About the Guide
This guide provides the INSEAD research community with guidelines and best practices to manage data more effectively throughout the research data lifecycle. It covers governance, planning, security, curation, and the support services available at each stage.
1. Data Governance
Data Ownership
It is important to know who has ownership of research project data, including:
- Before sharing or publishing data.
- When engaging in collaborative or cross-institutional projects.
- When working at an institution or on a project within a limited time frame.
Institutionally, INSEAD serves as the Data Owner and, under applicable laws, acts as the Data Controller for institutional and research-related personal data. The Principal Investigator (PI) may also be a Data Controller under relevant laws, thereby imposing legal responsibilities on both INSEAD and the PI.
Legal Compliance
It is essential to comply with applicable data protection laws, including the GDPR (General Data Protection Regulation) in the EU and PDPA (Personal Data Protection Act) in Singapore, the UAE's Abu Dhabi Global Market Data Protection Regulation (ADGM DPR), the UAE Personal Data Protection Law (PDPL), and INSEAD's internal policies; see 'Useful Links' below, as well as any other relevant laws that apply to the research projects being conducted.
Data Retention
What do we keep? How long does the data need to be preserved? Who is responsible for the data at the end of the project?
- Research data is retained for 10 years after the research study's publication, with anonymised data kept indefinitely in the public interest.
- Retention periods may vary based on Study Protocol and Research Agreements with third parties.
- Project-specific data is retained for the duration of the project or scientific review, and longer if further research is planned.
- Administrative data retention follows INSEAD's data retention policy; see 'Useful Links' below.
Useful Links
- INSEAD ResearchNet (INSEAD SSO is required)
- INSEAD Data Protection and Privacy Policy (INSEAD SSO is required)
- Data Management and GDPR (INSEAD SSO is required)
2. Planning (DMP)
Mandatory Data Management Plan (DMP)
A Data Management Plan (DMP) is a document that outlines how research data will be collected, documented, stored, secured, and preserved both during and after a project, ensuring its long-term accessibility and reuse.
A mandatory Data Management Plan (DMP) may be required in certain cases, such as grant-funded research. This is not an INSEAD requirement.
See DMP Templates:
See also INSEAD Policies (INSEAD SSO required).
Metadata & Documentation
Metadata is structured information that makes an information resource easier to find, use, and manage. Effective metadata improves the discoverability, organisation, and interoperability of research outputs, boosting their visibility, reuse, citation, and facilitating better discovery by large language models (LLMs).
- Social science metadata e.g.:
- Humphrey, C. (2014). Metadata in the Social Sciences. In: Michalos, A.C. (eds) Encyclopedia of Quality of Life and Well-Being Research. Springer, Dordrecht. https://doi.org/10.1007/978-94-007-0753-5_1795.
- Cavanagh, Jack; Fliegner, Jasmin Claire; Kopper, Sarah; Sautmann, Anja. 2023. A Metadata Schema for Data from Experiments in the Social Sciences. Policy Research Working Papers;10296. © World Bank. https://doi.org/10.1596/1813-9450-10296.
Supplier Management
All suppliers related to INSEAD activities must be managed by Procurement. Contact Procurement at least one month in advance for any supplier engagement (e.g. software, hardware, tools, consultants). The process includes due diligence, contracts, and internal governance. A Data Processing Agreement (DPA) is required before sharing personal data with a vendor, and B2B licenses are mandatory. Contact Research Specialists when considering the purchase of new datasets.
Research Agreements
Necessary for collaborations with third parties to address legal, IP, confidentiality, data protection, commercial, and liability issues. Contact the Research Agreements Team at least one month prior.
3. Security & Compliance
Security planning is essential to protect research participants’ privacy and safeguard sensitive, personally identifiable information. Follow the guidelines below as far as possible.
Data Collection & De-identification
Minimise data collection and collect only the data strictly necessary for the stated research purpose. Excess or redundant data must be deleted promptly once no longer required.
De‑Identification removes or alters personally identifiable information (PII) in a dataset. This can include deleting direct identifiers (e.g., names) or using techniques like masking or aggregation to reduce re‑identification risk. Anonymisation goes further by making re‑identification reasonably impossible. The aim is to enable data analysis or sharing without exposing individual identities. Research involving human participants must comply with institutional ethical standards and participant protection requirements.
Encryption converts readable data into unreadable ciphertext using an encryption key, ensuring only authorised users can restore it. It protects data both at rest and in transit. Data integrity—ensuring information remains accurate and unaltered—can be supported through digital signatures and hashing used alongside encryption. Sensitive participant data must be encrypted at rest and in transit throughout the research lifecycle.
Secure Devices and Approved Platforms
Use only IT-approved institutional devices and cloud platforms (e.g. SharePoint, OneDrive). Personal accounts and unapproved applications are non-compliant. In any case, devices must be encrypted.
Informed Consent
Obtain written informed consent from all participants before data collection begins. Consent forms must clearly outline data usage, storage, retention, and participant rights. If the data will be used in future research, participants should be informed and provide specific consent for this reuse.
Data storage
Secure storage prevents unauthorised access, loss, or corruption and typically involves protected servers, controlled access, routine backups, and security measures such as firewalls. Archiving and retention practices: Archived datasets should be anonymised whenever possible.
Secure Sharing of Information
Share data only with authorised team members via approved encrypted channels, such as OneDrive. Sharing via personal email or unencrypted platforms is strictly prohibited.
Useful links (INSEAD SSO Required):
4. Curation
Repositories
If your project is funded, check your funder's policies for recommended data repositories.
If a publication has co‑authors from different institutions, each co‑author may deposit the paper in their own university’s repository, subject to publisher and copyright policies (e.g., self-archiving policies: when and how authors may share copies of their publications outside the publisher’s website).
- Institutional and national repositories (e.g. university repositories or France’s HAL https://hal.science/).
- Subject repositories (e.g. PubMed Central, arXiv).
Useful Links:
Persistent IDs and DOI (Digital Object Identifier)
A DOI (Digital Object Identifier) is a unique, persistent identifier for digital or non‑digital objects, regardless of whether they are online. Supported by the International DOI Foundation and its Registration Agencies, DOIs ensure reliable, long‑term access and accurate identification. They can be assigned to a wide range of scholarly outputs, including datasets, publications, software, workflows, and websites.
Useful Links:
- See, https://www.doi.org/.
- See, Data storage options provided by INSEAD IT (INSEAD SSO is required).
5. Human Subject Research & Support
All research conducted at INSEAD that involves participants and/or human data—whether through our labs, online platforms, classrooms, or interviews with managers—must undergo an ethical review by the Institutional Review Board (IRB) (INSEAD SSO Required). Researchers are required to adhere to institutional guidelines regarding ethics, legal obligations, and compliance procedures.
Mandatory ethics training (PHRP)
Principal Investigators and researchers submitting an ethics application involving human participants must complete the Protecting Human Research Participants (PHRP) training prior to ethics approval. PHRP training (approx. 1–2 hours): Required for human-participant research and IRB/ethics submissions. Please visit this website for more information: https://phrptraining.com.
There are online training courses available to support your Research Data Management journey that you can complete at your own pace.
Useful Links:
- Elsevier Research Academy: RDM Training Program (Total Time: 4+ hours)
Visit the Research Intranet for more information and contacts.
For guidance on your INSEAD research journey, you can also contact the Research Specialists.