Working with Proprietary & Confidential Research Information

Overview

Researchers may receive proprietary or confidential research information from sponsors, collaborators, companies, universities, nonprofit organizations, and other external organizations while conducting research.

Although most proprietary or confidential research information does not require additional review by the Office of Research Security (ORS), certain research activities may involve research security, export control, sponsor, contractual, or other institutional requirements.

The Office of Research Security assists researchers in identifying research security and export control considerations that may apply before proprietary or confidential research information is received, accessed, shared, stored, or used.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS


Contact ORS Before You

Contact ORS before you:

  • Receive proprietary technical information, software, source code, or other information that may be subject to U.S. export control regulations.
  • Receive proprietary or confidential research information that restricts access based on citizenship, nationality, or export control status.
  • Receive research information subject to special information protection, cybersecurity, or access requirements beyond the University's standard business or research practices.
  • Share proprietary or confidential research information with collaborators or organizations outside the United States.
  • Receive proprietary or confidential research information from a foreign company, foreign government, foreign military or defense organization, or other organization that may require additional research security review.
  • Receive research information subject to sponsor, contractual, or government-imposed restrictions on access, sharing, publication, or dissemination.
  • Are uncertain whether research security, export control, sponsor, or other institutional requirements apply.

Key Considerations 

Some proprietary or confidential research information may also be subject to U.S. export control regulations.

Examples include:

  • Technical information
  • Technical data
  • Software
  • Source code
  • Engineering designs
  • Manufacturing information
  • Technology subject to the Export Administration Regulations (EAR) or International Traffic in Arms Regulations (ITAR)

Depending on the information involved, export licenses, Technology Control Plans, or other export control requirements may apply.

ORS can assist in determining whether export control requirements apply.

Some proprietary or confidential research information may restrict access by foreign persons or require U.S. government authorization before access may be provided. When the information includes controlled technology, source code, or technical information, release to a foreign person may constitute a deemed export under U.S. export control regulations.

Restrictions may arise from:

  • Export control regulations
  • Sponsor requirements
  • Contractual obligations
  • Other project-specific requirements

Researchers should consult ORS before providing foreign persons access to proprietary technical information whenever export control or research security considerations may apply.

Sharing proprietary or confidential research information with individuals or organizations outside the United States may involve export control regulations, sponsor requirements, or other research security considerations.

Before sharing research information internationally, researchers should consider:

  • Whether export control regulations apply.
  • Whether sponsor or contractual restrictions limit sharing.
  • Whether the recipient or organization should be screened.
  • Whether additional approvals are required.

ORS can assist researchers in identifying applicable research security and export control requirements before information is shared internationally.

Some sponsors, companies, and collaborators require proprietary or confidential research information to be protected using safeguards beyond the University's standard business or research practices.

Examples may include:

  • Controlled access to research information
  • Sponsor-required cybersecurity safeguards
  • Secure computing or storage environments
  • Restrictions on copying, sharing, or transmitting information
  • Data Protection Plans or other project-specific security measures

When proprietary or confidential research information is subject to special protection requirements, researchers should identify these requirements before receiving the information. ORS can assist in determining whether research security, export control, sponsor, or other institutional requirements apply and coordinate with the appropriate University offices, as needed.

Research agreements, Non-Disclosure Agreements (NDAs), Confidential Disclosure Agreements (CDAs), Data Use Agreements (DUAs), Material Transfer Agreements (MTAs), software licenses, and other agreements frequently establish requirements governing proprietary or confidential research information.

These agreements may include requirements affecting:

  • Access to research information
  • Sharing or dissemination
  • Publication
  • Export controls
  • Information protection
  • Foreign person participation
  • International collaborations

Researchers should review applicable agreement requirements and consult ORS whenever research security or export control considerations may apply.

Some research sponsors establish additional requirements governing proprietary or confidential research information.

Depending on the sponsor and research activity, these requirements may address:

  • Information protection
  • Cybersecurity
  • International collaborations
  • Export controls
  • Sharing research information
  • Foreign participation
  • Sponsor approvals

ORS can assist researchers in identifying sponsor-specific research security requirements that may apply.


Related Guidance

Related Guidance Description
Sponsor & Agreement Requirements Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements.
Working with Government Information Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information.
Sharing Research Information Guidance for sharing research information, data, software, technology, technical information, presentations, publications, or other research outputs with collaborators, sponsors, companies, government agencies, or other third parties.
International Transfers (Shipments, Hand-Carry & Electronic Transmissions) Guidance for shipping, mailing, hand-carrying, or electronically transferring research equipment, materials, software, technology, technical information, or research information internationally.
Protect Export-Controlled Equipment, Technology, & Information Guidance for protecting export-controlled equipment, materials, software, technology, technical information, and other research assets from unauthorized access.
Deemed Exports Learn when releasing controlled technology or source code to a foreign person within the United States may constitute a deemed export.
Foreign Person Participating in Research Guidance for employing foreign national faculty, staff, postdoctoral researchers, and students participating in research activities.
Secure Research Computing Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards.
Data Protection Plans Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans.
Restricted Entity Screening Learn how organizations and individuals are screened against U.S. government restricted party and entity lists before certain University activities.

Frequently Asked Questions

Does proprietary or confidential research information always require ORS review?

No. Most research involving proprietary or confidential research information does not require ORS review. However, researchers should consult ORS whenever export control, research security, sponsor, or other institutional requirements may apply.


Can proprietary or confidential research information be export controlled?

Yes. Some proprietary technical information, software, source code, engineering information, and technology are subject to U.S. export control regulations.

ORS can assist in determining whether export control requirements apply.


Can foreign persons access proprietary or confidential research information?

Possibly.

Access depends on the nature of the information, applicable agreements, sponsor requirements, and export control regulations. When controlled technology, source code, or technical information is involved, release to a foreign person may require additional export control review or authorization.

Researchers should consult ORS whenever they are uncertain whether access restrictions apply.


Should I contact ORS before sharing proprietary or confidential research information internationally?

Yes, if you are uncertain whether export control, sponsor, contractual, or other research security requirements apply.


What if an agreement requires additional cybersecurity or information protection measures?

Some agreements establish project-specific information protection requirements beyond the University's standard business or research practices.

Researchers should identify these requirements before receiving the information. ORS can assist in determining whether research security or export control requirements apply and coordinate with the appropriate University offices, as needed.


Need Assistance?

Early consultation with ORS helps researchers identify applicable research security, export control, sponsor, contractual, and information protection requirements before proprietary or confidential research information is received, accessed, shared, stored, or used.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS