This page is still under construction. Your feedback is very welcome!
Mail to privacy.gw@uu.nl or privacy.rebo@uu.nl.

The General Data Protection Regulation (GDPR) applies just as much to students who are going to conduct research as it does to researchers affiliated with Utrecht University and to the university as a whole.

Who is responsible?

It is the teacher’s responsibility to ensure that students conducting research that involves the processing of personal data are familiar with the fundamental principles of the GDPR.

So, if students have a question about the GDPR, it’s up to you to answer it. Of course, you don’t know everything either. Are you having trouble formulating an answer? If so, you can always reach out to the privacy officers for support at privacy.gw@uu.nl or privacy.rebo@uu.nl. Only in very exceptional cases the privacy officers will only handle questions from students themselves.

A booklet is available to inform both students and instructors: Are you a student planning to conduct independent research? Here’s what you need to know about the GDPR. Ask your students to review this handy booklet before they begin planning their research. This will allow them to take privacy regulations into account from the very start. This is known as privacy by design.

It is highly recommended that you, as an teacher, read through this booklet carefully so that you at least have a head start on your students.

In the sections below, you will find (among other things) a brief summary of some of the topics covered in the booklet. For an explanation of some basic concepts of the GDPR, please refer to the booklet itself and to the Data Privacy Handbook.

Data Management Plan (DMP)

At the university or faculty level, students are not required to prepare a data management plan. There is one exception to this rule, at least in the Humanities, namely when students wish to conduct research involving participants and, in consultation with you as their instructor, have decided to publish their research in a professional journal. In that case, you may submit a request for ethical review on their behalf to the Faculty Ethics Review Committee for the Humanities (FETC-HUM). The FETC-GW will only consider applications if they are accompanied by a data management plan.

There are other circumstances in which a DMP is recommended. When a student’s research is so extensive or disorganized that chaos threatens, you, as the teacher, can advise the student to draw up a DMP. After all, a DMP is an excellent tool for creating order in impending chaos.

Informing participants

Students working with participants (e.g., interviews or questionnaires) must inform those participants about the purpose and nature of the research and about what is expected of them. The requirements for this information provision by students are the same as those applicable to professional researchers, although the information provided by the student will likely be somewhat more concise. In most cases, the student will write an information letter, but other forms of information provision, such as verbally, via email, or through the introduction of an online questionnaire, are also conceivable.

If the student processes personal data of participants as part of the research (which will very often be the case), the provision of information will need to be more extensive than when the research is conducted completely anonymously. This is because the GDPR requires participants to be informed about various aspects of the processing of their personal data. For example, the student must explain which personal data they will process, how long they will retain that data, how they will secure it, with whom they may share it, and what GDPR rights the participants have. The most important rights are: withdrawing consent, accessing personal data and – if necessary – having it corrected or deleted, and filing a complaint with the UU or the Dutch Data Protection Authority. An example of an information letter can be found in the aforementioned booklet for students.

Asking participants for consent

When students ask their participants for consent, it usually serves a twofold purpose:

  1. The consent must guarantee that the participants – based on all relevant information – have decided to participate voluntarily. This is traditional informed consent or ‘ethical consent’.
  2. If the student intends to process personal data of the participants, those participants must in most cases give consent for this (see below for some exceptions). This is consent within the meaning of the GDPR.

The GDPR places high demands on consent. For consent to be legally valid, it must be given freely, be specific, be based on all relevant information, and be verifiable. You can find more about this, including an example of a consent form, in the aforementioned booklet.

Exceptions to the requirement to obtain consent within the meaning of the GDPR:

  • The student participates in a research project conducted by the lecturer, or takes on part of that research. In many cases, the lecturer can rely on another legal basis, namely the fulfillment of a task of general interest. More information on this can be found on the intranet.
  • In consultation with the lecturer, the student has decided to publish the research in a professional journal, and for that reason, the lecturer requests ethical review from the Faculty Ethics Review Committee (FETC) on behalf of the student. If the FETC approves the research, the student may base the processing of personal data on the aforementioned legal basis of ‘public interest’. This is one of the very few situations in which the student may use this basis.

