As part of your Data Access Request, you must submit an Intended Data Use (IDU) statement in English describing the proposed research project and how the data will be securely used and managed. The IDU helps data access committees evaluate whether the proposed research use is scientifically appropriate, aligned with participant consent and data use limitations, and supported by adequate privacy and security protections. IDU statements are limited to 500 words.
Required Components of an IDU Statement
Your IDU statement should address the following topics:
-
Scientific Purpose
-
Data Analysis Plan and AI Use
-
Datasets to Be Used
-
Computing Environment
-
Data and Safety Monitoring Plan
-
Outputs Vetting Strategy
-
Sharing Plan
Scientific Purpose
Describe the primary scientific goals of your research project and explain how the work will advance scientific knowledge or benefit the public good.
Consider including:
-
The research question or hypothesis
-
The broader scientific or clinical relevance
-
Expected impact or outcomes
Data Analysis Plan
Explain how you plan to analyze the data, including analytical methods, statistical approaches, and computational workflows.
Consider including:
-
Statistical or computational methods
-
Data processing procedures
-
Validation or benchmarking approaches
-
Expected analytical outputs
AI and Generative AI Use
Describe any planned use of AI, machine learning, generative AI, or external AI-enabled tools or services in connection with the controlled-access data.
Consider including:
-
Whether you will develop, refine, or use existing AI/ML models
-
Whether controlled-access data will be entered into external AI platforms or services
-
Safeguards to prevent data retention, disclosure, or unauthorized reuse by AI providers
Datasets to Be Used
List the datasets you plan to use and explain why they are necessary for your research objectives.
Consider including:
-
Specific programs, projects, or dataset collections
-
Data types required (e.g., genomics, clinical, imaging)
-
Why these datasets are appropriate for the study
Computing Environment
Describe where the data will be stored and analyzed and what safeguards are in place to protect the data.
Consider including:
-
Secure enclaves, virtual private cloud (VPC) environments, or institutional systems
-
Encryption and multi-factor authentication
-
Access controls and compliance certifications
Data and Safety Monitoring Plan
Describe how you will protect participant privacy and reduce the risk of data leakage or re-identification.
Consider including:
-
Privacy-preserving analysis methods
-
Protections against model memorization
-
Access restrictions and monitoring procedures
Data Outputs & Vetting Strategy
Describe the outputs you expect to generate and how you will ensure they do not compromise participant privacy.
Examples of outputs include:
-
Statistical summaries
-
Machine learning models
-
Visualizations
-
Publications
Consider addressing:
-
Small cell-size suppression
-
Re-identification risk review
-
Reverse-engineering protections
Sharing Plan
State whether research outputs or models may be used commercially now or in the future, and explain how data use restrictions will be maintained in downstream use cases.
Models trained on controlled-access data and their parameters are considered data derivatives and may only be shared under controlled access through the original data repository.
Requesting additional IDU support
If you still have questions or issues related to a DUC, please contact our Access & Compliance Team (ACT). You can use any of the following methods to contact the ACT:
-
Use the ARK Portal Help Desk
-
Use the ACT Help Desk