scieee AI-readable full text Open interactive document viewer

Adding Data Visitation Language to an IRB protocol

Buendia, Patricia; Kim, Seonyoung

Abstract

Adding Data Visitation (DV) language to an IRB protocol requires placing the description within the sections that address data handling, privacy protections, security, and external data access. Although IRB protocol templates vary across institutions (e.g., HRP-503 for biomedical studies, HRP-583 for social/behavioral studies, HRP-593 for drug/device trials), all templates share common core sections where DV language can be incorporated. This document provides adaptable DV language designed to fit the most common IRB protocol sections, regardless of the specific template used.

Full text

DV4RDA Page 1 Adding Data Visitation language to an IRB protocol Template Version: Template Date: 1.1c November 24, 2025 Prepared by: Patricia Buendia, Seonyoung Kim, DV4RDA project of the EOSCFuture/RDA Artificial Intelligence and Data Visitation Working Group (AIDV WG), Research Data Alliance (RDA) DOI: 10.15497/RDA00142 DESCRIPTION Adding Data Visitation (DV) language to an IRB protocol requires placing the description within the sections that address data handling, privacy protections, security, and external data access. Although IRB protocol templates vary across institutions (e.g., HRP-503 for biomedical studies, HRP-583 for social/behavioral studies, HRP-593 for drug/device trials), all templates share common core sections where DV language can be incorporated. This document provides adaptable DV language designed to fit the most common IRB protocol sections, regardless of the specific template used. HOW TO USE THIS DOCUMENT This guidance applies to three categories of research scenarios where DV may be relevant: 1. Single-institution primary studies with mixed access levels 2. Multi-institution primary studies 3. External secondary reuse of sensitive data Depending on the scenario, DV language may appear in different IRB sections. The sections provided below include optional DV paragraphs that can be added or omitted depending on whether DV is used for internal analysis, cross-institution collaboration, or external secondary access. IMPORTANT CONSIDERATIONS FOR THE IRB When inserting DV language into an IRB protocol, ensure that the description is: ●Clear: Avoid overly technical language. IRBs must understand how DV preserves confidentiality. ●Specific: State where the data is stored, who has access to that storage, what system/platform is used for data visitation, how the visiting tools are authorized/controlled, and how outputs are de-identified ● Compliant: Ensure alignment with HIPAA, GDPR, institutional security policies, data-use limitations stated in consent forms DV4RDA Page 2 ●Risk-Aware: DV should be described as a risk-mitigating strategy that reduces data movement, duplication, and unauthorized access. USE CASES DV language benefits IRB protocols in three use cases: 1. Single-Institution Primary Studies with Mixed Access Levels Although many single-institution primary studies grant full data access to all members of the internal research team, this is not always appropriate or permitted. In practice, primary study teams often include individuals in different roles who should not have full visibility into the raw, identifiable dataset. In these situations, Data Visitation (DV) can serve as a secure primary workflow to support role-appropriate analytics while maintaining regulatory and institutional compliance. When DV is Relevant in a Single-Institution Primary Study DV may be used within a single institution when the research team includes members who have limited or restricted access to identifiable data, such as: ●Contractors, external vendors, or software engineers: These individuals may support data processing, platform development, quality control, or analytic pipelines, but are not institutionally authorized to view identifiable data. DV enables them to execute code or perform system-level tasks without exposing raw data outside the secure environment. ●Students, trainees, postdocs, or junior personnel: Some team members may contribute to analysis or exploratory work but are not approved (or do not need) to see the full dataset. DV supports educational or analytical engagement through controlled, privacy-preserving outputs. ●Remote or hybrid workers: For compliance or security reasons, certain institutions restrict the storage or handling of sensitive data on personal or off-site devices. DV eliminates the need to download or transfer data to remote systems by keeping all computation within the secure institutional environment. Benefits of Using DV Within a Single-Institution Study Using DV as an internal workflow can: ● Prevent unnecessary creation of duplicate datasets across devices and storage locations (a common but under-recognized security risk) ● Reduce the need to grant broad access privileges beyond what is justified for each role ● Enhance auditability and compliance with IRB-approved access limitations ● Streamline collaboration by allowing controlled analysis without relocating data DV4RDA Page 3 2. Multi-Institution Primary Studies Multi-institution primary studies involve research teams distributed across two or more organizations, often with different technical infrastructures, security controls, data access policies, and regulatory requirements. In these settings, Data Visitation (DV) can serve as a primary mechanism for secure, coordinated data analysis across institutions without moving or duplicating sensitive