Safeguarding / Referral Protocol Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal Introduction The PATH2EU project involves direct engagement with unaccompanied minors (UAMs), a group considered highly vulnerable under both international child rights frameworks and European data protection law. To ensure their safety and well-being, this protocol sets out the procedures for identifying, responding to, and documenting any safeguarding concern that arises during research activities. The protocol applies to all project staff, interns, and external collaborators (e.g., transcription vendors). It is designed to comply with:  UN Convention on the Rights of the Child (CRC, 1989)  EU Charter of Fundamental Rights (2000)  General Data Protection Regulation (GDPR, 2016/679)  National child protection laws in Spain, Italy, and Belgium  Institutional safeguarding policies at Universidad Pontificia Comillas and partner organisations Key Principles  Best interests of the child (CRC Art. 3) guide all decisions.  Do no harm: participation must never worsen the child’s situation.  Confidentiality with limits: information is kept private except where disclosure is needed to protect the child from harm.  Timely referral: researchers are not social workers; they must pass concerns to competent child protection authorities without delay. Step-by-Step Safeguarding Procedure Stage Action Responsible Documentation 1. Identification Researcher notices or hears something suggesting the child may be at risk (abuse, exploitation, trafficking, mental health crisis, immediate danger). PI Fieldnotes (coded, never names) 2. Immediate response Ensure the child is safe in the moment (e.g., stop interview, provide calm support, never press for details). If urgent risk (e.g., violence, self-harm), PI Incident note (time, place, summary) 56 contact emergency services immediately. 3. Internal reporting Within 24h, researcher informs the Principal Investigator (PI) and the Institutional Safeguarding Officer/DPO. PI → DPO Incident Report Form 4. Assessment & decision PI and DPO review the concern. If valid, they notify the local Child Protection Authority / NGO partner in the country (Spain, Italy, Belgium). PI + DPO Decision log 5. Referral Concern is formally referred to the competent authority (e.g., municipal child protection service, NGO case manager). If in Belgium, may involve Youth Aid Office; if in Spain, regional child protection authority; if in Italy, appointed guardian and social services. PI / Partner NGO Referral form, copy of notification 6. Follow-up Researcher does not investigate further but ensures that the referral was received. Any further contact with child is only for research purposes if safe and authorised. PI + Safeguarding Officer Follow-up note 7. Closure Once referral is accepted and logged, the safeguarding case is considered closed for research purposes. Documentation stored securely (separate from research data). DPO Safeguarding log Emergency Contacts (to be adapted per site) Spain (Madrid): SAMUR Social / Dirección General de la Infancia, Comunidad de Madrid Italy (Rome): Tribunale per i Minorenni, local social services, guardian networks Belgium (Brussels): Youth Aid Office (Aide à la Jeunesse / Jeugdhulp), Minor-Ndako NGO Documentation Tools (Annexed separately) Incident Report Form (to be filled by researcher immediately after event) Referral Form (used by PI/DPO when notifying authorities) Safeguarding Log (master record kept by DPO, separate from research data) Closing Statement This protocol ensures that PATH2EU fulfils its ethical and legal obligations towards children while maintaining the integrity of the research. Researchers are not expected to solve child protection cases; their duty is to recognise risk, respond safely, and refer appropriately. 57 Annex 14a – Incident Report Form Researcher completing form: ___________________________ Date of report: ____ / ____ / ______ Location of incident: ___________________________ 1. Basic information  Child’s code (not name): ___________________________  Research activity (interview, workshop, photovoice, living lab): ___________________________  Date and time of incident: ___________________________ 2. Description of concern Please describe what happened or what was disclosed. Use the child’s own words where possible. 3. Immediate response  What did you do at the time? (stopped activity, ensured safety, comforted child, etc.) 4. Next steps taken  Who was informed (PI, DPO, NGO staff)?  