Handling information responsibly across the Commons
Privacy, Data, Consent, and Confidentiality explains how the Commons approaches information, personal data, consent, confidentiality, access, restricted material, research information, event records, publication, preservation, and related responsibilities.
The Commons depends on the responsible use of information.
Information may help people find knowledge, participate in Community Groups, access Working Spaces, attend events, apply for Membership, contribute to research, submit manuscripts, deposit materials, join Partnerships, receive support, make enquiries, and use Commons resources.
Information may also create risks.
It may concern individuals, communities, institutions, research participants, contributors, Members, authors, reviewers, volunteers, event participants, partners, funders, providers, or other people whose privacy, dignity, safety, rights, cultural interests, professional interests, or legal interests require protection.
The Commons should handle information in a way that is lawful, fair, transparent, proportionate, secure, respectful, and consistent with its Principles and Values.
This page explains the Commons’ wider information-governance framework.
It works alongside:
- The Commons Privacy Policy
- The Cookie Notice
- Terms and Conditions
- Membership conditions
- Community Group and Working Space conditions
- Event registration, recording, photography, and participation notices
- Research protocols, ethics arrangements, and data-management plans
- Journal author, reviewer, editor, and publication guidance
- Repository Deposit and Access Conditions
- Confidentiality agreements
- Data-sharing agreements
- Partnership, funding, sponsorship, provider, and service agreements
- Safeguarding procedures
- Accessibility and participation-support guidance
- Other applicable policies, notices, agreements, and legal requirements
Where a legal Privacy Policy, contract, research protocol, data-sharing agreement, safeguarding requirement, Repository condition, applicable law, or other specific arrangement imposes a more detailed or stricter requirement, that requirement applies.
Privacy and Information Enquiries
Use the Privacy, Data, and Confidentiality route if you need help with:
- Personal information
- Privacy
- Consent
- Confidentiality
- Access to information
- Restricted information
- Research data
- Event recordings, photographs, transcripts, or chat records
- Membership information
- Repository deposit or access
- Data correction, restriction, deletion, or objection requests
- A suspected information-security or data-protection issue
- Intellectual property, attribution, authorship, licensing, or reuse
- Another information-related concern
Read the Privacy Policy
Read the Cookie Notice
Make a Privacy, Data, or Confidentiality Enquiry
Why Privacy, Data, Consent, and Confidentiality Matter
The Commons may collect, create, receive, use, preserve, share, restrict, archive, or dispose of information through its activity.
This may include information connected to:
- Public access and website use
- Account registration
- Individual Membership
- Institutional Membership
- Authorized institutional representatives
- Community Groups
- Working Spaces
- Critical Issues
- Events and Learning
- Volunteer and Contributor Opportunities
- Calls and Opportunities
- Commissioned Research
- Research participation
- Journal Publication
- Repository deposit, access, preservation, and discovery
- Partnerships and External Collaboration
- Funding, Sponsorship, and Support
- Contact and Support
- Governance, decision-making, financial administration, and record keeping
- Safeguarding, conduct, complaints, review, appeal, and incident management
The Commons should not collect, use, retain, share, or preserve information merely because it may be useful in the future.
Information handling should have a clear purpose.
The Commons should collect only what is necessary, use it only in appropriate ways, limit access to people with a legitimate need, protect it against unauthorized use or loss, retain it for an appropriate period, and dispose of it securely when it is no longer required.
The Commons should also recognize that not all information is the same.
A public Journal Publication, an individual’s Membership application, a confidential research interview, a Working Space discussion, a Repository metadata record, a funding agreement, a safeguarding concern, a community contribution, and a culturally protected record may each require different treatment.
Types of Information
The Commons may handle different categories of information.
Public information
Public information is material that the Commons has made openly available.
It may include:
- Public website content
- Public guidance
- Public Critical Issues
- Public event information
- Open Calls and Opportunities
- Public Journal Publications
- Open Repository records
- Publicly available reports, resources, tools, recordings, summaries, and learning materials
- Public announcements
- Approved public communications
Public information may still be subject to copyright, licensing, attribution, terms of use, access conditions, preservation requirements, or other restrictions.
Public availability does not mean that material may be copied, altered, commercialized, republished, misrepresented, or used without regard to its applicable rights and conditions.
Personal information
Personal information is information that relates to an identifiable or potentially identifiable person.
It may include:
- Name
- Contact details
- Account details
- Profile information
- Professional, academic, institutional, community, or other background
- Membership information
- Event registration and attendance information
- Communication preferences
- Application, submission, nomination, role, or contribution information
- Payment, expenses, honoraria, or fee information
- Correspondence, enquiries, support requests, complaints, or feedback
- Images, recordings, voice, video, or other media where a person may be identifiable
- Online identifiers, system records, or usage information where applicable
- Other information that relates to an identifiable person
Sensitive or special-category information
Some information may require a higher level of care because of its nature, sensitivity, or possible consequences if used, disclosed, or accessed inappropriately.
This may include information relating to:
- Health, disability, access, communication, or support needs
- Safeguarding concerns
- Children or vulnerable people
- Race, ethnicity, tribe, nationality, religion, belief, gender, sexual orientation, or identity
- Political, policy, advocacy, regulatory, or public-position commitments
- Financial hardship or other economic circumstances
- Criminal allegations, investigations, convictions, or proceedings
- Personal, traumatic, private, or lived experience
- Research participants
- Cultural, traditional, sacred, or community-protected knowledge
- Biometric, genetic, or other highly sensitive information where applicable
- Confidential professional, institutional, commercial, legal, or security-related information
The Commons should collect sensitive information only where necessary, lawful, proportionate, and supported by appropriate safeguards.
Institutional information
Institutional information may relate to an organization, institution, department, network, professional body, community organization, public body, partner, funder, provider, or another entity.
