Ethics and legal compliance

Ensure your research data meets ethical and legal requirements. Discover how to securely collect, share and dispose of sensitive data.

 

What to consider in your DMP

As part of your project, you may be planning to collect sensitive or confidential research data. Before starting any research activity, think about:

  • what kind of sensitive data you'll collect
  • how to protect that data
  • whether it can be securely shared and with whom
  • who will own the data
  • methods for safe disposal.

Sensitive data

'Sensitive data' is a broad term in research data management which typically refers to:

  • Research data containing personally identifying information and special category data as defined in UK data protection legislation
  • Commercially sensitive or confidential data, including data generated or used under a restrictive commercial research funding agreement
  • Data relating to species of plants or animals where the release of data may adversely affect rare or endangered species
  • Data likely to harm an individual or community or have a significant negative public impact if released

Researchers at the University who are working with human subjects or animals should consult the Research Code of Practice, Academic Ethics Policy as well as the Data Protection Policy.

Special category data

Special category data is personal data that needs additional protection because it is more sensitive. Data is classified as special category where it includes information about a person's:

  • racial or ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic data
  • biometric data (where used for identification purposes)
  • health
  • sex life
  • sexual orientation

Security-sensitive data

Extra care should be taken when handling data with research security implications. Security-sensitive research can be that which:

  • is commissioned by the military
  • involves the acquisition of security clearances
  • concerns terrorist or extreme groups
  • involves IT encryption design for public bodies or business
  • involves anything else which the University considers as putting researcher(s) at risk

Please contact the Information Governance team for details of where this data should be stored. A record of the permission to store this data will be required.

More information on research security and trusted research can be found .

Safe sharing

Sensitive and confidential research data can be shared ethically and legally when this has been planned and agreed before collection. Relevant professional, ethical and discipline-specific standards must be followed. You can employ strategies to safely share sensitive data; these include: 

  • obtaining informed consent for data sharing from participants
  • anonymising the identity of participants
  • controlling access to data.

Informed consent

It's important to inform participants about what will happen to their data during and after your research project. This includes communicating the purpose and benefits of sharing their data for future research.

Informed consent forms should tell participants:

  • how their data will be collected and processed
  • with whom their data will be shared (both during and after the project)
  • where their data will be shared (e.g. via a recognised data repository)
  • details of when data will be destroyed, if applicable.

De-identifying data

Anonymisation and pseudonymisation are valuable tools that allow data to be shared, whilst protecting the privacy of research participants.

A person’s identity can be disclosed from:

  • Direct identifiers such as names, address, postcode or pictures.
  • Indirect identifiers which, when linked with other available information, could identify someone, for example information on workplace, occupation or age.

Anonymisation requires personally identifying information in a dataset to be removed, substituted, distorted, generalised or aggregated. True anonymisation removes the ability of anyone, including the researcher, to re-identify individuals. 

Pseudonymisation removes or replaces direct identifiers with pseudonyms such as codes or numbers. It breaks the link between the data and the individual, but allows individuals to be re-identified using a separate, securely stored ‘key’.

Remember: if it is possible to re-identify participants in your research project, your data is pseudonymised rather than anonymised.

The UK Data Service provides guidance on de-identifying and anonymising , as well as the anonymisation process for .

Access controls

Sensitive data can be securely shared by carefully controlling access. Access controls allow you to decide:

  • who can access the data
  • what they can do with it
  • how long they can access it for and under what restrictions.

A common example of access control is depositing data in a repository under an embargo and making the data available upon request.

Data disposal

You must securely dispose of research data identified for deletion with particular concern for the sensitivity of the data. For example, where data has been anonymised, the raw data may need to be destroyed.

When deciding which data to dispose of, you should consider:

  • Funder, ethical or legislative requirements
  • Contractual agreements with external partners
  • Discipline-specific norms.

When data is destroyed it must be irreversible with no chance of recovery.  Paper can be shredded using a shredder. Extra care should be taken with sensitive or confidential information and a secure paper destruction service bin used. Digital data may be destroyed by deleting or overwriting information.

Disposal of research data should be carried out in accordance with legal, contractual, regulatory, or ethical requirements and the University’s Information Security Policy.

Intellectual property

Intellectual property rights (IPR) affect the way both you and others can use research data. It's vital to clarify rights in relation to your research data and any secondary data. This will affect your ability to use and share the data.

IP and data ownership

The University owns all intellectual property, research data and software created by researchers in the course of their academic research activities.

Postgraduate research (PGR) students generally retain ownership of the research data they generate. However, ownership must be discussed with supervisors at an early stage, as arrangements may vary according to disciplinary and project-specific circumstances. For example, data collected within a laboratory, research group, or Centre for Doctoral Training (CDT) may be subject to different ownership arrangements and may not be owned solely by the PGR student.

Collaborative research

Where external partners are involved in a research project, you must ensure research data ownership is established and confirmed contractually in advance of the research project starting. Data ownership should be confirmed in accordance with the University's Intellectual Property Policy and relevant third-party agreements. Access to research data by third parties must be managed in accordance with the Information Security Policy.

You can find more information, including details of certain exceptions, in the University’s Intellectual Property Policy. If you have further questions, please get in touch with the IP & Commercialisation team.