Research Data Management
What is Research Data Management?
Research Data Management (RDM) involves the systematic organization, documentation, storage, sharing, and preservation of research data throughout the lifecycle of a research project. The primary objective of RDM is to ensure that data remains accessible, usable, secure, and well-documented over time.
Effective data management includes:
- File organization
- Documentation and version control
- Storage and access management for security and collaboration
- Archiving and preservation for future accessibility
- Policies and procedures for data sharing and reuse
Why Manage Data?
Good data management practices help researchers:
- Ensure long-term access to and use of data
- Meet sponsor, funder, and publisher requirements
- Receive appropriate credit for their work
Examples of Data Management Components
Data Transfer Use Agreements (DTUAs) and Data Use Agreements/Certifications (DUA/DUC)
A Data Transfer Use Agreement (DTUA) is a contractual document used for the transfer of data developed by an institution, nonprofit organization, government agency, or private industry when the data is nonpublic or otherwise subject to restrictions on its use. Examples include records from government agencies, institutions, or corporations; student records; and existing human subjects research data. This data is often a necessary component of a research project and may or may not include human subjects data from a clinical trial or a Limited Data Set, as defined by HIPAA. DTUAs are similar to confidentiality agreements because they restrict the use and disclosure of data.
A Data Use Agreement or Data Use Certification (DUA/DUC) is a binding agreement that outlines the terms and conditions for accessing and handling nonpublic data provided by one entity (the “Provider”) to another (the “Recipient”). These agreements are essential when external organizations share data with Charlotte or when Charlotte shares data with other organizations. As research-related agreements, DUAs must be reviewed and signed by the Division of Research Office of Research Services (ORS) in accordance with the University’s Delegation of Signing Authority.
Requirements for DUA/DTUA Compliance
The ORS serves as the University’s authorized signatory for DUAs and DTUAs. Researchers are not authorized to sign, including through electronic signature systems, DUA or DTUA documents on behalf of Charlotte. Researchers are responsible for understanding and complying with all terms and conditions of the agreement and may use the data only for the purposes specified therein.
ORS assumes that any researcher who submits a DUA or DTUA for processing has reviewed the agreement and agrees to comply with its terms, regardless of whether the researcher’s signature is required on the document.
Data Security Plan (DSP)
A DSP is the primary document used to protect research data through established data management and security procedures. The plan outlines requirements for data storage, access controls, and data protection measures that align with the University’s information security standards.
A DSP may be required in situations involving:
- Sponsored research award requirements
- Sensitive or restricted data
- Data sharing with subcontractors or external collaborators
Researchers work with their college’s Data Security Officer (DSO) to develop, implement, and review the plan. Complete the Data Registration Form to start the process with your DSO.
Data Security Plan Compliance
To comply with the DSP, researchers must ensure that data storage aligns with the required data classification levels and adhere to the terms outlined in the Data Use Agreement (DUA). The research team, along with the IRB and all other affected parties, needs to be notified immediately when data breaches or unauthorized access occur. Research protocols guide scientists to follow established procedures that protect both participants and research data from potential harm.
Technology Control Plan (TCP)
A Technology Control Plan (TCP) is a critical compliance document used to manage export-controlled data, equipment, and materials throughout a research project. A TCP is required for projects involving information, technology, or items subject to U.S. export control regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). The TCP establishes protocols for the secure handling, storage, use, transfer, and disposal of regulated items and information.
DSPs vs. TCPs
| DSP | TCP |
|---|---|
| Protects research data | Protects export-controlled items and information |
| Driven by security requirements | Driven by export control regulations |
| Often required for sensitive data | Required for ITAR/EAR-controlled projects |
Data Management & Sharing Plan (DMSP)
A Data Management and Sharing Plan (DMSP) is a written document that describes how data will be collected, organized, stored, protected, managed, and shared during a research project and after its completion.
National Institutes of Health (NIH)
The NIH established the Data Management and Sharing (DMS) Policy, effective January 25, 2023, to promote the sharing of scientific data. All NIH-funded projects that generate Scientific Data must have a Data Management and Sharing Plan (DMSP) in place.
National Science Foundation (NSF)
Since 2011, the NSF has required Data Management Plans (DMPs) for all grant proposals. These plans are evaluated as part of the proposal review process and describe how research data will be managed, preserved, and shared, as well as any associated costs.
Resource: Preparing your data management and sharing plan