Data Protection
The legal and methodological practices used to secure research data against unauthorized access, loss, or corruption.
What is Data Protection?
Data protection encompasses the technical, physical, and administrative safeguards applied to research data throughout its lifecycle (collection, storage, analysis, sharing, and destruction). It involves encryption, secure servers, access controls, and compliance with legal frameworks like GDPR or HIPAA to ensure that sensitive participant information is not compromised.
Why Data Protection Matters
Strong data protection prevents devastating breaches of confidentiality, keeps researchers compliant with legal regulations, and ensures the integrity and longevity of the dataset for future replication or secondary analysis.
Example
A public health researcher working with patient medical records stores all data on a specialized, air-gapped university server, uses strong encryption for all files, and ensures that only three approved team members have the decryption keys.
Common Mistakes
- Emailing spreadsheets containing identifiable participant data to co-authors without encryption.
- Storing master keys that link participant names to ID numbers in the same folder as the de-identified data.
- Failing to establish a clear protocol for how and when data will be securely destroyed after the retention period expires.