Document the route, not merely the result
A finished dissertation rarely reveals why a paper was excluded, an interview recoded or a value corrected. Documentation closes that gap. It supports quality control, supervision, correction and investigation of a concern. The DFG Code expects relevant records to make findings and their development traceable while recognising that disciplinary reasons can limit recording or access.
Students do not need a continuous surveillance record. Preserve consequential decisions, original materials, processing and attribution. Records should be timely, intelligible and protected from silent overwriting. Assessment, privacy, ethics and retention rules of the institution take priority. Seek competent advice early for sensitive or contractually restricted material.
Record promptly and name versions meaningfully
Write down a reason while you still know it. Reconstruction can confuse an initial plan with a later explanation. A concise entry contains date, input version, observation, options, decision, rationale, implementation and reporting location. Routine actions deserve less detail than an exclusion capable of changing the conclusion.
Use consistent names containing date, content and version. Never overwrite the original material. Store processed data, transcripts and images as new states; version control may help with code. A readme explains folders, formats, dependencies and responsibility. Proprietary formats may need a documented accessible export when rights and data protection permit it.
Match records to the method
A literature project needs search routes, selection criteria, notes and locations. Quantitative work needs variable definitions, instrument, original state, cleaning and analysis parameters. Qualitative research records consent, topic guide, transcription conventions, codebook, memos and category development. Software projects may require requirements, data sources, versions, tests and known limitations.
The form should explain your method rather than imitate somebody else’s checklist. A laboratory book, electronic notebook, spreadsheet log or versioned text can all work. Readability, timing and connection to results matter. Unexplained screenshots are weak; a brief decision linked to the relevant version is often stronger.
Combine traceability with privacy
Documentation must not create avoidable risk. Keep identifying lists separate from research data with restricted access and suitable backups. Pseudonymisation is not anonymisation: a key that restores identity remains sensitive. Record authorised users, backup location and the event or date that triggers deletion or archiving.
Open research does not mean uploading everything. Metadata, methods, code or aggregate results can often be shared while raw records remain controlled. State the boundary honestly. Contracts, third-party rights, consent and institutional decisions determine permissible access. Credentials never belong in a public research folder.
Do not invent a retention period
The DFG Code provides a general institutional framework for retaining research data and central materials and allows disciplinary reasons to be considered. It should not be converted casually into an identical student obligation for every file. Examination policies, archives, funding, consent and privacy deletion duties can establish different periods. Record the source and version of the rule that applies.
Where obligations conflict, seek guidance rather than guessing. A data protection officer, examinations office, library, research-data service or supervisor can clarify responsibility. “Keep forever” is no safer than immediate deletion after marking. A defensible plan combines a legitimate purpose, an authoritative requirement and secure implementation.
Close-out audit for the evidence package
- Every central claim connects to an analysis and correct data version.
- Every consequential change has a date and substantive reason.
- Source locations and search route remain understandable.
- External contributions and tools correspond to the submitted version.
- Sensitive records, linkage keys and consent forms are protected separately.
- Retention and deletion follow documented local rules.
- A readme allows an authorised knowledgeable person to navigate the package.
Freeze the submitted file and receipt. Review access rights and deadlines at appropriate intervals. Documentation then becomes a bounded, responsibly maintained evidence package rather than an accidental archive of everything.
Once a month, open one central file and ask whether it is the stated version, whether provenance is recorded, whether the next processing step can be found, whether this storage location is authorised and whether a deletion trigger is documented. Test that one backup can actually be read. Record only the outcome and action, not the sensitive content again.