Data minimization

An important principle of the GDPR is that you do not collect and process more personal data than is necessary to achieve the purpose pursued by the processing. This includes, among other things:

  • That the student investigates whether there are ways to achieve the same goal with less or no personal data (e.g., literature research instead of interviews).
  • That the student only collects the personal data that are really necessary;
  • That it is not permitted to use data collected for a specific purpose (e.g. student administration) for a purpose that is “incompatible” with that purpose (e.g. research by students);
  • That the student attempts to anonymize the collected personal data as soon as possible; and
  • That the student establishes a retention period for the non-anonymized personal data, after which the student deletes the personal data.

Handling personal data safely

Students can be expected to handle the personal data entrusted to them by research participants securely. As a lecturer, try to ensure as much as possible:

  • that students don’t use insecure software (e.g. Dropbox) or insecure hardware (e.g. USB sticks without a password),
  • that they secure their laptop properly,
  • that they don’t include personal data in AI prompts, and
  • that they email securely.

You can find more information in the aforementioned brochure for students.

Participants’ rights

Individuals whose personal data are processed (the so-called data subjects) have various rights. These rights are aimed at giving data subjects maximum control over the personal data relating to them and over the processing thereof. The most important right is that data subjects are informed regarding the processing. After all, if you don’t know that your personal data is being processed, you can’t exercise your other rights either. By writing an information letter or otherwise informing participants, the student complies with this right.

In addition, participants in student research have the right to access their personal data (for example, recordings – if they still exist – or transcripts of interviews) so that they can verify whether all the data is correct. If something is indeed incorrect, the participant has the right to have it corrected. This will often be done in consultation with the student (and with you as the lecturer). If participants wish to have their personal data erased entirely, in most cases it is best for them to simply withdraw their consent for the processing of their personal data. The student is then obliged to delete that personal data, but everything the student has done with it up to that point may remain unchanged. The deletion therefore has no retroactive effect.

An important right of participants is the right to complain. Students are inexperienced in conducting research and can therefore easily make mistakes. Participants can file a complaint with them – or with you as the lecturer – regarding the way in which the student in question has handled their personal data. For support in handling such a complaint, you can contact privacy.gw@uu.nl or privacy.rebo@uu.nl.

If you are unable to reach an agreement with the complainant, the complainant may lodge a complaint with the UU Data Protection Officer (DPO). This is our internal advisor and auditor regarding the GDPR. If the DPO is also unable to satisfy the complainant, the complainant may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). However, let us do everything we can to prevent it from coming to that.

The final thesis

Official student theses are considered so-called forms of academic expression. Within the framework of academic freedom and freedom of (scientific) expression, such expressions can count on legal protection under the GDPR. To give ample scope to these freedoms, Article 43 of the Dutch GDPR Implementing Act (the UAVG) stipulates that the GDPR largely does not apply to such academic expressions (just as it does not apply to journalism, art, and literature). This means that the GDPR cannot be used to silence scientists. (Naturally, other relevant legal restrictions do apply, particularly regarding torts, including defamation and libel.)

Even though the GDPR does not prohibit students from including various personal data in their thesis, it is ethically important for you as a lecturer to ensure that the student handles personal data responsibly in their thesis. This handling must above all be proportionate: personal data should only be published if the academic (or potentially societal) interest prevails over the private interest of the individuals to whom the personal data relates. The student must be able to justify this on a case-by-case basis. Naturally, this is all the more important when a student chooses to publish their thesis in Osiris Zaak (Intranet).

A good working practice is for students to make binding arrangements with the participants in their research regarding how those participants are cited in the thesis. For example, do they wish to be cited anonymously, or may their names be mentioned? In appropriate cases, the student can, of course, consult with the participant again before the thesis is finalized and published.