Privacy & Personal Information in Research
Overview
Research activities may involve personal information that is subject to privacy, sponsor, contractual, cybersecurity, research information protection, or institutional requirements. Applicable requirements vary depending on the type of information involved, the research activity, and applicable federal, state, international, sponsor, or contractual requirements.
The Office of Research Security (ORS) assists researchers in identifying research security, sponsor, contractual, cybersecurity, and research information protection requirements that may apply when research involves personal information. When privacy or human subjects requirements are involved, ORS coordinates with the appropriate University offices.
CONTACT ORSPersonal Information in Research
Research may involve many types of personal information, including:
- Personally Identifiable Information (PII)
- Protected Health Information (PHI)
- Human subjects research data
- Genomic or other sensitive research data
- Educational records
- Financial information
- Biometric information
- Other regulated personal information
The applicable requirements depend on the information involved and the laws, regulations, sponsor requirements, agreements, and institutional policies governing the research activity.
Important: Not all personal information is subject to the same requirements. The protections required for a particular research project depend on the type of information, how it is obtained and used, and the requirements applicable to the research activity.
Stony Brook University's Sensitive Information Classification Policy establishes the University-wide framework for classifying University Data and determining appropriate information protection requirements. Research involving personal information may also be subject to additional or more specific privacy, human subjects, sponsor, contractual, regulatory, data access, or other requirements.
Common Privacy & Information Protection Considerations
Research involving personal information may require consideration of:
- Privacy laws and regulations
- Human subjects protections
- Sponsor requirements
- Data Use Agreements (DUAs)
- Contractual confidentiality requirements
- Research cybersecurity requirements
- Research information protection requirements
- Specialized computing, storage, or technical safeguards, when required
- International privacy and data protection requirements
- Restrictions on access, use, sharing, or disclosure
More than one requirement may apply to the same research activity.
Sponsor & Data Use Requirements
Sponsors, data providers, repositories, and research collaborators may establish requirements governing access to and protection of personal information used in research.
These requirements may be established through:
- Award terms and conditions.
- Data Use Agreements (DUAs).
- Data access agreements or certifications.
- Repository terms and conditions.
- Sponsor cybersecurity requirements.
- Data Protection Plans.
- Contractual confidentiality requirements.
- Other project-specific information protection requirements.
Depending on the project, these requirements may establish restrictions on who may access the information, how it may be used or shared, where it may be stored or processed, and what cybersecurity safeguards must be implemented.
Researchers should identify applicable sponsor, repository, and agreement requirements before receiving or accessing research information.
Controlled-Access Research Data
Some sponsors, federal agencies, and research repositories provide access to research data through controlled-access mechanisms.
Controlled-access data may be subject to specific requirements governing:
- Authorized users.
- Permitted research uses.
- Access and sharing.
- Storage and computing environments.
- Cybersecurity safeguards.
- Data retention or disposition.
- Reporting or incident response.
- Other sponsor or repository requirements.
Requirements vary by sponsor, repository, dataset, and applicable agreement.
Researchers planning to use controlled-access data should review the applicable requirements before requesting or receiving access and contact ORS when sponsor, cybersecurity, or research information protection requirements apply.
Related Guide: NIH Controlled-Access Data (dbGaP)
International Research Involving Personal Information
Research involving the collection, access, use, storage, transfer, or sharing of personal information across international borders may be subject to additional legal, sponsor, contractual, and institutional requirements.
Examples include:
- International research collaborations.
- International data sharing.
- Research involving participants located outside the United States.
- Foreign collaborators accessing research information.
- Cross-border transfer of research participant information.
- International cloud storage or computing services.
- International repositories or controlled-access databases.
Depending on the activity, researchers may need to consider foreign privacy or data protection laws, Data Use Agreements, sponsor requirements, institutional policies, export controls, and research information protection or cybersecurity requirements.