It may include:
- Organizational identity
- Legal or operational information
- Authorized representatives
- Institutional interests
- Membership details
- Partnership, funding, sponsorship, provider, or service arrangements
- Institutional resources, collections, facilities, data, or expertise
- Contracts, agreements, reports, invoices, and financial records
- Other organizational information relevant to Commons activity
Institutional information may still include personal information, confidential information, commercial information, or other protected material.
Research information and research data
Research information may include:
- Research questions
- Concept Notes
- Commission Requests
- Commissioning Briefs
- Research protocols
- Ethics information
- Participant information
- Consent records
- Interview, survey, observation, workshop, consultation, or other research material
- Research notes
- Data descriptions
- Datasets
- Analytical material
- Findings
- Draft reports
- Final reports
- Methodology
- Review records
- Dissemination materials
- Repository records
- Data-management plans
- Project governance and administration records
Research information may be public, confidential, restricted, anonymised, pseudonymised, controlled-access, embargoed, metadata-only, or otherwise subject to stated conditions.
Confidential information
Confidential information is information that should not be made public or shared beyond authorized people.
It may include:
- Personal information
- Research participant information
- Unpublished manuscripts
- Peer-review information
- Editorial discussion
- Working Space material
- Private Community Group discussion
- Project records
- Partnership discussions
- Financial information
- Legal advice
- Commercial information
- Provider proposals
- Security information
- Safeguarding records
- Restricted Repository material
- Other information shared in confidence or subject to an obligation of confidentiality
Confidential information should be used only for the agreed, authorized, lawful, and necessary purpose.
Restricted and controlled information
Restricted information is material that is available only to people who meet specific access conditions.
Controlled information is material subject to additional access, handling, security, ethical, legal, cultural, contractual, or governance requirements.
Restricted or controlled information may include:
- Confidential project information
- Personal data
- Sensitive data
- Research data
- Restricted Repository records
- Embargoed publications
- Working Space material
- Data requiring approved access
- Information subject to a confidentiality agreement
- Information subject to a data-sharing agreement
- Material that requires ethical, institutional, legal, or project approval
- Culturally protected knowledge
- Commercially sensitive information
- Information connected to a safeguarding, conduct, research-integrity, editorial-integrity, financial, or legal matter
Restricted or controlled information should not be shared merely because a person is a Member, contributor, partner, funder, sponsor, provider, institution, or participant in related activity.
Access should depend on need, role, authority, purpose, applicable permissions, and relevant conditions.
Culturally protected and community-sensitive knowledge
Some knowledge, records, practices, stories, images, language, names, materials, or experiences may have cultural, community, historical, spiritual, traditional, collective, ethical, or other forms of protection.
The Commons should not assume that information may be made public, deposited, recorded, reused, translated, summarized, published, or preserved merely because it has been shared in a discussion, event, consultation, research project, Community Group, Working Space, or Partnership.
Where culturally protected or community-sensitive knowledge is involved, the Commons should consider:
- Who has authority to share the knowledge
- Whether individual or collective consent is required
- Whether there are cultural, traditional, ethical, spiritual, historical, or community restrictions
- Whether attribution, anonymity, collective recognition, or another arrangement is appropriate
- Whether the material should be public, restricted, controlled, embargoed, metadata-only, withdrawn, returned, preserved under specified conditions, or not retained
- Whether community representatives, knowledge holders, advisers, or other appropriate people should be involved in access, use, preservation, and publication decisions
Anonymised and pseudonymised information
Anonymised information has been processed so that a person cannot reasonably be identified from it.
Pseudonymised information has had direct identifiers replaced or separated, but may still be capable of being linked to a person through additional information.
The Commons should not assume that removing a name alone makes information anonymous.
Context, location, role, event, institution, combination of details, quotations, images, dates, recordings, or other information may still make a person identifiable.
Metadata and metadata-only records
Metadata is descriptive information about an item, record, event, publication, resource, dataset, project, collection, or other material.
Metadata may include title, author, contributor, date, version, description, subject, rights, access conditions, citation, identifier, provenance, preservation information, or other contextual details.
A metadata-only record provides information about material that is not itself openly available.
The Commons may use metadata-only records to support discovery, citation, transparency, accountability, preservation, or future access enquiries while protecting confidential, restricted, embargoed, personal, culturally protected, or otherwise unavailable content.
Information Access and Classification
The Commons may classify information according to the access conditions that apply.
Public access
Public material may be accessed by anyone, subject to applicable terms, rights, licenses, attribution requirements, and technical conditions.
Member access
Member-access material may be available to eligible Individual Members or Institutional Members through authorized representatives, subject to Membership category, permissions, and applicable conditions.
Community Group access
Community Group material may be available to people who have joined a particular eligible Group or who otherwise meet that Group’s participation conditions.
Working Space access
Working Space material may be available only to people who have a relevant role, invitation, permission, project involvement, Community Group condition, confidentiality agreement, data authorization, safeguarding approval, training requirement, or another approved access route.
Project or role-based access
Project or role-based material may be available only to people formally involved in a specified project, research activity, event, publication process, consultation, Partnership, funding arrangement, provider process, editorial process, review process, or other defined activity.
Restricted access
Restricted material may be available only on request or only to eligible people who satisfy stated conditions.
Those conditions may include legitimate purpose, identity verification, ethical approval, institutional approval, data agreement, confidentiality agreement, legal authority, role appointment, training, safeguarding condition, community approval, or another appropriate safeguard.
Controlled access
Controlled-access material may require a formal approval process, agreement, monitored use, secure environment, restricted copying, prohibition on onward sharing, reporting, or another specified condition.
