Skip to main content
v2026.11,772 entries · CC-BY 4.0
Dictionary termTrack BProposedv2026.2

Sensitive-data repository

A repository specifically designed to hold sensitive research data — typically personal data, health data, criminal-justice data, commercially-confidential data, or culturally-sensitive Indigenous data — with enhanced access controls, audit logging, contractual access conditions, and (often) a secure analysis environment.

ByCASRAI Editorial Board
· Last updated 22 Aug 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about Sensitive-data repository

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    EGA (European Genome-phenome Archive) for consented human-subject genomic data.

  • Is an instance

    dbGaP at NCBI for sensitive genotype-phenotype data.

Counter-examples

Looks similar, but isn't

  • Not an instance

    An open repository like Zenodo is not a sensitive-data repository.

  • Not an instance

    A clinical electronic health-record system is not a research-purpose sensitive-data repository.

Editorial commentary

A sensitive-data repository is a repository purpose-built to hold sensitive research data — typically identifiable or re-identifiable human-subjects data, health data, criminal-justice data, commercially confidential data, or culturally sensitive Indigenous data — using controlled-access deposit rather than open download. Access to a specific dataset normally requires an application, an ethics/data-access-committee review, and a signed data use agreement, with audit logging of who accessed what and when.

Two distinct control models — and why this term is not the same as “data safe haven”

It is worth being precise about a real, easily blurred distinction. A sensitive-data repository, in the sense used here, is fundamentally a controlled-access deposit and retrieval model: an approved researcher applies for access and, once approved, typically downloads the requested files under the terms of the data use agreement — the repository’s job is gatekeeping who gets a copy, and of what, not preventing the data from ever leaving. A data safe haven (near-synonymous internationally with a trusted research environment) is a different, stricter control model built around the Five Safes framework, where the data structurally never leaves a controlled analysis environment at all — the researcher’s analysis code goes to the data, not the reverse, and only disclosure-checked outputs are released. In practice these models are often combined (a sensitive-data repository may require analysis to happen inside an attached secure environment rather than permitting bulk download), but they are answering different questions and a page or policy that uses the two terms interchangeably is eliding a real operational difference researchers need to plan around.

Real examples

The European Genome-phenome Archive (EGA) holds consented human-subject genomic and phenotypic data under a controlled-access application model. dbGaP, operated by NCBI, holds sensitive genotype-phenotype data under a comparable application-and-approval process, with data made available to approved investigators at approved institutions. Both are commonly cited alongside safe-haven-style national health-data services (see the data safe haven entry for examples of that model specifically), and a single national data ecosystem may operate both a controlled-access repository and a safe haven side by side for different data-sensitivity tiers.

Worked example / counter-example

A consortium depositing consented rare-disease genomic data in EGA, with each approved external researcher signing a data use agreement before download, is a sensitive-data repository in operation. An open repository such as Zenodo, with no access-approval step, is not a sensitive-data repository regardless of what is deposited in it — and a clinical electronic health-record system used only for direct patient care, with no research-access governance layer at all, is not a research-purpose sensitive-data repository either.

References

  • Lappalainen, I. et al., “The European Genome-phenome Archive of human data consented for biomedical research,” Nature Genetics 47(7), 2015.

Also known as

Controlled-access repository

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Sensitive-data repository"
      vocab-term-identifier="https://casrai.org/dictionary/term/sensitive-data-repository" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/sensitive-data-repository",
  "name": "Sensitive-data repository",
  "identifier": "https://casrai.org/dictionary/term/sensitive-data-repository",
  "description": "A repository specifically designed to hold sensitive research data — typically personal data, health data, criminal-justice data, commercially-confidential data, or culturally-sensitive Indigenous data — with enhanced access controls, audit logging, contractual access conditions, and (often) a secure analysis environment.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/data-infrastructure#set",
  "url": "https://casrai.org/dictionary/term/sensitive-data-repository",
  "sameAs": [
    "Controlled-access repository"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-05-21T02:22:47",
  "dateModified": "2026-08-22T16:26:42",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.