NF Data Portal Documentation

Governance Models

Our governance team at Sage Bionetworks will select the appropriate governance model for your data to ensure proper data access & use restrictions, in accordance with information you have provided in your data sharing plan. Below are the standard governance model options to regulate Synapse data access and use. If you are seeking access to your own data, contact your project administrator (found under ‘Project Tools' > 'Project Sharing Settings’ on the top right of each project) or email us at nf-osi@sagebionetworks.org.


Registered Synapse Users - Users must have a Synapse account to access and use the Data.

  • Users must agree to the Synapse Terms and Conditions of Use.

  • Users must commit to the Synapse Pledge.

Attribution Required - Users must accept the requirement to acknowledge the data
contributors by including contributor-specified statements in future publications.


The Open Tier includes non-sensitive content such as metadata, aggregate data, study descriptions, citations, and intended data use statements. Carefully selected metadata in the Open tier feeds exploration functionality for the RDDC. Anyone can access this content without restriction and access to it is not tracked.


The Registered Tier includes de-identified, non-sensitive data that may be accessed only by logged-in users who have registered an account and electronically agreed to terms of access. Non-human data will commonly be classified within the Registered Tier. Data access is tracked.

  • No Data use or access limitations, other than proper attribution.

  • The Provider may indicate a license name and justification for use.


The Limited Tier includes de-identified non-sensitive data, processed data, or tools that may be used by registered users. 

  • Users must agree to use limitations such as an area of research, licensing requirements, and/or return of results requirements.


The Controlled Tier includes data that may pose more than minimal risks of re-identification to data subjects or communities and data whose access is restricted by the contributor due to organizational or contractual obligations. Access to controlled tier data is purpose-based and subject to approval by a Data Access Committee. Data access is tracked. Requests must include:

  • Intended Data Use statement required. Required components:

    • Objectives of the proposed research

    • Study design

    • Analysis plan

  • Approved statements will be publicly available on Synapse

  • Disposition Requirement: delete locally stored Data upon conclusion of research or
    expiration of Data Access

  • IRB Documentation, if required

  • Data access expiration/renewal period: 1 year

Controlled Access for HIPAA Limited Data Sets - Additional data use and access limitations will be implemented in addition to the standard controlled access conditions listed above.

  • IRB/Ethics Approval or Waiver Documentation required

Data Use Limitations:

  • General Research Use only (Any types of scientific research)

  • Additional Data Use Limitations are addressed on a case-by-case basis

Data Access Committee - Sage Bionetworks Access & Compliance Team (ACT) reviews
access requests.


Different data types require different access restrictions.
Different data types require different access restrictions. Our governance team will help determine which access level is appropriate for your data.