Time and method of notification. Signature of researcher: ________________________ Date: ____ / ____ / ______ 64 Annex 18. Encryption & Storage Protocol Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Encryption & Storage Protocol Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Purpose This protocol describes the technical and organisational measures used in PATH2EU for secure storage, encryption, and transfer of sensitive research data, in compliance with GDPR, national laws, and institutional IT policies. 2. Storage locations  Primary storage: o Encrypted institutional servers (OneDrive/SharePoint – Universidad Pontificia Comillas). o Automatic institutional backups with redundancy in EU-based datacentres.  Local storage (temporary only): o Password-protected laptops with full-disk encryption (BitLocker / FileVault). o Approved encrypted external drives (AES-256) only for fieldwork or transfer.  Partner institutions (Italy & Belgium): o Equivalent secure institutional servers with EU-only backups. o No third-party uncontrolled storage permitted. 3. Encryption standards Data at rest: AES-256 encryption for institutional servers, external drives, and local devices. Data in transit: Secure transfer protocols only: o SFTP, HTTPS, or institutionally approved VPN. o Password-protected links with expiry dates (no open email attachments). Keys and passwords: o Strong passwords (12+ characters, mixed types). o Two-Factor Authentication (2FA) required for institutional accounts. o Keys stored separately from encrypted files. 4. Access control  Access restricted to authorised project members.  Role-based permissions applied (PI, Data Manager, Research Assistants).  Audit logs maintained for all access events (see Access Log Template).  DAC approval required for any external access. 5. Transfer rules  Fieldwork data uploaded within 48 hours to institutional server. 65  Raw media (audio/video) deleted from local devices once upload confirmed.  Transcription vendors must transfer files via SFTP or institutional cloud, never personal accounts. 6. Retention and disposal  Raw identifiable files (audio, video) deleted within 6 months after transcription.  Anonymised datasets stored for at least 10 years in trusted repositories (Zenodo).  Secure deletion software (e.g., DoD 5220.22-M method or institutional equivalent) used for disposal. 7. Responsibilities  PI: overall responsibility for data security compliance.  Data Manager: day-to-day monitoring of encryption, backups, and secure transfer.  DPO: oversight of GDPR compliance and incident response.  IT services: maintain institutional security infrastructure and incident response mechanisms. 8. Incident response In case of suspected breach (loss of device, unauthorised access, transfer error):  Immediately report to PI and DPO.  Contain incident (revoke access, reset passwords, suspend accounts).  Log event in Breach Notification Template within 24h.  Notify supervisory authority within 72h if risk to data subjects. 66 Annex 19. Dataset README Template Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Dataset README Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public 1. Dataset Overview  Dataset title:  Description: (Brief explanation of the dataset: what it contains, purpose, context of collection)  Associated deliverables: (e.g., D2.1, D3.2, WP references)  Timeframe of data collection: (Month/Year – Month/Year)  Geographical coverage: (Spain, Italy, Belgium – specify region if relevant) 2. Data Structure  File formats: (e.g., .csv, .xlsx, .docx, .mp4, .pdf)  File organisation: (folders by country, activity type, anonymisation level, etc.)  Number of records/files: (approximate count)  Metadata standards used: (e.g., Dublin Core, CESSDA controlled vocabularies) 3. Methodology & Sources  Collection methods: (interviews, workshops, ethnographic notes, policy document analysis, etc.)  Target population: (Unaccompanied minors, guardians, professionals, policymakers)  Instruments used: (interview guides, focus group prompts, creative activities, observation sheets)  Ethical approval: (Reference to institutional ethics clearance and informed consent/assent process) 4. Data Processing  Anonymization method: (pseudonymization, redaction of identifiers, aggregation of sensitive details)  Transcription protocol: (professional services, validation, removal of identifiers)  Quality checks: (double review, researcher validation, pilot coding)  Version control: (see Version Control & Changelog) 5. Access & Licensing  Access level: (Open, Restricted, or Closed – justify if restricted)  Embargo period (if any): (e.g., 12 months after project end)  License: (CC-BY 4.0 for open data; specify otherwise if restrictions apply)  Repository: (Zenodo, institutional archive)  DOI / Persistent identifier: (to be assigned upon deposit) 67 6. Data Protection & Safeguards  Legal basis: Article 6(1)(a) GDPR (explicit consent); Article 9(2)(a) (sensitive data).  