Data Sharing Policy

Version Number: PRF-DSP-001-2026

Effective Date: 15 August 2026


1. Purpose and Scope

Placeboes Research Foundation (“Placeboes”, “Foundation”, “we”, “our”, or “us”) is committed to advancing scientific knowledge through responsible collaboration, transparency, reproducibility, and appropriate sharing of research and institutional data.

This Data Sharing Policy establishes the principles governing the sharing, access, transfer, publication, reuse, and protection of data generated, collected, received, processed, or maintained by Placeboes Research Foundation.

The Policy applies, as appropriate, to research data, scientific datasets, participant-derived data, collaborative data, technical and computational data, and other information for which Placeboes has responsibility or stewardship.

Data sharing must remain consistent with applicable law, research ethics, informed consent, privacy and confidentiality requirements, contractual obligations, intellectual-property rights, and the legitimate interests of research participants, collaborators, and the Foundation.


2. Principles of Responsible Data Sharing

Placeboes supports data sharing where it can advance scientific knowledge, enable verification and reproducibility, facilitate responsible secondary research, encourage collaboration, or otherwise contribute to societal benefit.

Data sharing will be guided by the following principles:

  • scientific value and legitimate purpose;
  • respect for research participants and individuals;
  • privacy and confidentiality;
  • appropriate informed consent and ethical approval;
  • proportionality between scientific benefit and potential risk;
  • data minimization;
  • appropriate security and access controls;
  • transparency and accountability;
  • scientific integrity and appropriate attribution;
  • respect for intellectual-property and contractual rights; and
  • compliance with applicable laws, regulations, policies, and agreements.

The principle of openness does not imply that all data should be made publicly accessible.


3. Categories of Data

Data governed by this Policy may include:

Research Data

Data generated, collected, observed, measured, derived, or analysed during scientific research, including experimental, clinical, behavioural, physiological, imaging, survey, computational, laboratory, or other research data.

Participant-Derived Data

Information obtained from or concerning research participants, patients, volunteers, community participants, or other individuals involved in research.

Derived and Analytical Data

Processed datasets, statistical outputs, computational representations, annotations, classifications, models, features, or other information derived from primary data.

Collaborative Data

Data received from or generated jointly with universities, hospitals, research institutions, investigators, industry partners, community organizations, or other collaborators.

Technical and Technology Data

Data arising from software, prototypes, devices, digital platforms, algorithms, simulations, artificial intelligence systems, or technology-development programmes.

Institutional Data

Operational, administrative, programme-related, or organizational information generated or maintained by Placeboes.

Different categories of data may require different levels of protection and access.


4. Levels of Data Access

Where appropriate, Placeboes may classify shareable research data into different access levels.

Open Access Data

Data may be made publicly available where there are no material privacy, confidentiality, ethical, contractual, security, or intellectual-property restrictions.

Controlled Access Data

Data may be made available to qualified applicants following review of the proposed use and subject to appropriate agreements and safeguards.

Restricted Data

Data presenting greater privacy, confidentiality, ethical, commercial, security, or re-identification concerns may be accessible only to specifically authorized individuals or collaborators.

Non-Shareable Data

Certain data may not be shared where sharing would conflict with law, consent, ethical approval, confidentiality, contractual obligations, intellectual-property protection, participant interests, security considerations, or other legitimate restrictions.


5. Research Participant Data

Protection of research participants takes precedence over the objective of maximizing data availability.

Participant-derived data may be shared only where sharing is consistent with:

  • the informed-consent process;
  • applicable research protocols;
  • approval or requirements of the relevant ethics committee or institutional review body;
  • applicable privacy and data-protection requirements;
  • commitments made to participants; and
  • appropriate safeguards against unauthorized identification or disclosure.

Where required, data should be de-identified, anonymized, pseudonymized, aggregated, or otherwise appropriately protected before sharing.


6. De-identification and Re-identification Risk

Removal of direct identifiers does not necessarily eliminate the possibility that an individual could be re-identified.

Placeboes may therefore consider the nature of the dataset, combinations of variables, rarity of characteristics, sample size, availability of external information, technological developments, and other relevant factors when assessing re-identification risk.

Additional safeguards or controlled-access arrangements may be required where de-identified data retain a meaningful possibility of re-identification.

Recipients of data must not attempt to re-identify individuals from de-identified or pseudonymized datasets unless expressly authorized for a legitimate and ethically approved purpose.


7. Data Minimization

Only data reasonably necessary for the approved scientific, collaborative, or institutional purpose should be shared.

Where a legitimate purpose can be achieved using aggregated, anonymized, summarized, or otherwise less sensitive information, such forms of data should ordinarily be preferred.


8. Requests for Research Data

Requests for non-public research data should ordinarily identify:

  • the applicant and institutional affiliation;
  • the data requested;
  • the scientific or other legitimate purpose;
  • the proposed analyses or intended use;
  • the duration for which access is required;
  • proposed data-storage and security arrangements;
  • individuals who will have access to the data;
  • relevant ethics or institutional approvals, where applicable;
  • intended outputs or publications; and
  • any proposed onward sharing.

Placeboes may request additional information where necessary to evaluate a data-access request.

Submission of a request does not create an entitlement to receive data.


9. Review of Data Sharing Requests

Data-sharing requests may be evaluated according to factors including:

  • scientific merit and legitimacy of purpose;
  • consistency with participant consent;
  • ethical and regulatory requirements;
  • privacy and re-identification risk;
  • qualifications and institutional accountability of the requester;
  • data-security arrangements;
  • contractual or collaborative obligations;
  • intellectual-property considerations;
  • potential conflicts with ongoing analyses or publication;
  • feasibility and resources required to prepare the data; and
  • potential benefits and risks associated with sharing.

Placeboes reserves the right to approve, condition, defer, or decline a request where appropriate.


10. Data Sharing Agreements

Where appropriate, access to non-public data may require a Data Sharing Agreement, Data Use Agreement, Material Transfer Agreement, collaboration agreement, confidentiality agreement, or other suitable instrument.

Such agreements may specify:

  • permitted purposes of use;
  • authorized users;
  • duration of access;
  • confidentiality requirements;
  • security requirements;
  • restrictions on re-identification;
  • restrictions on onward transfer;
  • requirements concerning publications and attribution;
  • intellectual-property arrangements;
  • incident-reporting obligations;
  • data retention and destruction requirements; and
  • termination of access.

11. Data Security

Recipients of non-public data must implement security measures appropriate to the nature and sensitivity of the information.

Such measures may include access controls, authentication, encryption, secure storage, restricted copying or downloading, audit mechanisms, secure transfer procedures, and organizational safeguards.

Data must not be stored or transferred using systems that provide inadequate protection for the applicable level of sensitivity.


12. Confidential and Sensitive Data

Confidential, sensitive, proprietary, or otherwise restricted information must not be publicly released merely in the interest of openness.

Additional safeguards may be required for data involving identifiable individuals, health information, confidential collaborator information, unpublished discoveries, proprietary technologies, commercially sensitive information, security-sensitive information, or information subject to contractual restrictions.


13. Collaborative Research

Data generated through collaborative research will be governed by the applicable research protocol, ethics approvals, collaboration agreements, funding conditions, institutional policies, intellectual-property arrangements, and other agreed terms.

No collaborator should independently disclose jointly governed data where such disclosure would violate an applicable agreement, participant commitment, or legitimate right of another party.

Data stewardship responsibilities should, where practical, be established at the beginning of collaborative projects.


14. Publications and Supporting Data

Placeboes supports responsible availability of data underlying scientific publications where doing so is ethically, legally, scientifically, and practically appropriate.

Supporting datasets may be:

  • included with publications;
  • deposited in appropriate repositories;
  • provided in aggregated or de-identified form;
  • made available through controlled-access mechanisms; or
  • made available following reasonable request and appropriate review.

The form of sharing should reflect the nature and sensitivity of the data.


15. Public Data Repositories

Where research data are deposited in external repositories, repositories should be selected with consideration of scientific appropriateness, sustainability, access controls, metadata standards, security, preservation, participant consent, and applicable legal or contractual requirements.

Repository deposition does not remove obligations relating to privacy, ethics, intellectual property, or responsible stewardship.


16. Secondary Use of Data

Data originally collected for one research purpose may be used for secondary research only where such use is ethically and legally permissible and consistent with the applicable consent, research approvals, agreements, and governance requirements.

Where required, additional ethics review, authorization, consent, or other safeguards must be obtained before secondary use.


17. Artificial Intelligence and Computational Use

Research data must not be uploaded to external artificial intelligence systems, generative AI services, machine-learning platforms, or other computational services where doing so could compromise confidentiality, privacy, intellectual property, research integrity, contractual obligations, or participant protections.

Identifiable participant data and confidential research information should not be entered into general-purpose public AI systems.

Where AI or machine-learning methods form part of an approved research programme, the use of data should be governed by the applicable research protocol, ethics approval, data-management arrangements, security requirements, and relevant Placeboes policies.


18. Intellectual Property

Sharing data does not automatically transfer ownership, copyright, database rights, patent rights, know-how, or other intellectual-property rights.

Where datasets contain or relate to potentially patentable inventions, proprietary technology, software, algorithms, commercially sensitive information, or other protectable intellectual property, disclosure may be delayed or restricted where reasonably necessary to protect legitimate rights.


19. Attribution and Scientific Credit

Recipients should appropriately acknowledge the origin of shared datasets and recognize the contributions of researchers, participants, collaborators, institutions, and funding organizations where applicable.

Citation, acknowledgement, or authorship expectations should be determined according to applicable scientific standards and the nature of the contribution.

Provision of a dataset alone does not automatically establish entitlement to authorship, nor does access to data eliminate obligations to provide appropriate attribution.


20. Prohibition on Unauthorized Onward Sharing

Recipients must not transfer, disclose, publish, sell, sublicense, redistribute, or otherwise make restricted data available to another individual or organization unless such sharing is expressly permitted.

Where additional investigators require access, appropriate authorization should be obtained before access is provided.


21. Commercial Use

Data shared for scientific, educational, or non-commercial purposes must not be subsequently used for commercial purposes unless such use is expressly authorized.

Commercial access may require separate review, licensing, contractual arrangements, or intellectual-property agreements.


22. Data Retention and Destruction

Shared data should be retained only for as long as reasonably required for the authorized purpose or as required by applicable legal, ethical, scientific, contractual, or institutional requirements.

Where required by an agreement or authorization, recipients must securely delete, destroy, or return data at the end of the approved access period and confirm such action when requested.


23. Data Breaches and Unauthorized Use

Any suspected or confirmed unauthorized access, disclosure, loss, alteration, re-identification, misuse, or security breach involving data shared by Placeboes should be reported promptly to the Foundation.

Recipients are expected to cooperate with reasonable measures to investigate, contain, mitigate, and remediate such incidents.

Placeboes may suspend or terminate access where data are used contrary to the approved purpose, applicable agreement, or this Policy.


24. Withdrawal or Restriction of Access

Placeboes may restrict, suspend, or withdraw access to shared data where necessary because of:

  • violation of applicable agreements or policies;
  • privacy or confidentiality concerns;
  • ethical or regulatory requirements;
  • security incidents;
  • unauthorized use or onward sharing;
  • newly identified re-identification risks;
  • participant-related obligations;
  • intellectual-property concerns; or
  • other legitimate scientific, legal, or institutional reasons.

25. Cross-Border Data Sharing

Where data are transferred across national jurisdictions, Placeboes and recipients should consider applicable data-protection laws, ethical requirements, contractual safeguards, transfer restrictions, and security requirements.

International collaboration does not remove the obligation to protect research participants and other individuals whose information may be contained in shared datasets.


26. Data Stewardship and Accountability

Researchers and project leads responsible for data should take reasonable measures to ensure that data are appropriately documented, stored, protected, retained, and shared throughout the research lifecycle.

Where appropriate, research projects should establish data-management and sharing arrangements before data collection begins.

Responsibility for data stewardship continues after publication where datasets remain under the control of Placeboes.


27. Relationship to Other Policies

This Policy should be read together with applicable Placeboes policies and governance documents, including the:

  • Privacy Policy;
  • AI Use Policy;
  • Ethics Policy;
  • Terms of Use;
  • Website Disclaimer; and
  • Copyright and Intellectual Property policies.

Where a research protocol, informed-consent document, ethics approval, collaboration agreement, funding condition, data-sharing agreement, or applicable law imposes more specific requirements, those requirements apply to the relevant data and activity.


28. Changes to This Policy

Placeboes may revise this Data Sharing Policy periodically to reflect developments in research practices, technology, ethical standards, institutional requirements, or applicable law.

Revisions will be published on the Foundation's website together with an updated effective date.


29. Contact Us

Questions concerning this Data Sharing Policy or requests relating to access to Placeboes research data may be directed to:

Placeboes Research Foundation
No. 963/151, 2nd Main, 4th Block
Near Tagore Memorial School
Rajajinagar, Bengaluru
Karnataka 560010
India

Email: info@placeboes.org
Website: www.placeboes.org