![]() | We interviewed Alexis Goltra about the Policy on Privacy in Research that was published January 2026. Alexis Goltra is Chief Privacy Officer and Senior Privacy Attorney, responsible for managing Northeastern’s global privacy and data protection compliance program. Prior to joining Northeastern, Alexis was Chief Privacy Officer & Managing Associate General Counsel at Citrix, and prior to that, VP & Chief Privacy Officer at Oracle. Alexis started his legal career as an associate at Palmer & Dodge LLP in Boston. Alexis is a graduate of Harvard College, Cambridge University and the University of Virginia School of Law. |
For researchers who are hearing about Policy 127 for the first time, how would you describe what it covers in a sentence or two and how does it overlap with other areas of research compliance?
In a nutshell, the new Policy on Privacy in Research is designed to facilitate Northeastern’s compliance with global privacy laws, streamline grant / award submission and contracting, and enable regulators to quickly confirm the university’s privacy practices in the research context. The policy is important for researchers and the university because it both simplifies and reinforces compliance with applicable privacy laws and helps build confidence in Northeastern’s privacy practices.
This policy is designed to complement the IRB’s privacy practices grounded in the human subject research requirements in 45 CFR 46 and 21 CFR 50 & 56. But unlike the IRB requirements, the policy is focused on meeting global privacy law requirements related to providing adequate notice to research subjects about their privacy rights and Northeastern’s obligations when handling their personal information. It also applies to both exempt and non-exempt research.
What do you hope this policy does for the research community at Northeastern?
My primary goal in creating this policy was to simplify privacy compliance in the research context. By using the new IRB Consent template that now incorporates this policy, PIs can meet their notice and consent obligations, regardless of where the research subjects are located (except in some limited cases involving the use of AI and automated decision making – contact the Privacy Office if those are in scope).
The policy uses some broad language around “personal information” — financial data, location, online identifiers, and more. Can you walk us through the range of what it’s meant to protect and what the rationale is behind the policy and these global privacy laws?
Unlike the older US federal privacy laws that govern only on specific categories of information (like FERPA for student records and HIPAA for health data), new privacy laws in the US and around the world govern any information that (i) relates to an individual and (ii) identifies or can be used to identify an individual. That is very broad, so our policy has to address that universe of data.
Given the breadth of research at Northeastern – both in terms of the data being used as well as the locations of research subjects and the activities being performed at our global network – it is important to have a policy that enables compliance with the legal requirements that apply to all of the data that falls under the definition of personal information across global jurisdictions. This new policy accomplishes that.
For a researcher working with international participants or data, what’s the good news — how does the policy help smooth that path?
The good news is that no matter where the PI is doing their work or the research subjects are located, using the new IRB Consent template that incorporates the new policy means they are good to go from a notice/consent privacy compliance perspective (with some limited exceptions, as noted above).
When a researcher has a privacy question, what’s the easiest way for them to reach you, and what kinds of things do you love to help with?
PIs can either email me directly at [email protected] or the privacy inbox at [email protected]. Either will get to me. PIs should also review the “Research” tab located on the new Global Privacy Program portal for more detailed information and guidance tailored to privacy in the research context (including a Privacy in Research FAQ).
The favorite part of my job working with researchers is finding creative, straightforward, and low-impact solutions to the challenges that can sometimes be raised by the complex web of global privacy laws.
What’s something about research privacy that researchers are often pleasantly surprised to learn your office can help with?
I find that PIs are often pleasantly surprised how quickly and effectively we can find straightforward solutions that don’t impact their study.