Safeguards applied: o Encryption of files at rest and in transit (AES-256, SFTP, institutional cloud). o Separation of consent forms and personal data from anonymised datasets. o Restricted access based on role (PI, Data Manager, approved researchers).  Retention: o Raw data deleted after transcription (max. 6 months). o Anonymised datasets stored minimum 10 years. 7. Citation & Acknowledgement Please cite this dataset as: Ortiz-López, J.E., Dataset on unaccompanied minors’ pathways to social inclusion in Spain, Italy, and Belgium. Universidad Pontificia Comillas. Zenodo. DOI: [insert DOI] Acknowledgement: This dataset was produced under the Horizon Europe Marie SkłodowskaCurie Actions Postdoctoral Fellowship, grant agreement 101206931. 8. Contact  Principal Investigator: Juan Eduardo Ortiz – [email protected]  Data Protection Officer (Comillas): [email protected] 68 Annex 20. DataCite Metadata Schema Template Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: DataCite Metadata Schema Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Public 1. Identifier  Mandatory: DOI (assigned automatically by Zenodo upon submission).  Example: 10.5281/zenodo.1234567 2. Creators Name: Ortiz-López, Juan Eduardo Affiliation: Instituto Universitario de Estudios sobre Migracioness (IUEM), Universidad Pontificia Comillas, Madrid, Spain. Orcid: https://orcid.org/0000-0002-8756-7012 3. Title  Clear, descriptive dataset title.  Example: Dataset on unaccompanied minors’ pathways to social inclusion in Spain, Italy, and Belgium (PATH2EU) 4. Publisher  Universidad Pontificia Comillas 5. Publication Year  Year when the dataset is made public.  Example: 2027 6. Resource Type  General: Dataset  Specific: Qualitative data / anonymised interview transcripts / codebook Resource Type: Resource Type General: Dataset Resource Type: Qualitative interview transcripts and codebook 7. Subjects  Keywords (3–5 minimum).  Example: o Unaccompanied minors o Migration o Child protection 69 o Social inclusion o Europe (Spain, Italy, Belgium) 8. Contributors o Data Protection Office o [Name] – Transcription vendor (role anonymised in metadata) 9. Dates  Relevant dataset dates: o Collected: 2026 o Created: 2027-01-15 o Published: 2027-12-01 10. Language  Languages of transcripts or data.  Example: es, it, fr, ar, ary, bm, ff, ti 11. Alternate Identifiers  Optional: internal project codes.  Example: Grant Agreement Number: 101206931 (MSCA PF) 12. Related Identifiers  Links to related works or DOIs.  Example: o IsSupplementTo: 10.5281/zenodo.9876543 (Codebook) o IsReferencedBy: DOI of related journal article 13. Sizes  Approximate dataset size.  Example: 250 anonymised interview transcripts (~1GB) 14. Formats  File formats included.  Example: o .docx (transcripts) o .pdf (policy briefs) o .csv (metadata tables) 15. Rights  This dataset is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). 16. Description  Narrative dataset summary.  Example: This dataset contains anonymised qualitative interview transcripts, codebooks, and related documentation collected within the PATH2EU project (Horizon Europe MSCA PF 101206931). Data was gathered between 2026–2027 in Spain, Italy, and Belgium, focusing on unaccompanied 70 minors’ pathways to social inclusion. Sensitive information has been anonymised following GDPR and institutional protocols. 17. Funding Reference o Funder: European Commission – Horizon Europe o Grant Number: 101206931 o Funding Program: MSCA Postdoctoral Fellowships (PF) 71 Annex 21. Codebook Template Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Codebook Template Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted Code Definition Inclusion Criteria Exclusion Criteria Example (Anonymised) Source Sensitivity Notes / Language Version Coder(s) LEG_SUPPORT Legal assistance or representation provided to UAMs Mentions of lawyers, NGOs, or guardians helping in legal cases General mentions of "support" without legal focus “The lawyer explained my asylum process.” Deductive (policy/legal framework) Medium Spanish, Italian v1.0 (202509-15) Ortiz, J.E. SCHOOL_INT Experiences related to school integration References to classes, teachers, classmates, language learning Mentions of informal learning outside school “At school, I was put in a welcome class.” Inductive (interview) Low French v1.0 Ortiz, J.E. TRAUMA References to traumatic events before/during migration Violence, loss of family, detention, dangerous journeys General stress unrelated to migration (e.g. school exams) “I saw people drown on the boat.” Inductive (interview) High Arabic (Moroccan) v1.0 Ortiz, J.E. FUTURE_ASP Aspirations and expectations for future life Mentions of career goals, education, dreams Immediate needs (food, housing) “I want to study to be a doctor.” Inductive Low Bambara v1.0 Ortiz, J.E. 72 Annex 22. Dataset Provenance Sheet – Template Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Dataset Provenance Sheet Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Dataset Identification Dataset title: [e.g., Spain – Interviews with UAMs – 2025] Dataset ID/code: [unique alphanumeric code, e.g., ES_UAM_INT_2025_V1] Work Package (WP): [e.g., WP3 – Fieldwork] Type of data: [Interview transcripts / Policy corpus / Workshop notes] 2. Collection Details Collection date(s): [DD/MM/YYYY – DD/MM/YYYY] Collection site(s): [Madrid, Rome, Brussels, etc.] Institution(s) involved: [SAMUR Social, Associazione Virtus Italia, Minor-Ndako, etc.] Data collector(s): [Name / role] Instrument(s): [Interview guide, workshop protocol, observation grid] Language(s): [Spanish, Italian, French, Arabic (Moroccan), Bambara, etc.] 3. Processing & Transformations Transcription vendor: [Name – under DPA] Translation applied: [Yes/No; into which language] Anonymization actions: [Direct identifiers removed, pseudonyms applied, sensitive context generalised] File formats: [TXT/UTF-8, CSV, PDF/A, Atlas.ti project] Versioning applied: [Dataset version #, changelog reference] 4. Quality Assurance Accuracy checks: [10% transcript sample vs. audio] Reviewer(s): [Name / role] Corrections logged: [Yes/No – location of correction log] 5. Data Sensitivity & Access Risk classification: [Low / Medium / High] Restrictions: [Open access / Restricted (DAC approval) / Not shareable] Access conditions: [DUA required, on-site only, secure virtual environment] 6. Custodianship & Archiving Custodian: [Name, PI or data manager] Storage location: [Comillas institutional OneDrive, encrypted local drive] Archival repository: [Zenodo, institutional archive] Retention period: [10 years minimum] 73 7. Documentation Links Consent/assent form IDs: [e.g., Annex 3, Annex 4, Annex 5] DPIA reference: [DPIA v1.2 – 2025] ROPA reference: [ROPA entry code] Anonymization log: [File path or reference code] Version control changelog: [Reference to doc] Ethical and Legal Note: This sheet must be stored in a secure repository, separate from the dataset itself, and updated every time the dataset changes status. It is part of the traceability required under GDPR Article 5(2) (accountability principle) and by MSCA requirements. 80 Annex 27. Protocol for Non-Participant Observation Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Protocol for Non-Participant Observation Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Purpose of the protocol The purpose of this protocol is to regulate the use of non-participant observation as a data collection method within PATH2EU. Observation is used to better understand the everyday contexts, interactions, and institutional practices that shape the social inclusion of unaccompanied children and adolescents in Spain, Italy, and Belgium. 2. Scope and application  Applied in reception centres, schools, community programmes, and public workshops where project activities are conducted.  The researcher observes interactions without intervening or influencing behaviours.  Separate guidance applies depending on whether the observed subjects are minors or adults. 3. Ethical considerations Informed awareness: Adults (staff, guardians, educators) are informed about the researcher’s role as observer and provide written consent. Assent/consent for minors: Minors are not individually asked to consent to mere observation in public/shared spaces if it is non-intrusive and anonymised. However, when observation takes place in semi-private contexts (classroom, closed group activities), guardians’ consent and minors’ assent are required. Confidentiality: No names or directly identifiable details are recorded. Safeguarding: If the researcher identifies a situation that indicates risk of harm to a child, they must follow the Safeguarding/Referral Protocol (Annex 12). 