#  Data Use Agreements 

 



 ##  

  expand\_more  

 
  

 

##  Data and Data Use Agreements (DUAs) 

A Data Use Agreement (DUA) is a contract that governs the terms and conditions around the transfer of data into or out of Harvard. DUAs are commonly used when researchers, institutions, or companies wish to share data, especially if the data contains sensitive, confidential, or protected information (such as personally identifiable information).

The project PI is responsible for ensuring that any future approved access is compliant with a DUA, including updating the data provider before approving access, if required. A researcher cannot sign a DUA on behalf of Harvard; the signature must come from HU-OSP, regardless of funding considerations. Prior to review, negotiation, and signature, the officer assigned to a specific DUA will require evidence of IRB protocol review, level of security, and IT approved protections for the data. The fully executed DUA is sent to the sponsoring data provider by HU-OSP.

[Full University guidance about how DUAs are processed at Harvard](https://researchsupport.harvard.edu/data-use-agreements-and-data-safety-protection-support)

[Research Data Management Website](https://research.harvard.edu/research-policies-compliance/research-data-management/)



 

  Open all sections   Close all sections  



###    DUA Request System  expand\_more  

The University has an [Agreements System](https://dua.harvard.edu/) designed to give researchers an efficient way to route legal agreements like DUAs. The system provides transparency into the review/negotiation process and improved compliance for handling these agreements University-wide. Researchers may initiate the DUA process directly in the system, though students should first discuss any possible DUAs with their mentors or relevant faculty members. The system should be utilized for all actions related to the submission, review, and management of DUAs, including:

- requesting the drafting of new DUA;
- requesting the review of a DUA received from another entity;
- corresponding with the DUA reviewer (normally an HU-OSP negotiator);
- tracking the status of the review and eventual approval of the DUA, which includes visibility into local IT review of the DUA’s data security requirements; and
- managing active DUAs (including extension requests).

If you have any questions or need help navigating the system, please contact either your HGSE OSP representative or <duahelp@harvard.edu>.

 

 



###    Data Security Levels  expand\_more  

If you are collecting or using data from humans or animals, you should first contact [Harvard’s Institutional Review Board (IRB) and/or Institutional Animal Care and Use Committee (IACUC)](https://cuhs.harvard.edu/).

**Committee on the Use of Human Subjects**  
As part of its review responsibilities, the CUHS (aka IRB) determines the level of security required for any given protocol. Often, the CUHS reviews the draft DUA from the entity supplying the data for any indications that the data may require specific protections. The level of security determined by CUHS informs the data security that IT will recommend for your project; once the level of security is determined, the next step is to work with HGSE-IT to develop the correct data security plan.

**IT and Data Security**  
Research and Infrastructure Technology serves the HGSE research community from study design through dissemination via:

- Hosted solutions for data and applications, secure file sharing &amp; data storage, website development and hosting;
- Technical consultations for all research technology needs, such as capacity planning, networking, hosting options;
- Methods and software support for quantitative and qualitative analysis, including consultations and workshops for Stata, Mplus, R, Atlas.ti and NVivo;
- Security consultations and risk assessment services for staff, faculty, and researchers managing potentially sensitive or confidential data
- Review of physical, technical, and administrative data management plans to ensure regulatory compliance and adherence to Harvard’s data security policies.

Visit [HGSE IT Research Security](https://its.gse.harvard.edu/services/security/research) page for further information.

 

 



 

 

 

 

##  Helpful Links 

- [Harvard Research Data Security Policy site](https://vpr.harvard.edu/pages/harvard-research-data-security-policy)
- [Applications Summary and Order of Reviews](https://research.harvard.edu/files/2022/10/Summary-of-HRDSP-Applications-with-Order-of-Reviews_07.01.2020_2021.pdf)
- [Agreements - DUA Submission Guide](https://ras.fss.harvard.edu/files/ras/files/dua_agreement_submission_guide.pdf)
- [Research Data Management Website](https://research.harvard.edu/research-policies-compliance/research-data-management/)
- [Agreements System](https://ras.fss.harvard.edu/agreements)