What are you looking for?
Birds of a Feather (BoF) Session July 2, 2024

Trusted Research Environments for Sensitive or Confidential Data: FAIRness for Controlled Data and Processes

Plenary: RDA 23rd Plenary Meeting – San José, Costa Rica

Submitted by

Meeting objectives

The goal of this meeting is to discuss and integrate the feedback obtained on the Case Statement that will have been submited by the end of July, to finalize it and – hoping for a positive evaluation – prepare the WG launch by the beginning of 2025.

The conflicting goals of protecting and maintaining control over sensitive or confidential data while also thriving to give third parties access to the data pose a significant challenge. Trusted Research Environments (TREs) / Secure Research Environments (SREs) have been established in the last decade that, if properly set-up and operated, help ease this problem through providing high security guarantees of a highly controlled and monitored environment with trust.

In many settings, both academia and industry have a need to safeguard access to highly sensitive / confidential data that is commonly referred to as closed data. This sensitivity/confidentiality requirements can arise from e.g. commercial value or privacy requirements and warrants careful data management through support of technical-, organizational- and legal measures intertwined within a TRE.

The FAIR Guiding Principles for scientific data management and stewardship addresses infrastructures supporting reuse of scholarly data specifically targeted at machine-readability and –actionability of this data. While the guiding principles cover the management of all research data and aid in identifying necessary steps towards FAIR research data, they do not provide a best practice guideline / template or design decisions to make closed data FAIR per se.

We found that many TREs/SREs are similar in architecture design and technical implementation. There is however a lack of openly available guidelines and design decision explanation for setting up and running TREs.

We thus aim at establishing a WG that will:

– identify and publish a blue-print/reference architecture for the technical architecture, roles and processes commonly found in such trusted research environments based on the evaluation of existing solutions
– make it easier for institutions to set up data infrastructures that allow researchers to gain access to sensitive data (irrespective of whether that sensitivity stems from privacy/GDPR reasons or is due to the commercial/IPR sensitivity of the data). It will demonstrate that such data, in spite of not being freely share-able can still be FAIR, made available for research.
– demonstrate how results obtained on such closed data can still be made reproducible and transparent to the degree permitted by data sensitivity, establishing a clear public metadata record on the research performed as well as supporting findability of the data, linked to clear access request/permission processes and public verification of access by specific trusted parties.
– increase interoperability between such environments on a technical, legal and organizational level, hopefully enabling easier set-up of ad-hoc joint TREs in settings where specific data sources need to be joined but may not be passed on to a third party for hosting.
– make it easier to set-up data visiting platforms where trusted code can be executed, with monitoring and result inspection processes clearing results for return to a researcher so that, in some cases, even a completely shielded interaction with sensitive data may be possible.

The goal is to document, abstract from and establish best practices for balancing these differing requirements for access limitations and flexibility of interaction / analysis, understanding associated risks, with the goal of making data accessible and usable to research that otherwise would not be possible.

Based on an extremely well-attended BOF Session held at P21 in Gothenburg and Salzburg (>100 participants, more than 80 participants registering their name in the collaborative meeting notes), we have prepared the Case Statement document to establish a Working Group. The (semi-final) draft of the Case Statement has been available for several months now at

https://docs.google.com/document/d/1877OtQyZ46QCHVZ8_1QqRgZJPXyImZdW1qYVyKItMSQ/edit

for discussion, integrating suggestions made during the BOF sessions and on-line. This draft Case Statement will be submitted to TAB in the next in the next few days for feedback. At the next Plenary we would like to finalize the Case statement incorporating feedback from participants and start launching the actual activities in preparation for the establishment of the WG pedning its approval.

Meeting presenters

Andreas Rauber, TU Wien (Austria) Rob Baxter, DARE UK (UK) Lucas van der Meer, ODISSEI (The Netherlands) Ville Tenhunen, EGI Foundation (Finland) Martin Weise, TU Wien (Austria) (NN, to be confirmed) (US) (NN, to be confirmed) (Australia)

Meeting agenda

– Short summary of BOF sessions in Gothenburg and Salzburg and subsequent calls

– Presentation of planned WG activities, draft Case Statement document, and feedback received so far

– Refining activity plan, “signing up” volunteers for coordinating specific activities

– Sanity check on feasibility given time (18 months) and resource (no dedicated additional funding) constraints

– Finalizing Case Statement for submission

Have you presented a session on the same topic at any previous plenaries?

Yes

Previous presentation details

BOF Session Trusted Research Environments at P20 in Gothenburg to launch the idea; and P21 in Salzburg to draft the Case Statement

Additional links to informative material

* draft of the Case Statement has been available for several months now at https://docs.google.com/document/d/1877OtQyZ46QCHVZ8_1QqRgZJPXyImZdW1qYVyKItMSQ/edit * Working notes of the TRESD BOF Session held at P20 in Gothenburg on March 23 2023. https://docs.google.com/document/d/1pQheT3ZIp1SUU4iYc0Z4IO7PVOT6_-N7QjdZTWS-sIk Desai, T, Ritchie, F and Welpton, R. 2016. Five Safes: Designing data access for research [Online]. Economics Working Paper Series 1601. DOI: https://doi.org/10.13140/RG.2.1.3661.1604 Palmgren, J, Rasmussen, T, Bengtström, M, Kahri, P, Ebbing, M, Henrichsen, B, Nilsson, M and Høst, G. 2019. A vision of a Nordic secure digital infrastructure for health data: The Nordic Commons. (Technical report). Oslo: Nordic Council of Ministers, NordForsk. United Kingdom Health Data Research Alliance. 2020. Trusted Research Environments [Online]. URL: https://ukhealthdata.org/projects/aligning-approach-to-trusted-research-environments/. Accessed September 2020. Version 2.0. Weise, M., Kovacevic, F., Popper, N. and Rauber, A., 2022. OSSDIP: Open Source Secure Data Infrastructure and Processes Supporting Data Visiting. Data Science Journal, 21(1), p.4. DOI: https://doi.org/10.5334/dsj-2022-004

Estimate of the required venue room capacity

Between 60-100 seats

Applicable Pathways

FAIR, CARE, TRUST - Adoption, Implementation, and Deployment
Data Infrastructures and Environments - Discipline Focused

Please indicate at least (3) three breakout slots that would suit your meeting.

Breakout 1. Tuesday, 12 November, 16:00-17:30 UTC
Breakout 4. Wednesday, 13 November, 16:00-17:30 UTC
Breakout 5. Wednesday, 13 November, 18:30-20:00 UTC
Breakout 6. Thursday, 14 November, 16:00-17:30 UTC
Breakout 7. Thursday, 14 November, 18:30-20:00 UTC