All research must be open to some extent.
The choice is between being, at any stage of the research journey, more open or less open. There may be ethical, legal or commercial restrictions on the degree of openness that can be achieved for some research. Researchers should continuously review how much of their processes, data and findings can be made open and at which stage of the research journey.
Research Data
Principle #2 of the Concordat on Open Research Data states there are sound reasons why the openness of research data may need to be restricted but any restrictions must be justified and justifiable. It is important that constraints on openness must not be applied on a blanket basis but should be justified and justifiable case by case.
At each stage, we encourage you to ask the questions:
- Is there a more open way to do this?
- What difference will my choice make (to me, and to others)?
- Are there good reasons for making the open choice or indeed for restricting access to this data?
Reasons why access must be restricted include maintaining confidentiality, protecting individuals’ privacy, non-disclosure of commercially sensitive or valuable data until appropriate protections are in place e.g. patents, respecting consent terms, as well as managing security or other risks. Access must take full account of legal, regulatory and ethical requirements – including applicable data protection laws and relevant codes on research ethics and research integrity.
You will find links to relevant Ulster policy documents on these requirements at the send of this page and if you have any questions, further advice is available from Research & Impact Research Governance team.
Sensitive data can be safeguarded by regulating or restricting access to, and use of, the data.
Even if completely open data sharing is not possible, it is still possible to provide controlled or restricted access to your research.
There are a number of ways in which controlled or restricted access to sensitive data may be achieved:
If you wish to restrict access to your data for commercial reasons (e.g. to apply for a patent), your best option is to deposit in Ulster’s PURE repository under an embargo.
This will ensure that you can deposit the data at convenient point in your research process and have it automatically made public at a future date.
Funders generally encourage commercialisation of research results, but generally impose a limit on how long data can be embargoed for: in most cases the data must be available within 12 months of the end of the project.
For more information, check your funder’s data policy.
Researchers will need to ensure that data sharing is considered from the very beginning of study planning. Making provision for future data sharing a standard component of study design is therefore essential.
How a researcher asks for consent has a great impact on the accessibility of research data. It is tempting to use wording as a way of reassuring participants that their data will not be misused, but this may be overly restrictive. In general, think very carefully about any wording that restricts – forever – uses of the data. If what you are trying to do is to build trust with participants, telling them how their data can be safely used in diverse ways is a better approach! The best way to achieve informed consent for data sharing is to identify and explain the possible future uses of their data and offer the participant the option to consent on a granular level (CESSDA Training Team (2017 - 2022). CESSDA Data Management Expert Guide).
Researchers should make sure that consent does not unnecessarily prevent preservation, sharing and reuse of data (consent forms should not promise to either destroy the data or that the data will only be seen or accessed by the research team). Data sharing should be enabled by ensuring adequate protections are applied to the creation or subsequent access to data through anonymisation techniques and access restrictions where these are required. Consent forms should indicate that the data will be anonymised and that whilst data will be made openly available to other researchers, confidentiality will be protected. They should also specify any access restrictions that will apply to the data in the future e.g. safeguarded access.
If you are making your data available on a restricted basis it can sometimes be difficult for people to discover that the data exists and is available.
Any data set or document made available for sharing should be associated with concise, publicly available and consistently structured discovery metadata, describing not just the data object itself but also how it can be accessed.
This is to maximise its discoverability by both humans and machines. Ulster’s Research Data Management webpages provide Sample Data Access Statements that can be tailored to suit your publication.
If you cannot make your data widely available, you may still be able to make bilateral agreements with individual researchers or groups to ensure the data is used in line with the consent obtained.
This will probably involve drawing up a formal data sharing or collaboration agreement. Sinead Hunter, Intellectual Property Manager can help you with more information on data sharing agreements.
Some data repositories provide a facility to allow carefully controlled access to sensitive information. These typically require interested researchers to prove their credentials, sign a non-disclosure agreement and analyse data in a dedicated facility without a network connection, taking away only anonymous information or statistics. One example of this is the UK Data Service, which provides a Secure Lab.
Ulster University hosts a SafePod to provide remote access to research datasets held by Data Centres across the UK. The Ulster University SafePod is a secure, small room located on the Coleraine Campus that lets researchers safely access sensitive and confidential data. The SafePod replicates a traditional safe setting, including a controlled access system, CCTV camera and secure storage areas for IT hardware and equipment. No datasets are held within the SafePod. Instead a secure connection is provided from a SafePod to a Data Centre for a researcher to view and analyse their project datasets. Information on the Data Centres available from the SafePod and guidance on how to book this service can be found via the SafePod Network.
Established disciplinary repositories (e.g. UK Data Service) have access levels negotiated with the data owner which depends on the detail, confidentiality and sensitivity of the data. Ulster University's institutional data repository (PURE Datasets) has processes to facilitate restricted access to sensitive data. You can contact pure-support@ulster.ac.uk with queries, or for support, on using PURE to provide restricted access to research data.
Consent and Anonymity
Can I provide access to an existing dataset without explicit consent for sharing?
There is, of course, no question that identifiable information should ever be shared without explicit consent and all datasets must be fully anonymised.
However, aggregate information that cannot be identified as belonging to an individual and cannot be traced back to that person can be shared for research purposes even if their consent to share it is not in place. Fully anonymised data are those from which the original data subject cannot be identified by anyone, including any member of the research team, using either the dataset itself, or any other available dataset or mechanism.
If researchers wish to share identifiable data with a third party and this has not been agreed by the data subject in the original study consent, the researchers must contact the individual concerned and seek and obtain explicit permission to do so.
There may be instances in which sharing even anonymised data without consent is problematic, for example, sharing of datasets based on studies of groups of individuals with rare conditions. In such instances while participants are technically anonymous, they may be identified by knowledgeable individuals. Data sharing in such instances must be reviewed on a case by case basis and if you think your dataset might present such challenges you should contact Research Governance.
Restricted data should have open metadata
All data associated with published research articles must have a metadata record in PURE Datasets.
Even if your data can not be openly shared, you should have an open description of your data (i.e. metadata) published in a data repository. This helps others to discover and cite your data and it provides essential information on any grounds through which the data can be accessed. Doing this is putting FAIR principles into action.
You are interested in reading more?
Guidelines for Sharing Data on Human Participants is a resource developed within the COORDINATE Project. The guidelines were intended primarily for researchers who are producing data about children and youth. However, in exploring benefits of data sharing and addressing doubts of researchers, the guidelines make a useful read for all researchers who work with data about people.
Relevant Ulster policy documents
- Code of Practice for Professional Integrity in the conduct of research
- Intellectual Property Policy
- Policy for the Governance of Research involving Human Participants
- Policy on Research using Human Tissue
Office of the University Secretary
- Data Protection
- Research Data Management Policy



