A short plan can expose important gaps
A data management plan, or DMP, turns an intended research workflow into decisions about files, responsibility, protection and future use. A dissertation does not need the administrative scale of a funded consortium. A single precise page can nevertheless prevent uncertainty over which file is the untouched source, whether an export has been backed up, or who should hold confidential interviews after the student leaves. Specific locations and named roles make the plan operational; phrases such as “stored securely” do not.
The DFG describes planning, documentation, storage and possible reuse as elements of responsible research-data handling. Those principles scale to student work, but the implementation depends on discipline, method, participant consent and institutional requirements. A desk-based review, laboratory experiment and interview project require different controls. Treat any generic template as a set of questions, not as approval for a particular practice.
Map every data object, not only the final spreadsheet
Research data may include measurements, audio, transcripts, photographs, observation notes, survey exports, code, simulations and derived tables. Data obtained from elsewhere need their source, licence or terms, access conditions and version. For each type, record its format, approximate volume, means of creation, sensitivity and responsible person. Estimates may be rough at first, provided that the plan makes them easy to revise.
Keep supporting records visible in the inventory. A codebook, README, consent documentation, cleaning log and analysis script explain different stages; calling them all “appendices” loses that structure. Identifying keys should normally be separated from research content in sensitive projects. The precise technical and organisational controls must be agreed through the university’s authorised support, ethics and data-protection routes.
Storage, backup and access form one system
A personal laptop is not a complete storage strategy. Use services approved by the institution and identify which location holds the authoritative working copy. Record how backups are made and test how one file would be restored. Synchronisation alone may reproduce an accidental overwrite or deletion across devices; investigate the service’s version history and recovery window rather than assuming it is a backup.
For personal or confidential data, “password protected” is too vague. Record roles, encryption, transfer channel, separation of identifiers, retention and deletion using the procedures provided by your university. The DMP does not grant ethics or data-protection clearance. Its job is to expose decisions that require formal advice. Open-science aspirations never justify publishing participant records, consent forms or re-identification keys without the necessary rights and safeguards.
Review the plan at moments of change
Give the DMP a date and version. Revisit it after a pilot, when new formats appear, whenever collection changes, before cleaning begins and before a deposit is prepared. Record the reason for each material revision and the person who agreed it. This prevents the final document becoming a fictional account of decisions supposedly made at the start.
A concise monthly review is often enough: Are storage locations and access roles current? Have new data types been added to the inventory? Can a backup be restored? Are file names and versions unambiguous? Are recodes, exclusions and transcript corrections entering a change log? The value of the review lies in testing the record against practice, not merely changing its revision date.
Plan retention, deposit and deletion before submission week
Decide with the relevant institutional staff which data substantiate the reported findings, which records must remain restricted, and which formats will remain readable. A repository may provide metadata, access conditions and persistent identifiers for material that can be deposited. It does not conduct the rights, confidentiality or consent assessment for you, and not every dataset can appropriately be made open.
Prepare a closure inventory containing the path, file revision, checksum, sensitivity and intended action for each significant object. Remove redundant temporary copies in a controlled process, but do not independently delete evidence that must be retained. If the university assumes custody, document the transfer and future contact. Distinguish the public package, the restricted evidence archive and material scheduled for authorised deletion.
Weak plans and how to strengthen them
“Regular backups” becomes testable only after a service, frequency, responsible person and restoration test are named. “Data will be anonymised” needs an approved method and a review of residual disclosure risk. Plans also fail when they cover raw observations but omit code, metadata and change history. Avoid a private cloud account or personal device as the long-term handover route. Your future self should be able to understand the arrangement after months away from the project.
