Data Protection in Research

Data protection matters in research projects

Are you an employee of a research group working on a research project that involves data processing? Are you a student writing a Bachelor’s or Master’s thesis, or undertaking a research placement?

In that case, you’ll generally need to look into data protection as well. On this page, you can find out more about this in a clear and concise way.


Tools for classifying a project (external)

To do this, you can categorise your project using the three tools listed on the right. These have been developed by BERD@NFDI. NFDI stands for ‘National Research Data Infrastructure’, an initiative supported by all 16 federal states with the aim of making research and scientific data available, interconnected and sustainable for long-term use (see also: Link).
The tools consolidate the relevant information in the form of a questionnaire comprising straightforward yes/no questions. These are then used to generate an assessment of the extent to which specific data protection regulations must be observed in relation to the project.

External tools for assessing the project’s compliance with data protection regulations:

1. Is any personal data being processed at all, or does the GDPR even apply to my project?
Tool IVA 1 of the BERD@NFDI

2. What do I need to bear in mind when using consent as a legal basis?
Tool IVA 2 from BERD@NFDI

3. What other research-specific legal provisions apply to my project?
Tool IVA 3 of the BERD@NFDI

Note: The tools mentioned above are in no way associated with the University of Koblenz, but are the in-house development of the BERD@NFDI.


Model data protection policy for research projects (external)

When planning your research project, you can also use the tried-and-tested ‘Template: Data Protection Concept for Research Projects as Part of Final Theses or Doctoral Projects’ issued by the Hessian Authorised Representative for Data Protection and Freedom of Information (HBDI) as a guide. Link to the sample (external)

Important: The linked template is intended to provide a structural guide; it contains references to Hessian state law! Section 24 of the HDSIG, which is repeatedly referred to, applies only to public bodies in Hesse – in particular, universities – and applies only to research projects under the responsibility of a university in the State of Hesse. For projects in Rhineland-Palatinate, the Rhineland-Palatinate State Data Protection Act applies. In Rhineland-Palatinate, § 22 LDSG RLP generally applies in place of the cited Hessian provision from the HBDI template. The basic requirements of the GDPR remain unchanged and, in this respect, the structure of the policy is generally unaffected.


A visual overview of key steps relating to data protection

To get an overview of the basic steps that generally apply, the diagram below can also serve as a guide and point of reference.

Important: The diagram below is intended merely as a rough guide. Specific circumstances, such as the involvement of third-party service providers or cooperations with external partners, and other factors are not covered here!
For information on risks and detailed explanations, please refer to the FAQ, as well as the Privacy Policy page and, in particular, ask your Information Security and Data Protection officer.

When processing personal data, all (!) data protection requirements must always be met (in particular, the documentation obligation and retention periods see link).