Data Sharing Throughout the Research Lifecycle


Decisions and activities at each stage of the study’s lifecycle impact data sharing. Select a tab to learn more about key topics in a lifecycle stage, why they matter, and what actions you can take.

Start Up


Different actors and organizations have varying data sharing goals and ideas of how best to accomplish them. Identifying goals and roles early is especially important in collaborative research where multiple individual and organizational stakeholders must reach a consensus.

Lessons learned: If data sharing goals and roles aren’t agreed upon at a project’s beginning, obstacles can arise when it’s time to share data. There may be disagreements among collaborators about what data can or should be shared, and how or where to share it. Collaborators may mention local regulations or organizational policies circumscribing data sharing that other collaborators weren’t previously aware of. The collaborator(s) responsible for data management may not have planned ahead for sharing, necessitating extra effort to curate data and incurring costs the study didn’t budget for. Unanticipated obstacles can arise even when researchers share data within a collaboration, such as when a researcher at one organization transfers data to a collaborator at another organization.

What to do:

  • Build consensus about data sharing goals and roles across stakeholders early. Document conversations and their outcomes.
  • Refer to this documentation when establishing governing documentation [Memoranda of Understanding (MOUs), collaboration agreements, IRB protocols] and contracts to ensure alignment.
  • Define data rights and data decision-making roles. Data rights include ownership, access, and usage rights. Determine who decides if and how data will be shared, and who implements decisions. Document roles with a RACI matrix or similar tool.

HEAL studies often involve sensitive data (e.g., identifiable human subjects data and proprietary intellectual property) subject to legal, contractual, and/or regulatory requirements. Understanding your organization’s compliance requirements is essential when setting data sharing goals, selecting resources, and designing data workflows.

Lessons learned: Responsible data sharing doesn’t always mean open access. Sensitive HEAL data can be shared safely using techniques like de-identification, anonymization, date shifting, dimensionality reduction, introducing statistical noise, and controlled data access. Sharing data too permissively carries risk, but failing to maximize appropriate data sharing may violate HEAL Initiative compliance expectations.

What to do:

  • Talk to organizational privacy and compliance offices to ensure awareness of applicable requirements and policies. Understand how these impact data sharing.
  • Draft documents that impact data sharing to align with any sensitive data handling requirements. IRB application materials, Data Management and Sharing Plans (DMSPs), contracts, Data Security Plans (DSPs), and other study governing documents should accurately reflect relevant requirements.
  • Build in privacy protections to data management and sharing workflows. Technology resources and data handling processes should maintain required privacy protections throughout the entire data pipeline.

Additional resources:

Studies can support ethical data by using frameworks that balance risks and benefits for all stakeholders, including researchers, study subjects, funders, and affected communities. This is especially important in HEAL studies involving groups like substance use disorder patients or American Indian & Alaska Native peoples (AI-AN) communities.

Lessons learned: Ethical data practices support scientific validity, build trust, and support long-term collaboration. Overlooking data ethics can lead to data quality issues, strained relationships, and lost opportunities for future collaborations.

What to do:

Research data is often subject to various contracts. Some contracts focus on data directly, like Data Transfer Agreements (DTAs), Data Use Agreements (DUAs), Data Sharing Agreements (DSAs), data licenses, or Terms of Use in data repositories. Other contracts that govern the research project more generally, such as Research Agreements or Confidentiality Agreements, may also have implications for data sharing.

Lessons learned: How contracts impact data sharing may not always be obvious, especially when contracts are signed early in the study lifecycle, long before data are actually shared. Using boilerplate language or templates uncritically, or signing contracts without fully understanding their implications, can result in contracts that do not accurately reflect the project’s data sharing requirements, goals and roles. It’s important to understand what contracts mean for data rights and data sharing before signing them to prevent unanticipated obstacles later in the study**.**

What to do:

  • When working with institutional legal or contracts offices, ensure they understand study data sharing requirements and goals and draft or review contracts with those goals in mind.

Research data is often handled through numerous hardware and software components. Each component may have its own data privacy, security, compliance, usability, and accessibility considerations. Moreover, these components may be spread across multiple institutions with differing policies governing data and technology.

Lessons learned: Technology choice must balance two critical factors: the study’s requirements, and organizational requirements related to privacy, security, and compliance. IT departments often recommend pre-vetted technologies meeting organizational requirements, but these options don’t work for every study. Technologies which meet all study requirements (e.g., storing very large data, collecting data electronically offline, or enabling access for collaborators at other organizations) may not have been vetted by the organization, leading to privacy/security risks or consequences for not complying with organizational policy. Working with institutional IT departments to choose technology produces the best outcomes; however, it’s important study teams clearly communicate their requirements so IT colleagues can make appropriate recommendations.

What to do:

  • Consult your IT department to identify appropriate technology resources for handling study data. Consider both hardware and software components.
  • Choose secure and compliant file storage for the study data type(s). Your organization may only allow the use of certain data collection or file storage solutions for human subjects data or sensitive data. Consider long-term data storage requirements, which often extend beyond study’s end.
  • Test the full technology infrastructure end-to-end to identify any issues before using it to handle data. This is especially important for multi-institution research collaborations. For example, external collaborators may not be allowed to access all technologies hosted by your organization, or an organization may have policies governing data removal from certain technology resources.
  • Document the project’s technical infrastructure. Documentation may include information about hardware and software components (including versioning and update schedule), a data flow diagram, and data backup or disaster recovery plans. Some organizations require studies to have a Data Security Plan (example).

Additional resource: