Handling and Storing Personal Data

How should researchers handle and store personal data?

 In accordance with Singapore’s PDPA, HBRA, and NTU’s DGP and IRB-SOP for Handling and Protecting of Personal Data, researchers must safeguard research participants’ personal data against loss, and unauthorised access, use, or disclosure.

 This includes (but not limited to) the below:

  1.  Anonymise datasets  [Refer to:  Ways to anonymise data.]
  • Minimise the use of datasets containing direct identifiers.
  • Use coded identifiers for datasets undergoing analysis wherever feasible. (e.g. P001, P002, etc)
  • Store the master file containing identifiers and data linkages separately from de-identified datasets, with appropriate safeguards.
  • Apply anonymisation techniques wherever possible so that individuals cannot be readily identified by any party accessing the data.
  1. Access controls

A) Restrict access (need-to-know basis)

  • Limit access to individually identifiable data to authorised study team members only, as determined by the PI.

B) Secure storage of data

  • Store electronic files in access-controlled folders or devices within NTU-approved storage systems in accordance with NTU Data Governance Policy.
  • Keep hardcopy documents in locked cabinets within access-controlled rooms or offices. 

C) Protection for identifiers

  • Encrypt re-identification keys (linkage files) and source documents containing personal data.
  • Store these separately in access-controlled folders or devices on NTU-approved storage systems in accordance with NTU Data Governance Policy.

 [Note: Confidential documents containing identifiers should not be stored on any non-NTU approved cloud servers.] 

The above are in line with guidance from PDPC.