Sponsor & Contractually Restricted Information

Overview

Research activities may involve information that is subject to sponsor, contractual, confidentiality, data use, access, or dissemination restrictions.

These requirements may be established through sponsored research agreements, contracts, subcontracts, confidentiality agreements, Data Use Agreements (DUAs), collaboration agreements, material transfer agreements, licenses, data provider terms, or other agreements governing the research activity or information.

The specific requirements depend on the information involved and the terms accepted by the University. Requirements may affect who may access the information, how it must be stored or transmitted, whether it may be shared with collaborators, and what administrative, physical, or technical safeguards must be implemented.

The Office of Research Security (ORS) assists faculty, staff, and students in identifying research security, export control, cybersecurity, and research information protection requirements associated with sponsor- or contractually restricted information and coordinates with the appropriate University offices when additional safeguards are required.

CONTACT ORS


What Is Sponsor- or Contractually Restricted Information?

Sponsor or contractually restricted information is research information whose access, use, storage, sharing, transmission, or dissemination is limited by the terms governing the research activity or the information.

Examples may include:

  • Sponsor-provided confidential or proprietary information.
  • Company or collaborator proprietary information.
  • Information received under a Non-Disclosure Agreement (NDA) or Confidential Disclosure Agreement (CDA).
  • Information subject to a Data Use Agreement (DUA).
  • Information provided under a research, collaboration, testing, service, or other agreement.
  • Information subject to restrictions established by a data provider or repository.
  • Information subject to sponsor-required cybersecurity or information protection requirements.
  • Information subject to restrictions on access, use, sharing, publication, or dissemination.

The existence of a restriction does not necessarily mean that the information is export controlled, government controlled, or otherwise regulated. The applicable requirements depend on the information and the terms governing its use.


How Researchers May Receive Restricted Information

Researchers may receive sponsor- or contractually restricted information through many types of research activities.

Common examples include:

Sponsored Research

A sponsor may provide information for use in a research project or establish requirements for protecting information generated or used during the project.

Award or agreement terms may establish requirements related to confidentiality, cybersecurity, access, storage, transmission, sharing, or dissemination.

Confidentiality Agreements

Non-Disclosure Agreements (NDAs), Confidential Disclosure Agreements (CDAs), and similar agreements may require researchers to protect information received from an outside organization or individual.

Researchers should understand the confidentiality, access, use, and disclosure requirements applicable to information received under these agreements.

Data Use Agreements

Data Use Agreements may establish requirements governing access to, use of, storage of, sharing of, or security for research data.

Requirements vary depending on the data provider and the information involved.

Collaborations & Other Research Agreements

Research collaborations, testing agreements, service agreements, material transfer agreements, licenses, and other arrangements may include provisions governing confidential, proprietary, technical, or otherwise restricted information.


Common Protection Requirements

Requirements vary by sponsor, agreement, information type, and research activity.

Depending on the applicable terms, researchers may be required to:

  • Limit access to authorized project personnel.
  • Use computing, storage, or technical environments that meet applicable requirements.
  • Implement required cybersecurity safeguards.
  • Protect physical records, equipment, or research spaces.
  • Use approved methods for transmitting or sharing information.
  • Restrict downloading or use of portable media.
  • Restrict access by collaborators or other third parties.
  • Restrict international access or sharing.
  • Maintain confidentiality of information.
  • Follow specified retention or destruction requirements.
  • Complete required training.
  • Implement a Data Protection Plan, Technology Control Plan, or other project-specific safeguarding plan.

Researchers should not assume that ordinary University research computing, storage, or collaboration resources satisfy all sponsor or contractual requirements.


Relationship to Other Research Information Requirements

Sponsor- or contractually restricted information may also be subject to other requirements.

Depending on the project, the information may also constitute or include:

  • Government information.
  • Controlled Unclassified Information (CUI).
  • Federal Contract Information (FCI).
  • Export-controlled information.
  • Personal information subject to privacy requirements.
  • Data subject to controlled-access or repository requirements.

More than one set of requirements may apply to the same information.

For example, information received under a confidentiality agreement may also be export controlled, or information provided under a federal contract may also constitute CUI or FCI.

ORS can assist researchers in identifying overlapping requirements.


Research Computing & Storage

Sponsor- or contractually restricted information should be stored, processed, and transmitted using University-supported resources appropriate for the applicable requirements.

The appropriate computing, storage, or technical environment depends on the information involved and the requirements established by the sponsor, agreement, contract, data provider, or other applicable terms. Resources appropriate for ordinary research information may not satisfy project-specific safeguarding or cybersecurity requirements.

ORS assists researchers in identifying applicable research-specific information protection and cybersecurity requirements. Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University technology offices provide technical expertise, services, and support within their respective areas of responsibility when specialized computing, storage, cybersecurity, or other technical solutions are required.

ORS coordinates with the appropriate University offices when additional safeguards or specialized technical environments are required.

Contact ORS before receiving, accessing, storing, or processing sponsor- or contractually restricted information if you are uncertain what protection requirements apply or whether a proposed resource is appropriate.


Before Receiving Restricted Information

Whenever possible, applicable requirements should be identified before restricted information is received or accessed.

Researchers should:

  • Ensure that required agreements have been reviewed and executed by the appropriate University office or authorized University official.
  • Understand applicable confidentiality, access, use, sharing, and dissemination restrictions.
  • Identify sponsor or contractual cybersecurity requirements.
  • Determine whether specialized computing, storage, or physical safeguards are required.
  • Confirm who is authorized to access the information.
  • Identify any restrictions on international access or sharing.

Do not accept restricted information outside established University processes when an agreement or institutional review is required.


How ORS Can Help

ORS assists researchers by:

  • Reviewing applicable sponsor, contractual, data access, research security, cybersecurity, and export control requirements.
  • Identifying information protection requirements associated with sponsor- or contractually restricted research information.
  • Assessing whether baseline safeguards are sufficient based on applicable research-specific requirements and identifying when additional administrative, physical, or technical safeguards may be required.
  • Identifying overlapping government information, export control, privacy, controlled-access data, or other research security requirements.
  • Identifying when Data Protection Plans, Technology Control Plans, or other project-specific safeguarding documentation may be required.
  • Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, Intellectual Property Partners, and other appropriate University offices.
  • Providing research-specific guidance throughout the research lifecycle.

Related Guidance

Reference Guide Description
Research Information Classification Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, government, data access, and other requirements help determine the appropriate classification and protection of research information.
Research Information Protection Learn how administrative, physical, and technical safeguards are identified and applied to protect research information.
Government Information Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply.
Export-Controlled Information Learn about protecting technical data, technology, software, source code, and other information subject to U.S. export control regulations.
Privacy & Personal Information in Research Learn about research involving personal information and overlapping privacy, sponsor, contractual, cybersecurity, data access, and research information protection requirements.
Data Protection Plans Guidance for developing and maintaining project-specific plans documenting sponsor, contractual, data-provider, or other information protection requirements.

Need Assistance?

If your research involves confidential, proprietary, sponsor-provided, contractually restricted, or other information subject to restrictions on access, use, storage, sharing, or dissemination, contact the Office of Research Security before receiving or accessing the information if you are uncertain what requirements apply.

ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices when additional safeguards are required.

CONTACT ORS