4. Observation procedure  Preparation: o Notify the hosting institution and obtain written approval (institutional consent form). o Ensure DPO validation of observation templates.  During observation: o Researcher takes discreet notes on context, interactions, practices. o No photos, audio, or video are taken unless explicit prior consent has been obtained from both guardians and minors.  For minors: o Notes must be written in coded form (no names, only roles or pseudonyms, e.g. “M1, age 15, male”).  For adults: 81 o Notes may indicate professional role (e.g. “social worker,” “teacher”) but not personal identifiers. 5. Data handling  Notes are typed into the institutional encrypted template within 48 hours.  Raw notes (paper) are destroyed after digitisation.  All anonymised observation files are stored in the secure OneDrive/SharePoint repository.  Retention: 10 years (anonymised). 6. Risks and safeguards  For minors: Minimal risk if anonymity is respected; main risk is unintentional disclosure of sensitive behaviour. Safeguard: strict anonymization and safeguarding protocol.  For adults: Risk of reputational exposure if critical practices are observed. Safeguard: anonymization of roles and contexts. 7. Researcher obligations  Complete the Safeguarding checklist after each session.  Register observation event in the ROPA (Records of Processing Activities). 8. Observation Template (extract)  Date / Location  Setting description (type of activity, environment)  Participants present (coded: M1, M2… / A1, A2…)  Observed interactions (summary, coded)  Researcher reflections (interpretive notes)  Safeguarding concerns (Yes/No – if Yes, referral triggered) 82 Annex 28. Protocol for Semi-Structured Interviews Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Protocol for Semi-Structured Interviews Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Purpose and scope This protocol establishes the ethical, legal, and methodological standards for conducting semistructured interviews within PATH2EU. Interviews aim to explore perceptions, experiences, and pathways to social inclusion of unaccompanied children and adolescents, as well as the views of professionals, guardians, and policymakers involved in their reception and support. 2. Participants  Children and adolescents (10–17 years old): Always with guardian consent + child’s assent.  Adults (professionals, guardians, policymakers): Standard informed consent required.  Special safeguards apply to children, following GDPR, LOPDGDD (Spain), Law 47/2017 (Italy), and Belgian Youth Protection Law, depending on site. 3. Ethical and legal considerations Voluntariness: Participation is voluntary; refusal has no adverse effects. Safeguarding: If child protection concerns arise, referral protocols are activated (See Annex 14). Data protection: Personal data will be pseudonymised; raw audio deleted within 6 months. Consent and assent: Multilingual forms ensure comprehension; researchers verify understanding. 4. Interview procedure Preparation: o Review consent/assent and confirm signatures. o Ensure privacy and a safe setting. o Prepare recording equipment (only if consented). Conduct: o Use interview guide (open-ended prompts on school, daily life, inclusion). o Respect participant’s pace; allow breaks or withdrawal. o Avoid pressuring children or adolescents to disclose migration journeys unless they choose to. Closure: o Summarise key points, thank participant, and remind of rights (withdrawal, deletion). o Offer safeguarding or referral information if distress was observed. 83 5. Risks and safeguards Emotional distress: Some questions may trigger difficult memories. Researchers stop immediately and offer referral information. Confidentiality risks: Mitigated through pseudonymization and encrypted storage. Power imbalance with children: Addressed via child-friendly communication and cocreation opportunities. 6. Data handling Recording: Audio (and video if applicable) stored in encrypted institutional servers. Transcription: Outsourced only under GDPR-compliant DPA; transcripts pseudonymized. Retention: Anonymised transcripts preserved 10 years; raw files deleted after transcription. Access: Restricted to PI, authorised researchers, and auditors. 7. Researcher obligations  Verify guardian and child/adolescent consent before interview.  