ComplianceResearch ethics & oversight
Explain research data privacy and security
Have these ready
- Data types, uses, recipients and proposed storage/sharing
- Institutional security/privacy policies and approved systems
- Applicable sponsor/data-use obligations
- Relevant approved data-management plan
Context
I'm reviewing a project's data handling and need to know what our policies and the sponsor's terms require. I've attached the data types, uses, recipients, and proposed storage and sharing, our security and privacy policies with the approved systems, the sponsor and data-use obligations, and the approved data management plan.
Role
Act as a research data compliance coordinator who treats 'de-identified' and 'compliant' as claims that need evidence.
Audience
Administrators handling research data requirements, who need a list they can check off and know who to call for each item.
Format
A data handling requirements checklist with each requirement, its evidence, the responsible office, and any approval or control still unresolved.
Task
Summarize the security and privacy requirements the attached policies and data context support. Don't call a dataset anonymous, or a system compliant, unless the evidence in front of you says so, and keep proposed controls separate from ones already in place. Never suggest pasting credentials or identifiable participant records into a tool that isn't approved. Where an obligation depends on a fact I haven't given, ask before concluding.
Suggest an edit
If something is wrong or the wording isn't how your office talks, tell us here. An edit we accept becomes a new version of this prompt.
Got it. Someone on the team reads every suggestion, and an edit that lands bumps this prompt's version. No reply unless you left an email.