Embargoed access
Embargoed material may be unavailable for a stated period because it is under review, awaiting publication, subject to legal, contractual, commercial, ethical, cultural, research, or other restrictions.
Metadata-only access
Metadata-only access allows users to discover that material exists and understand its context, without accessing the content itself.
The Commons should state access conditions clearly where possible.
A person should not assume that access to one item, Community Group, Working Space, event, project, record, Partnership, or role gives them access to other restricted material.
What the Commons May Collect
The Commons may collect information directly from a person, from an institution acting through an authorized representative, through a permitted third party, from publicly available sources where appropriate, or through activity carried out within the Commons.
Information may be collected when a person:
- Uses a Commons page, service, system, or form
- Creates an account
- Applies for Individual Membership
- Applies for Institutional Membership
- Acts as an authorized representative
- Joins or participates in a Community Group
- Requests or receives Working Space access
- Registers for or attends an event
- Participates in a learning activity
- Makes an enquiry
- Requests accessibility or participation support
- Raises a concern, complaint, review, or appeal
- Applies for or undertakes a volunteer, contributor, reviewer, editor, facilitator, adviser, project, provider, or other role
- Responds to a Call or Opportunity
- Submits a Commission Request, Concept Note, Event Proposal, manuscript, resource, Repository item, Partnership enquiry, funding proposal, sponsorship proposal, or other contribution
- Participates in research, consultation, evaluation, review, or community engagement
- Deposits, accesses, cites, or requests access to Repository material
- Enters a Partnership, External Collaboration, funding, sponsorship, donation, provider, service, or other agreement
- Receives payment, reimbursement, honoraria, funding, or another financial arrangement
- Communicates with the Commons
- Uses a service, platform, event system, or other Commons technology
The Commons should collect only information that is relevant and necessary for the stated purpose.
The Commons should not require a person to provide personal, sensitive, financial, medical, family, cultural, professional, institutional, or other information that is not reasonably necessary for the activity concerned.
Why the Commons May Use Information
The Commons may use information for legitimate and stated purposes, including:
- Providing public information, resources, services, events, learning, publications, Repository access, and other Commons activity
- Creating and managing accounts
- Administering Membership
- Managing Community Group and Working Space participation
- Registering and supporting event participants
- Delivering Events and Learning activity
- Managing applications, submissions, nominations, Calls, opportunities, appointments, and roles
- Administering research, research participation, projects, ethics, governance, evaluation, dissemination, and preservation
- Managing Journal submissions, peer review, editorial activity, publication, correction, retraction, authorship, and attribution
- Managing Repository deposit, metadata, access, preservation, citation, licensing, and discovery
- Administering Partnerships, External Collaboration, funding, sponsorship, donations, service arrangements, procurement, provider engagement, and other agreements
- Providing accessibility, participation support, reasonable adjustments, translation, interpretation, communication, or other support
- Managing payment, fees, expenses, honoraria, grants, donations, funding, sponsorship, financial records, and reporting
- Responding to enquiries, requests, concerns, complaints, review requests, appeals, privacy enquiries, safeguarding matters, and incidents
- Protecting people, systems, information, rights, safety, integrity, and the public-interest purpose of the Commons
- Meeting applicable legal, ethical, institutional, contractual, financial, regulatory, safeguarding, governance, and record-management requirements
- Improving Commons pages, systems, services, accessibility, events, participation routes, resources, and activity
- Preserving material of lasting scholarly, professional, institutional, cultural, community, or public-interest value where appropriate and authorized
The Commons should not use information for a new or materially different purpose without considering whether that use is appropriate, lawful, transparent, proportionate, and consistent with the information provided to the person or organization concerned.
Consent and Participation
Consent is one way in which a person may agree to a defined use of their information, contribution, image, recording, participation, research data, or other material.
Consent should be informed, meaningful, voluntary, specific to the relevant activity where appropriate, and recorded in a suitable form.
The Commons may need consent when, for example, a person agrees to:
- Participate in research
- Contribute personal or lived experience
- Be recorded, photographed, filmed, or quoted
- Have an event contribution published, transcribed, preserved, or shared
- Receive certain non-essential communications
- Deposit or share material where consent is required
- Participate in a consultation, case study, interview, workshop, or evaluation
- Share personal information with a specified third party
- Use their name, biography, profile, image, voice, or contribution in a stated way
- Participate in a community, cultural, research, or other activity that requires specific agreement
Consent should not be assumed merely because:
- A person is a Member
- A person attends an event
- A person participates in a Community Group or Working Space
- A person has submitted an application or manuscript
- A person has previously contributed
- A person is affiliated with an institution
- A person receives funding, payment, expenses, an honorarium, or another benefit
- A person has entered a public or digital space
- A person does not object immediately
The Commons should explain clearly:
- What a person is being asked to agree to
- Why the agreement is needed
- What information, material, contribution, recording, image, data, or activity is involved
- How it may be used
- Who may have access
- Whether it may be public, restricted, published, deposited, preserved, shared, reused, or transferred
- What risks, limitations, or conditions apply
- Whether participation is voluntary
- Whether payment, expenses, honoraria, recognition, or another arrangement applies
- Whether and how a person may withdraw or change their consent
- What may happen to material already published, shared, preserved, relied on, anonymised, aggregated, or incorporated into an output if consent is withdrawn
A person may withdraw consent through the appropriate route where consent is the relevant basis for the activity.
Withdrawal may not always require the removal of material that has already been lawfully published, anonymised, aggregated, preserved under a legitimate retention requirement, incorporated into a research output, or retained to meet legal, ethical, safeguarding, financial, contractual, or record-management obligations.
The Commons should explain applicable limits clearly and respectfully.
Confidentiality and Its Limits
Confidentiality protects information shared in circumstances where it should not be disclosed beyond authorized people.
The Commons may apply confidentiality arrangements to:
- Membership information
- Community Group discussion
- Working Space material
- Project records
- Research information
- Research participant information
- Journal manuscripts and peer-review information
- Editorial discussion
- Repository access requests
- Partnership and External Collaboration information
- Funding, sponsorship, donor, provider, and financial information
- Safeguarding, conduct, complaint, review, and appeal information
- Legal, commercial, institutional, cultural, or other protected material
A person who receives confidential information through the Commons should:
- Use it only for the authorized purpose
- Access only what is necessary
- Keep it secure
- Avoid unnecessary copying, downloading, forwarding, publishing, discussing, or retaining
- Follow applicable access, confidentiality, data, safeguarding, intellectual-property, and security conditions
- Raise a concern promptly if information is lost, disclosed, accessed, or used inappropriately
- Return, delete, archive, or otherwise manage information as required when their role, access, project, Working Space participation, Partnership, or other activity ends
The Commons cannot promise absolute confidentiality in every circumstance.
Information may need to be shared where this is necessary, lawful, proportionate, and authorized, including where there is:
- A safeguarding concern
- A significant risk of harm
- A legal obligation
- A court, regulatory, professional, institutional, contractual, or other lawful requirement
- A serious data-security concern
- A serious concern about fraud, financial misconduct, research integrity, editorial integrity, professional conduct, or another material matter
- A need to obtain appropriate expert, legal, safeguarding, ethical, financial, data, institutional, or governance advice
- A need to investigate or respond to a complaint, concern, review, appeal, or incident fairly
The Commons should share only the information necessary for the stated purpose and should consider privacy, confidentiality, safety, fairness, dignity, and applicable conditions before doing so.
Community Groups and Working Spaces
Community Groups and Working Spaces may involve discussions, documents, resources, proposals, research activity, lived experience, professional exchange, feedback, collaboration, and other information.
Not every Community Group or Working Space is private or confidential.
The conditions of each Group or Working Space should state, where relevant:
- Whether activity is public, Member-access, Group-specific, invitation-only, project-based, or restricted
- Who may join or access the space
- Whether posts, comments, chat, documents, recordings, notes, or other material may be viewed, shared, quoted, published, preserved, or reused
- Whether confidentiality applies
- Whether personal, sensitive, restricted, project, research, commercial, cultural, or other protected information may be discussed
- Whether material may be used to inform research, publication, events, reports, Repository records, funding, Partnerships, or other activity
- Whether recording, screenshots, copying, downloading, forwarding, or external sharing are permitted
- Who is responsible for moderation, access, escalation, and support
- How a person can raise a concern or request clarification
A person should not share Community Group or Working Space material outside the relevant space unless they have appropriate permission and the applicable conditions permit it.
A person should not assume that content may be treated as anonymous merely because a name is not visible.
Context, role, contribution, event, organization, location, writing style, image, date, or other details may identify a participant.
Events, Learning, Recording, and Participation
Events and Learning activity may involve:
- Registration
- Attendance records
- Access requirements
- Payment, fees, expenses, or honoraria
- Presentations
- Speaker biographies
- Questions and answers
- Chat messages
- Contributions
- Recordings
- Photography
- Video
- Audio
- Streaming
- Transcription
- Captions
- Interpretation
- Feedback
- Evaluation
- Resources
- Follow-up communications
- Event reports
- Repository records
- Learning materials
The Commons should determine in advance whether an event will be recorded, photographed, streamed, transcribed, summarized, reported, published, deposited, restricted, or otherwise documented.
Participants should be informed clearly about:
- Whether recording or photography will occur
- What may be included in the record
- Whether questions, chat messages, names, images, voices, or contributions may be captured
- Who may access the material
- Whether the material will be public, Member-access, Community Group-specific, invitation-only, project-based, or restricted
- Whether material may be published, reused, cited, deposited in the Repository, or preserved
- Whether an opt-out or low-visibility participation route is available
- How privacy, consent, confidentiality, safeguarding, and withdrawal requests will be managed
- Whether attendee data may be shared with a co-host, partner, platform provider, speaker, sponsor, or another authorized party
- How long information and recordings may be retained
Not every event should be recorded or made public.
Recording may be inappropriate where it could reduce candid discussion, create privacy or safeguarding risks, expose personal information, conflict with cultural protocols, affect research participants, or be unsuitable for restricted Working Space activity, a sensitive consultation, a complaint process, a safeguarding discussion, or another protected setting.
Research, Data, Ethics, and Participation
Research may involve information that is sensitive, personal, confidential, identifiable, restricted, controlled, culturally protected, or subject to ethical, legal, contractual, institutional, or safeguarding requirements.
The Commons should manage research information through appropriate research governance, ethics, consent, data-management, security, access, preservation, and dissemination arrangements.
Before research begins, the Commons and relevant research providers, project leads, participants, advisers, partners, and institutions should consider:
- The purpose of the research
- What information will be collected or created
- Whether personal or sensitive information is involved
- Who will participate
- How participants will be informed
- Whether consent, ethics approval, institutional approval, community approval, legal authority, or another authorization is required
- What risks may arise
- How information will be stored, accessed, shared, analyzed, anonymised, pseudonymised, preserved, restricted, returned, deleted, or disposed of
- Who will have access
- Whether information may be transferred across institutions, jurisdictions, systems, or service providers
- What publication, dissemination, Repository deposit, citation, and preservation arrangements apply
- Whether material should be public, restricted, controlled, embargoed, metadata-only, anonymised, or unavailable for release
- How participants may raise questions, withdraw, request support, or make a complaint
- What will happen if a safeguarding concern, data incident, research-integrity issue, or other serious concern arises
Research data should not be made public merely because it was collected through a Commons research activity.
