Case study analysis reveals compliance and data breach vulnerabilities in informal academic data transfers, highlighting the necessity of privacy-by-design workflows.
In academic research, data sharing, particularly secondary data reuse, relies heavily on informal networking. ‘Grey’ transfers of data motivated by research purposes are common. In this paper, working through three case studies primarily in human subject research, presented by professionals in digital health, research governance and high-risk data management and publication, we explore the compliance challenges of informal data sharing, its detection, policy challenges such as penalties and associated risks such as accidental data breach and scientific impact. We highlight challenges of maintaining researcher awareness of best practice, given the complex UK legal and regulatory landscape; the plethora of inaccurate, inconsistent, or jurisdiction-specific guidance accessible to non-experts via web search or AI chatbot; and the need to ensure compliance with standards required by key research partners in the EU. We then explore how good data privacy practices, privacy impact assessments, principles of privacy by design and existing frameworks might be used to support the process of engineering systems that provide the needed flexibility to researchers while minimising the risks.
No takes yet. Share an insight, caveat, or question.
Beckles et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: