Data Protection Plans
Overview
Some research projects are subject to sponsor, contractual, regulatory, data access, export control, or other information protection requirements beyond the University's standard research computing and information security practices.
These requirements may apply to proprietary or confidential research information, government information, export-controlled information, NIH controlled-access data, sponsor- or contractually restricted information, or other research information requiring specialized safeguards.
When these requirements apply, a Data Protection Plan (DPP) may be required to document the administrative, physical, and technical safeguards that will be used to protect research information throughout the research lifecycle.
The Office of Research Security (ORS) assists researchers in identifying whether project-specific requirements call for a Data Protection Plan and coordinates development of the plan with the Principal Investigator and appropriate University offices.
Contact ORS Before You
Contact ORS if:
- A sponsor, agreement, data provider, or other applicable requirement requires a Data Protection Plan or similar safeguarding plan.
- A sponsor or agreement establishes specific requirements governing access, storage, processing, transmission, sharing, or protection of research information.
- The research involves government information, export-controlled information, controlled-access data, or other information subject to specialized safeguarding requirements.
- A Data Use Agreement (DUA), Non-Disclosure Agreement (NDA), research agreement, or other agreement establishes project-specific information protection requirements.
- The project requires specialized computing, storage, cybersecurity, physical security, or access controls.
- You are uncertain whether project-specific information protection requirements require a DPP or safeguards beyond applicable University baselines.
Key Considerations
Not all research projects require a Data Protection Plan.
A Data Protection Plan may be required when a project involves:
- Sponsor-required information protection measures.
- Contractual information protection requirements.
- Proprietary or confidential research information subject to specific safeguarding requirements.
- Government-controlled information.
- NIH controlled-access data.
- Secure research computing requirements.
- Other project-specific information protection requirements established by a sponsor, agreement, or regulation.
Researchers should identify these requirements before research begins whenever possible.
A Data Protection Plan documents the project-specific safeguards required to satisfy applicable information protection requirements.
Depending on the project, a Data Protection Plan may address:
- The research information covered by the plan.
- Authorized users.
- Information storage locations.
- Secure research computing requirements.
- Access controls.
- Information sharing and transfers.
- Data retention and disposition.
- Sponsor, contractual, or regulatory requirements.
- Other project-specific safeguards.
The specific requirements depend on the project and the applicable sponsor, contractual, or regulatory obligations.
A Data Protection Plan may require computing, storage, cybersecurity, or other technical safeguards beyond those used for ordinary research information.
ORS identifies the research-specific requirements that must be addressed by the DPP. When technical safeguards or specialized computing environments are required, ORS coordinates with Research Computing & Informatics (RCI), DoIT, and other appropriate University technology offices to support identification and implementation of technical solutions that meet those requirements.
Researchers should not assume that a particular University storage, cloud, computing, or collaboration service satisfies all project-specific requirements.
A Data Protection Plan applies throughout the period in which the research information is subject to the requirements addressed by the plan.
The Principal Investigator and research team are responsible for following the safeguards and procedures established in the DPP, including applicable requirements for access, storage, use, sharing, and protection of research information.
A DPP should be reviewed when there is a material change that may affect the project's information protection requirements or safeguards. Examples may include:
- Adding or removing project personnel.
- Receiving a new type or source of restricted research information.
- Changing the computing or storage environment.
- Adding a collaborator or external organization.
- Changing how research information is accessed or shared.
- Modifying an applicable agreement or data access arrangement.
- Receiving new or revised sponsor requirements.
Researchers should contact ORS when a proposed change may affect the requirements or safeguards documented in the DPP.
ORS Support
ORS assists researchers by:
- Reviewing sponsor, contractual, regulatory, export control, data access, and other project-specific information protection requirements.
- Determining whether applicable requirements call for a Data Protection Plan.
- Coordinating development and review of Data Protection Plans with investigators and appropriate University offices.
- Identifying the administrative, physical, and technical requirements that must be addressed by the plan.
- Coordinating with RCI, DoIT, and other appropriate University offices when specialized computing, storage, cybersecurity, or other safeguards are required.
- Supporting review and updates to the DPP when project requirements materially change.
- Providing research-specific guidance throughout the research lifecycle.
Related Guidance
| Related Guidance | Description |
|---|---|
| Research Information Classification | Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, data access, and other requirements help determine the appropriate classification and protection of research information. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Working with Proprietary & Confidential Research Information | Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations. |
| Working with NIH Controlled-Access Data | Guidance for requesting, receiving, storing, sharing, and using NIH controlled-access data and other sponsor-controlled research repositories. |
| Working with Government Information | Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information. |
| Secure Research Computing | Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards. |
| Sharing Research Information | Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties. |
| Sponsor & Agreement Requirements | Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements. |
Frequently Asked Questions
Does every research project require a Data Protection Plan?
No. Most research projects do not require a Data Protection Plan. A DPP may be required when a sponsor, agreement, regulation, data provider, or other applicable requirement establishes project-specific information protection requirements or requires documentation of the safeguards used to protect research information.
Who develops the Data Protection Plan?
ORS coordinates development of the Data Protection Plan with the Principal Investigator and appropriate University offices based on the requirements applicable to the project.
When the DPP includes computing, storage, cybersecurity, or other technical safeguards, ORS coordinates with RCI, DoIT, and other appropriate University technology offices within their respective areas of responsibility.
Who is responsible for following the Data Protection Plan?
The Principal Investigator and research personnel with access to information covered by the DPP are responsible for following the applicable safeguards and procedures established for the project.
Is a Data Protection Plan the same as secure research computing?
No. A Data Protection Plan documents the requirements and safeguards applicable to a research project. A specialized or secure research computing environment may be one of the safeguards used to satisfy those requirements.
Is a Data Protection Plan the same as a Technology Control Plan?
No.
A Technology Control Plan (TCP) is an export control compliance document used to establish controls for access to export-controlled equipment, software, technology, technical information, or other controlled research assets.
A Data Protection Plan (DPP) documents project-specific information protection requirements and the safeguards used to address those requirements.
Depending on the research activity, a project may require one or both.
Does a DPP need to be updated?
It may. Changes to project personnel, research information, collaborators, computing or storage environments, agreements, data access arrangements, or sponsor requirements may affect the safeguards documented in the DPP.
Contact ORS when a material change may affect the project's information protection requirements.
Need Assistance?
Contact ORS if your research involves sponsor, contractual, regulatory, data access, export control, government, or other project-specific information protection requirements and you are uncertain whether a Data Protection Plan is required.
ORS will help identify applicable research-specific requirements and coordinate development of a DPP with the Principal Investigator and appropriate University offices when required.