Data Management Plan (DMP)

What is a Data Management Plan (DMP)?

A Data Management Plan (DMP) is one of the most important components of responsible research data management. In its simplest form, it is a formal document describing what will happen to research data throughout their entire data lifecycle. The document provides detailed information on the types of research data involved, the conditions governing their use, as well as the procedures for data sharing and archiving during and after the completion of a research project or research activity.

A well-prepared Data Management Plan offers the following benefits:

– facilitates cooperation between scientists working on a research project;
– helps coordinate research implementation;
– strengthens control of data access, security and quality;
– minimizes project risks, such as the protection of personal data from unauthorized use;
– supports the organization of long-term data storage.

How to prepare a Data Management Plan in compliance with the requirements of the National Science Centre (NCN)?

From 2019, the Data Management Plan is a mandatory element of every research project carried out under NCN funding. It is worth noting that it is a “dynamic” document that can change as the project progresses. While submitting the final report, you have to update the Data Management Plan, which is subject to evaluation by NCN.

Diagram illustrating the six key components of a Research Data Management Plan (DMP). At the center is an icon of a document with a checklist and a lightbulb, symbolizing planning and data management. Surrounding the central icon are six colored hexagonal panels arranged in a circular pattern and numbered from 1 to 6. The panels represent: (1) Data Description and Collection or Re-use of Existing Data, (2) Documentation and Data Quality, (3) Storage and Backup During the Research Process, (4) Legal Requirements and Codes of Conduct, (5) Data Sharing and Long-term Preservation, and (6) Data Management Responsibilities and Resources. The graphic provides an overview of the main stages and considerations involved in managing research data throughout its lifecycle.

NCN prepared the guidebook, where you can find detailed information on how to complete the DMP: Guidelines for applicants to complete the Data Management Plan form in the proposal.

Before you start to fill in your DMP form:

  • Please check whether any data has already existed that corresponds to the planned research. It is important to carry out a preliminary analysis. Not taking into account data that has already been available will be treated as a mistake by NCN.
  • Please verify if the planned research requires a positive opinion of the KUE University Research Ethics Committee. More information can be found at: https://uek.krakow.pl/nauka/uczelniana-komisja-etyki-ds-badan-naukowych-uniwersytetu-ekonomicznego-w-krakowie
  • It is worthwhile to consult the planned activities with the relevant entities, for example:
    – the university’s Data Protection Officer – iod@uek.krakow.pl (in the case of collecting personal and sensitive data),
    – the university’s Legal Counsel Team kucharst@uek.krakow.pl (in the case of establishing licences, property rights, creating agreements with external entities),
    – the university’s Center for IT Systems – jobg@uek.krakow.pl (in the case of data storage, backups, etc.).
  • It is worth remembering that NCN obliges beneficiaries of grants to make research data available under a CC0 or CC-BY license.
  • Familiarize themselves with the current regulations operating at KUE in the context of data protection:
    – the policy of personal data security;
    – IT system management instruction;
    – information security incident management procedure;
    – clean desk policy;
    – and cloud working regulations.

Essential information to be included in a Data Management Plan:

Below, you will find infographics on how to prepare a Data Management Plan (DMP) in accordance with NCN guidelines. Please ensure that the recommendations provided are adapted to the objectives of your project and the activities planned. The DMP will be evaluated by NCN experts in the context of the proposed project.