Maintain neutrality and respect cultural/linguistic diversity.  Document deviations (e.g., skipped questions, early termination).  Record interview details in the official log immediately after completion. 8. Interview Record Template Field Entry Interview ID [Unique code – no names] Date & Location [dd/mm/yyyy – site] Participant category ☐ Child (10–13) ☐ Adolescent (14–17) ☐ Guardian ☐ Professional ☐ Policymaker Consent/assent confirmed ☐ Yes ☐ No (explain) Language of interview [Specify] Interpreter present ☐ Yes ☐ No (if yes, provide interpreter code) Recording method ☐ Audio ☐ Video ☐ Notes only Duration [Minutes] Safeguarding issues raised ☐ None ☐ Yes (describe + referral action) Notes on participant comfort [E.g., breaks taken, emotional response] Deviation from protocol [If any, explain] Researcher initials [ ] 84 Annex 29. Protocol for Photovoice Activities Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Protocol for Photovoice Activities Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Purpose and scope This protocol governs the use of photovoice as a participatory method within PATH2EU. The method empowers unaccompanied children and adolescents and, where relevant, professionals, to capture photographs that represent their experiences of social inclusion, challenges, and aspirations. Photovoice is used both as a research tool and as a co-creation strategy, ensuring young people’s voices are represented through visual means. 2. Participants  Children and adolescents (10–17 years old): Guardian consent + child/adolescent assent required.  Special attention to child-centred communication and ensuring participants fully understand the use and potential dissemination of images. 3. Ethical and legal considerations Consent: Explicit consent for taking, sharing, and using photographs (separate opt-ins for exhibitions, publications, or reports). Privacy: Faces and identifiable features of third parties must not be captured unless written consent is obtained. Researchers will train participants in ethical image-taking. Safeguarding: Images raising protection concerns (e.g., evidence of harm or neglect) trigger referral protocols. Data protection: Original photos will be anonymised (faces blurred, identifiers removed) before archiving or sharing. 4. Procedure Preparation:  Explain the objectives of the activity and participants’ rights clearly, using multilingual consent and assent materials.  Provide disposable cameras (no personal phones).  Conduct a brief photography training session (30–45 minutes) covering: o Basic technical skills: framing, light, focus, and storytelling through images. o Ethical photography: respecting others’ privacy and dignity; obtaining permission before photographing anyone; avoiding identifiable or unsafe settings (e.g., police, detention centres, or private homes). o Creative expression: using photography as a tool for self-representation and voice, focusing on places, objects, or moments that symbolise inclusion, belonging, or transition. 85  Provide handouts or visual examples (multilingual if possible) to reinforce the training content. Implementation:  Participants take photographs over a defined period (3–5 days), choosing moments and spaces that reflect their experiences or aspirations.  Researchers ensure safe collection and storage of the cameras/devices.  No identifiable images of other individuals will be retained without written consent.  After collection, photographs are printed (and digitised for archival storage), and each participant selects a small number of images for discussion in follow-up sessions. Reflection and discussion:  In individual sessions, participants explain what their images mean to them.  Discussions are facilitated with care, focusing on empowerment and interpretation rather than evaluation.  With participant permission, selected anonymised photographs and quotes may be used in project reports, exhibitions, or digital repositories. Closure:  Participants receive a printed copy set of their photographs as a personal keepsake (a compiled album gift).  Researchers verify participants’ comfort with how images will be used and obtain final confirmation before dissemination.  A brief debriefing and emotional check-in conclude the process. 5. Risks and safeguards Privacy risks: Prevented through anonymization, face-blurring, and prior training. Emotional distress: Images may trigger memories or emotions; safe spaces and referral protocols apply. Reputational/legal risks: No images of illegal activities, authorities, or vulnerable third parties. 