Four Resources to Strengthen Stewardship of Research Data

Why this matters for IRB review

Every protocol submitted to the IRB includes a data plan: where data will be stored, how it will be secured, whether and when identifiers are removed, and who will have access. The IRB reviews that plan and approves the study on the basis of how well the plan will protect the privacy and confidentiality of the participants. There are other institutional requirements at Northeastern that you also need to comply with. These requirements are spread across multiple offices, but these offices have worked together to create guidance, as described below by Amanda Humphrey in the Summer 2026 issue of the NU-RESearch Quarterly.


Four Resources to Strengthen Stewardship of Research Data

By Amanda Humphrey. Originally published in the NU-RESearch Quarterly, Summer 2026.

There are many offices involved in protecting and stewarding research data, including NU-RES (all functions from pre-award to DHR and Research Compliance), the OGC’s Privacy Office, Office of Information Security, and Research Computing, to name a few. As a global network of campuses, Northeastern not only has to manage privacy regulations related to many countries, but also multiple sets of regulations governing the sharing or research data, which are increasing research compliance complexity for faculty and staff alike.

No single office can support these requirements alone, which can make it hard for the community to understand who to interface with and when. So we have been working together to identify opportunities to reduce burden while helping researchers ensure that they are meeting their ethical and legal obligations as stewards of research data. The resources outlined here represent efforts to both reduce burden and enhance compliance within the research ecosystem at Northeastern across the global campus network.

Research Data Classification Guidelines:

While the university has had robust university data guidelines for several years, we have received more than a few requests for research-specific classifications. In response, NU-RES, the Privacy Office, OIS, and Research Computing have created research data classification guidelines available here to address research-specific classification needs. The research data classification guidelines include lock levels, as well as recommended storage locations.

Privacy Office Guidance:

The Privacy Office also expanded its offerings to the research community through a new Global Privacy Program share point that includes valuable resources targeted at research such as process guidance on de-identification and FAQs on privacy in research. Whether you need information on the differences between anonymized and de-identified data or how the DOJ’s Bulk Data Rule may impact your project, this resource will help.

HIPAA Compliant REDCap Instance:

As of late July, Northeastern researchers have a new resource: an internal HIPAA compliant instance of REDCap. Researchers will need to request access to this environment through ServiceNow for themselves and all team members that require access to the data.

Streamlining Research Data Review:

OIS, Research Computing, Research Compliance, and the Privacy Team are piloting a new research data security and privacy review form (feel free to try it out). This form provides faculty with logic-based questions designed to streamline the consultation processes for data classification, storage, and regulatory obligations. More updates will be coming.