The data security plan in a Walden IRB application: storage, access, de-identification, destruction
The data security plan is the part of a Walden IRB application where a general answer is a wrong answer. The board is not asking whether you intend to be careful; Walden's handbook requires the application to explain how data will be stored and destroyed, audio recordings included — and federal criteria oblige the board to confirm those provisions are adequate. A plan that names the device, the protection, the people who may open it, where identities separate from responses, and when the files cease to exist answers every question in one pass. A plan that says "data will be kept securely" invites the board to ask all five.
Walden's IRB expects the data security plan to name the storage location, the protection on it, the access list, the de-identification step, the retention period after final approval, and the destruction method — for every form the data takes, recordings and transcripts included.
What is the Walden IRB actually reading the data security plan for?
Two texts sit behind the board's questions. The first is federal: Walden's IRB operates under the Federal Policy for the Protection of Human Subjects, 45 CFR 46, and among the criteria the board must satisfy before approving any study is §46.111(a)(7) — that, when appropriate, the study makes "adequate provisions to protect the privacy" of participants and to keep their data confidential. The board cannot find those provisions adequate if the application does not say what they are. The second is Walden's own: the handbook's description of what an ethics submission must contain lists, alongside recruitment and consent, an explanation of how collected data will be stored and destroyed — naming audio recordings specifically, the data most often forgotten.
Read together, they explain the board's posture: it is not auditing your hard drive. It checks that every promise the consent document makes about confidentiality has a mechanism somewhere in the plan — a location, a lock, a list, a date. Where the promise has no mechanism, the reply letter asks for one.
Where may the data live, and what counts as naming the storage?
Naming the storage means the sentence survives a reader who cannot ask follow-up questions. "A password-protected computer" is close but not there; whose computer, protected how, and what happens to the copy the survey platform keeps? A plan the board does not need to query typically states, for each form the data takes:
- The location — the specific device or account: an encrypted laptop under your sole control, a private account on the platform the application names, a locked cabinet for paper.
- The protection — password, encryption, or physical lock, stated plainly rather than implied.
- The copies — where recordings sit before transcription, where transcripts sit after, and when the platform-side copy is deleted — an online study leaves one behind until you remove it.
- The separations — signed consent records kept apart from responses; any code key kept apart from the coded data.
Whether a particular cloud service, survey tool, or transcription arrangement is acceptable for a given design shifts between terms; Walden's current handbook and IRB portal govern. Describe the tool you will actually use, so the board rules on the real plan, not a placeholder.
Who may open the data — and who is on the access list whether you write them down or not?
The access list is where Walden differs most from the generic advice candidates arrive with. At many institutions "only the researcher will have access" is the safe sentence. At Walden it is inaccurate, because Walden's handbook builds committee oversight into the data itself: a doctoral candidate's raw dataset, final dataset, and analysis process must be electronically available to the committee, the candidate keeps a log of recruitment and every data-management step, and the IRB and committee may review the raw data or the log at any time. The handbook is equally specific about outsiders: beyond university staff, only a committee-approved transcriber may touch the raw dataset, and a transcriber signs a confidentiality agreement with you before hearing a word of a recording. One exclusion is modern: Walden's conduct rules bar entering capstone data or participants' identities into open AI tools, — an AI transcription shortcut is an access-list breach, not a convenience.
The honest access list for a typical capstone reads: you; the committee, electronically; any named transcription arrangement, under its signed confidentiality agreement. Writing that list out does not weaken the file; it shows the board you know who is actually inside the study. It also has to agree with the consent document: if the consent form tells participants that responses are seen only by you, and the plan grants a transcriber access, the file contradicts itself, and the board will say so politely. The same version-matching discipline covered in the consent form requirements applies here sentence by sentence.
What does de-identification mean in this plan — and when does HIPAA enter?
The board reads "anonymous" and "confidential" as different claims, and the plan must know which one it is making. Anonymous means identities were never collected and cannot be reconstructed — a survey with no names, no emails, no link. Confidential means identities exist somewhere and the plan controls them — usually codes, with the key kept separate. A plan that promises anonymity while collecting email addresses for follow-up has made the wrong claim, and the correction ripples through consent and recruitment alike.
