KEVOS
ArticlesServicesCase studiesAboutContact
ArticlesServicesCase studiesAboutContact
← ArticlesResearch Data Storage, Retention and OwnershipProject Delivery · Research ProjectsLesson 95/115← PrevNext →
GuidePublished 16 Aug 202615 min readBy KEVOS Editorialresearch data retention five yearsresearch data storage requirementsseven year data retention governmentidentifiable re-identifiable non-identifiable
On this page

Ask about this page

KEVOS AIResearch Data Storage, Retention and Ownership

KEVOS knowledge first · trusted web sources when needed

KEVOS/Project Delivery/Research Projects/Research Ethics
Project DeliveryResearch ProjectsCoreResearch Ethics

Research Data Storage, Retention and Ownership

These are the only hard requirements anywhere in the supplied teaching material — everything else in it is guidance, example or prompt. They are also the answer to a question this library previously had to record as unanswered.

Reading time16 minutes
LevelCore
Topic streamResearch Ethics
Source materialResearch Ethics
Updated2026-08-16

In brief

  • Research data must be stored securely, in a safe environment, for a minimum of five years — stated as flowing from a named national code, not as a local preference.
  • The form asks you to outline any variations, and gives one: a minimum of seven years where a state government department is involved.
  • You must declare which of three identifiability classes your data falls into: individually identifiable, re-identifiable (coded), or non-identifiable.
  • Where a recording is transcribed, the tape is still retained as the raw data. A certified transcript is an addition, not a substitute.
  • Student researchers normally own the data they collect; the university normally owns data and results from staff research. Both statements carry the word normally.
  • The source states the duration and the classification. It states no storage medium, no security method, no destruction procedure, and no start date for the clock.

The only hard requirements in the supplied material

Nearly all the ethics material this library is built on is guidance: principles introduced with "typically they include", lists introduced with "things such as", questions posed and left unanswered. This section is different in kind, and the difference is stated by the source itself.

From the source

Retention and identifiability, as stated

"Describe what you will do with the recorded data once it has been analysed. In order for the University to comply with the Australian Code for the Responsible Conduct of Research your research data must be stored securely for a minimum of five years in a safe environment."

"Please outline any variations to this, for example, if the project involves a South Australian government department, data must be retained for a minimum of seven years."

"Describe how, where and in what form the data will be stored and whether the data will be individually identifiable; re-identifiable (coded) data; or non-identifiable data."

5 yrsminimum secure storage
7 yrsthe one variation the form names
3identifiability classes to declare

Two features of that wording are load-bearing. The first is minimum — in both figures. These are floors, not periods after which data must be destroyed, and the source says nothing about an upper bound.

The second is the framing of the seven-year figure. It is introduced as an example of a variation you are asked to outline, not as the only variation that exists. The form's instruction is to identify what applies to your project; the state government department case is illustrative of the kind of thing that changes the answer. Do not read it as an exhaustive list of exceptions.

Source gap

What the requirement does not settle

The code these obligations are attributed to is named in the supplied material and is not reproduced there. Everything on this page is the source's statement of the requirement, not the code's own text.

The source states a duration and two adjectives — securely, and in a safe environment. It states no storage medium, no security standard, no encryption or access-control expectation, no repository, no destruction procedure, and no named custodian.

It also does not say when the five years starts. The retention sentence is attached to what you do with data once it has been analysed, while the recording rule refers to storage at the completion of the project. Those are not the same moment, and neither is defined as the start of the clock.

Nor is there a rule for what happens if you leave the institution or the employer mid-retention, or a definition of what counts as research data as against working files. Take the durations and the classification from here; take the method, the start date and the custody arrangements from the body that will assess you.

The three identifiability classes

The declaration required alongside storage is a three-way classification, and it is the point at which an abstract privacy promise becomes a property of a file.

The three classes, as the form names them

Individually identifiable
The data identifies a specific person — by name, by identifier, or by a combination of attributes that resolves to one individual.
Re-identifiable (coded) data
Identifiers have been replaced by a code, with a separate key that allows the code to be resolved back to the individual.
Non-identifiable data
No specific individual can be identified from the data, and no key exists that would allow it.

