Privacy in Research
The Texas A&M University Privacy Office supports researchers by helping ensure that studies involving identifiable data are designed and conducted in a privacy‑protective, compliant, and practical way. Our goal is to support your research, reduce delays, and clarify privacy expectations—while allowing your study to move forward efficiently.
HOW IS THE PRIVACY OFFICE INVOLVED IN RESEARCH?
The Privacy Office conducts privacy ancillary reviews across multiple research workflows at Texas A&M University. We are not limited to a single system or process.
You may see the Privacy Office involved when a research project includes identifiable data (and coded data), including:
- IRB‑reviewed studies, when direct or indirect identifiers are collected or used;
- Maestro submissions, such as data use agreements (DUAs), data transfer agreements, or sponsored projects involving identifiable data;
- Externally funded or collaborative research, where contracts, funders, or partners impose privacy or data‑handling requirements; and
- Other research contexts where identifiable data are collected, accessed, shared, retained, linked, or analyzed—even if the project does not meet the definition of human‑subjects research under the IRB.
Our role is to understand what data you are using, why you are using them, and how privacy risks are managed, so we can provide proportionate, study‑specific guidance.
Privacy by Design: What Does This Means for PIs?
The Privacy Office encourages a privacy‑by‑design approach in research. In practice, this means:
- collecting only the data necessary to achieve the study purpose;
- limiting the use and retention of identifiers;
- choosing tools and storage locations that match the sensitivity of the data; and
- making sure privacy practices described in protocols, consent forms, and agreements align with how the study actually operates.
Our Privacy by Design in Research guidance document (https://privacy.tamu.edu/privacy-by-design-in-research-practical-guide-for-principal-investigators/) explains these concepts and is intended to help PIs think through privacy considerations early—before they become review comments or revisions. It is a resource, not a checklist, and complements IRB, sponsor, and compliance requirements.
What Do We Typically Need to Complete a Privacy Review?
When the Privacy Office is asked to review a research project, having the right information up front helps us complete the review quickly and minimize follow‑up questions. Depending on the context, we typically request:
- A data dictionary
- A list or description of the data elements involved in the study, including which fields are identifiable, coded, or de‑identified.
- A list or description of the data elements involved in the study, including which fields are identifiable, coded, or de‑identified.
- Relevant agreements or documents (if applicable)
- For example: data use agreements, data transfer agreements, memoranda of understanding, sponsor data requirements, collaboration agreements, grant document.
- For example: data use agreements, data transfer agreements, memoranda of understanding, sponsor data requirements, collaboration agreements, grant document.
- A scope of work – a description of the study scope
- In the IRB context, this is usually the research protocol.
- In Maestro or other non‑IRB contexts, this can be a short scope‑of‑work document summarizing:
- the purpose of the project;
- how data are collected, accessed, or received;
- how data are used, shared, and stored; and
- the scope and duration of the activity.
- In the IRB context, this is usually the research protocol.
This information allows us to understand data flows and tailor our feedback to the specific project, rather than applying one‑size‑fits‑all recommendations.
What to Expect During an IRB Privacy Ancillary Review?
If your IRB study involves identifiable data, the Privacy Office may ask targeted follow‑up questions during the IRB review process. These questions are meant to clarify data handling and ensure consistency across study materials.
The document “Privacy Ancillary Review – Sample Questions” (https://privacy.tamu.edu/privacy-ancillary-review-sample-questions/) provides a PI‑friendly overview of the types of questions we often ask—such as questions about identifiers, data retention, tools, withdrawals, or data sharing.
Key points to know:
- Not all questions apply to every study;
- Many answers are already in your protocol, consent form, or data management plan; and
- Clear responses up front usually reduce review time and back‑and‑forth.
Our Role: A Research Partner, Not a Roadblock
The Privacy Office’s role in research is advisory and risk‑focused. We work collaboratively with:
- Principal Investigators and study teams,
- the IRB,
- Sponsored Research Services,
- IT and security partners, and
- other campus offices,
to help identify practical safeguards and align privacy expectations across institutional processes.
If you have questions about privacy in research, you can engage the Privacy Office through the IRB or Maestro workflows, or by contacting us at privacy@tamu.edu.
Additional Research Resources can be found at https://privacy.tamu.edu/research/.