When the data begins life as health records, the vocabulary sharpens, because the site holding them answers to HIPAA. The Privacy Rule's Safe Harbor standard at 45 CFR 164.514(b)(2) lists eighteen identifiers that must be gone before health information counts as de-identified — names; geography smaller than a state; dates more specific than the year; contact, record, and account numbers; device and web identifiers; biometrics; full-face images; and any other unique identifying number or code. Two of those trip chart-review plans constantly: dates (a service date is an identifier; the year alone is not) and "any other unique code" (a re-identification code is only permissible if it is not derived from the identifiers and the key is not disclosed — 45 CFR 164.514(c)). A plan for records-based work should say who strips the identifiers, on which side of the transfer, and in which form the data crosses to you; the site's requirements travel with the records — one more reason the letter of cooperation and any data use agreement are drafted against the same plan.
How long is the data kept, and what does destruction actually mean?
Retention is the one number in this plan Walden publishes. The handbook currently requires the dataset to be kept in a confidential, secure manner for five years beyond the university's final (CAO) approval of the completed work, unless the IRB indicates otherwise — the current handbook's wording governs. (The board can approve exceptions through the application — sensitive recordings destroyed right after transcription, for instance.) Two consequences follow. The destruction date is not a calendar date but an event — a fixed period after final approval — and the plan should describe it that way. And "I will delete everything when the study ends" is a sentence the board must return: it contradicts the retention the university itself requires.
Destruction is named per medium: files erased from the named devices and accounts, recordings deleted, paper shredded, the code key with them. The plan reads cleanest when each row of data has all five answers in one place:
| The data, in the form it takes | Stored where, protected how | Who may open it | Identities handled how | Kept until, destroyed how |
|---|---|---|---|---|
| Interview audio | Encrypted device under your control; platform copy deleted after download | You; committee electronically; approved transcriber under signed confidentiality agreement | Names replaced with codes at transcription; key stored separately | Handbook retention period, then deleted from every device |
| Transcripts | Encrypted device; backup in one named location | You; committee electronically | Coded; no names in the text | Same period; files erased |
| Survey responses | Named platform account, then exported to encrypted device | You; committee electronically | Anonymous if no identifiers collected — and the consent document says the same | Same period; platform copy and export both deleted |
| Signed consent records | Stored apart from responses | You | Inherently identifiable — kept separate for that reason | Same period; shredded or erased |
| Extracted record data | Received de-identified where the design allows; encrypted device | You; committee electronically | Site strips identifiers per the agreement; Safe Harbor list where HIPAA applies | Same period; erased; any code key destroyed by its holder |
Why do data security plans come back more than they fail?
A weak plan rarely sinks a Walden file; it delays one. The board's reply asks the plan to name what it left general — and each revision pass is a full pass through the correspondence, so specificity withheld the first time is the classic avoidable return. The other classic is contradiction: a specific plan that disagrees with the consent document about who sees the data, or with the recruitment materials about anonymity. The board reads the whole file as one document; the plan must hold up against every promise made on the other pages. That is the discipline behind how we build the file — one version, every claim matching — and why the plan is written alongside the consent document, not after it. For where the plan sits among the rest of the enclosures, see the application checklist, enclosure by enclosure.
What to do next
If your plan still says "data will be stored securely," you already know the letter that sentence earns. Write the five answers for each form your data takes — location, protection, access, identities, destruction — and check each one against your consent document. Or send us what you have: we read the file as the board will, plan included, and the review is free. Write to the desk, or start with the fifteen short answers on the FAQ.
Sources
- Walden University handbook — Doctoral Learning and Resources (IRB; doctoral responsibilities regarding research data, retention, transcriber confidentiality): academics.waldenu.edu/handbook/learning-modalities/doctoral-research-resources
- Walden University — Research Ethics Review Process (Office of Research and Doctoral Services; sign-in may be required): academicguides.waldenu.edu/research-center/research-ethics/review-process
- Walden University handbook — conduct rules on capstone data and open AI tools (Conduct and Responsibilities section): academics.waldenu.edu/handbook
- 45 CFR 46.111 — what a board must find before approving, privacy and confidentiality provisions included: Cornell LII, 45 CFR 46.111
- 45 CFR 164.514 — de-identifying protected health information, Safe Harbor and coding rules: Cornell LII, 45 CFR 164.514
- OHRP — Federal Policy for the Protection of Human Subjects (45 CFR 46): hhs.gov/ohrp/regulations-and-policy/regulations/45-cfr-46