WHAT EACH CLASS PERMITS AND WHAT IT COSTS

ClassWhat it still allows you to doWhat it rules outWhat must be true of your storage
Individually identifiableEverything — follow-up, pairing, member checking, individual withdrawalNothing methodologically; the cost is exposure if the store is breachedAccess restricted to those directly involved, and you can name them
Re-identifiable (coded)Follow-up, pairing across time points, honouring a withdrawal requestNothing much — until the key is destroyed, at which point the data becomes non-identifiableKey stored separately from the data, with its own access list and its own disposal decision
Non-identifiableAnalysis and reporting with the lowest exposure of the threeFollow-up, second rounds, transcript return, individual withdrawal — permanentlyNo key anywhere, including in recruitment lists and collection platforms

The three classes are the source's. The consequences in columns two to four are analysis added here.

Caution

The class governs the whole retention period, not just analysis

Whatever class you declare applies for the full minimum five years, not until you finish writing. A coded dataset whose key sits in the same folder is individually identifiable in practice, and it stays that way for the whole retention period.

The most common failure is drift: the study is careful, and then the archive is a single folder containing the coded data, the key, the recruitment list and the recordings. Decide where each of those lives and how long each lives for, before you archive anything.

Which class your design can honestly support — and why one common design choice removes the strongest option — is worked through in Confidentiality and Anonymity.

Recordings: the tape is the raw data

From the source

The recording and transcript rules

"If you recorded your research data on audio or video tape, and will make a certified transcript, the tape must be retained as the raw data to be stored at the completion of the project. A certified transcript of the taped material may also be made and stored."

"It should be clearly explained on the participant information sheet where and how the taped material will be stored, who will have access to the tapes and whether there will be a period during which access will not be available."

"Where tapes are to be retained for any purpose the consent form should incorporate the conditions under which the taped material can be used but release the University from any obligation to reimburse research participants for the use of the recorded material."

The first rule is the one people get wrong. Transcription feels like conversion — the recording becomes text, and the audio is a working file you can delete. It is not. The tape is the raw data, and a certified transcript is something that may also be made and stored.

That has a consequence worth stating plainly: a decision to record is a decision to hold identifiable material for the whole retention period, because a voice is identifying and a face more so. Written notes do not carry that obligation. Choosing your recording medium is therefore a retention decision as much as a data-quality one.

The second and third rules push disclosures back to before consent. Storage location, access list and any embargo period belong on the participant information sheet; the conditions of use, and the release from reimbursement, belong on the consent form. Both documents are written before the first approach — see Voluntary Participation and Informed Consent.

What must be settled before you switch a recorder on

  • Where the taped material will be stored, and in what form
  • Who will have access to the tapes, named rather than described by category
  • Whether there will be a period during which access is not available, and how long
  • Whether you are retaining exclusive access for research purposes, and for how long
  • The conditions under which the taped material may be used, written into the consent form
  • The release from any obligation to reimburse participants for use of the recorded material
  • Where the transcript will live, and whether it is stored separately from the tape

Access and ownership

From the source

Who owns it, as stated

"Specify who (apart from yourself and your supervisors, if applicable) will have access to the research data and results, and any conditions to be placed on that access."

"Detail who will own the data and the results of your research. Student researchers normally own the data that they collect. The University normally owns the data and results of research undertaken by staff."

The slides add: "This provision protects you as the researcher should there be any questions raised about the validity of your research data."

The stated defaults

  • Student researchers normally own the data they collect
  • The university normally owns data and results from research undertaken by staff
  • Access defaults to you and your supervisors
  • Anyone else needs naming, with conditions attached
  • The obligation to follow the named national code covers responsible practice, misconduct, authorship, storage and retention

What the source does not resolve

  • What happens when you are both a student and an employee studying your own workplace
  • Whether an employment contract or intellectual property policy overrides the stated default
  • Whether a sponsoring or hosting organisation can claim ownership as a condition of access
  • Who holds the data after you finish, and who is responsible for it during retention
  • How ownership interacts with the confidentiality promise made to participants

The word to hold on to is normally. It appears in both sentences, and it is doing the work of an entire clause elsewhere — the default holds unless something else says otherwise, and the source does not say what that something else might be.

For this readership the conflict is not hypothetical. A practising project manager studying their own organisation may be a student in one relationship and an employee in another, with a contract that speaks to work product. Where a sponsor is involved, the independence question sits alongside the ownership one — see Sponsors and Researcher Independence.

Note

Why the form treats ownership as protective

The slides attach a rationale to this part that reframes it: specifying access and ownership "protects you as the researcher should there be any questions raised about the validity of your research data".

That is the same logic the source applies to ethics review itself, which it says protects the organisation and the researcher as well as participants. Retained raw data with a documented custody position is what allows a disputed finding to be checked rather than argued about — which is a reason to take the retention obligation seriously beyond the fact that it is one.

A gap this library previously had to leave open

The earlier process material in this library reaches data storage as the final step of a ten-step model, and says only that your research report and your data need to be stored appropriately, and that the institution has specific requirements in this matter. Those requirements were not in the material available at the time, and the page recording that step had to say so.

This page closes that gap. The requirements referred to there are the ones set out above: a minimum of five years' secure storage in a safe environment, a minimum of seven where a state government department is involved, a declared identifiability class, retention of tapes as raw data, and a stated position on access and ownership. Steps 9-10: Writing the Report and Storing the Data should now be read alongside this page rather than on its own.

Caution

What closing the gap does not mean

The step said the institution has specific requirements. What has been supplied is one form's statement of those requirements, attributed to a national code that is not itself in the dataset.

So the substance is now known — durations, classification, recording rules, ownership defaults — and the authoritative text is still not. Treat this page as the shape of the obligation and confirm the current detail with your approving body before you build an archive around it.

Building retention into the project rather than after it

Retention is the only obligation in the ethics material that outlives the project by years, and it is the only one you cannot fix retrospectively — a recording deleted in the week you submitted cannot be produced in year three.

  1. In the applicationDeclare the recording medium, the storage form and location, the identifiability class, the retention period that applies, and who has access on what conditions.
  2. Before the first approachPut storage location, access list and any embargo on the participant information sheet, and the conditions of use on the consent form.
  3. During collectionKeep the key, the recruitment list and the coded data in separate places from the outset. Separating them later is a migration; separating them now is a habit.
  4. At analysisWork from coded extracts where the class allows it, and keep raw recordings out of general working folders and off shared drives that were never in your access list.
  5. At completionArchive the raw data — including tapes — in the stated form and location. Record what was archived, where, in what class, by whom, and the date the retention period is measured from.
  6. Through the retention periodThe access conditions and confidentiality promise continue to apply. If you change institution or employer, establish who now holds custody before you move.
  7. At the end of the minimum periodThe obligation is a minimum, not an expiry. Check the position before disposing of anything, and record whatever you decide.
Check before you proceed

The year-three test

Imagine a question is raised about one of your findings three years after submission — not an accusation, just a query about how a number was produced.

Can you locate the raw data? Do you still hold the recording, or only the transcript? Do you know who has access to it now? Can you show which identifiability class it was archived under and what participants were told about it?

If any answer is no, the retention obligation has not been met, whatever the file dates say.

How these declarations sit inside the application as a whole is in Writing an Ethics Application.

What to carry forward

  1. Minimum five years' secure storage in a safe environment, attributed to a named national code — the only hard requirement in the supplied material.
  2. The seven-year figure is offered as one example of a variation you are asked to identify, not as the only exception there is.
  3. Declare one of three identifiability classes, and remember it governs the whole retention period rather than just the analysis phase.
  4. A certified transcript does not replace the tape. Recording is a decision to hold identifiable material for years.
  5. Storage, access and embargo go on the information sheet; conditions of use and the reimbursement release go on the consent form — both before consent.
  6. Students normally own data they collect and the university normally owns staff research data. Normally is not always; check your own arrangement.
  7. The source gives durations and a classification, not a method, a start date or a custody rule. Get those from the body that will assess you.

Frequently asked questions

How long do I have to keep my research data?

The supplied source states a minimum of five years, stored securely in a safe environment, as a requirement flowing from a named national code. It then asks you to outline any variations, giving the example of a project involving a state government department, where the minimum is seven years. Both figures are floors rather than expiry dates, and the source sets no upper limit.

When does the five years start?

The supplied material does not say. The retention sentence is attached to what you do with the data once it has been analysed, while the recording rule refers to storage at the completion of the project, and neither is defined as the start of the clock. Establish the start date with your approving body and record it alongside the archive.

Can I delete the audio once I have a transcript?

No. Where research data was recorded on audio or video and a certified transcript will be made, the tape must be retained as the raw data to be stored at the completion of the project; the transcript may also be made and stored. The transcript is an addition to the raw data, not a replacement, so deleting the recording removes the thing you are required to keep.

Who owns the data — me, my university or my employer?

The form states that student researchers normally own the data they collect and that the university normally owns data and results from research undertaken by staff. The qualifier matters: if you are a staff member, or a student whose employment contract or workplace agreement addresses research outputs, the default may be displaced. The source states the defaults and does not resolve that conflict.

Does the source say how the data has to be stored?

No. It requires storage that is secure and in a safe environment, and asks you to describe how, where and in what form — but it specifies no medium, no encryption or access-control standard, no repository and no destruction procedure. The method is yours to propose and defend, and worth confirming against whatever your approving body expects to see.

What if I change employer during the retention period?

The supplied material is silent on this, as it is on who holds custody after a project ends. Because the obligation continues and the access conditions you declared continue with it, treat a move as a custody question to settle in advance rather than an administrative detail — and get the position in writing from whoever will hold the archive.

References and source attribution

  1. Australian Code for the Responsible Conduct of Research (2007) — named in the supplied source as the instrument behind the retention periods, the identifiability classification and the obligations on responsible research practice, misconduct, authorship and data retention. The code itself is not reproduced in the supplied material.
  2. Cooper, D. & Schindler, P. 2008, Business Research Methods, 10th ed., McGraw-Hill — the text the supplied source draws on for its treatment of research ethics.
  3. Quinlan, C. 2011, Business Research Methods, 1st ed., Cengage Publishing, Chapter 3 — the prescribed reading accompanying the ethics material.
  4. Trochim, W. M. K. 2006, Research Methods Knowledge Base (http://www.socialresearchmethods.net/kb/probform.php) — the source of the excerpt on ethical protections underlying the confidentiality obligations that retention must carry.
  5. The supplied teaching source: consolidated weekly teaching notes and slide material on research ethics and on the research process, which supplies the retention, identifiability, recording and ownership statements quoted on this page, and the ten-step process whose data storage step they complete.

Suggested questions for Ask KEVOS

  • Draft the data recording, storage and retention section of my ethics application for audio-recorded interviews.
  • Work out which retention period applies to my project and what evidence I need for that decision.
  • Design an archive layout that keeps the coded data, the key, the recruitment list and the recordings properly separated.
  • Write the storage, access and embargo wording for my participant information sheet and consent form.
  • I am a staff member studying my own workplace. Help me work out who owns the data and what to check first.

Related KEVOS knowledge

Writing an Ethics ApplicationCore · research ethicsConfidentiality and AnonymityCore · research ethicsSteps 9-10: Writing the Report and Storing the DataCore · research processVoluntary Participation and Informed ConsentCore · research ethicsEthics Review and Approval ProcessesCore · research ethicsSponsors and Researcher IndependenceCore · research ethics
KEVOS® · Project Delivery · Research Projects Page KVS-PM-RES-0095 · v1.0.0 · content 2026.08 Last reviewed 2026-08-16

Continue learning

Writing an Ethics ApplicationGuide · Research ProjectsNEXT LESSON →Plagiarism and Research IntegrityGuide · Research ProjectsEthics Review and Approval ProcessesGuide · Research ProjectsSponsors and Researcher IndependenceGuide · Research Projects
KEVOS · Engineering, manufacturing and project improvement
ArticlesServicesCase studiesAboutContact
© 2026 KEVOS®