Data Protection Plans

Overview

Some research projects involve information that is subject to sponsor, contractual, regulatory, or other information protection requirements beyond the University's standard research computing and information security practices. This may include proprietary or confidential research information received from companies, sponsors, collaborators, or other external organizations; NIH controlled-access data; government-controlled information; or other research information requiring enhanced safeguards.

When these requirements apply, a Data Protection Plan (DPP) may be required to document how project-specific information protection requirements will be implemented and maintained throughout the research project.

The Office of Research Security (ORS) assists researchers in identifying whether project requirements call for a Data Protection Plan, coordinates development of the plan, and works with the appropriate University offices to support implementation of project-specific information protection requirements.

SCHEDULE A CONSULTATION

CONTACT ORS


Contact ORS Before You

Contact ORS if your research project:

  • Requires a Data Protection Plan.
  • Involves sponsor, contractual, or regulatory information protection requirements beyond normal University practices.
  • Includes proprietary or confidential research information received from a company, sponsor, collaborator, or other external organization that is subject to specific information protection requirements.
  • Involves NIH controlled-access data or other controlled-access research repositories.
  • Involves government-controlled information.
  • Requires use of a secure research computing environment.
  • Includes a Data Use Agreement (DUA), Non-Disclosure Agreement (NDA), research agreement, or other agreement establishing specific information protection requirements.
  • Are uncertain which project-specific information protection requirements apply.

Key Considerations 

Not all research projects require a Data Protection Plan.

A Data Protection Plan may be required when a project involves:

  • Sponsor-required information protection measures.
  • Contractual information protection requirements.
  • Proprietary or confidential research information subject to specific safeguarding requirements.
  • Government-controlled information.
  • NIH controlled-access data.
  • Secure research computing requirements.
  • Other project-specific information protection requirements established by a sponsor, agreement, or regulation.

Researchers should identify these requirements before research begins whenever possible.

A Data Protection Plan documents the project-specific safeguards required to satisfy applicable information protection requirements.

Depending on the project, a Data Protection Plan may address:

  • The research information covered by the plan.
  • Authorized users.
  • Information storage locations.
  • Secure research computing requirements.
  • Access controls.
  • Information sharing and transfers.
  • Data retention and disposition.
  • Sponsor, contractual, or regulatory requirements.
  • Other project-specific safeguards.

The specific requirements depend on the project and the applicable sponsor, contractual, or regulatory obligations.

Some projects requiring a Data Protection Plan must be conducted within an approved secure research computing environment.

ORS coordinates the administrative review and access process for the University's secure research computing environment and works with the appropriate University offices to support projects requiring enhanced information protection.


ORS Support

ORS assists researchers by:

  • Review sponsor, contractual, regulatory, and other project-specific information protection requirements.
  • Determine whether applicable project requirements call for a Data Protection Plan.
  • Coordinate development of Data Protection Plans with investigators and appropriate University offices.
  • Coordinate the administrative process for secure research computing access, when applicable.
  • Support implementation of project-specific information protection requirements throughout the research lifecycle.

Related Guidance

Related Guidance Description
Working with Proprietary & Confidential Research Information Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations.
Working with NIH Controlled-Access Data Guidance for requesting, receiving, storing, sharing, and using NIH controlled-access data and other sponsor-controlled research repositories.
Working with Government Information Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information.
Secure Research Computing Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards.
Sharing Research Information Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties.
Sponsor & Agreement Requirements Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements.


Frequently Asked Questions

Does every research project require a Data Protection Plan?

No. Most research projects do not require a Data Protection Plan. These plans are generally required only when a sponsor, agreement, regulation, or other project-specific requirement establishes information protection standards beyond the University's standard research computing and information security practices.


Who develops the Data Protection Plan?

ORS coordinates development of the Data Protection Plan with the principal investigator and the appropriate University offices based on the specific requirements of the project.


Is a Data Protection Plan the same as a Technology Control Plan?

No.

A Technology Control Plan (TCP) is an export control compliance document used to protect export-controlled equipment, software, technology, technical information, or other controlled research assets from unauthorized access.

A Data Protection Plan documents project-specific information protection requirements established by sponsors, research agreements, Data Use Agreements, regulations, or other applicable requirements.


 

Need Assistance?

Contact ORS if your research involves sponsor, contractual, regulatory, or other project-specific information protection requirements and you are uncertain whether a Data Protection Plan or enhanced safeguards are required.

SCHEDULE A CONSULTATION

CONTACT ORS