Publication, Repository deposit, preservation, and access should be determined according to applicable consent, ethics, privacy, data-protection, confidentiality, intellectual-property, cultural, legal, contractual, research-integrity, and public-interest requirements.
The Commons should consider a Data Protection Impact Assessment or another proportionate privacy and risk assessment before beginning a project or process that is likely to create significant privacy or data-protection risk. A data-protection impact assessment is designed to identify and reduce data-protection risks in a planned activity.
Journal Publication, Editorial Activity, and Peer Review
Journal Publication may involve:
- Author information
- Contributor information
- Manuscripts
- Supplementary material
- Reviewer information
- Editor information
- Peer-review records
- Editorial discussion
- Conflict-of-interest declarations
- Copyright and licensing information
- Authorship and contributor statements
- Research data descriptions
- Publication agreements
- Corrections
- Retractions
- Ethical concerns
- Correspondence
- Published work
- Repository deposit and preservation
The Commons should protect the confidentiality, independence, fairness, integrity, and appropriate access conditions of editorial and peer-review processes.
A person who receives a manuscript, peer-review record, editorial discussion, author information, reviewer information, unpublished finding, or another protected publication-related item should use it only for the authorized purpose and should not disclose, copy, reuse, cite, publish, exploit, or share it without appropriate permission.
Publication may make certain information public.
However, publication should not disclose unnecessary personal, sensitive, confidential, restricted, culturally protected, participant-related, or otherwise protected material.
The Commons should ensure that authors, editors, reviewers, contributors, and other participants understand applicable authorship, attribution, licensing, privacy, confidentiality, intellectual-property, consent, research-integrity, conflict-of-interest, correction, retraction, and preservation conditions.
Repository, Preservation, and Access
The Repository is the Commons’ durable knowledge record.
It may preserve research reports, evaluations, evidence syntheses, Journal Publications, datasets or data descriptions, frameworks, toolkits, training resources, project records, event outputs, collections, metadata, and supporting materials.
Repository deposit, access, preservation, and reuse should be managed responsibly.
Before deposit, the Commons should consider:
- Who owns or controls the material
- Whether the depositor has authority to deposit it
- Whether consent, permission, license, contract, ethical approval, institutional approval, or another authorization is required
- Whether personal, sensitive, confidential, restricted, culturally protected, commercial, legal, research, or other protected information is included
- Whether redaction, anonymisation, pseudonymisation, restriction, embargo, controlled access, metadata-only access, or another measure is needed
- What rights, attribution, citation, licensing, version, provenance, access, and preservation information should accompany the record
- Whether material may be copied, reused, translated, adapted, cited, downloaded, shared, or preserved
- How long material should be retained
- Whether material may need to be corrected, updated, withdrawn, superseded, restricted, or removed from public access
Repository deposit does not automatically mean that an item will be openly available.
The Commons may preserve a record while restricting the underlying content.
A public Repository record does not automatically mean that all associated source information, participant data, project records, peer-review records, raw data, confidential material, commercial information, or cultural knowledge is public.
The Commons may retain metadata, citation information, version history, provenance, access conditions, or a withdrawal statement even where content is restricted, removed from public view, superseded, or otherwise unavailable.
Partnerships, External Collaboration, Funding, and Providers
External Collaboration, formal Partnerships, funding, sponsorship, donations, grants, provider engagement, service arrangements, co-hosting, co-commissioning, and other relationships may involve information sharing.
The Commons should ensure that information sharing is necessary, appropriate, lawful, proportionate, transparent, and subject to suitable safeguards.
Before information is shared with a collaborator, partner, funder, sponsor, donor, provider, institution, researcher, event platform, service provider, editor, reviewer, or another external party, the Commons should consider:
- The purpose of sharing
- Whether sharing is necessary
- What information is required
- Whether personal, sensitive, confidential, restricted, controlled, culturally protected, research, financial, commercial, or other protected information is involved
- Whether the recipient has authority, capacity, security arrangements, and a legitimate need to receive the information
- Whether consent, notice, contract, data-sharing agreement, confidentiality agreement, ethics approval, institutional approval, or another authorization is required
- What access, security, onward-sharing, retention, return, deletion, preservation, breach-response, and closure conditions apply
- Whether sharing could compromise research integrity, editorial independence, fair process, participant safety, community rights, privacy, confidentiality, or public trust
- Whether the relationship involves cross-border, cross-institutional, platform, technical, legal, regulatory, financial, or other considerations
A funder, sponsor, donor, provider, partner, or institution should not receive access to personal, confidential, restricted, controlled, research, editorial, peer-review, Member, Community Group, Working Space, or other protected information merely because it provides funding, support, resources, services, institutional capacity, or another contribution.
Access should be limited to what is necessary, authorized, lawful, and appropriate.
Intellectual Property, Authorship, Attribution, and Licensing
Privacy, confidentiality, intellectual property, authorship, attribution, and licensing are related but distinct.
A person may have privacy interests in information about them.
A person, community, institution, author, contributor, researcher, or rights holder may have intellectual-property, authorship, licensing, moral-rights, cultural-rights, contractual, or other interests in a work, resource, contribution, record, image, recording, dataset, design, software, collection, or output.
The Commons should make appropriate arrangements concerning:
- Ownership
- Authority to share or deposit material
- Copyright
- Licensing
- Authorship
- Contributor recognition
- Attribution
- Citation
- Moral rights
- Translation and adaptation
- Reuse
- Publication
- Preservation
- Repository deposit
- Withdrawal, correction, retraction, restriction, or removal
- Use of images, recordings, quotations, personal stories, community knowledge, data, metadata, and other material
The Commons should not claim ownership, authorship, credit, control, or rights of use over another person’s, community’s, institution’s, or organization’s work without an appropriate basis and agreement.
A person should not submit, upload, publish, deposit, share, record, reproduce, translate, adapt, or reuse material unless they have the necessary authority and have complied with relevant conditions.
Data Sharing and External Service Providers
The Commons may use external service providers, platforms, systems, payment services, event platforms, communications services, research tools, storage services, technical providers, editors, reviewers, partners, institutions, or other authorized parties to support Commons activity.
Where information is shared with another party, the Commons should consider:
- The identity and role of the recipient
- The purpose of sharing
- The information being shared
- Whether sharing is necessary and proportionate
- Whether the recipient is authorized to receive the information
- Applicable privacy, confidentiality, data-protection, security, legal, ethical, contractual, and institutional requirements
- Whether a written agreement is required
- Access controls
- Security measures
- Restrictions on onward sharing
- Retention, return, deletion, archive, or disposal arrangements
- Incident reporting and breach response
- Contact and escalation arrangements
The Commons should not share personal, confidential, restricted, or sensitive information with a third party merely because sharing is convenient.
The Commons should provide appropriate information to people about material data sharing that affects them, subject to applicable legal, safeguarding, confidentiality, security, or other legitimate limitations.
Access, Correction, Restriction, Deletion, and Other Requests
A person may use the Privacy, Data, and Confidentiality Enquiries route to ask about information held by the Commons and, where applicable, request:
- Information about how personal data is used
- Access to personal information
- Correction of inaccurate, incomplete, out-of-date, or misleading information
- Restriction of processing or use
- Withdrawal of consent
- Objection to a particular use of information
- Deletion or erasure of personal information
- A copy or transfer of information where applicable
- Clarification of a confidentiality, access, recording, publication, Repository, data, licensing, or attribution condition
- Access to eligible restricted material
- A correction to a Repository record, profile, publication, event record, metadata record, or other item
- Review of an access, correction, restriction, deletion, or other information-related decision
- Information about a suspected privacy or data-security issue
The Commons should respond to requests in accordance with applicable law, the nature of the information, the identity and authority of the requester, privacy and security requirements, the rights of others, confidentiality obligations, research and publication integrity, preservation needs, legal and contractual obligations, and other legitimate considerations.
The Commons may need to verify a person’s identity or authority before providing access, making a correction, changing access conditions, deleting information, or taking another action.
The Commons may not be able to grant every request.
For example, information may need to be retained because of a legal, ethical, contractual, financial, safeguarding, research-integrity, editorial-integrity, publication, preservation, security, dispute, complaint, review, or other legitimate requirement.
Where a request cannot be granted in full, the Commons should explain the position appropriately where possible.
Information Security
The Commons should take proportionate technical, organizational, operational, contractual, physical, and procedural measures to protect information against unauthorized access, disclosure, loss, alteration, destruction, misuse, or other inappropriate handling.
Appropriate safeguards may include:
- Role-based access controls
- Strong passwords and account protections
- Multi-factor authentication where appropriate
- Secure systems and service providers
- Encryption or other protective measures where appropriate
- Access logging and monitoring
- Secure transfer arrangements
- Confidentiality agreements
- Data-sharing agreements
- Staff, volunteer, contributor, editor, reviewer, provider, and partner guidance
- Training and induction
- Secure storage
- Backups and recovery arrangements
- Data minimization
- Pseudonymisation or anonymisation where appropriate
- Restrictions on downloading, copying, printing, forwarding, or reuse
- Secure deletion and disposal
- Incident reporting and response procedures
- Periodic review of access permissions, systems, arrangements, and risks
No system can guarantee absolute security.
People who use Commons systems, resources, Community Groups, Working Spaces, events, research spaces, publication processes, Repository services, or other activity also have responsibilities to protect information.
They should:
- Keep account credentials secure
- Avoid sharing passwords or access links
- Use information only for authorized purposes
- Avoid accessing information they do not need
- Avoid storing protected material in insecure locations
- Avoid forwarding, downloading, copying, photographing, recording, or sharing protected material without permission
- Report suspected loss, unauthorized access, disclosure, malware, phishing, account compromise, incorrect recipient, privacy concern, data incident, or other security issue promptly
- Follow relevant privacy, confidentiality, access, data, safeguarding, intellectual-property, and security conditions
Information-Security Incidents and Data Breaches
An information-security incident may include:
- Lost or stolen device, document, material, or record
- Incorrect email recipient
- Unauthorized access to an account, Community Group, Working Space, event platform, system, project, record, or Repository item
- Unauthorized disclosure
- Inappropriate use of information
- Lost, altered, deleted, corrupted, or inaccessible information
- Cybersecurity incident
- Phishing, malware, ransomware, or account compromise
- Misconfiguration
- Failure of a service provider or platform
- Accidental publication of restricted material
- Inappropriate use of a recording, image, transcript, data, or other output
- Another event that may affect privacy, confidentiality, availability, integrity, security, safety, rights, or trust
A person who becomes aware of an actual or suspected incident should report it promptly through Contact and Support or the relevant emergency, safeguarding, technical, data, or security route.
The Commons should assess the incident proportionately and take appropriate steps to:
- Contain or reduce the immediate risk
- Protect affected people and information
- Record the incident
- Assess the nature, scope, sensitivity, and potential impact
- Determine whether internal, external, legal, regulatory, institutional, contractual, safeguarding, partner, provider, or other notification is required
- Communicate appropriately with affected people where necessary
- Correct the underlying issue where possible
- Review controls, practices, training, systems, agreements, or access arrangements
- Capture learning to reduce the risk of recurrence
The Commons should not conceal a serious information-security or data-related concern.
Where a breach or incident may create a material risk to people’s rights, safety, privacy, dignity, or other interests, the Commons should follow the applicable notification, reporting, escalation, and response requirements.
