Sensitive data can be shared thoughtfully and carefully

Much research data – even sensitive data – can be shared legally if researchers employ strategies of informed consent, anonymisation and controlling access to data.

Ulster University image

What is Sensitive Data?

The term 'sensitive data' is used to refer to data relating to people, animal or plant species, data generated or used under a restrictive commercial research funding agreement, and any data likely to have significant negative public impact if released.

There are sound reasons why the openness of research data may need to be restricted but any restrictions must be justified and justifiable. It is important that constraints on data access must not be applied on a blanket basis but should be justified and justifiable case by case.

Potential reasons for restricting data include:

  • Access to the data has been purchased from a commercial provider;
  • Research data containing personal identifying information (i.e. 'personal data' as defined in the General Data Protection Regulation);
  • The data contains sensitive, personal information about human subjects, it may violate the Data Protection Act, ethics codes, or your own written consent forms to share it, even with other researchers. However, there might be ways of anonymising the data to make it shareable;
  • The data has been obtained under a non-disclosure agreement from a partner;
  • The data has financial value or is the basis for potentially valuable patent that could be exploited by the University - it may be unwise to share it;
  • The work building on the data may lead to a commercial opportunity and a patent.

A word about Personal Data

Personal data is data that identifies individual participants, whether by name or another identifier, such as an ID number, IP address, or by circumstances relating to that individual.

A subset of personal data is sensitive personal data (or from 25th May 2018 "special categories of personal data"), which relates to areas including ethnicity, religion, sexuality, trade union membership, political views, mental and physical health and from 25th May 2018 genetic and biometric data that is processed for the purpose of uniquely identifying an individual.

Data still counts as personal data if it is possible to deduce identify. For example, if a survey didn't collect people's names but did collect job titles and company names, then it's likely this would include personal data because (in some cases at least) you could work out which responses came from which people by their job titles.

Handling Personal Data

Ulster University's guidance on the Classification, Storage & Retention of Research Project Data outlines a series of principles which should be adopted when handling personal information.  All staff involved in the process of handling personal data part of a research project should refer to the University's GDPR Policy.  GDPR requires that personal data should only be kept in an identifiable form for as long as necessary, and that, where possible, the data is anonymised as soon as is feasible.

Providing safeguarded access to sensitive data

Even if open data sharing is not possible, it is often still possible to provide controlled or restricted access to your research. Access controls should always be proportionate to the kind of data and level of confidentiality involved.

Ulster University image

There are a number of ways in which controlled or restricted access to sensitive data may be achieved:

Deposit in PURE under an embargo

If you wish to restrict access to your data for commercial reasons (e.g. to apply for a patent), your best option is to deposit in Ulster’s PURE repository under an embargo.

This will ensure that you can deposit the data at convenient point in your research process and have it automatically made public at a future date.

Funders generally encourage commercialisation of research results, but generally impose a limit on how long data can be embargoed for: in most cases the data must be available within 12 months of the end of the project.

For more information, check your funder’s data policy.

Obtain informed consent for data archiving and sharing

Researchers will need to ensure that data sharing is considered from the very beginning of study planning. Making provision for future data sharing a standard component of study design is therefore essential.

How a researcher asks for consent has a great impact on the accessibility of research data. It is tempting to use wording as a way of reassuring participants that their data will not be misused, but this may be overly restrictive.  In general, think very carefully about any wording that restricts – forever – uses of the data. If what you are trying to do is to build trust with participants, telling them how their data can be safely used in diverse ways is a better approach!  The best way to achieve informed consent for data sharing is to identify and explain the possible future uses of their data and offer the participant the option to consent on a granular level (CESSDA Training Team (2017 - 2022). CESSDA Data Management Expert Guide).

Researchers should make sure that consent does not unnecessarily prevent preservation, sharing and reuse of data (consent forms should not promise to either destroy the data or that the data will only be seen or accessed by the research team). Data sharing should be enabled by ensuring adequate protections are applied to the creation or subsequent access to data through anonymisation techniques and access restrictions where these are required. Consent forms should indicate that the data will be anonymised and that whilst data will be made openly available to other researchers, confidentiality will be protected.   They should also specify any access restrictions that will apply to the data in the future e.g. safeguarded access.

Provide a Data Access Statement

If you are making your data available on a restricted basis it can sometimes be difficult for people to discover that the data exists and is available.

Any data set or document made available for sharing should be associated with concise, publicly available and consistently structured discovery metadata, describing not just the data object itself but also how it can be accessed.

This is to maximise its discoverability by both humans and machines. Ulster’s Research Data Management webpages provide Sample Data Access Statements that can be tailored to suit your publication.

Share under a Data Sharing Agreement

If you cannot make your data widely available, you may still be able to make bilateral agreements with individual researchers or groups to ensure the data is used in line with the consent obtained.

This will probably involve drawing up a formal data sharing or collaboration agreement. Sinead Hunter, Intellectual Property Manager can help you with more information on data sharing agreements.

Use a secure data repository

Some data repositories provide a facility to allow carefully controlled access to sensitive information. These typically require interested researchers to prove their credentials, sign a non-disclosure agreement and analyse data in a dedicated facility without a network connection, taking away only anonymous information or statistics.  One example of this is the UK Data Service, which provides a Secure Lab.

Ulster University hosts a SafePod to provide remote access to research datasets held by Data Centres across the UK.  The Ulster University SafePod is a secure, small room located on the Coleraine Campus that lets researchers safely access sensitive and confidential data.  The SafePod replicates a traditional safe setting, including a controlled access system, CCTV camera and secure storage areas for IT hardware and equipment. No datasets are held within the SafePod. Instead a secure connection is provided from a SafePod to a Data Centre for a researcher to view and analyse their project datasets.  Information on the Data Centres available from the SafePod and guidance on how to book this service can be found via the SafePod Network.

Use a data repository which has processes for facilitating restricted access

Established disciplinary repositories (e.g. UK Data Service) have access levels negotiated with the data owner which depends on the detail, confidentiality and sensitivity of the data.  Ulster University's institutional data repository (PURE Datasets)  has processes to facilitate restricted access to sensitive data.  You can contact pure-support@ulster.ac.uk with queries, or for support, on using PURE to provide restricted access to research data.

Where can I safely share sensitive data?

Established disciplinary repositories (e.g. UK Data Service) have access levels negotiated with the data owner which depends on the detail, confidentiality and sensitivity of the data.  Ulster University's institutional data repository (PURE Datasets)  has processes to facilitate restricted access to sensitive data.  You can contact pure-support@ulster.ac.uk with queries, or for support, on using PURE to provide restricted access to research data.

For further help on choosing a data repository, explore more on publishing your research data.

Ulster University image

Restricted data should always have open metadata

Even if your data can not be openly shared, you should have an open description of your data published in a data repository. This helps others to discover and cite your data and it provides essential information on any grounds through which the data can be accessed.  Doing this is putting FAIR principles into action.

All research data should have an corresponding metadata record in Ulster's Datasets Repository (PURE).  If you have any queries on this point, please contact: pure-support@ulster.ac.uk

Read more about Archiving and Publishing your research data

Ulster University image