Uploaders considering Zenodo for the storage of non anonymized or encrypted/unencrypted sensitive personal data are advised to use bespoke platforms rather than open dissemination services like Zenodo for sharing their data.
Zenodo is an open dissemination research data repository, and the uploader of content responsible to ensure that the content is suitable for open dissemination and that it complies with applicable laws, including, but not limited to, privacy, data protection, and intellectual property rights. Thus, an uploader shall ensure that sensitive personal data is either anonymized to an appropriate degree or fully consent cleared.
In terms of EU GDPR this means that the legal basis for transferring personal data to Zenodo/CERN would be the usage of derogations for specific situations as set out in art. 49 GDPR, such as consent or public interest.
See also: