Data Security & Categories
Why Research Data Protection Matters
UNC Charlotte maintains an active research environment grounded in openness, collaboration, and integrity. As an R1 institution, Charlotte must protect its research activities from three significant threats: foreign government interference, intellectual property theft, and research integrity violations. Protecting research data is essential for maintaining compliance with federal regulations, supporting national security, and preserving public trust in the University’s research activities.
Principal Investigator (PI) Responsibilities
Compliance with data protection and data use requirements is the responsibility of the PI. Each PI should review all applicable data use agreements, grants, contracts, and other governing documents to determine whether specific data protection requirements apply.
Charlotte personnel working under such agreements, grants, or contracts must, at a minimum, comply with all applicable protection requirements and any data retention or disposition obligations. In addition, PIs are responsible for ensuring that all required reviews are completed, including Data Security Reviews, Data Use Agreement (DUA) Reviews, Institutional Review Board (IRB) Reviews, and other research-related reviews.
Research Data Ownership, Retention, and Access
Quick Facts:
- All research data and related records belong to the University unless ownership is otherwise specified by the terms of an award or other agreement.*
- When a faculty member serving as a PI leaves Charlotte, the transfer of research data requires prior approval.
- A PI is responsible for developing, maintaining, and implementing policies and procedures governing their data assets, including the management, sharing, retention, security, and disposition of research data.
- Research data must be retained for at least three years after the conclusion of a research project; however, certain circumstances, sponsor requirements, or regulations may require longer or shorter retention periods.
Award terms and conditions, U.S. federal laws and regulations, international laws, or other circumstances may impose additional obligations and require more stringent data protection standards.
The nature and source of the data determine the level of protection required. Researchers must comply with the data protection requirements specified in applicable agreements, contracts, grants, and other governing documents.