Responsible Access
Responsible data use is not a single approval step. It begins with a legitimate purpose and appropriate access, continues through analysis and interpretation, and ends with responsible dissemination, renewal, or closure. This workflow helps practitioners understand what to consider at each stage while recognizing that institutional policy, FERPA guidance, data-governance requirements, and approved agreements remain authoritative.
CORE RULE: Access should be tied to a legitimate institutional purpose, limited to the minimum necessary data, and reviewed throughout the project lifecycle.
The Responsible Access Lifecycle
Document the purpose, population, variables, users, outputs, audience, duration, and institutional benefit.
Minimum standard:
- The institutional purpose is clear.
- The requested data are specific.
- Users, outputs, audience, and duration are identified.
Watch for: Requests that begin with available data rather than a defined institutional question.
Confirm stewardship, policy, FERPA, sensitivity, minimum necessary fields, method readiness, and dissemination risk.
Minimum standard:
- The appropriate data steward is involved.
- Minimum necessary data have been identified.
- Required policy, privacy, and methodological considerations have been reviewed.
Watch for: Treating access approval as evidence that a project is automatically appropriate for every intended use.
Record scope, conditions, reviewers, expiration, and any restrictions on linkage or output.
Minimum standard:
- The approved purpose and scope are documented.
- Conditions and restrictions are explicit.
- Expiration or review timing is established.
Watch for: Informal expansion of a project beyond its original purpose.
Complete required training and establish the secure workspace, roles, version control, and documentation needed for the project.
Minimum standard:
- Required training is complete.
- Access is limited to approved users.
- Data are stored and transferred using approved methods.
- Documentation and version control are established.
Watch for: Downloading or moving data simply because it is technically possible.
Follow the approved purpose, limit exports, protect identifiers, and document transformations and analytical decisions.
Minimum standard:
- Use remains within the approved scope.
- Identifiers are protected and minimized.
- Transformations and analytical decisions are documented.
- Exports are limited to what is necessary.
Watch for: Reusing data, adding fields, or changing the population without revisiting the approved purpose.
Apply suppression, de-identification, interpretation, and dissemination review before sharing.
Before you share, confirm:
- The audience is approved.
- Identifiers are removed or necessary.
- Small cells are suppressed or combined.
- Combinations of fields do not create an unreasonable re-identification risk.
- Titles and labels accurately describe the population and period.
- Limitations are visible where the result appears.
- Causal language has been checked.
- Required reviewers have approved the product.
Watch for: A technically accurate result that becomes misleading, identifying, or inappropriate when presented outside its original context.
Remove access, archive approved materials, document disposition, or submit a renewed purpose and scope.
Minimum standard:
- Access is removed when no longer needed.
- Approved materials are archived appropriately.
- Disposition is documented.
- New uses or substantial changes trigger renewed review.
Watch for: Treating project closure as the end of responsibility rather than part of the data lifecycle.
Use this quick check to confirm that the core practices for responsible data use are in place. It can serve as a final review before dissemination or as a checkpoint during the project lifecycle.
| Practice | Standard | Status? |
|---|---|---|
| Purpose | Institutional purpose and intended use are documented. | |
| Access | Users, fields, population, duration, and access level are appropriate and approved. | |
| Security | Approved storage, authentication, transfer, and export practices are in place. | |
| Privacy | Identifiers and small-cell risks have been addressed. | |
| Documentation | Source, version, transformations, conditions, and analytical decisions are recorded. | |
| Interpretation | Claims accurately reflect the design, method, and limitations. | |
| Dissemination | Required reviews have occurred before sharing. | |
| Lifecycle | Access will be reconfirmed, changed, or removed as the project evolves. |
Responsible use is continuous: Responsible data use does not end when access is approved or results are produced. Revisit purpose, access, protections, interpretation, and dissemination whenever the project, people, data, or intended use changes.