datasets. Why DV is Valuable in Multi-Institution Studies When multiple institutions collaborate, it is rarely appropriate for all partners to receive full-access copies of the raw data. Challenges include: ● Data Transfer Restrictions: Sensitive or regulated data (e.g., PHI, genomic data, behavioral data) may not be legally or contractually transferable across institutions due to regulatory requirements. ● Role-based access requirements: Moving data between institutions creates multiple uncontrolled copies, increasing the risk of divergence, corruption, or unauthorized use. ● Heterogeneous security environments: Not all institutions meet the same security standards (e.g., HIPAA, NIST 800-171), making it unsafe to distribute the raw dataset widely. DV addresses these challenges by enabling computation to occur where the data reside, while collaborators interact only with controlled interfaces and approved outputs. Common Scenarios Where DV Supports Multi-Institution Studies DV is particularly effective for: ● Cross-site analysis in consortia, including pooled model training or federated-style workflows ● Collaborators contributing statistical code or models without needing raw data ● External analysts or methodologists who require access to patterns, results, or trends but not identifiers ● Cloud-based or platform-based pipelines where partner institutions have limited access permissions Benefits of Using DV in Multi-Institution Studies DV offers several advantages in inter-institutional collaboration: ● Removes the need to transfer, replicate, or harmonize sensitive data across organizations ● Enforces consistent, centralized security and access controls ● Simplifies compliance with differing or conflicting institutional policies ● Supports reproducibility by ensuring all analyses operate on the same authoritative data source ● Provides audit logs and access controls for cross-institution interactions DV4RDA Page 4 3. External Secondary Reuse of Sensitive Data (DV as an Alternative to DUA) External secondary reuse involves researchers outside the original study team requesting access to data collected during the primary study. Traditionally, these requests are handled through a Data Use Agreement (DUA) that allows the secondary researcher to receive a copy of the dataset. However, DUA-based access often presents significant legal, ethical, and administrative barriers – especially for sensitive or potentially re-identifiable data. DV offers a secure alternative that enables meaningful analysis without transferring raw data outside the originating institution. Why DV Is Valuable for External Secondary Reuse The DUA route can place a high burden on both the originating institution and the requesting researcher due to: ● Legal and contractual constraints: DUAs require multi-level review (legal, compliance, data governance), prolonged negotiation, and assessment of the receiving institution’s security environment. ● Ethical limitations: Participant consent may restrict redistribution of identifiable, genomic, or sensitive data. Transferring a dataset can raise compliance concerns. ● Security risks: Once data leave the original environment, the data owner loses control over storage, downstream sharing, and long term-stewardship. ● Administrative workload and delays: DUA processing is often slow, resource-intensive and inconsistent across institutions. DV avoids these issues by allowing external users to conduct analysis without receiving a physical copy of the data. Common Scenarios Where DV Supports Secondary Reuse DV is particularly effective when external researchers: ● Need access to patterns, aggregate trends, or feasibility-level results ● Analyze highly sensitive data that cannot be redistributed ● Must comply with consent language that limits broad data sharing ● Require exploratory work before a possible formal data transfer ● Do not have an approved secure environment to store sensitive data Benefits of Using DV for Secondary Reuse Using DV as an access pathway offers several advantages: ● No data transfer: eliminates legal and technical review tied to dataset export ● No proliferation of copies: reduces governance, tracking, and compliance burden ● Supports restrictive consent: enables analysis compatible with limited-sharing language ● Greater security: access is auditable, time-limited, and tightly controlled ● Lower administrative barrier: often faster approval compared to DUAs ● Risk reduction: minimizes institutional liability by keeping data in one secure environment DV4RDA Page 5 PLACEMENT OF DV LANGUAGE IN IRB PROTOCOLS Across common IRB templates (HRP-503, HRP-583, HRP-593), the most appropriate sections to include DV language are: ● Data Management and Security ● Privacy and Confidentiality Protections ● Secondary Use, Future Use, or Data Sharing (when present) ● Data Analysis Plan (if DV affects how analysis is performed) ● Informed Consent (if DV affects how participant data move or are protected) Not all studies will require DV language. The IRB language provided in later sections is optional and should be included only when DV meaningfully affects how data are collected, analyzed, shared, or protected. PROPOSED ADDITIONS TO IRB PROTOCOL TEMPLATE The following sections provide optional DV language that can be inserted into an IRB protocol when applicable. 