4  Data Protection

Protection of LGBTQIA+ participants’ data is a core concern in The PRIDE Study. Working with data in research studies must be grounded in the respect for the people and communities whose information is represented in the data. Thus, we must follow precise and strict guidelines to maintain data privacy and protect sensitive information in The PRIDE Study.

4.1 Data Security and Storage Guidelines

When new members or trainees join the team, their work computer must be encrypted and have institutional security management software installed prior to being granted access to study data. If your computer is not encrypted, please contact your direct supervisor (Annesa Flentje, Daniel Moretti, Mitchell Lunn, or Juno Obedin-Maliver) for support. This is a mandatory prerequisite for all data access privileges.

The PRIDE Study data is stored on secure, HIPAA-compliant servers with restricted access controls. For internal data sharing among The PRIDE Study team, it is recommended that data be shared through Stanford Medicine Box or, if using email, sent through the Secure Email service designated for Moderate or High Risk Data.

For team members who receive access to raw data from The PRIDE Study, it is recommended to never download any data to your personal work device (even if it is encrypted) as this creates unnecessary risk of data breach, loss, or unauthorized access. Instead, store all study data in a secure network drive or institutional cloud storage system, such as Stanford Medicine Box.

When conducting analyses, store raw data files only on the approved secure storage system, specify the secure file path in your integrated development environment, and access and analyze data from the secure location without creating local copies. Refer to Section 6.3.1 for suggested R workflows implementing these practices.

If you need additional guidance on secure data sharing or storage protocols, please contact Nguyen Tran or Mitchell Lunn before handling any study data.

4.2 Human Participant Protection

4.2.1 Training

Each internal team member and/or trainee must complete required trainings on the protection of human subjects when working with The PRIDE Study data. Additional trainings may be required depending on the study.

4.2.2 IRB

The PRIDE Study maintains active IRB approval through Stanford University and the Western Institutional Review Board Copernicus Group (WCG) covering all study activities. IRB requirements for Ancillary Studies differ based on whether they involve secondary data analysis of existing PRIDE Study data or primary data collection through novel questionnaires (see Section 5.4 for more details).

In general, Ancillary Studies using only existing PRIDE Study data do not require modifications to the Stanford or WCG IRB approvals. It is covered under the current Stanford and WCG IRB. For Ancillary Studies administrating new questionnaires, The PRIDE Study submits a WCG IRB modification that includes this new questionnaire once it is finalized.

Regardless of the type of Ancillary Study, any external collaborators should consult their home institution(s) regarding local IRB requirements.

4.2.3 Certificate of Confidentiality

The PRIDE Study is protected by a Certificate of Confidentiality from the National Institutes of Health. This certificate helps protect the privacy of research participants by allowing researchers to refuse to disclose identifying information about participants in any civil, criminal, administrative, legislative, or other proceedings, whether at the federal, state, or local level. The Certificate of Confidentiality protects against compulsory legal demands, such as court orders and subpoenas, for identifying information or identifying characteristics of research participants. This protection helps ensure that sensitive information collected during the study — including sexual orientation, gender identity, and health data — remains confidential and cannot be involuntarily disclosed to third parties.