Recommended Free Tools
Protecting human genomic data starts with matching access to consent and permitted uses, then following the repository’s and agreement’s requirements throughout the data’s lifecycle. De-identifying a file and uploading it is not enough: access decisions, user obligations, institutional oversight, and responsible-use expectations all matter.
What should a research team establish before sharing genomic data?
Start by identifying the rules that apply to the particular dataset—not by assuming every repository or funder has the same requirements. For NIH Genomic Data Sharing (GDS) submissions, relevant documents include the consent under which the samples or data were collected, the repository’s policies, the applicable Data Use Certification or other data-use agreement, and the submitting institution’s certification. NIH distinguishes requirements for NIH-supported repositories and access systems from obligations for people who use data. See the NIH GDS overview and NIH repository and user requirements.
- Check consent and use limits. Confirm what participants agreed to and whether that consent permits the proposed sharing and secondary uses. For NIH GDS, consent informs whether submission is appropriate and whether access should be unrestricted or controlled, as NIH explains in its GDS policy notice.
- Identify the governing terms. Record the repository, the agreement or certification that applies, and any institutional commitments. Do not assume requirements from one dataset or repository automatically apply to another.
- Choose an access tier consistent with those limits. Make the decision through the relevant institutional and repository process; do not treat de-identification alone as authorization for public release.
- Plan for the environment where data will be used. If controlled-access data will be stored or analyzed using a cloud provider or other third-party IT system, determine whether it meets the standards that apply to the agreement and repository.
- Assign oversight. Make clear who in the institution is responsible for ensuring that approved users, storage, and analysis remain within the applicable terms.
NIH’s current guidance is specifically about NIH genomic-data sharing. Other funders, repositories, jurisdictions, and agreements may impose different conditions.
Should human genomic data be open access or controlled access?
Neither option is universally right. For NIH GDS, the submitting institution uses consent and its institutional certification to inform whether data should be unrestricted or controlled. Controlled access routes secondary-use requests through review for consistency with established data-use limitations; it does not make re-identification impossible. The comparison below summarizes the distinction described in NIH’s GDS notice and user guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
| Consideration | Unrestricted/open access | Controlled access |
|---|---|---|
| Consent compatibility | Consent informs whether unrestricted submission is appropriate. | Consent and established data-use limitations inform which secondary uses may be approved. |
| Who may access | Available without individual access approval. | Access is approved for a particular proposed research use. |
| Use conditions | Users should not attempt to identify participants and should acknowledge the datasets and repositories used. | Approved users must follow the applicable Data Use Certification or similar agreement. |
| Security and oversight | NIH still expects users to manage data in a way that protects participant privacy. | Approved users and their institutions have continuing confidentiality, integrity, and security responsibilities under applicable terms and NIH best practices. |
If consent or use limits do not support unrestricted release, public availability is not an appropriate shortcut. If controlled access is selected, the agreement and repository requirements become part of the operational plan, not just an approval step.
Does de-identifying genomic data make it safe to share publicly?
Not by itself. The NIH GDS policy makes consent and data-use limitations central to deciding whether data belong in unrestricted or controlled access. Controlled review is a governance measure for assessing proposed uses; it is not a guarantee that a dataset cannot be linked back to a person. Therefore, a team should not treat removing direct identifiers as proof that unrestricted release is permitted or risk-free.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
For unrestricted/open-access human genomic data, NIH instructs users not to try to identify participants. That obligation remains relevant after release; open access does not erase privacy responsibilities. NIH’s guidance on using genomic data responsibly states that users of both controlled-access and unrestricted/open-access human genomic data should manage and secure it in a way that protects participant privacy.
What security rules apply to NIH controlled-access genomic data?
Approved users and their institutions must protect confidentiality, integrity, and security in accordance with the applicable Data Use Certification or similar agreement and NIH security best practices. The exact obligations depend on the terms governing the dataset and system. NIH says its updated best-practice expectations apply to new or renewed user agreements from January 25, 2025. Agreements approved earlier follow the standards stated in those agreements until project close-out or renewal. The separate NIH repository and user requirements page has its own effective dates, so confirm which terms apply rather than assuming the user-agreement date answers every repository question.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
NIH also treats violations of access terms or the user code as data management incidents. Teams should therefore know the applicable incident and reporting procedures in their agreement and institutional policies, and raise suspected violations through the responsible institutional channels.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who is responsible if genomic data are stored in the cloud?
The institution remains responsible for oversight. NIH expects cloud providers and other third-party IT systems used to store or analyze controlled-access data to meet the same applicable standards as the project’s other systems; using an outside service does not transfer institutional accountability. Before putting data there, the institution should assess the service and its configuration against the governing agreement and repository requirements. NIH does not endorse a particular vendor or say that purchasing a particular cloud plan alone makes a project compliant. See the NIH user guidance.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How can sharing remain responsible after access is granted?
Responsible sharing includes more than technical security. The GA4GH Framework for Responsible Sharing of Genomic and Health-Related Data centers human rights, privacy, non-discrimination, and procedural fairness. In practice, teams should ensure that the intended use fits the consent and access terms, that decisions follow the relevant review process, and that participants’ interests remain visible after data are made available.
For NIH unrestricted/open-access datasets, users should not attempt to identify participants and should acknowledge the datasets and repositories used in presentations and publications. For controlled-access data, users and institutions must continue to follow the agreement and applicable security practices during storage, analysis, and any authorized sharing within the project. These expectations are stated in NIH’s guidance for using genomic data responsibly.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

