03 · What You Need to Know
How to Manage a Study When Someone Else Controls the Data
Data existence and data access are separate questions
The first distinction is simple but consequential. A dataset can exist without being accessible to you.
A university may have detailed student records. A hospital may retain the clinical information your study requires. A government agency may hold individual-level administrative data. A company may possess years of customer or employee records. None of this establishes that those data can be released for your proposed research.
Data availability
The information required by the research has actually been collected or generated and exists in a potentially usable form.
Data access
You have the authorization and practical means required to obtain or use the relevant data under the applicable conditions.
Before dealing with permission, you should already have established whether the data your research requires actually exist. Once existence is reasonably established, access becomes its own feasibility question.
Identify who actually controls access
The person who knows about the data may not be the person who can authorize their use.
A faculty member may know that a university database exists but have no authority to release student records. A physician may support your project but not control access to hospital data. An employee may be willing to share organizational information but lack permission to provide it for research.
Depending on the setting, authority may rest with a data custodian, records office, research office, repository, government agency, information-security unit, privacy or data-protection office, institutional review board or ethics committee, legal office, database owner, or another designated authority. Several may be involved.
Ask specifically: Who has the authority to approve the particular access I need?
That question is more useful than asking whether someone inside the organization is generally supportive of the research.
Determine exactly what kind of access you need
"I need the dataset" is usually too vague for serious access planning.
Specify the records, variables, population, dates, level of detail, identifiers, linkage requirements, and intended analysis. Determine whether you need identifiable data, coded or pseudonymized records, de-identified data, aggregate statistics, a public-use file, restricted microdata, or access through a secure environment.
The level of access can materially change the approval process.
For example, a provider may be able to release aggregate statistics relatively easily while individual-level records require additional review. A public-use dataset may suppress detailed geography or dates, while a restricted version contains them under tighter controls. A provider may permit analysis but require that the data remain on its servers.
Request the minimum level of access capable of answering the research question rather than automatically asking for the most detailed version available.
Find the official access process
Do not rely exclusively on informal advice when the provider has an established application procedure.
Repositories and government data providers often publish eligibility criteria, application forms, data-use conditions, security requirements, fees, approval procedures, and information about available datasets. Institutional data offices may have their own request systems. Some providers require researchers to submit a detailed list of variables or a research proposal before they will assess the request.
Read those requirements before finalizing your study. They may reveal that you are not eligible, that the data cannot be used for your intended purpose, or that the approval process is incompatible with your timeline.
If the process is unclear, preliminary contact with the appropriate custodian can help. This is one reason it may be useful to contact a potential data provider before finalizing the research question when the entire study depends on that source.
Expect access conditions, not simply a yes or no
Permission is often conditional.
A provider may approve access only for specified researchers, variables, purposes, periods, or locations. Data may have to remain in an approved computing environment. Researchers may be prohibited from attempting re-identification, linking the data with external sources, redistributing files, publishing small cell counts, or using the data for purposes outside the approved project.
Some restricted-data systems also review analytical outputs before researchers can remove them from a secure environment.
For example, the U.S. Census Bureau's Federal Statistical Research Data Centers provide qualified researchers access to restricted federal statistical data for approved projects within secure facilities. Access involves a formal proposal process, and approved researchers must satisfy relevant requirements. Similarly, ICPSR distinguishes among public-use, restricted-use, and other controlled access arrangements, with additional requirements applying to sensitive data.
The important planning question is therefore not only Can I get access? It is also Under what conditions would I be allowed to conduct the analysis?
A data use agreement can shape the study
Access to restricted data may involve a data use agreement or similar contractual instrument.
Such agreements can specify who may access the data, the permitted purpose, storage and security requirements, restrictions on disclosure or redistribution, requirements following completion of the project, and consequences of noncompliance. The exact terms vary by provider and jurisdiction.
Read the agreement rather than treating it as paperwork to be signed after the methodological decisions have already been made.
If the agreement prohibits linkage with another dataset, for example, and your research question depends on that linkage, you have a methodological problem rather than merely an administrative inconvenience. Likewise, if collaborators must individually receive authorization, your staffing plan may need to reflect that requirement.
Ethics approval and data-provider permission are not necessarily the same thing
Researchers sometimes assume that approval from one authority automatically satisfies another.
It may not.
Your institution may require ethics or institutional review for the proposed research. Separately, the data provider may require its own authorization before releasing or allowing access to records. A provider may also impose privacy, security, contractual, or legal requirements independent of the research-ethics process.
Conversely, receiving permission from a data custodian does not automatically establish that all research-ethics requirements have been satisfied.
Research ethics or institutional approval
Determines whether the proposed research satisfies the applicable ethical and institutional requirements within the relevant review framework.
Data-provider authorization
Determines whether the organization controlling the data permits the requested access and use under its policies, agreements, legal obligations, and other requirements.
The exact sequence varies. Some data providers require ethics documentation before reviewing access. Others may provide preliminary confirmation needed for an ethics application. Verify the requirements rather than assuming a universal order.
Privacy and identifiability can determine what you receive
Many access restrictions exist because research data can reveal information about individuals or organizations.
Removing obvious identifiers such as names does not necessarily eliminate disclosure risk. Detailed combinations of age, location, occupation, dates, diagnoses, institutional characteristics, or other variables can sometimes make records identifiable.
Providers may therefore suppress variables, aggregate categories, alter dates, remove geographical detail, or restrict access to secure environments. These protections can affect whether the released dataset retains enough detail for your analysis.
Do not assume that because the provider possesses a variable, you will receive that variable in its original form.
Data minimization can improve both feasibility and protection
Requesting every potentially interesting variable can make an access application harder to justify and create unnecessary data-management obligations.
Instead, map each requested variable to the research question and planned analysis. If a field does not contribute to the study, consider whether you need it at all.
This approach can reduce exposure to sensitive information and make the request easier to explain. It also forces useful methodological discipline: every variable should have a reason for being there.
In settings governed by privacy frameworks, data minimization may also reflect formal principles or requirements. Researchers should follow the rules applicable to their institution, provider, jurisdiction, and dataset.
Find out whether the data can leave the provider
Access does not always mean receiving a file that you can download to your computer.
Highly sensitive data may be available only through a secure data enclave, remote desktop, controlled laboratory, virtual environment, or physical research data center. The provider may restrict internet access, software installation, external storage, copying, printing, or removal of analytical outputs.
This can materially affect feasibility. If your planned analysis requires software unavailable in the secure environment, you may need another analytical approach or permission to install it. If access requires physical travel, costs and scheduling become relevant. If all outputs undergo disclosure review, publication timelines may need additional allowance.
Ask how access is technically delivered before assuming that approval means you will simply receive a spreadsheet.
Check whether all members of the research team can obtain access
Restricted access may be granted to named individuals rather than to an entire research group.
Your supervisor, statistician, research assistant, programmer, or collaborator may need separate authorization, training, confidentiality agreements, or institutional affiliation. Some data cannot be shown to anyone who has not been approved, even if that person is advising the project.
This can create an unexpected problem for student researchers. You may obtain access but later discover that the specialist helping with the analysis cannot see the data.
If methodological support is likely to be necessary, investigate access requirements for collaborators before assuming they can work directly with the dataset.
Approval timelines belong in your research timeline
Permission can take longer than expected, particularly when several organizations or review processes are involved.
The sequence might include preparing a proposal, obtaining institutional endorsement, ethics review, provider review, revisions, legal or contractual review, security assessment, signing agreements, completing training, account creation, and eventual data provisioning.
Not every request involves all of these stages, but even a subset can consume a meaningful portion of a thesis or grant period.
Ask the provider what steps normally occur and what timelines can reasonably be expected. Then include those stages when estimating whether the study can be completed within your deadline.
Approval can still be denied
A well-prepared request does not guarantee access.
The provider may determine that the proposed use falls outside participant consent, applicable law, institutional policy, contractual restrictions, or the dataset's permitted purposes. Disclosure risk may be too high. The requested variables may be unavailable for release. The organization may lack the resources to prepare the data. Another agreement may prevent sharing.
This possibility should influence how heavily you allow the project to depend on unapproved data.
Permission can be narrower than expected
Sometimes the answer is not "no" but "not quite."
You may request ten years of records and receive five. You may ask for exact dates and receive month and year. You may request individual-level geography and receive region. You may want to link two files but receive permission to analyze them separately.
A conditional or reduced-access approval can therefore require changes to the question, analysis, or claims.
When access is granted, compare what was actually approved with the data requirements of your research question. Do not proceed merely because the word "approved" appears in the correspondence.
Do not describe access as secured before it is secured
Researchers should use precise language when describing the status of data access.
| Status |
What it means |
How to treat it in planning |
| Potential source identified |
You know an organization or repository appears to possess relevant data. |
Access is unverified. |
| Preliminary enquiry completed |
The provider has indicated that an access route may exist. |
Useful feasibility evidence, but not permission. |
| Application submitted |
A formal request is under review. |
Access remains uncertain. |
| Conditional approval |
Access may proceed after specified requirements are satisfied. |
Verify that the conditions are achievable and compatible with the study. |
| Authorized access |
The required approvals and agreements are in place for the specified use. |
Proceed only within the approved scope and conditions. |
These distinctions are especially important in proposals. Saying "the data are available" when you mean "I have identified an organization that may consider an application" can make a study appear substantially more feasible than it actually is.
Consider the consequences of a single point of failure
Some studies have several possible data sources. Others depend completely on one organization.
If one restricted dataset is the only source containing the exposure, outcome, population, and timeframe required by your question, denial of access may end the project as currently designed.
That does not necessarily mean you should avoid the study. It does mean you should recognize the dependency explicitly.
Ask what happens if access is denied, delayed, narrowed, or revoked. Could another dataset answer the question? Could you collect primary data? Could the question be modified without becoming trivial or fundamentally different?
This prepares you for the next decision: whether you should base a research project on data you have not yet been guaranteed access to.
Watch Out
Do not begin using restricted, confidential, identifiable, or otherwise controlled data simply because someone informally sent you a copy. Verify that the person had authority to provide the data and that your proposed possession and use comply with the applicable approvals, agreements, institutional requirements, and data-protection obligations.
Keep a realistic alternative when the dependency is critical
A fallback is particularly valuable when approval may take months or when denial would otherwise make the project impossible.
An alternative might be another dataset, a public-use version with a narrower question, primary data collection, another provider, a different timeframe, or a modified analysis. The fallback should still represent worthwhile research rather than a hastily invented emergency project.
There is also a point at which maintaining two elaborate studies "just in case" becomes inefficient. The objective is risk management, not conducting two theses simultaneously. Identify the smallest credible alternative that protects the project from a foreseeable access failure.