6. Data handling Collection: Photos transferred securely to encrypted institutional devices. Storage: Encrypted servers (OneDrive/SharePoint); local encrypted copies only if necessary. Anonymization: As photographs are taken using analogue cameras, no digital metadata (EXIF, GPS) are generated. Scanned versions will be stored without identifying technical metadata. Retention: Physical photographs will remain with participants as part of their personal album and are not retained by the project. Only digitised, anonymised copies—used for research, dissemination, and exhibition purposes—will be preserved for a minimum of ten years in secure institutional storage. Intermediate digital files (pre-anonymization scans) will be deleted immediately after anonymization is verified. Access: PI, designated data manager, authorised researchers, and auditors. 7. Researcher obligations  Ensure multilingual, age-appropriate explanation of photovoice.  Provide training on safe, ethical photography. 86  Document all consent/assent and permissions for image use.  Verify anonymization before data deposit or dissemination. 8. Photovoice Activity Log Field Entry Photovoice ID [Unique code – no names] Date & Location [dd/mm/yyyy – site] Participant category ☐ Child (10–13) ☐ Adolescent (14–17) ☐ Guardian ☐ Professional Consent confirmed ☐ Yes ☐ No Device used ☐ Project camera ☐ Project phone ☐ Other (specify) Number of photos taken [ ] Photo topics/themes [Free text – general description only] Captions/notes provided ☐ Yes ☐ No Workshop discussion held ☐ Yes ☐ No Images selected for use [Codes or short list] Anonymization completed ☐ Yes ☐ No Safeguarding concerns raised ☐ None ☐ Yes (describe + referral action) Researcher initials [ ] 87 Annex 30. Protocol for Living Labs Project Title: PATH2EU – Pathways to Social Inclusion for Unaccompanied Minors in Europe Grant Agreement No.: Horizon Europe MSCA PF 101206931 Document Title: Protocol for Living Labs Version: 1.0 – 05/11/2025 Prepared by: Juan Eduardo Ortiz López (Principal Investigator) Host Institution: Universidad Pontificia Comillas, Madrid (Spain) Contact: [email protected] Confidentiality Level: Internal / Restricted 1. Purpose and Scope The Living Labs in PATH2EU are participatory and multi-stakeholder spaces where unaccompanied children and adolescents, professionals, and researchers co-create ideas, test interventions, and reflect collectively on pathways to social inclusion. They serve not merely as research settings, but as collaborative environments that empower young people and professionals to jointly design actionable and ethically sound solutions, ensuring that findings are grounded in lived realities and responsive to local contexts. The PATH2EU Living Labs unfold over a one-week cycle (4–5 sessions), allowing for progressive movement from diagnosis to co-design, validation, and reflection. This aligns with Horizon Europe’s Responsible Research and Innovation (RRI) and MSCA-PF values of societal engagement, co-production of knowledge, and sustainable impact. 2. Objectives 1. To create safe, inclusive, and creative spaces for dialogue between unaccompanied minors and professionals. 2. To translate lived experiences into actionable outputs, such as digital or physical prototypes, welcome kits, or policy inputs. 3. To strengthen agency and digital literacy among minors through collaborative design processes. 4. To build bridges between children, social workers, educators, and policymakers. 5. To generate replicable, policy-relevant models for local and EU-level child inclusion initiatives. 3. Participants  Unaccompanied children and adolescents aged 10–17 (voluntary participation, guardian consent, and minor assent required).  Adults: professionals, NGO staff, educators, guardians, and policymakers (informed consent required).  Facilitators: 1–2 trained researchers responsible for moderation, safeguarding, and notetaking.  Observers (optional): invited ethics advisors or institutional partners (no data collection). Each Lab will include 8–12 participants, ensuring diversity (gender, origin, experience) and a balanced representation of youth and adults. Participation is voluntary and free of coercion, with explicit safeguards to avoid power imbalances. 