Health Data Research UK’s Public Advisory Board, together with the Pan UK Data Governance Steering Group, have developed Transparency Standards, to support data custodians in strengthening openness and accountability in data access processes, helping to build public trust while simplifying procedures for researchers.
Data custodians should:
• Publish the data access application form that can be accessed without the need for registration or any other additional requirements.
• Publish guidance notes, including details as to why the information in the form is being requested (e.g. for compliance with national standards or legislation), as well as examples of completed forms, including successful or unsuccessful submissions.
• Clearly set out each step in the data access process in a transparent format with appropriate structure and language (e.g., through diagrams, videos, animations, swim lane diagrams or process flows) understandable to both researchers and the public, indicating timescales for each step where possible and defining where responsibility lies.
• Provide clear guidance notes and requirements for the application process.
• Include a description on the website on how the data access process incorporates the Five Safes Framework and explain what this means in a transparent way.
• Explain how applications are assessed, including how members of the public are involved in assessing applications and in developing the criteria used to assess applications.
• Terminology for secure data platforms, such as Trusted Research Environment (TRE), Secure Data Environment (SDE), and Data Safe Haven (DSH), varies across data custodians despite describing similar systems for managing sensitive data. In the absence of standardised terms, clear definitions should be provided.
• Ensure information about the data access process is easy to locate and clearly communicated from the homepage. If including it directly on the homepage is not feasible, use clear signposting, such as drop-down menus, to guide users to the relevant information. Include clear information about how public benefit is assessed.
• Have separate website sections for information about clinical trials and for the re-use of data in research (where applicable).
• Where the data custodian supports different types of data access with distinct processes (e.g., service improvement versus research), have separate sections of the website with the required information.
• For linked data sets with multiple controllers, provide clear and detailed information on requirements for data access, with a clear pathway setting out what the researcher should expect in terms of approvals, timescales, access, and information about the role of relevant data controllers.
• Consider accessibility when creating website content to suit different audiences.
• Consider having separate website sections for researchers and members of the public, in each case using appropriate language for the target audience.
• Involve researchers, information governance professionals and members of the public in writing and checking of all materials to ensure that the web design and its contents are accurate, accessible, and transparent.
• Provide a mechanism for members of the public and researchers to provide feedback on the language, structure, and content.
• Consider how to provide information in an appropriate language to members of the public who may not have access to the internet.
• Commit to regular review cycles, for example every six or twelve months, to assess and update website content, ensuring the information remains accurate, current, and aligned with operational and policy changes.
• Where there are downloadable application forms and guidance notes, custodians should include the last review date and the next review date to ensure researchers, and the public know they have the current version.
• Have a “frequently asked questions” section and or equivalent on the website and keep this regularly updated.
Custodians should:
• Publish a summary of approved studies/protocols (lay summary, technical summary, public benefit etc) and resulting research outputs for full transparency within 3 months of approval. Where data controllers set precedents, these should be openly shared to drive continuous improvement across the sector and to encourage consistency of decision-making.
• Publish minutes and/or core decisions made in Data Access Committee meetings (noting that redaction of sensitive information may be appropriate).
• Publish case studies each year, particularly those that highlight public benefit and examples of how lives are improved by use of data for research.
• Publish a data use register that is updated at regular intervals.
• Publish decisions on data access requests that have been rejected, with consideration for the level of detail that is appropriate to share publicly (e.g., it may not be appropriate to publish names of organisations or researchers). Publishing the reason why certain types of requests are rejected may give the public reassurance that standards are being upheld and encourage consistency of decision making. The reasons do not have to be sensitive or give details around a specific researcher; they could be summaries such as data sensitivity, type of organisation requesting access, public perspective, etc.
• Consider publishing how changes in areas such as governance, transparency, regulation, access mechanisms, and data or technology issues have affected certain projects, to show how these improvements support better use of data endorsed by the public.
• Publish an up-to-date and clear privacy notice in compliance with data protection legislation.
• Publish:
The full text can be found here: Improving transparency in data access processes: Developing best practice standards and promoting system-wide change through a competitive funding call