Researchers planning international research involving personal information should consult the appropriate University offices early in the planning process. ORS can assist in identifying research security, sponsor, contractual, export control, cybersecurity, and research information protection considerations and coordinate with other University offices when appropriate.
Protecting Personal Information in Research
Safeguards for personal information should be based on the requirements applicable to the particular research activity.
Depending on the project, safeguards may include:
- Limiting access to authorized personnel.
- Secure storage and transmission.
- Computing, storage, and technical environments appropriate for the applicable requirements.
- Administrative, physical, and technical safeguards.
- Access, use, and disclosure restrictions.
- Sponsor-required cybersecurity measures.
- Data Protection Plans or other project-specific safeguards.
The appropriate safeguards depend on the type of information involved and applicable legal, sponsor, contractual, human subjects, and institutional requirements.
When Should I Contact ORS?
Contact the Office of Research Security when research involving personal information also includes:
- Sponsor-imposed cybersecurity or research information protection requirements.
- Controlled-access research data or repositories.
- Data Protection Plans or other sponsor-, agreement-, or data-provider-required safeguarding measures.
- International sharing, transfer, or access involving research information.
- Government information or export-controlled information.
- Specialized computing, storage, cybersecurity, or other technical requirements established by a sponsor, agreement, or data provider.
- Questions regarding research security, cybersecurity, export control, or research information protection requirements associated with personal information.
ORS coordinates with the appropriate University offices when privacy, HIPAA, human subjects, contractual, or other institutional requirements require additional review.
How ORS Can Help
ORS assists researchers by:
- Identifying sponsor, contractual, research security, cybersecurity, export control, and research information protection requirements involving personal information.
- Reviewing research activities for overlapping government information, export control, international research, controlled-access data, and information protection requirements.
- Identifying when sponsor-, agreement-, or data-provider-required safeguards may apply.
- Coordinating Data Protection Plans and other project-specific research information protection measures, when applicable.
- Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, and other appropriate University offices when specialized technical safeguards are required.
- Coordinating with the appropriate University offices when privacy, HIPAA, human subjects, contractual, or other institutional review is required.
- Providing research-specific guidance throughout the research lifecycle.
Related Guidance
| Reference Guide | Description |
|---|---|
| NIH Controlled-Access Data (dbGaP) | Learn about requirements for accessing, using, storing, and protecting data obtained through NIH controlled-access repositories. |
| Research Information Classification | Learn how the University information classification framework and applicable sponsor, contractual, regulatory, privacy, data access, and other requirements help determine the appropriate classification and protection of research information. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Government Information | Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply. |
| Data Protection Plans | Guidance for developing and maintaining project-specific plans documenting sponsor, contractual, data-provider, or other information protection requirements. |
Related University Resources
Depending on the research activity, investigators may also need to work with one or more of the following University offices.
| University Office | Primary Role |
|---|---|
| Chief Privacy Officer | Institutional privacy guidance, privacy compliance, and privacy program oversight. |
| HIPAA Privacy & Security | Guidance regarding research involving Protected Health Information (PHI) and HIPAA Privacy and Security Rule requirements. |
| Institutional Review Board (IRB) | Oversight of human subjects research and protection of research participants. |
| Office of Sponsored Programs (OSP) | Sponsor agreements, contractual requirements, and award administration. |
| Research Computing & Informatics (RCI) | Research computing, storage, and technical expertise supporting University research, including assistance with specialized research computing requirements. |
Additional information about these and other University resources is available on the University Research Data Protection & Cybersecurity Resources page.
Need Assistance?
If research involving personal information includes sponsor, contractual, research security, cybersecurity, export control, international research, controlled-access data, or research information protection requirements, contact the Office of Research Security.
ORS will assist in identifying applicable research-specific requirements and coordinate with the appropriate University offices, as needed.
Questions specifically concerning privacy, HIPAA, or human subjects requirements should be directed to the University office responsible for that area.