1. Section: Data Collection & Management ● Where to add: Within the description of how data will be collected, stored, and accessed for analysis. ● Standard Protocol Language: Participant data collected for this study, including [specify data types], will be stored securely at [location] in accordance with institutional policies and all applicable regulations. ● Optional DV Language (include only if DV is used): If this study uses Data Visitation (DV) for internal analysis, multi-institution collaboration, or external secondary access, sensitive participant data will remain within the secure computing environment where they are originally stored (e.g., institution-managed secure research servers or an approved data enclave). Access to this environment is restricted to authorized personnel as defined in the IRB-approved study roles. Rather than transferring or downloading raw data, approved analytical code or models are brought to the data’s location using a secure DV platform (e.g., FAIRlyz). All code execution is permission-controlled, logged, and reviewed. Only aggregated, de-identified outputs that meet institutional privacy thresholds and comply with HIPAA, GDPR (if applicable), and participant consent restrictions will be accessible outside the secure environment. No identifiable or individual-level data will be exported, copied, or stored locally by users. DV4RDA Page 6 2. Section: Confidentiality & Privacy ● Where to add: Within the description of how the study protects participant privacy. ● Standard Protocol Language: Protecting participant privacy is essential. Identifiable data will be limited to authorized personnel, and secure storage systems will be used to maintain confidentiality. ● Optional DV Language (include only if DV contributes to privacy protections): The study may use Data Visitation (DV) as a privacy-preserving strategy to prevent unnecessary movement or duplication of identifiable data. Under DV, raw data remain in the secure computing environment, and analyses occur locally within that environment. Only approved aggregate or de-identified results may leave the secure environment. Access to the DV system is logged, monitored, and restricted to authorized individuals. No identifiable data leaves the secure environment at any time. Results are also reviewed to ensure they do not unintentionally reveal information about individuals. 3. Section: Data Analysis Plan ● Where to add: Within the description of analytical methods. ● Optional DV Language (include only if DV affects analysis workflows): If the study uses Data Visitation (DV), analytical code will be executed within the DV platform, which enforces secure, controlled access to the underlying data. Statistical analyses, computational models, or machine learning workflows will run inside the secure environment, ensuring that raw data are never exported or replicated. Only aggregated results or de-identified outputs that meet disclosure control requirements and comply with HIPAA and institutional policies will be returned for study interpretation and reporting. 4. Section: Storage of Data and Specimens ● Where to add: Within the description of where data are stored and how long they are retained. ● Optional DV Language (include only if DV is used): When DV is used, all analysis occurs within the secure storage environment, reducing the creation of duplicate datasets and minimizing the risk of unauthorized access through data transfer. DV4RDA Page 7 5. Section: Secondary Use, Future Use, or External Data Sharing ●Where to add: In the section describing how study data may be shared with external researchers. ●Optional DV Language (recommended for sensitive data): External requests for access to study data may be supported through either (1) a traditional Data Use Agreement (DUA), which permits the transfer of a dataset to an external investigator, or (2) a Data Visitation (DV) pathway that allows external researchers to run approved analyses within a secure environment without receiving raw data. Under the DV approach, the data remain within the institution’s secure environment, and external users receive only aggregate or de-identified results. Before any results are released, the DV system reviews the outputs to ensure they do not contain small cell sizes, identifiable combinations, or other information that could potentially reveal participant identities. Outputs that do not meet the institution’s privacy standards are not released. 6. Section: Participant Notification and Informed Consent ●Where to add: In the section describing how participants will be informed about data handling. ●Optional DV Language (include only when DV affects consent language): Participants may be informed that their identifiable data will remain in a secure environment and will not be transferred outside that environment for analysis. If DV is used, analyses occur only within a secure, access-controlled environment, and only de-identified summaries or aggregate results are shared externally. This approach reduces privacy risks by minimizing data movement and preventing the export of identifiable information. Cite as: P Buendia, S Kim. “Adding Data Visitation language to an IRB protocol.” DV4RDA Project of the EOSC-Future/RDA Artificial Intelligence and Data Visitation Working Group. Research Data Alliance. DOI: 10.15497/RDA00142 November 15, 2025. Acknowledgements This DV4RDA project has received funding through RDA TIGER from the European Union’s Horizon Europe framework programme under grant agreement No. 101094406. Views and opinions expressed are however those of the authors only and do not necessarily reflect those of the European Union or institutions represented here. Neither the European Union nor the institutions can be held responsible for them.