Privacy & Personal Information in Research
Overview
Research activities may involve personal information that is subject to privacy, sponsor, contractual, cybersecurity, research information protection, or institutional requirements. Applicable requirements vary depending on the type of information involved, the research activity, and applicable federal, state, international, sponsor, or contractual requirements.
The Office of Research Security (ORS) assists researchers in identifying research security, sponsor, contractual, cybersecurity, and research information protection requirements that may apply when research involves personal information. When privacy or human subjects requirements are involved, ORS coordinates with the appropriate University offices.
CONTACT ORSPersonal Information in Research
Research may involve many types of personal information, including:
- Personally Identifiable Information (PII)
- Protected Health Information (PHI)
- Human subjects research data
- Genomic or other sensitive research data
- Educational records
- Financial information
- Biometric information
- Other regulated personal information
The applicable requirements depend on the information involved and the laws, regulations, sponsor requirements, agreements, and institutional policies governing the research activity.
Important: Not all personal information is subject to the same requirements. The protections required for a particular research project depend on the type of information, how it is obtained and used, and the requirements applicable to the research activity.
Common Privacy & Information Protection Considerations
Research involving personal information may require consideration of:
- Privacy laws and regulations
- Human subjects protections
- Sponsor requirements
- Data Use Agreements (DUAs)
- Contractual confidentiality requirements
- Research cybersecurity requirements
- Research information protection requirements
- Secure research computing environments
- International privacy and data protection requirements
- Restrictions on access, use, sharing, or disclosure
More than one requirement may apply to the same research activity.
Sponsor & Data Use Requirements
Sponsors, data providers, repositories, and research collaborators may establish requirements governing access to and protection of personal information used in research.
These requirements may be established through:
- Award terms and conditions.
- Data Use Agreements (DUAs).
- Data access agreements or certifications.
- Repository terms and conditions.
- Sponsor cybersecurity requirements.
- Data Protection Plans.
- Contractual confidentiality requirements.
- Other project-specific information protection requirements.
Depending on the project, these requirements may establish restrictions on who may access the information, how it may be used or shared, where it may be stored or processed, and what cybersecurity safeguards must be implemented.
Researchers should identify applicable sponsor, repository, and agreement requirements before receiving or accessing research information.
Controlled-Access Research Data
Some sponsors, federal agencies, and research repositories provide access to research data through controlled-access mechanisms.
Controlled-access data may be subject to specific requirements governing:
- Authorized users.
- Permitted research uses.
- Access and sharing.
- Storage and computing environments.
- Cybersecurity safeguards.
- Data retention or disposition.
- Reporting or incident response.
- Other sponsor or repository requirements.
Requirements vary by sponsor, repository, dataset, and applicable agreement.
Researchers planning to use controlled-access data should review the applicable requirements before requesting or receiving access and contact ORS when sponsor, cybersecurity, or research information protection requirements apply.
Related Guide: NIH Controlled-Access Data (dbGaP)
International Research Involving Personal Information
Research involving the collection, access, use, storage, transfer, or sharing of personal information across international borders may be subject to additional legal, sponsor, contractual, and institutional requirements.
Examples include:
- International research collaborations.
- International data sharing.
- Research involving participants located outside the United States.
- Foreign collaborators accessing research information.
- Cross-border transfer of research participant information.
- International cloud storage or computing services.
- International repositories or controlled-access databases.
Depending on the activity, researchers may need to consider foreign privacy or data protection laws, Data Use Agreements, sponsor requirements, institutional policies, export controls, and research information protection or cybersecurity requirements.
Researchers planning international research involving personal information should consult the appropriate University offices early in the planning process. ORS can assist in identifying research security, sponsor, contractual, export control, cybersecurity, and research information protection considerations and coordinate with other University offices when appropriate.
Protecting Personal Information in Research
Safeguards for personal information should be based on the requirements applicable to the particular research activity.
Depending on the project, safeguards may include:
- Limiting access to authorized personnel.
- Secure storage and transmission.
- Appropriate research computing environments.
- Administrative, physical, and technical safeguards.
- Access, use, and disclosure restrictions.
- Sponsor-required cybersecurity measures.
- Data Protection Plans or other project-specific safeguards.
The appropriate safeguards depend on the type of information involved and applicable legal, sponsor, contractual, human subjects, and institutional requirements.
When Should I Contact ORS?
Contact the Office of Research Security when research involving personal information also includes:
- Sponsor-imposed cybersecurity or information protection requirements.
- Controlled-access research data or repositories.
- Data Protection Plans or other sponsor-required safeguarding measures.
- International sharing, transfer, or access involving research information.
- Government information or export-controlled information.
- Secure research computing requirements established by a sponsor or agreement.
- Questions regarding research security, cybersecurity, or research information protection requirements associated with personal information.
ORS will coordinate with the appropriate University offices when privacy, human subjects, contractual, or other institutional requirements require additional review.
How ORS Can Help
ORS assists researchers by:
- Identifying sponsor, contractual, research security, cybersecurity, and research information protection requirements involving personal information.
- Reviewing research activities for overlapping government information, export control, international research, and information protection requirements.
- Identifying when sponsor-required safeguards or secure research computing environments may be necessary.
- Coordinating Data Protection Plans and other project-specific research information protection measures, as applicable.
- Coordinating with the appropriate University offices when privacy, human subjects, contractual, or other institutional review is required.
- Providing guidance throughout the research lifecycle.
Related Guidance
| Reference Guide | Description |
|---|---|
| NIH Controlled-Access Data (dbGaP) | Learn about requirements for accessing, using, storing, and protecting data obtained through NIH controlled-access repositories. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Government Information | Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply. |
Related University Resources
Depending on the research activity, investigators may also need to work with one or more of the following University offices.
| University Office | Primary Role |
|---|---|
| Chief Privacy Officer | Institutional privacy guidance, privacy compliance, and privacy program oversight. |
| HIPAA Privacy & Security | Guidance regarding research involving Protected Health Information (PHI) and HIPAA Privacy and Security Rule requirements. |
| Institutional Review Board (IRB) | Oversight of human subjects research and protection of research participants. |
| Office of Sponsored Programs (OSP) | Sponsor agreements, contractual requirements, and award administration. |
| Research Computing & Informatics (RCI) | Secure research computing environments, research storage, and technical implementation of research cybersecurity safeguards. |
Additional information about these and other University resources is available on the University Research Data Protection & Cybersecurity Resources page.
Need Assistance?
If research involving personal information includes sponsor, contractual, research security, cybersecurity, export control, international research, or research information protection requirements, contact the Office of Research Security.
ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices, as needed.