Evaluating Data Requests

Institutional data is a strategic university resource that is used to power research and education, support operations, make strategic plans, and enable integration with third-party solutions, including AI technology.

When evaluating any request for institutional data, data stewards and custodians are guided by the following principles:

  • Ensure quality
    Determine whether the quality of requested institutional data is appropriate to the proposed use and assess risks to the quality of output.
  • Protect privacy and security and ensure compliance
    Ensure institutional data is protected in accordance with applicable laws, regulations, and university policies and standards.
  • Uphold university values
    Confirm the proposed use of institutional data aligns with the values of transparency, respect, fairness, equity, and non-discrimination, and does not pose risks to individuals or university reputation.
  • Make data appropriately accessible
    Provide appropriate and timely access to institutional data to authorized individuals and systems in support of U-M missions and decision-making.

Assessment Framework

Responsible stewardship requires careful evaluation of every request for institutional data and heightened attention when that data will be used in systems and tools, including AI models, where the consequences of poor data quality, insufficient oversight, or inappropriate use can be difficult to detect, and can significantly affect outcomes.

The following assessment framework assists data stewards with this evaluation.

Ask: Who is making the request and are they authorized to access this data?

  • Does the requester have a legitimate university or external role related to this data?

Ask: Why is this data needed, and is the purpose legitimate?

  • Is there a clear, documented academic, research, or operational need?
  • Does the stated use align with university policies and applicable laws?

Ask: Is the data as requested required to accomplish the specified purpose?

  • Is the data available in existing reports?
  • Could the purpose be achieved with aggregated or de-identified data instead of individual-level records?
  • Is the scope of the request (time range, population, fields) appropriately limited?

Ask: What are the risks, and are there legal, policy, or ethical constraints?

  • Does the request involve multiple data areas?
  • Will the data be combined with other institutional data and may change the risk profile of the data set?
  • Does the request involve Moderate, High, or Restricted data?
  • Are there applicable data protection regulations, such as FERPA, HIPAA, GLBA, Common Rule, or export control requirements? Has the requestor completed required training?
  • Does the request require a contractual agreement, such as Data Sharing Agreement or Memorandum of Understanding?
  • Are there legal or ethical considerations around automated processing or decision making, including through the use of AI?
  • Does the request pose a legal, ethical, or privacy risk to an individual?
  • Does the request pose a risk to U-M’s reputation?
  • What human oversight is planned for automated or AI-powered data processing and output validation?
  • Will AI outputs be clearly labeled as such to downstream users?
  • Is there a documented escalation path when outputs are questionable or contested?

Ask: How will the data be stored, shared, and disposed of?

  • Will the data be stored in a system approved for the sensitivity level?
  • How will the data be accessed?
  • Who will have access to the data? Who will the data/reports/analysis be shared with?
  • For how long is the data needed?
  • Is there a plan for secure disposal or return of the data after use?

Ask: Can the request be fulfilled as specified?

  • Does the requested data exist, and is it accessible?
  • Are there data quality concerns that could affect the output?
  • Are known data limitations, gaps, inconsistencies, biases, etc. documented and disclosed to the requestor?
  • Does the requestor demonstrate sufficient data literacy, understanding of the impact of data limitations, and ability to validate output against ground truth or alternative sources?
  • Does fulfillment require coordination with or approval from other stakeholders, such as IRB, Procurement Services, OGC, ITS Information Assurance?
  • What effort is required to fulfill the request and do we have the capacity and resources?
  • Can the request be fulfilled within the desired timeline?