88 4. Ethical and Legal Considerations Consent & Assent: Written, multilingual forms provided. Explicit options for recording, publication, and anonymised data use. Confidentiality: All personal identifiers removed. No names appear in transcripts or public materials. Safeguarding: PATH2EU Child Safeguarding & Referral Protocol applies. Researchers must act immediately if protection concerns arise. Non-harm principle: Activities are forward-looking, focusing on inclusion rather than past trauma. Data Protection: GDPR-compliant; secure storage and controlled access per institutional DPO guidance. Equal participation: Rotating facilitation to ensure all voices, particularly minors’, are heard. 5. Preparation Phase Recruitment: via trusted institutions (NGOs, shelters, schools). Information: age-appropriate and multilingual briefings on purpose, rights, and expected outputs. Safeguarding review: emergency contacts and protection measures verified in advance. Session design: thematic prompts, participatory mapping, storytelling, and co-design exercises. Materials: notebooks, markers, paper, digital tablets (if available), and catering for comfort. Facilitator briefing: verification of consent, safeguarding awareness, and division of roles (lead, assistant, observer). 6. Procedure Duration: Five sessions (4 hours each, over one week) Day Focus Objectives Example Activities Expected Outputs 1. Welcome & Diagnosis Build trust and map experiences Icebreakers, “life in Europe” mapping, collective rulesetting Collective Map of Inclusion 2. Exploring Themes Identify barriers and aspirations Role-play, challenge mapping, discussion cards Matrix of Challenges and Hopes 3. Co-Designing Solutions Brainstorm concrete inclusion tools Design sprint, sketching prototypes Solution Prototypes 4. Prototyping & Validation Refine and test outputs Small group refinement, peer feedback Final Prototype / Beta Version 5. Reflection & Dissemination Present results, plan follow-up Showcase, feedback circle, exhibition Living Lab Exhibition & Policy Input Document Methodological Principles  Participatory co-creation: every participant acts as both informant and designer.  Non-extractive, empowering focus: oriented toward future life projects.  Multilingual facilitation and visual aids to support inclusion.  Reflexive practice: facilitators maintain observation diaries on participation and ethics. 89 7. Data Handling Collection: fieldnotes, anonymised transcripts, creative artefacts, digital mock-ups. Storage: encrypted institutional servers (OneDrive/SharePoint); pseudonymized versions only. Anonymization: removal of all identifiers; blurred photos where minors appear. Retention: anonymised versions stored for 10 years; raw notes destroyed post-verification. Reuse: only anonymised, co-created outputs (e.g., prototypes or guides) may be archived in Zenodo under CC-BY 4.0. Access: restricted to PI, authorised researchers, DPO, and ethics auditors. 8. Risks and Safeguards Potential Risk Mitigation Strategy Emotional distress Immediate pause; debrief; activation of safeguarding protocol if needed. Power imbalance (adult dominance) Structured facilitation, youth-led subgroups, equitable speaking rounds. Confidentiality breach (media misuse) Use project-owned devices only; explicit consent for any image/audio use. Dropout due to scheduling Early coordination, flexibility, digital follow-up option. 9. Evaluation and Feedback Session-level: brief anonymous cards on comfort, inclusion, and usefulness. Facilitator debrief: daily meeting between research team and mediators. Final reflection: group discussion on lessons and next steps. Output audit: all materials logged for repository submission and internal quality review. 10. Researcher Obligations  Use child-friendly communication at all times.  Keep all consent and assent records updated and securely stored.  Ensure participants understand how their input contributes to policy and research.  Record session data using the Living Lab Session Log below. 11. Integration with Other PATH2EU Components The Living Labs are interwoven with the broader PATH2EU methodology:  Photovoice: visual narratives inform the themes and prototypes developed.  Interviews: prior interviews shape the agenda for collective sessions.  WP5 Dissemination: co-created tools feed into seminars, policy briefs, and the EU observatory webinars.  Ethics and GDPR compliance: full consistency with PATH2EU’s Data Protection and Safeguarding Frameworks. 12. Ethical Alignment and Added Value This protocol ensures that:  Participation is voluntary, informed, inclusive, and co-owned.