skip to content
 

Purpose of the policy framework

The purpose of this policy framework is to provide guidance to members of the research community at the University of Cambridge by defining their responsibilities in managing the research data they use and material they produce, securely, legally and ethically, throughout the research data lifecycle. This guidance facilitates the continued maintenance and preservation of research data, making them available to the widest possible audience for the highest possible impact, and in support of the University's mission and core values. It is intended to align with the FAIR and CARE principles.

Scope of the policy framework

This policy framework applies to all members of staff and students and research-enabling staff (e.g. professional services, technical) at the University. For simplicity, ‘researchers’ is used throughout this document to refer to all of these. See ‘Definitions’ below for an expanded description. The policy framework is accompanied by a user-friendly Top 10 Research Data Management Actions for the Research Community checklist.

 

Principles
  1. The University’s Open Research Position Statement, ‘promotes and supports open research across all disciplines … to improve discoverability and maximise access to and reuse of knowledge and resources in accordance with our mission to contribute to society through the pursuit of education, learning, and research at the highest international levels of excellence’.
  2. The University is committed to achieving compliance with the data policies of its external research sponsors, publishers and governmental agencies, and requires its research staff and students to abide by terms and conditions agreed with third parties.
  3. As stated in the Open Research Position Statement the University is ‘committed to supporting the freedom of researchers to pursue new knowledge and to choose how and where to publish it. Yet, within that free choice, the University encourages outputs of research to be made as open as possible and only as closed as necessary. The nature of research outputs, and their ownership, varies considerably both by discipline and by research context. Across the disciplinary spectrum there are a wide range of cultural settings that influence both capacity for and appropriateness of open research … Any access restrictions need to be proportionate and justified’. In addition, the University is committed to the principle, and to the promotion of, freedom of speech, as outlined it its Code of Practice on Freedom of Speech.
  4. As a member of Universities UK, the University follows the principles set out in the Concordat on Open Research Data which helps to ensure that the research data gathered and generated by members of the UK research community are made openly available for use by others wherever possible, as consistent with relevant legal, ethical, and disciplinary and regulatory frameworks and norms.
  5. Many of the University’s researchers are funded by UKRI. The University follows the UKRI common principles on research data which outline how UKRI expects research data arising from its funding to be made as open as possible and as restricted as necessary, and expects researchers to follow good research data management practices throughout their project.
  6. Research data storage and preservation have long-term resource implications for sustainability. The University is a signatory of the Concordat for the Environmental Sustainability of Research and Innovation Practice which commits to continue delivering cutting-edge research but in a more environmentally responsible and sustainable way. LEAF (Laboratory Efficiency Assessment Framework) is implemented in laboratories and technical environments across the University: it provides practical, standards-based guidance for reducing the environmental impact of research practices, including data-intensive workflows, storage decisions, and equipment use.
  7. The University is a signatory of the San Francisco Declaration on Research Assessment (DORA) and has committed to following its principles. DORA “calls for the recognition in research assessment of the value of a broad range of research outputs, such as research datasets, software and code”. The principles of DORA align with this policy framework.
  8. The University advocates improved research practices and culture. Effective research data management is synonymous with research quality and transparency, which are pillars of good research practice.
  9. The University recognises digital preservation as a core component of research data management through its CUL Digital Preservation Policy. Digital preservation involves the active and ongoing management of digital data throughout the research data lifecycle, to ensure their continued access, usability, authenticity and integrity over time, beyond the lifespan of the systems in which they were created.
Responsibilities of the University

The University is responsible for:

  1. Disseminating information to its research staff and students about the requirements under this policy framework and under funder open data policies in relation to research data.
  2. Developing and supporting infrastructure and services that enable research data management (RDM) to be practiced across the institution and to support long-term data preservation. This includes, but is not limited to, infrastructure such as active data storage options, the University Apollo repository, research information systems, and services such as Open Research, University of Cambridge Libraries and Archives including Digital Preservation, University Information Services (UIS), Research Office, Research Integrity, Research Ethics, and Cambridge Enterprise. Considering consultation with technical staff that have expertise in data storage systems, instrument data pipelines, and lab workflows when planning and implementing research data infrastructure.
  3. Providing a dedicated advisory service (info@data.cam.ac.uk helpdesk and free consultancy) for all University researchers. The Research Data Management service can advise on managing research data across the research data lifecycle and all disciplines, in line with good practice and University and funder expectations where applicable. This includes advice on related issues such as data protection, data security, research ethics and integrity, copyright and intellectual property rights.
  4. Providing a Data Management Plan review service where the Research Data team reviews draft plans on request and gives feedback on any missing or unclear information, suggests improvements, and checks that the plan meets funder and other relevant policies.
  5. Managing websites (Open Research and Research Data Management) providing guidance for the University’s research staff and students in good data management practice.
  6. Providing training to promote best practice in RDM.
Responsibilities of researchers

Researchers are responsible for:

Planning

  1. Reading, understanding and complying with the terms of their research funding as specified in funder open data policies.
  2. For Principal Investigators, establishing and maintaining clear RDM responsibilities within their research group to ensure good practice throughout the project and by all group members, including technical staff, to a level appropriate to the demands and nuances of the research discipline.
  3. Preparing a Data Management Plan (DMP) at the start of a research project (whether as a research group or individual) – this is good practice but also usually a funder requirement (researchers should check their funder’s open data policy).
    1. The DMP should be updated at project close to record how data have been managed and, where appropriate, published. This is good practice for all projects.
    2. Guidance on writing DMPs is provided by the University of Cambridge. The free DMPOnline tool is available for free to support writing DMPs using funder templates.
    3. DMPs may be published in an appropriate repository (anonymised to protect confidentiality if necessary) at the end of the research project so that others can benefit when writing their own. This makes it possible for funders and the public to see how the data supporting research were managed. Guidance on choosing a suitable repository is available from the University of Cambridge.
  4. Ensuring that ethical constraints on release of research data are considered at the initiation of the research process and throughout both the research and data life cycles. This may involve obtaining ethical approval for the research they plan to do and obtaining informed consent to match the intended use or publication of the data. 
  5. Ensuring that wherever it is an eligible cost, appropriate funds must be fully costed in research applications to meet all data management requirements for the entire project lifecycle and retention period, including data storage, archival, publication, and staff time (such as technicians or data managers). Not all research data can or should be retained indefinitely, and appraisal and selection decisions should consider research value, legal and regulatory requirements, and sustainability. Long-term preservation has ongoing costs, therefore retention decisions should be proportionate and justified.
  6. Considering the security of their research against potential threats. Legal and contractual constraints on the release of data should be considered throughout both the research and data life cycles. As stated in the Good Research Practice guidelines, ensuring “regulatory and compliance issues relating to their research projects are identified and managed. All appropriate licences, permissions and approvals must be in place before research starts.”. There are a range of regulatory requirements that apply to research that are designed to minimize the risk that research will be misused for harmful purposes, support national security, and control the export of dual-use or military technology. Researchers should ensure that they are aware of the compliance requirements that apply to their work and seek advice when unsure.
  7. Carrying out due diligence checks on new funders and partner organisations to identify any issues that may pose a risk to the University and undermine their research. This covers the legal status of an organisation, where it is based, the nature of its business and governance, any exposure to sanctions and any negative news or other concerns.
  8. For research projects that have commercial potential, agreeing on intellectual property implications from the outset and ensuring these are made in alignment with institutional agreements, with legal advice where appropriate.

Active Data Management

  1. Collecting research data using software as appropriate for the classification level for the data, especially sensitive data.
  2. Complying with any legal, ethical, contractual and policy constraints pertaining to how data are stored, published and retained, and applying for an ethics amendment before deviating from these constraints if necessary.
  3. Storing data (where it will be backed-up) in an appropriate location, preferably using University-provided storage solutions, following the Guidelines on University data security classifications, and assessing potential risks to data based on the impact that compromise of these data would have.
  4. Backing-up data regularly to ensure they are protected and recoverable. It is important to understand the back-up procedures for any active data storage platform being used (e.g. if location is appropriate for the data security risk level, whether servers are mirrored, frequency of back-up, how long data are available for before final deletion, how or if data can be recovered).
  5. Understanding that data storage, backup, and security methods utilised for active data management do not in themselves constitute long-term preservation. Additional workflows and infrastructure are required for long-term retention (see ‘Publishing and preserving data’.)
  6. Ensuring the proper management of physical data (and associated metadata) such as  samples, materials, or calibration records, as well as digital data in line with departmental or faculty rules, and funder and government requirements. Storage of physical data or samples obtained from human participants should be managed in line with the participant’s informed consent. This may require research ethics approval to be sought at the project planning stage.
  7. Following University Data security for researchers guidance when collaborating with international researchers, when travelling with or sharing data, including outside of the UK where export control may apply.
  8. Being aware of and complying with any contractual obligations under collaboration agreements and other relevant research contracts such as data access or material transfers.
  9. Being aware of their obligations and potential liability when handling data that impact Indigenous Peoples, nations and communities, as described by the CARE principles.
  10. Being aware of their obligations and potential liability when handling data protected by the UK General Data Protection Regulation, the Data Protection Act 2018, and any other applicable data protection legislation.
  11. Following University data protection Data Protection Policy, University Research Ethics Policy, and completing mandatory online data protection training.
  12. Documenting and outlining responsibilities for the data being generated through the research project. Funder terms and research contract terms may impact on data ownership and rights to use. It is necessary to clarify who has access rights to use the data, and for what purpose; specifically, what rights the University or the individual researcher has, and other institutions that may have rights to access or use the data. Documentation allows for assessment of what data can or should be deleted, retained or transferred to others on completion of the project. This information should be handed over before staff leave a project or an institution and could be documented in a DMP.
  13. Using electronic research notebooks (ERNs) where possible. These are more robust and secure than paper notebooks and have extra features which allow for collaboration and searching and integration with other research systems. Many ERNs are available and it is important to consult staff with relevant data expertise such as technicians when implementing an ERN.
  14. Complying with University cyber security awareness and training guidance and completing mandatory annual cyber security awareness training.
  15. Following University Freedom of Information guidance and acting according to this guidance where applicable.
  16. Complying with any requirements from the University, research funders, or publishers when using Generative AI as a tool when undertaking or disseminating research, or when applying for funding, or in the assessment of research. The use of Generative AI tools has implications for sensitive data (e.g. personal, confidential), data ownership, copyright, intellectual property, research ethics and integrity, information security, and environmental sustainability, including when reusing research data created utilising them. At present there is no distinct University policy for using Generative AI tools in research. Since this is a fast-paced area of change in research practice, this policy framework will be regularly reviewed and updated considering significant developments in Generative AI.
  17. Reviewing and revising the DMP throughout the research project.

Publishing and preserving data

  1. Making their research data underpinning published research findings as widely and openly available as possible, ideally by depositing them in appropriate repositories (funder-specified, discipline-based, institutional, or generic – in that order of preference). Such data should be assigned persistent Uniform Resource Identifiers (URIs), such as Digital Object Identifiers (DOIs) to increase their findability in accordance with the FAIR principles.
  2. Providing a full citation including a persistent identifier e.g. DOI to any published research output as part of a data access/availability/sharing statement in their published works; indicating where the underlying/supporting evidence is located, which licence has been assigned indicating what is permitted or prohibited, any access restrictions that apply and how a request for access may be submitted, if applicable. Supporting data should be accessible online no later than the first online publication of the article.
  3. Ensuring that published research data have appropriate metadata description.
  4. Ensuring that research data records are retained in appropriate repositories for as long as the data are valuable to the data creator or to others, or for as long as is required by the funder or the University, or under relevant research contracts, or by the law or other regulatory requirements.
    1. If data are not published, ensuring they are kept safely in line with funder retention policies and ensure the data can be produced to demonstrate research integrity if needed. Research records that do not fall under the category of research data should be handled in line with funder policies and the Statement of Records Management Practice and Master Records Retention Schedule (Section 4). Where records are no longer required for research or funder or other regulatory requirements, they can be referred to the University Archives for consideration to be added to the collections, for use by other researchers in the future.
  5. Maintaining awareness of their funder’s terms and policies relating to open data and always acting in accordance with funder expectations and any regulatory bodies. Where funder terms and conditions require the exploitation of results, these requirements may influence the selection of licences for research outputs, including data. Cambridge Enterprise can advise.
  6. Registering for an ORCID to unambiguously indicate the authorship of research data, software or code. This helps authors to record and report their research output; it can be used in publications, grant applications, and in the institutional repository, Apollo.
  7. When depositing research data into external data repositories, choosing ‘trusted’ e.g. CoreTrustSeal certified repositories. These support ORCID, funder IDs and grant IDs and provide reliable, long-term access to managed digital resources.
  8. Storing publicly-funded research data that is not generated in a digital format in a manner to facilitate it being preserved and reused.
  9. Upholding the University principles in rigorous, reproducible research that is persistently available by using, wherever possible, non-proprietary, open formats for files, or file types, to align with FAIR principles.
  10. Providing transparency around each author’s contribution to a work in accordance with the University’s authorship guidance or CRediT (Contributor Role Taxonomy), and attributing others’ contributions to the research in acknowledgement statements (fair attribution).
  11. As detailed in the University’s Open Research Position Statement, working with the University’s professional services to determine the most appropriate approach when considering publishing sensitive data:
    1. Personal sensitive data (qualitative or quantitative) may need to be restricted. It may be necessary to determine whether it should remain closed or on limited access, or otherwise anonymised or pseudonymised. University Ethics Policies should be followed if working with human participants or personal data, or animals. Informed consent must be obtained for collection, reuse and publishing of anonymised or pseudonymised data.
    2. Environmentally or culturally sensitive data may also need to be restricted.
    3. Commercially sensitive data may need to be restricted.
Support and guidance

Specific guidance is available on the University’s Open Research and Research Data Management websites. These are managed by University of Cambridge Libraries and Archives.

Additional support for researchers is available from Data Champions embedded in faculties and departments, and the Research Information site (University login required).

For urgent support in the event of a data breach or a data or cyber security incident, please refer to the Data security web page.

AI (Artificial Intelligence)

It is recommended that research staff and students consult University Information Services (UIS) for technical guidance in the first instance.

  • UIS provides guidance on the use of CoPilot, Microsoft’s AI assistant that aims to provide personalised help for a range of tasks, including information on CoPilot’s data, privacy, and security at the University.
  • UIS provides guidance on the use of the AI assistants Google Gemini and NotebookLM at the University via its Google Workspace for Education licence. Technical support and training are available.
  • Information Compliance has Guidance for University of Cambridge Staff on the Administrative Use of Generative AI which includes useful facts for CoPilot, Gemini and NotebookLM and further reading on best practice with use of GenAI.
  • To aid research commercialisation Cambridge Enterprise can provide specialist advice for due diligence on AI derived innovations and data.
  • C2D3 (Cambridge Centre for Data-Driven Discovery) offers support for research proposals and projects involving AI.
  • ai@cam supports interdisciplinary AI research and innovation at the University.

Contracts

University Contracts team manages research collaboration or consortium agreements, confidential or non-disclosure agreements, contract amendments, data and material transfer agreements. It has contacts for each School.

Data protection (see also Sensitive data, ethics)

Information Compliance has information about Data protection and Freedom of Information.

Online data protection training is available.

Data retention

University Statement of Records Management Practice and Master Records Retention Schedule (Section 4) includes official University guidance on research data retention.

The Research Data Management service provides guidance on Preservation and Archiving.

Data and cyber security

University Information Services (UIS) gives practical guidance on:

Data storage and classification

University Information Services (UIS) provides University-provided storage solutions and has Guidelines on University data security classifications.

Digital preservation

CUL Digital Preservation has guidance on Preservation and Archiving research. Supports researchers with issues such as digital preservation strategy, files and formats, and workflow advice; some complex or at-risk formats may require specialist support.

Fair attribution

The Technician Commitment Network delivers events and training on fair attribution and publishing.

Freedom of Information

Information Compliance has information about Data Protection and Freedom of Information.

Freedom of speech

The University’s Governance and Compliance Division supports University governance processes including data and information compliance, and freedom of speech.

Intellectual Property (IP)

Cambridge Enterprise has a Guidance note from the Research Office and Cambridge Enterprise IP Policy in practice – how it works, who to approach and when?

Reproducibility

Reproducible Research Cambridge (RRCam) is the institutional node of the national UK Reproducibility Network (UKRN). RRCam is dedicated to advancing research reproducibility across all disciplines through provision of institutional support and skills provision for reproducible research practices, with the ultimate aim of improving the quality of research data and software. It provides training and support to researchers with a particular focus on reproducible data and software skills.

Research commercialisation

Cambridge Enterprise assists researchers to conduct due diligence on data sources, determine authorship and ownership, and apply appropriate licensing.

Research data management

Research Data Management service, Open Research provides the following:

Research integrity

Risk management

Research Services provides Manage risk guidance which covers audits, conflicts of interest contracts, due diligence, export control, Foreign Talent Recruitment Programs (FRTPs), Foreign Influence Registration Scheme (FIRS), Nagoya Protocol, NSI (National Security and Investment) Act, personal data, research ethics, security-sensitive research material, trusted research, and Worktribe risk assessment.

Secure software and platforms

Cambridge Integrated Data Environment (CAM:IDE) gives advice on recommended software tools and platforms including:

  • REDCap, a secure web application for building and managing online surveys and databases. 
  • XNAT is an open-source imaging informatics platform can be used to support a wide range of imaging-based projects. 

Identifiable and/or sensitive data should be collected and analysed on an ISO27001-certified safe haven such as the University’s Secure Research Computing Platform

Cambridge Service for Data-Driven Discovery (CSD3) offers a service for computationally intensive researchers.

UIS offers free and discounted software for students and staff at the University, including anti-virus software, file management software, software for audio and video recording, reference managers, and data and statistics software, that often have AI features.

