Home · Newsletter

The data security plan in a Purdue Global application: storage, access, de-identification, destruction

Purdue Global does not ask for a separate document called a data security plan. It folds one into the methodology section of the research plan summary as a short run of direct questions: how will you collect and record the information, who will administer the study, where will the information be stored, how will you store it and who will have access, how long will it be retained before being destroyed, will you collect personally identifiable data, and — if you are surveying online — will your tool be collecting addresses. Seven questions, each with a correct kind of answer and an incorrect one. The correct kind contains a name. The incorrect kind contains an adjective.

Victoria Halloran, PhD · 2026-08-23

Short answer

Purdue Global's methodology section asks seven questions about data: how it is collected, who administers it, where it is stored, who may open it, when it is destroyed, whether it identifies anyone, and whether your survey tool records addresses. Each answer needs a name.

What is the board really asking for?

Underneath the seven questions sits a single federal criterion: before approving research, a board must find that, where appropriate, there are adequate provisions to protect participants' privacy and keep their data confidential. "Adequate" is a judgement, and a judgement needs something concrete to weigh — which is why "data will be kept secure and confidential" fails. It gives a reviewer nothing to assess. Purdue Global's IRB makes the stakes plain in how it describes harm: answers escaping the research and landing on a participant as legal jeopardy, or as damage to their position at work, their employability, their reputation. The data plan is the account of what stands between the two.

The seven questions, and what a named answer looks like
The questionNot an answerA named answer
How is it collected and recorded?"Through surveys and interviews"The instrument by name, the medium, whether audio is recorded and what becomes of it
Who administers the study?"The researcher"Every person who will handle responses, their role, and the training each holds
Where is it stored?"Securely"The named location for each form the data takes: device, encrypted volume, institutional service
Who has access?"Only authorised persons"Named people, and the mechanism excluding everyone else
Retained how long, then what?"Until the study is complete"A retention point tied to a named event, and a destruction method for each copy
Is it personally identifiable?"No, it is anonymous"Which identifiers are collected, when they come off, and what links them meanwhile
Does the tool collect addresses?"The survey is anonymous"The tool named, the setting disabled, and a link to the tool's own documentation

Why does the IRB recommend an encrypted flash drive?

Purdue Global's data security guidance is unusual in that it shows its working, and the reasoning is worth reading rather than skipping past to the wording. The IRB observes that candidates commonly do research on their own personal computers, and typically reassure the board about antivirus software and a password on the user login. It then explains why that is thin: antivirus protection is not completely safe; the board cannot expect a personal machine to be used only for research and only during the research period; a laptop can be left somewhere, or a family member can get onto it; and data often has to be kept for some while afterwards. Each is a plausible route by which answers leave the study.

The university's conclusion is to suggest an encrypted flash drive holding everything related to the research, with suggested wording to match: the data stored on the researcher's encrypted flash drive, accessible only to the researcher, using a strong password known only to the researcher, with no other individuals having access. Read that as a specification rather than a phrase to copy. It contains four commitments — encryption, a single named holder, a strong credential, exclusivity — and a plan reproducing the sentence without honouring all four has written a promise it will break.

One honest caveat belongs here. This guidance carries its own revision stamp, and storage practice has moved on since guidance of that vintage was written; managed institutional services did not exist in the same form. If your circumstances point elsewhere, meet the four commitments the guidance encodes and check the wording currently published on the university's IRB pages before you file.

What counts as identifiable, and when do the identifiers come off?

Most files answer this too quickly, because "anonymous" feels true when no name is ever typed. It usually is not. A study is not anonymous while any link exists between a response and the person who gave it — a signed consent form filed beside the responses, a scheduling calendar, a voice recording, a sample small enough that three demographic fields identify one person.

Where health records are involved, the sharpest available yardstick is the identifier list in the HIPAA de-identification standard, which sets out what must be stripped for information to count as de-identified by that route. It runs to eighteen categories and is longer than people expect, reaching well past names into geography finer than a state, nearly every date tied to a person, a long run of record and account numbers, web and internet protocol addresses, biometrics including finger and voice prints, and full-face images, before closing with a catch-all for any remaining unique code. Voice prints catch interview studies — a recording is identifiable data until destroyed, whatever the transcript says.

This answer also shapes which review path is open to you, which is why the data plan is worth settling before the rest of the application. Several federal exemption categories turn on exactly this question: survey, interview and observation work can sit within an exemption where responses are recorded in a way that does not let a participant be picked out. Where a participant can be picked out, that route stays open only with a limited review aimed at the privacy criterion above. Purdue Global answers a submission in one of three ways — exempt and approved, modifications requested, or full review required — and these protections help shape which you receive. The step-by-step route sets out that sequence.

What about online surveys and addresses?

Purdue Global asks specifically whether an online survey tool will collect addresses, and sets a standard higher than assertion: you are expected to demonstrate an understanding of your tool's anonymity options and to supply a link to that tool's own anonymity procedure. Its suggested wording names the tool, states that addresses will not be collected, inserts the link to the documentation on switching that function off, and confirms the function will be used when the survey is built.

Three consequences follow. Choose the tool before writing this section, because the wording names it. Read the tool's actual documentation, because the link is part of the answer. And switch the setting off when you build the survey rather than intending to — configurations are checkable. If your consent page promises anonymity, this paragraph delivers it; the consent requirements article covers the promise from the other side.

How is data retained, and how is it destroyed?

Retention and destruction are one question, and Purdue Global asks it that way: how long will data be retained before being destroyed. A plan answering only the first half has described storage, not a lifecycle.

The university's published wording for signed consent documents shows the shape of a complete answer, in two routes. On the first, signed originals are collected, sealed, filed in a locked cabinet to which the researcher alone holds the key, held for a stated minimum, and then shredded. On the second, they are scanned, the originals shredded, and the files kept on the encrypted drive under a strong password with the researcher as the only person with access, again for a stated minimum, after which the participant files are — in the university's own phrase — double deleted. Confirm the current minimum on the university's page; structurally, each route names a place, a holder, an exclusion, a floor and a destruction method for every copy. Note where that wording goes: Purdue Global asks for it in your research plan summary, so consent handling is described in two documents at once.

Where does the data plan drift from the rest of the file?

  • Against the consent. The consent promises anonymity; the methodology keeps a linking list. Only one can be true.
  • Against the recruitment plan. Screening replies from people never recruited are data too, and need a home and an end. See the recruitment materials article.
  • Against the agency approval. The plan says records arrive de-identified; the permission reads as though a named list is being handed over.
  • Against the team. The plan names one person with access; the methodology mentions an assistant transcribing interviews.

One boundary is worth naming. If your study wants data about Purdue Global itself, that is a different route entirely: the university runs an external research request process, under the Family Educational Rights and Privacy Act as well as its own IRB policies.

How we draw the plan

We start by mapping every form the data takes across its whole life — the recording, the transcript, the spreadsheet, the signed forms, the screening list, the backup nobody mentioned — and give each a location, a holder, an exclusion mechanism, a retention point and a destruction method. Then we answer Purdue Global's seven questions in its own order with those names in place, name the survey tool and link its anonymity documentation, put the retention wording in both documents that need it, and measure the whole against the consent, the recruitment pack and the agency approval. Our how-it-works sheet and the questions page cover the rest. The data is yours and stays yours; the determination belongs to the board.

What to do next

Open your methodology section and read the seven questions against it. If any answer could be pasted into somebody else's application without changing a word, that answer has no name in it yet. Ask for the free application review and send the methodology with your consent draft; we will tell you which answers are load-bearing and where anonymity is being promised that the plan cannot deliver.

Sources

Give us the entire IRB process. Keep the study.

The free application review is where it starts. From there we carry everything — the determination and the plan, every document drawn to the same dimensions, the submission itself, and every reply to the board until the approval letter exists. The study, the data and the findings remain yours; the board's decision is its own.

Request the free application review Send whatever exists — drafts count.
Has the board measured your file yet?