Retention, Preservation and Disposal
The Commons should retain information only for as long as necessary for the purpose for which it was collected, created, received, or preserved, unless a longer period is required or justified by law, ethics, contract, research integrity, publication integrity, safeguarding, financial administration, archival value, preservation responsibility, dispute resolution, or another legitimate requirement.
Different information categories may require different retention periods.
For example:
- Account information may be retained while an account remains active and for an appropriate period afterward
- Membership records may be retained for administration, renewal, governance, financial, communication, review, and record-management purposes
- Event registration information may be retained for event administration, reporting, safeguarding, follow-up, evaluation, and record-management purposes
- Research information may be retained according to approved protocols, ethics arrangements, contracts, data-management plans, publication requirements, preservation obligations, and applicable law
- Journal records may be retained to support editorial integrity, publication history, correction, retraction, authorship, review, and preservation
- Repository records may be retained for long-term preservation, citation, provenance, version, access, and scholarly, professional, institutional, cultural, community, or public-interest value
- Financial, funding, sponsorship, donation, contract, provider, and agreement records may be retained for accounting, audit, reporting, legal, contractual, governance, and record-management purposes
- Safeguarding, complaint, concern, review, appeal, and incident information may be retained according to the sensitivity, seriousness, legal, ethical, safeguarding, governance, and review requirements of the matter
The Commons should maintain a Data-Retention and Disposal Schedule that identifies record categories, relevant retention criteria, archive requirements, disposal arrangements, legal holds, and responsible roles.
When information is no longer required, the Commons should delete, anonymise, archive, return, transfer, destroy, restrict, or otherwise dispose of it securely and appropriately.
Preservation does not always mean public access.
The Commons may preserve restricted content, metadata, contextual records, access conditions, provenance, or version information while limiting access to the underlying material.
Roles and Responsibilities
Privacy, data, consent, confidentiality, access, security, preservation, and information governance are shared responsibilities.
The Commons Administration should:
- Maintain appropriate information-governance arrangements
- Provide clear notices, forms, guidance, policies, agreements, and contact routes
- Collect only necessary information
- Manage access proportionately
- Maintain appropriate records
- Route privacy, data, confidentiality, access, consent, security, safeguarding, and related concerns appropriately
- Maintain operational procedures and escalation routes
- Review systems, practices, providers, agreements, access controls, retention arrangements, and risks
- Support compliance with applicable obligations
- Ensure that relevant people understand their responsibilities
Members, participants, contributors, volunteers, role holders, editors, reviewers, authors, researchers, providers, partners, funders, sponsors, and other people engaging with the Commons should:
- Provide accurate information where required
- Respect privacy, confidentiality, consent, access conditions, intellectual property, cultural protocols, and security requirements
- Access only information necessary for their role or purpose
- Use information only for authorized purposes
- Keep credentials, devices, records, and systems secure
- Disclose relevant conflicts of interest
- Avoid unauthorized disclosure, copying, sharing, publication, recording, reuse, or retention
- Report suspected privacy, confidentiality, access, security, safeguarding, or other information-related concerns promptly
- Follow applicable policies, notices, agreements, role conditions, research protocols, editorial guidance, Repository conditions, and legal or contractual requirements
Operational Documents and Procedures
This framework should be supported by proportionate public and internal documents.
Privacy Policy
The Privacy Policy should provide the formal legal and regulatory notice for personal-data processing.
It should identify, as applicable:
- The legal identity of the relevant data controller
- Contact information
- Data-protection contact information
- Categories of personal information collected
- Purposes of processing
- Applicable legal bases or other lawful grounds
- Data recipients and service providers
- International or cross-border transfer arrangements where relevant
- Retention periods or retention criteria
- Individual rights
- Complaint routes
- Cookie and tracking information
- Other information required by applicable law
Cookie Notice
The Cookie Notice should explain website cookies and similar technologies.
It should state:
- What cookies or similar technologies are used
- Why they are used
- Whether they are essential, functional, analytical, advertising-related, or another category
- How users may manage preferences
- Whether third-party services are involved
- How the notice relates to the Privacy Policy
Consent Form and Consent Record Template
The Commons should use consent forms and records where specific consent is required.
A Consent Form should identify:
- The activity
- The information, participation, recording, image, data, or contribution involved
- The purpose
- Who may access the material
- Whether it may be public, published, deposited, preserved, reused, shared, restricted, or transferred
- Relevant risks and limitations
- Withdrawal arrangements
- Contact information
- Date, method, and record of consent
Confidentiality Agreement Template
The Commons should use a Confidentiality Agreement where a person or organization receives confidential information through a role, project, Working Space, editorial process, research activity, Partnership, provider arrangement, funding arrangement, or other defined activity.
The agreement should address:
- Information covered
- Authorized purpose
- Permitted use
- Access restrictions
- Security requirements
- Restrictions on copying, sharing, publication, reuse, or onward disclosure
- Retention, return, deletion, archive, or destruction requirements
- Incident reporting
- Exceptions and legal obligations
- Duration and surviving obligations
Data-Sharing Agreement Template
The Commons should use a Data-Sharing Agreement where personal, sensitive, restricted, controlled, research, confidential, or other protected information is shared with another organization or party.
The agreement should address:
- Parties to the arrangement
- Purpose of sharing
- Categories of information
- Authority, lawful basis, consent, ethics, or other authorization where relevant
- Roles and responsibilities
- Access controls
- Security arrangements
- Use restrictions
- Onward sharing restrictions
- Retention, return, deletion, anonymisation, archive, or disposal
- Incident reporting and breach response
- Data-subject, participant, community, or contributor rights
- Monitoring, review, variation, suspension, and closure
Research Data-Management Plan Template
The Commons should use a Research Data-Management Plan for research activity involving data or other significant information handling.
The plan should address:
- Data collection and creation
- Data categories
- Participants
- Consent and ethics
- Privacy and confidentiality
- Storage and security
- Access and roles
- Data quality
- Documentation and metadata
- Anonymisation or pseudonymisation
- Data sharing
- Publication and dissemination
- Repository deposit and preservation
- Restrictions, embargoes, controlled access, or metadata-only records
- Retention, deletion, disposal, and closure
- Incident and breach arrangements
Event Recording, Photography, and Participation Notice
The Commons should use an Event Recording, Photography, and Participation Notice where an event may involve recording, photography, streaming, transcription, chat capture, publication, Repository deposit, or another form of documentation.
The notice should explain:
- What will be recorded or captured
- Why
- Who may access the material
- Whether it will be public or restricted
- Whether names, images, voices, questions, chats, or contributions may appear
- Available opt-out or low-visibility participation arrangements
- How long information may be retained
- How participants may ask questions or raise concerns
Repository Deposit and Access Conditions
Repository Deposit and Access Conditions should explain:
- Eligibility to deposit
- Authority to deposit
- Rights and permissions
- Copyright, licensing, authorship, attribution, and citation
- Confidentiality, privacy, personal data, cultural, ethical, legal, and contractual requirements
- Access classifications
- Embargoes, restrictions, controlled access, redaction, metadata-only records, and withdrawal
- Preservation, versioning, provenance, correction, retraction, and record retention
- Access-request procedures
- Responsibilities of depositors and users
Data Access, Correction, Restriction, and Deletion Procedure
The Commons should maintain a procedure through which people may request access to, correction of, restriction of, deletion of, or clarification about relevant information.
The procedure should explain:
- How to make a request
- How identity and authority may be verified
- What information may be needed
- How requests are assessed
- Applicable timeframes under relevant law or policy
- Grounds for granting, limiting, or declining a request
- How the rights of other people, confidentiality, research, publication, preservation, safeguarding, legal, contractual, and other requirements are protected
- How outcomes are communicated
- How review or complaint routes may be used
Information-Security and Data-Breach Procedure
The Commons should maintain an Information-Security and Data-Breach Procedure.
The procedure should explain:
- How incidents are identified and reported
- Who is responsible for response
- How incidents are contained
- How risks are assessed
- How records are kept
- When notification or escalation may be required
- How affected people may be informed
- How systems, access, agreements, training, or practices are improved after an incident
- How incident information is retained and protected
Privacy, Data, and Confidentiality Enquiry Procedure
The Commons should maintain a procedure for privacy, data, consent, confidentiality, access, correction, deletion, restriction, security, Repository, recording, and information-related enquiries.
The procedure should explain:
- How enquiries are received
- Who is responsible for responding
- How urgent matters are escalated
- How confidentiality and identity verification are managed
- When another process, authority, agreement, or external service is more appropriate
- How outcomes are communicated
- How records are retained
- How recurring issues improve Commons activity
Privacy, Data, Consent, and Confidentiality Enquiries
Use the Privacy, Data, and Confidentiality route if you need help understanding how information is handled in the Commons.
You may use this route to:
- Ask a privacy, data, consent, confidentiality, security, access, recording, publication, Repository, licensing, attribution, or intellectual-property question
- Request access to, correction of, restriction of, deletion of, or information about personal data where applicable
- Ask about event recordings, photography, transcription, chat records, or participation documentation
- Seek guidance about restricted, controlled, embargoed, culturally protected, or metadata-only information
- Ask about research data, Repository deposit, Repository access, preservation, licensing, or rights
- Report a suspected privacy, confidentiality, access, information-security, or data-related concern
- Request an alternative route for a privacy or information-related request
- Seek review of an information-related decision where an applicable process provides for this
Before making an enquiry, provide only the information necessary to explain the matter.
Do not send personal, sensitive, confidential, restricted, research, legal, commercial, safeguarding, culturally protected, or other protected information unless the Commons has provided an appropriate secure route or requested it.
So that Privacy, Data, Consent, and Confidentiality concerns are addressed the Commons strives to ensure that:
- People can understand how information may be collected, used, shared, protected, retained, preserved, restricted, corrected, deleted, or disposed of
- The distinction between public, personal, sensitive, confidential, restricted, controlled, culturally protected, anonymised, pseudonymised, embargoed, and metadata-only information is clear
- The Commons collects only information necessary for a legitimate and stated purpose
- People receive clear information about participation, recording, research, publication, Repository deposit, data sharing, access, consent, confidentiality, and relevant conditions
- Consent is meaningful, informed, proportionate, recorded where appropriate, and not assumed merely because a person participates, attends, joins, applies, or does not object
- Community knowledge, cultural rights, lived experience, research participation, personal information, and other sensitive contributions are treated with respect
- Community Groups and Working Spaces have clear information, privacy, confidentiality, access, and sharing conditions
- Event participants understand recording, photography, streaming, transcription, chat, publication, Repository, and follow-up arrangements
- Research information is governed through appropriate ethics, consent, data-management, security, access, dissemination, and preservation arrangements
- Journal and peer-review information is protected appropriately
- Repository deposit, access, preservation, citation, licensing, restriction, embargo, withdrawal, and metadata arrangements are clear
- Partners, funders, sponsors, providers, institutions, platforms, and other external parties receive only the information necessary for authorized activity
- People can request information, correction, restriction, deletion, access, clarification, or review through an understandable route
- Information-security incidents and data-related concerns are reported, assessed, contained, escalated, and learned from responsibly
- Retention, preservation, archive, deletion, disposal, and closure arrangements are proportionate and documented
- Privacy, data, consent, confidentiality, access, security, preservation, dignity, fairness, independence, and public trust are protected across the life of the Commons