HomeNewsletterData security
The data security plan at GCU: identifiers, code lists, access, and the destruction date
There is no single form at Grand Canyon University titled data security plan. There is something more demanding: the same questions, asked in the application and again in the privacy block of the consent template, whose answers a reviewer reads side by side. Together they have to describe one system — what identifies a person, who can link a code back to a name, where that link lives, who may open it, and the date on which it stops existing. Files rarely fail here because the safeguards are weak. They fail because the file tells the story three different ways.
The short answer
Describe one system: which identifiers exist, whether responses can be linked back, how any code list is made and secured, where electronic and paper materials live, who may reach them, how long they are held, and the date of destruction — identically everywhere.
What is the board actually checking?
Federal approval criteria — 45 CFR 46.111 — require a board to satisfy itself, where the design calls for it, that privacy is protected and data kept confidential by "adequate provisions". Two words there carry the weight. Adequate is measured against your design rather than against perfection: anonymous survey responses about workplace software oblige far less than interviews with clinicians about errors they witnessed. Provisions means arrangements a reader can follow — a described mechanism, never a promise of care.
GCU's application and consent template break that finding into questions with only one honest answer each. This is why the practical work is arithmetic rather than rhetoric. Every place identifiers appear in your file, they must appear the same way.
Confidentiality or anonymity — which is your study?
GCU publishes guidance on this distinction precisely because everyday speech treats the two words as interchangeable and research does not. Confidentiality means you know who your participants are — you interviewed them, you convened the focus group, you needed a name to route a questionnaire — and you undertake to keep that knowledge protected. Anonymity means no identifier exists that could link a response to a person at all: the survey platform is configured not to capture network addresses or contact details, and no code list is created, because there is nothing to code.
The consequences run through the whole file. Qualitative designs are almost always confidential rather than anonymous, so the answer to whether responses can be linked back is yes, and the rest of the privacy block has to explain how that link is protected. GCU also notes that a single study can hold both — an anonymous questionnaire alongside confidential interviews — in which case the consent document has to make the boundary explicit rather than average the two into one vague paragraph.
Then there is the risk that survives de-identification. GCU's guidance names deductive disclosure directly: in a small region, a single school, a modest department, a participant can be recognised from a description even with the name removed. The response is editorial as much as technical — report in aggregate, use pseudonyms and codes, avoid detail combinations that identify by triangulation, and consider whether the organisation itself should be named at all. GCU suggests agreeing that point with the site, and recording it in the authorization letter where it matters.
What must the plan answer, question by question?
The privacy block of GCU's current consent template is the most useful checklist in the file, because each prompt is a question a reviewer will read your application against.
- Can responses ever be linked back to the person? Yes or no, then the mechanism.
- Will the initial data contain identifiers? Names, addresses, contact details, recordings, demographic combinations — recordings count, and so do the specific demographics that make one participant unique.
- Will you assign research ID codes? For interviews and focus groups the answer is yes, which means a link exists between codes and names.
- How is that link created, secured, and for how long? Who holds it, where it sits, who may open it, and — GCU asks for this explicitly — an approximate destruction date written as a date.
- Where do electronic and paper materials live? Recordings, transcripts, completed instruments, signed consent documents, demographic files: each named, each with a location, each with the protection that location provides.
- Is any artificial intelligence tool involved? GCU's template asks candidates to say so, and to confirm that only de-identified data is exchanged with it. A transcription or analysis service is a third party like any other.
- Who may reach the protected data? The template carries a required statement that the researcher, the chair, committee members and College of Doctoral Studies reviewers may view the data as part of the review process. It is not editable, because those reviewers must be able to verify what the manuscript claims.
- Which third-party platforms are involved, and under what policies? Survey tools, conferencing platforms, transcription services and analysis tools are named, with their privacy policies linked.
- Where are signed consent documents kept? Separately from the data, so that the one page carrying a signature is not stapled — physically or in a folder structure — to the responses it would identify.
Retention has a floor rather than a ceiling: GCU's template states a minimum period for which protected data is kept and asks that the destruction date be given as an actual date rather than as a phase of the study. Where those numbers sit today is set by GCU's current doctoral handbook or IRB portal, and they are worth re-reading each time a file is built.
| The question | A usable answer | The classic failure |
|---|---|---|
| Linkability | Yes — interviews are coded, and one list maps codes to names | "Anonymous" claimed for a design that records who spoke |
| The code list | Named holder, named location, named access, dated destruction | Codes described in the application, list never mentioned again |
| Storage | Each material type with its own protected location | Recordings unaccounted for while transcripts are covered |
| Access | Researcher, chair, committee, reviewers — plus signed agreements for any helper | A transcriptionist appears in the procedures with no agreement filed |
What changes when health or education records are involved?
