Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Research Data Management (RDM)

Data Privacy, De-identification & Sharing Agreements

Not all research data can or should be shared openly, and this sub-cluster covers the legal, ethical, and technical mechanisms that govern access to data containing personal, sensitive, or culturally significant information. De-identification standards, most notably the HIPAA Safe Harbor method, specify which identifiers must be removed or altered from health data before it can be treated as no longer individually identifiable, and are a starting point (though not the only method) for handling human-subjects data in the United States. Governance of data about or from Indigenous peoples follows a separate and complementary framework: the CARE Principles for Indigenous Data Governance, developed by the Global Indigenous Data Alliance, assert that Indigenous data governance must account for Collective Benefit, Authority to Control, Responsibility, and Ethics, principles that sit alongside, rather than replace, the FAIR principles for data more broadly. Where data cannot be fully de-identified or openly shared, controlled access is typically governed by data sharing agreements or data use agreements, which specify permitted uses, security requirements, and downstream restrictions on data recipients; NIH guidance on data sharing agreements is a frequently cited reference point for structuring these. For a research administrator, this is one of the highest-stakes areas of data management, since errors here carry legal and reputational risk beyond the individual study. Pages in this sub-cluster cover de-identification methods and their limits, how to structure and negotiate a data sharing agreement, and how Indigenous data governance frameworks interact with institutional and funder policy.

Guides

All of Us Researcher Workbench: How Tiered Access Works

How NIH’s All of Us Research Program governs researcher access to its precision-medicine dataset through the Registered and Controlled Tiers, the institutional Data Use and Registration Agreement (DURA), and individual researcher requirements — plus the 2026 migration to Researcher Workbench 2.0.

EGA (European Genome-Phenome Archive): The EU’s Controlled-Access Counterpart to dbGaP

The European Genome-phenome Archive (EGA) is the EU’s controlled-access repository for human genomic, phenotypic, and clinical research data, jointly run by EMBL-EBI and CRG. Here is how its Data Access Committee model, GDPR compliance, and Federated EGA architecture work, and how it compares to dbGaP.

H3Africa’s Data and Biospecimen Access Committee (DBAC): A Governance Model for African Genomic Research

How H3Africa’s Data and Biospecimen Access Committee (DBAC) governs access to African genomic data and biospecimens collected under broad consent, including eligibility, the request process, and access conditions.

PhysioNet Credentialed Access: How to Get MIMIC and Other Restricted Data

How PhysioNet’s open, restricted, and credentialed access tiers work, and what the credentialing process (CITI training, identity review, and a per-dataset Data Use Agreement) requires before a researcher can access MIMIC and other physiological or clinical signal datasets.

Vivli: How the Data Request and Access-Review Process Works

Vivli is a non-profit platform for requesting individual participant clinical trial data. Here is how its request form, administrative check, data-contributor feasibility review, Independent Review Panel, data use agreement, and secure research environment actually work, step by step.

Data Trusts: A Community-Governed Model for Sharing Sensitive Research Data

What a data trust is, how it differs from a data sharing agreement, data governance policy, or data commons, and how research administrators can evaluate the fiduciary trustee model for sharing sensitive data.

Data Anonymisation in Research: Techniques, Standards, and When It’s Required

How researchers anonymise data: core techniques, the GDPR/HIPAA/NIST standards that define the term, and when anonymisation is actually required versus pseudonymisation or controlled access.

Data Security Incident Notification Requirements: GDPR, HIPAA, and State Law

A practical breakdown of when a data security incident involving research data triggers legal notification duties — GDPR Articles 33 and 34, the HIPAA Breach Notification Rule, and US state breach-notification laws — and how these differ from institutional IRB and sponsor notification obligations.

Data Breach Response Plan Template: A Worked Outline for Research Data

A section-by-section worked template for a research-data breach response plan, covering detection and reporting, triage and classification, containment, regulatory/contractual notification obligations (HIPAA, dbGaP, DUA, IRB, export control, 2 CFR 200.113), remediation, and a sample incident-log format.

Data Protection Act 2018 in Health and Social Care Research

How the UK Data Protection Act 2018 works alongside UK GDPR to govern health and social care research: special category conditions under Schedule 1, the Schedule 2 research exemption, and the 2026 move of safeguards from section 19 to UK GDPR Articles 84B/84C.

Data Use Agreement Template: A Worked Example, Clause by Clause

Two illustrative, clause-annotated Data Use Agreement examples — a bilateral HIPAA limited-dataset DUA and a dbGaP-style controlled-access certification — plus the checklist any defensible DUA needs to answer.

Data Availability Statement Sample: Worked Examples

Three fully worked data availability statement samples — open repository, restricted/controlled access, and no new data — as ready-to-adapt illustrative composites, not real study records.

Data Sharing Agreement: A Worked Example, Clause by Clause

A complete, fictional composite data sharing agreement walked through clause by clause — parties, permitted use, security, publication rights, retention, and liability — showing what filled-in language actually looks like.

Indigenous Health Equity Fund: What It Funds and What It Means for Data Governance

A guide to the Indigenous Health Equity Fund (ISC-administered, $2B/10yr): funding streams, eligibility, and the OCAP/CARE data governance obligations that attach to funded projects generating Indigenous health data.

Managing Participant-Level Research Data

How to de-identify, tier access to, and govern sharing of participant-level (human-subjects) research data under HIPAA and GDPR, distinct from informed consent and IRB review.

AIATSIS Code of Ethics for Aboriginal and Torres Strait Islander Research

What the AIATSIS Code of Ethics for Aboriginal and Torres Strait Islander Research requires: its four core principles, how it replaced GERAIS in 2020, and what it means for data governance and ethics review.

Health Data Research Service (HDRS): What It Is

What the UK Health Data Research Service (HDRS) is, where it came from, what it will provide, how it is funded and governed, and how it differs from HDR UK.

Data Sharing Agreements Between Collaborators and Institutions

What a data sharing agreement covers between collaborating institutions — ownership, permitted use, security/privacy obligations, publication rights, and retention/destruction terms — and how it differs from a Data Management Plan, a Data Use Agreement, and a Material Transfer Agreement.

How to Write a Data Availability Statement for Reproducibility

A practical, standards-based guide to writing a data availability statement that genuinely supports reproducibility: required elements, real ICMJE/PLOS/Springer Nature/NIH requirements, example wording for common data-sharing situations, and common mistakes to avoid.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →