Skip to main content
v2026.11,772 entries · CC-BY 4.0
Dictionary termTrack BProposedv2026.2

Data safe haven

A secure data-handling environment that allows controlled, audited access to sensitive datasets for approved research, applying technical, physical, and procedural safeguards; effectively a synonym for trusted research environment (TRE) in much current usage, though the term has older roots in NHS information governance.

ByCASRAI Editorial Board
· Last updated 22 Aug 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about Data safe haven

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    The Scottish eDRIS Safe Haven providing access to linked NHS Scotland data for approved researchers.

  • Is an instance

    A university-hosted Safe Haven implementing the Five Safes for a sensitive-data research project.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A research laptop in a locked office is not a data safe haven.

  • Not an instance

    An open-data portal is not a data safe haven.

Editorial commentary

The ‘data safe haven’ terminology was used in NHS England and Scottish government information-governance literature from the late 2000s onwards, predating the dominance of ‘trusted research environment’ (TRE) as the more internationally recognised term. In current practice the two terms overlap almost completely: a data safe haven is a secure, audited computing environment that lets approved researchers analyse sensitive — often identifiable or potentially re-identifiable — datasets without the underlying data ever leaving the controlled environment. Only disclosure-checked, aggregated, or otherwise approved outputs are released to the researcher.

The Five Safes framework

Most data safe havens are organised around the Five Safes framework, originally developed for official statistics access and widely adopted across health-data and social-science secure environments: safe people (only vetted, approved researchers are granted access), safe projects (access is scoped to an approved research purpose), safe settings (technical controls prevent data leaving the environment — no local downloads, controlled export review), safe data (data is de-identified or pseudonymised to the extent the project allows), and safe outputs (results are checked for disclosure risk before release). A safe haven typically implements controls across most or all five dimensions at once, not just the technical “safe setting.”

How it differs from an open data repository

A data safe haven is the opposite operating model from an open-access repository: an open repository maximises reuse by removing access friction once data is deposited, while a safe haven exists precisely because the data cannot be safely made open at all — re-identification risk, consent scope, or legal restriction (see HIPAA or an equivalent national health-data law) rules out open deposit. Which uses are permitted inside the safe haven is typically documented in a data use agreement, and a data protection impact assessment is a common precondition for establishing a new safe-haven project. Where individual-level control over future uses also matters, see dynamic consent, a complementary participant-facing mechanism rather than a substitute for the safe haven’s own technical controls.

Worked example

The Scottish eDRIS Safe Haven links de-identified NHS Scotland administrative and health data for approved research projects; researchers log in to a controlled virtual environment, run their analysis where the data lives, and only export disclosure-checked results. Wales’s SAIL Databank operates on the same underlying model.

Counter-example

A researcher’s password-protected laptop, even in a locked office, is not a data safe haven — the data itself has left the controlled environment and is subject only to whatever device-level security the researcher happens to maintain, with no independent output disclosure check.

References

  • NHS Scotland, ‘Charter for Safe Havens in Scotland’ (2015). Information Governance Review (Caldicott 2), ‘To Share or Not to Share’ (UK Department of Health, 2013).

Also known as

Safe haven · Data Safe Haven (NHS)

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data safe haven"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-safe-haven" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-safe-haven",
  "name": "Data safe haven",
  "identifier": "https://casrai.org/dictionary/term/data-safe-haven",
  "description": "A secure data-handling environment that allows controlled, audited access to sensitive datasets for approved research, applying technical, physical, and procedural safeguards; effectively a synonym for trusted research environment (TRE) in much current usage, though the term has older roots in NHS information governance.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/data-infrastructure#set",
  "url": "https://casrai.org/dictionary/term/data-safe-haven",
  "sameAs": [
    "Safe haven",
    "Data Safe Haven (NHS)"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-05-21T02:22:48",
  "dateModified": "2026-08-22T15:37:04",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.