Two regimes sit on top of the Common Rule, and each one changes the paperwork rather than merely the tone.
Health information is governed by the HIPAA Privacy Rule. Properly de-identified information may be used for research without individual authorization, and 45 CFR 164.514 offers two ways there: a qualified expert documents that the chance of re-identification is remote, or the listed identifier categories are stripped under the safe-harbor route, with no actual knowledge that the remainder could still point at someone. Short of de-identification, a covered entity may hand over a limited data set governed by a data use agreement — permitted uses fixed, recipients restricted, safeguards and breach reporting required, re-identification and contact forbidden. GCU publishes its own version of that agreement, listing the identifiers a limited set excludes, beside HIPAA authorization and waiver forms. The waiver route exists where research could not practicably proceed otherwise, and its criteria include a plan to shield identifiers from improper use and to destroy them at the earliest point the research allows.
Education records carry their own rule. Under 34 CFR 99.31(a)(6) an educational agency may disclose personally identifiable information from education records without consent to organisations conducting studies on its behalf, but only under a written agreement that specifies the purpose, scope and duration of the work, restricts the information to that purpose, and requires destruction when the information is no longer needed, within a stated period. In practice this is why a district asks for its own agreement before releasing anything, and why "de-identified test scores from the administrator" is a sentence that needs paperwork behind it — paperwork that also has to agree with what your site authorization letter says the site permits.
Who else touches the data?
Every additional pair of hands is part of the plan. GCU supplies a non-disclosure and confidentiality agreement for people who are not the principal investigator — transcriptionists, statisticians, interpreters, translators, assistants — and it is specific about what they undertake: no discussion or disclosure of names, responses or data; names kept apart from the data itself; paper and electronic material secured while held; everything returned when the work is done; extra copies destroyed, including files inside survey applications. Where an interpreter or translator is used, GCU also expects the agreement alongside the translated documents.
The same reasoning applies to software. A transcription service, an analysis tool, a survey platform and a conferencing system each receive something, hold it somewhere, and operate under a policy someone should have read. Naming them and linking those policies is not bureaucracy; it is the only way a reader can see the whole path your data travels.
How does the plan fail?
Almost always by contradiction rather than by weakness. The application says responses are anonymous while the procedures describe recorded interviews. The consent document promises deletion at completion while the application gives a later destruction date. The recruitment material offers a one-sentence protection promise that the plan does not keep. Each of those is small; together they tell a reviewer that nobody has read the file as a whole, and a file that cannot describe its own data handling consistently invites the question of whether the handling itself is consistent.
The remedy is unromantic. Draft the privacy answers once, in one sitting, and carry them into every document — the application, the consent document, the recruitment material, the site authorization letter, any agreement with a helper. That is the same discipline the rest of the file demands, described in the exhibits checklist and in consent documents at GCU.
How this desk handles it
We write the data plan before the documents that reference it, because everything else quotes it. That means settling what identifiers the design creates, what may be dropped at collection, how codes and links will work, where every category of material will live, who will be permitted near it, which third parties are involved, and what the destruction date will be — then writing that single account into each document in the words each document needs. Agreements for helpers, platform policies and any data use agreement are gathered as part of the same pass. Filing and the replies afterwards stay with us, as how it works describes; the data itself, and the findings, remain entirely yours.
What to do next
If you can describe your data handling out loud but could not point to where each element appears in the file, that gap is exactly what a reviewer opens on. Send the application draft and your consent document through the free application review, and you will get a written reading of whether the file tells one story about identifiers, access and destruction — and where it does not, precisely which sentences disagree. The FAQ covers what happens after that.
Sources
- Grand Canyon University, Informed Consent template, privacy and data security section — research.gcu.edu (Informed Consent template)
- Grand Canyon University, Confidentiality and Anonymity guidance — research.gcu.edu (Confidentiality and Anonymity)
- Grand Canyon University, Data Use Agreement template — research.gcu.edu (Data Use Agreement)
- Grand Canyon University, Non-Disclosure Confidentiality Agreement for research assistants — research.gcu.edu (Non-Disclosure Agreement)
- Grand Canyon University, HIPAA general information and researcher resources — research.gcu.edu/irb
- 45 CFR 46.111 — approval criteria, privacy and confidentiality among them — Legal Information Institute (45 CFR 46.111)
- 34 CFR 99.31(a)(6) — disclosure of education records to organisations conducting studies — Legal Information Institute (34 CFR 99.31)
- 45 CFR 164.514 — HIPAA de-identification, and limited data sets — Legal Information Institute (45 CFR 164.514)
GCU revises its templates and its portal instructions. Where anything on this page departs from GCU's current doctoral handbook or IRB portal, GCU's own material is what counts. This practice is independent of Grand Canyon University.