University and legal requirements

Research data management is a requirement for researchers at the University of Sheffield, as well as a condition of many funders and publishers. There are also legal requirements with which you should comply when using, creating and sharing research data.

University policy

The University of Sheffield maintains a Research Data Management Policy as part of its Good Research & Innovation Practices (GRIP) Policy. The key points are:

  • All researchers (staff and students) are responsible for looking after the data they collect and analyse, and overall responsibility lies with the lead researcher or supervisor
  • All research proposals should have a data management plan
  • Unless otherwise specified by a contract or the terms of a grant, data generated by research projects are the property of the University of Sheffield

You should also refer to the University’s Records Retention Schedule when deciding which data to retain and dispose of.

Strategic leadership for the University’s Research Data Management Policy is provided by the Open Access Advisory Group.

Legal requirements

Intellectual property

Rights to intellectual property (IP) created by University employees are generally owned by the University. When creating data, however, you must consider the IP rights of all stakeholders involved, including research partners, collaborators and funders. For further information, see Research Services (Impact and IP).

Copyright

When using existing data sources, you should always check who owns the copyright and the conditions under which you can reuse the data. For further information, see The Copyright Hub.

Data licensing

All published research data should be licensed to show what users may or may not do with it. Licences, or waivers, are granted by the IPR holder, who should be established from the outset of the project. Data repositories indicate which licences can be used for deposited data, from Creative Commons to more restrictive ones which may require permission for reuse.

For further information, see How to License Research Data (DCC).

Ethics approval and consent

It may not be possible to share, or even collect, personal or sensitive data unless specific consent is obtained from participants. It may, however, be possible to anonymise some data in order to make it available. The University provides detailed guidelines relating to this area of research integrity and ethics.

GDPR and data protection

The General Data Protection Regulation (GDPR) gives individuals the right to know what information is held about them, while ensuring this information is handled properly. Researchers must adhere to data protection requirements when sharing or managing research data. For further information, see GDPR and data protection, and also the University's Information Classification Scheme, which outlines potential data protection risks.

Freedom of Information (FOI)

As the University is a publicly funded organisation, any recorded information held, including research data, may be subject to FOI requests for access. If you object to the release of your data, for example on the grounds of confidentiality, you should contact the FOI Unit.

Commercial confidentiality

Data obtained from a commercial partner, or licensed from a provider, may be subject to a confidentiality or collaboration agreement. This may prevent data sharing or place restrictions on how data may be used. You should be aware if this is the case, but check with your supervisor if in doubt, or contact Research Services.

For further information, please contact rdm@sheffield.ac.uk