Long-term responsibility for research data
Ensuring ongoing access and preservation
Data producers and their research teams are responsible for managing and curating data during a project. After a project ends, responsibility for long-term preservation and access should and is usually transferred to a repository.
Planning for this transition is an important part of research data governance. It involves ensuring that:
- data and documentation are prepared to appropriate standards
- files are organised and quality checked
- data reuse legal and ethical requirements are met
- access conditions are clearly defined
- responsibilities for ongoing access and preservation are agreed.
As part of long-term responsibility planning, data producers should consider how data will be accessed and reused.
Access to research data exists along a spectrum, ranging from open access to highly controlled environments. Different access models may be appropriate depending on ethical considerations, data sensitivity, legal constraints and disclosure risk.
Accountability frameworks such as the Five Safes Framework approach are commonly used to support structured access decisions and risk management.
At the UK Data Service the access levels have been mapped to the Five Safes Framework as follows:
| Safe | Open (OGL/OPL/CC BY | Safeguarded (EULA & others) | Controlled (EULA & SAUA) * |
|---|---|---|---|
| Safe Data | Not Personal Data or Information with no real disclosure risk e.g. aggregate data or Personal Data/Information with consent to share as collected as Open access. | Not Personal Data or Information; sufficiently remote identification risk (effective anonymisation ensured.) | Personal Data or Personal Information where direct identifiers have been removed* or highly sensitive data, commercially or otherwise. |
| Safe People | No restrictions; anyone may access the data. | Registered user; awareness of ethical and legal data handling expected; training available; specific user type/location restrictions may apply. | Registered and accredited users; awareness of ethical and legal data handling demonstrated; training mandatory; other specific user type restrictions may apply. |
| Safe Projects | No project registration or approval required; reuse permitted under licence T&Cs (e.g. attribution, no commercial use, no derivative works etc. as applicable). | Project registration required; use must be specific and time-limited; project application and formal approval may apply. | Project registration and application required; use must be specific, time-limited, with clear public benefit and formally approved by data owner/their nominee. |
| Safe Settings | No restrictions; data may be used in any environment. | User-managed setting; e.g. safe device/endpoint with data accessible to the registered user only & securely deleted after project end; additional conditions may apply e.g. institutional device only. | Data Service Provider–managed secure setting (e.g. SecureLab, SafePod, IDAN); access only via approved institutional devices to a monitored and locked-down environment. |
| Safe Outputs | No restrictions or requirements. | User responsible for ensuring outputs are non-disclosive (e.g. min threshold 3 for primary, 10 for secondary, region as geography); additional outputs conditions may apply. | All outputs are checked and approved by the Data Service Provider before release; additional output conditions may apply. |
Further guidance on access models is provided in the Preparing data for sharing and reuse section.
In some cases, long-term access to research data is provided through Trusted Research Environments (TREs), also known as Secure Data Environments.
TREs provide controlled settings where only approved and accredited users can access and analyse data within a data provider-managed environment. They are commonly used for detailed personal data, administrative records and linked datasets with higher disclosure risk.
TREs are not required for all research data. They represent one access and governance option within a broader spectrum of sharing approaches.
Some responsible repositories offer TRE services alongside traditional repository deposit and download models. In other cases, TREs operate as standalone access platforms linked to preserved datasets.
If a project is likely to require TRE-based access, this should be considered during planning, including:
- Governance and approval processes.
- Consent and data sharing conditions.
- Technical requirements.
- Access costs and support arrangements.
- Whether additional versions of the data (for example, anonymised, aggregated, or derived datasets) could be made available outside the TRE.
- Whether synthetic data, can be shared openly to support discovery and transparency.
Considering multiple access routes supports the principle of making data “as open as possible and as closed as necessary”, while maintaining appropriate protections for sensitive information.
Data controllers and data processors
When research involves personal data, it is important to clarify legal responsibility for how those data are processed.
Under data protection legislation, organisations or individuals may act as:
- Data controllers those who determine the purposes and means of processing personal data.
- Data processors those who process personal data on behalf of a controller.
In many research projects, universities or research organisations act as data controllers, while external service providers (such as transcription services, survey platforms or data processors) may act as processors.
In collaborative projects, different partners may hold different roles. These responsibilities should be agreed and documented early, and reflected in data management plans, contracts and participant communication materials.
Clear identification of controllers and processors supports compliance with data protection law and helps ensure accountability throughout the data lifecycle.
Detailed guidance on data protection responsibilities is provided in the legal and ethical responsibilities section of the learning hub.