Sensitive data, ethics

Research Data Management service, Open Research provides Sensitive Data Guidance and training (personal and culturally, environmentally, commercially sensitive data).

There is guidance on Academic research involving personal data.

Research ethics training is also available and researchers can get advice from their relevant Research Ethics Committee.

Clinical School Research Governance can also give advice in relation to human data.

Information Compliance has Guidance for University of Cambridge Staff on the Administrative Use of Generative AI.

Sustainable research

Environmental Sustainability outlines its commitments, approach and progress in becoming an environmentally sustainable University.

The Environmental Sustainability of Research and Innovation Practice document contains guidance for researchers wishing to adopt or promote sustainable research practices aligned with the University’s commitment to the Concordat for the Environmental Sustainability of Research and Innovation Practice. It includes guidance on the considerations for the sustainability of research outputs such as data.

Training

Cambridge Digital Humanities (CDH) organises Data Schools and delivers a Methods Programme.

CaRM (Cambridge Research Methods) is an interdisciplinary programme providing research methods training. Courses cover qualitative and quantitative research methods, from basic training to advanced statistical analysis.​

Research Services offers Export Control training through the Higher Education Export Control Association's training programme.

Open Research delivers a Research skills training programme.

Research Informatics Training organises courses in data science, applied statistics, bioinformatics and machine learning.

University Information Services Training includes Cyber security awareness and training and Online data protection training.

Definitions

Research data – the evidence that underpins research findings which can be used to validate findings regardless of its form (e.g. print, digital, or physical). These might be quantitative information or qualitative statements collected by research staff, students or those supporting research in the course of their work by experimentation, observation, modelling, interview or other methods, or information derived from existing evidence. Data may be raw or primary (e.g. direct from measurement or collection) or derived from primary data for subsequent analysis or interpretation (e.g. cleaned up or as an extract from a larger data set) or derived from existing sources where the rights may be held by others.  Data may include for example statistics, digital images, sound recordings, interview transcripts, survey and field data observations, artwork, artefacts, published texts, software, code, or methods/protocols. However, some disciplines may not use the term ‘data’ or understand what this means for their discipline – ‘data’ can refer to the materials or documentation or methods involved in a project. (Source: UK Concordat on Open Research Data).

Research data management (RDM) - the decisions made and actions taken to manage research data across the research data lifecycle. The research data lifecycle covers the four phases of a research project: planning and preparing - actively researching – archiving, preserving and curating - discovery, access and sharing,

Manual research records – manual research records are any non-electronic documents and materials, regardless of format, which facilitate the research activities carried out by the University. This can include both the data underpinning research as well as records relating to research quality, standards and governance; research project development and management; and research commercialisation. See section 4 of the Statement of Records Management Practice and Master Records Retention Schedule for details of the specific kinds of records which fall under these categories along with their respective retention periods.

Researchers – this refers to the research community at the University that includes all members of staff and students involved in research within the course of their employment and/or studies, regardless of where that research is taking place, either in direct employment of the University or under formal agreement with the University in another capacity.

Active data – “Research data files that are in the process of continuous change and/or development. Files containing this data are accessed, amended and/or updated as new data is gathered and/or processed. Some datasets may never be ‘finished’. A ‘snapshot’ of active research data can be archived to create a version that is fixed and can be cited.” (Source: Cambridge University Libraries Digital Preservation Policy).

Data Management Plan (DMP) – a plan that documents how data will be managed throughout the research data lifecycle. Typically, a DMP will cover how data is collected, stored, used, reused, accessed and retained, considering ethical or legal requirements as appropriate.

Metadata – information that describes significant aspects of a dataset. For example, this may include authors, title, date of publication, unique identifier, a description of what the dataset contains and licence. This provides other researchers with the information needed to understand and reuse the dataset as well as making the dataset more findable.

Research data lifecycle – this describes the different stages of the research process, typically covering planning and preparation; active research, archiving, curating and preserving; discovery, access and publishing.

Digital preservation – refers to “the series of managed activities necessary to ensure continued access to digital materials for as long as necessary” (Source: Digital Preservation Handbook Glossary). 

Version

Version: 4

Date of policy review: 25 June 2026

Name of reviewer: Clair Castle, Research Data Manager, Open Research

Original policy creation date: 23 April 2015

Name of creator: Open Research Steering Committee

Date for next review: 25 June 2028

Frequency of reviews: Every two years.

Review is the responsibility of: Head of Open Research Services.

Location of policy: https://www.openresearch.cam.ac.uk/cambridge/policies-frameworks/rdm-policy-framework

Persistent identifier: https://doi.org/10.17863/CAM.10528.4