Skip to content

Commit cefacab

Browse files
Update data_management_policies.md
Added a bullet point list of key data management points that SSI staff should be aware of.
1 parent 6b1853b commit cefacab

File tree

1 file changed

+18
-0
lines changed

1 file changed

+18
-0
lines changed

ssi-handbook/data_management_policies.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,3 +31,21 @@ Non-sensitive data will be stored in Google Drive and GitHub, with backups at Ed
3131
Long-term data preservation is ensured through repositories like Zenodo, with metadata and documentation facilitating reuse. Data security measures include compliance with ISO 27001 standards, encryption protocols, and controlled access. Sharing will be facilitated under open licenses (CC BY for data, BSD 3-clause for software), with some restrictions for personal, proprietary, or confidential data. Exclusive use periods for project data will be clearly defined before transitioning to broader access.
3232

3333
Governance of data access ensures compliance with ethical, contractual, and regulatory obligations, including anonymisation strategies where necessary. The Principal Investigator, Neil Chue Hong, oversees data management, with operational responsibilities delegated within the team. Policies from the University of Edinburgh govern data security, protection, and sharing. The DMP emphasises transparency, responsible data use, and long-term sustainability of research outputs.
34+
35+
## Data storage - key points
36+
37+
The above text sets out the data management plan for SSI-4. The following bullet points are key points for SSI staff to be aware of:
38+
39+
- **Google Drive must *never* be used for any sensitive data.** This includes (but is not limited to) email addresses, dietary requirements, and accessibility information. This is the responsibility of *all* SSI staff.
40+
41+
- **Sensitive data must not be downloaded to personal devices** (including laptops, phones, USB sticks, or local drives) and, if shared, must be shared securely using approved methods only.
42+
43+
- **All sensitive data must be stored on OneDrive** and access must be restricted to individuals who need the data to carry out their role.
44+
45+
- **Sensitive data should be retained only for as long as necessary** and securely deleted in line with the retention schedule outlined at the point of collection.
46+
47+
- **In the case of a potential or suspected data breach**, SSI staff should:
48+
- Email **Neil** and the **PMO** immediately for advice.
49+
- **Report the incident to the University of Edinburgh** by emailing **[email protected]** with **“breach”** in the subject line.
50+
51+
- **All SSI staff have access to data security training** through their home institutions and must ensure that their training is up to date.

0 commit comments

Comments
 (0)