Blue and light-blue infographic labeled “1. Data Description and Collection or Re-use of Existing Data.” Section 1.1 asks how new data will be collected, produced, or re-used. A flow diagram shows four stages: primary data, secondary data, documentation, and processed data. Examples of primary data include surveys, questionnaires, photos, algorithms, samples, experiments, and observations. Secondary data include databases, publications, library collections, archives, legal acts, and official documents. Documentation covers data provenance, methods, and tools used for data acquisition. Processed data include summaries, graphs, tables, and similar outputs. Below, key issues highlighted are data provenance and rights, agreements with external entities, methods, tools and software used, and digitization of analogue materials. Section 1.2 asks what data will be collected or produced, covering types of research data, file formats, and data size. Examples include textual, numerical, audio, video, photographic, database, source code, and sample data; preferred open formats such as ODT, TXT, CSV, TIFF, JPG, WAV, XML, and PDF; and estimates of data volume including backups. Notes recommend using open formats and providing information on how data can be opened and reused if conversion is not possible.
Blue and light-blue infographic labeled “2. Documentation and Data Quality.” Section 2.1 asks what metadata and documentation will accompany the data. It highlights three documentation components: data organization (folders, subfolders, file names, and versions), metadata standards (such as Dublin Core, DDI, and DataCite), and additional documentation (README files, codebooks, protocols, methodological descriptions, and research assumptions). These elements are visually grouped and linked to an archive or repository icon.  Below, key issues emphasize that comprehensive documentation and metadata are essential for future interpretation and reuse of data. The infographic also advises selecting a suitable repository at the planning stage to facilitate metadata creation according to repository requirements.  Section 2.2 asks what data quality control measures will be used. A checklist includes: data cleaning procedures; data quality checks by independent personnel or qualified laboratory staff; use of research methodologies, protocols, and standards; regular equipment calibration; protection against unauthorized data modification; and use of validated software for data analysis and automated data cleaning.  At the bottom, a note states that when multiple institutions participate in a project, the data quality control process should be described separately for each institution. The infographic uses icons representing documentation, repositories, quality assurance, data analysis, databases, research teams, and monitoring.
Green and light-green infographic labeled “3. Storage and Backup During the Research Process.” Section 3.1 asks how data and metadata will be stored and backed up during research. A checklist presents storage options available at KUE: password-protected business laptops and desktop computers with antivirus software installed, KUE cloud storage with automatic backups, Microsoft OneDrive cloud storage, and password-protected external drives.  A central panel illustrates the 3-2-1 backup rule: maintain 3 copies of data, store backups on 2 different devices, and keep 1 copy in a separate location.  Below, key issues note that storing research data on USB flash drives, CDs, or DVDs is not recommended; costs of externally purchased storage devices should be reported as project expenses; and fieldwork projects should describe procedures for transferring data from mobile devices or field stations to institutional servers.  Section 3.2 asks how data security and protection of sensitive data will be handled during research. Four areas are highlighted:  Data security: encryption, password protection, antivirus software, and regular backups. Sensitive data: anonymization or pseudonymization, with codebooks and key files stored separately. Access management: user authentication, authorization, access controls, and role-based permissions. Data recovery: procedures for restoring data after loss or security incidents using backup copies.  A note at the bottom emphasizes compliance with internal KUE regulations and policies and recommends clearly defined data-transfer procedures when multiple institutions collaborate, particularly when sensitive data are involved. Icons throughout the infographic represent secure storage, cloud backup, cybersecurity, identity protection, access control, and data recovery.
A green and light-green informational graphic titled “Good to Know” featuring a warning icon with an exclamation mark. The graphic provides definitions related to the protection of personal and sensitive research data.  The first section, “Sensitive data,” defines sensitive personal data as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health information, data concerning sexuality or sexual orientation, and information about criminal convictions or offences.  The second section, “Anonymization,” explains that anonymization is the processing of data in a way that prevents information from being linked to a specific or identifiable person and that the process is irreversible. The panel notes that OpenAIRE recommends the Amnesia anonymization tool, which removes identifying information such as names, postal codes, and dates of birth.  The third section, “Pseudonymization,” explains that personal data are processed so that they can no longer be attributed to a specific person without additional information. The additional information is stored separately and protected with appropriate technical and organizational safeguards to prevent re-identification.  The design uses green headings and a pale green background to emphasize guidance on data privacy and protection.
Purple and light-purple infographic labeled “4. Legal Requirements, Codes of Conduct.” The infographic is divided into two sections addressing legal and ethical aspects of data management in research.  Section 4.1 asks how compliance with personal data legislation and data security requirements will be ensured when personal data are processed. The section highlights four key elements:  Compliance with GDPR requirements, including adherence to institutional regulations and policies of Krakow University of Economics (KUE). Personal data processing through anonymization or pseudonymization. Participant consent, requiring informed consent to participate in research and information about the future sharing and reuse of data. Consultation with the KUE Data Protection Officer (DPO) regarding consent forms and GDPR compliance issues throughout the project.  Icons depict GDPR compliance, secure data handling, data protection, and informed participation.  A note at the bottom states that if no personal data are processed, it is sufficient to declare this in the project documentation. It also recommends referencing relevant institutional policies, such as the KUE Personal Data Protection Policy, where applicable.  Section 4.2 asks how other legal issues, including intellectual property rights and ownership, will be managed and what legislation applies. A checklist includes:  Regulations for the Management of Intellectual and Industrial Property and Principles of Commercialization at Krakow University of Economics. The Act on Copyright and Related Rights. The Industrial Property Law Act of 30 June 2000. Agreements signed with the research funder. Terms of use of the RODBUK repository, if selected.  At the bottom, a “Please remember to” panel advises researchers to:  Define data ownership. Specify a data-sharing licence (for example, CC BY or CC0). Comply with licence agreements, including those related to databases. Comply with agreements made with other parties.  The design uses purple tones and legal-themed icons, including scales of justice, GDPR, copyright symbols, licences, and contractual agreements, to emphasize legal compliance and responsible data governance.
Blue and light-blue infographic labeled “5. Data Sharing and Long-Term Preservation.” The infographic is divided into four sections covering data sharing, preservation, accessibility, and persistent identifiers.  Section 5.1 asks how and when data will be shared and whether any restrictions apply. Three key topics are presented:  Data sharing: research data should be shared no later than the publication date of the associated publication. Data retention period: research data should be retained for at least 10 years, with metadata preserved indefinitely. Restrictions: possible limitations include commercialization plans, patents and embargoes, personal or sensitive data, contractual agreements, and ethical or legal considerations.  Section 5.2 addresses how data will be selected for long-term preservation and where it will be stored. It highlights:  Preservation of data supporting published research findings, in accordance with FAIR principles and high-quality standards. Selection of a repository where the data will be shared. Identification of data that will not be openly shared but still preserved. Determination of data that should be deleted due to legal, contractual, or regulatory requirements.  Section 5.3 asks what methods or software tools are needed to access and use the data. Guidance includes:  Sharing data in open, non-proprietary formats such as TXT, ODT, CSV, JPG, and TIFF. Ensuring data can be accessed using standard hardware and software. Documenting any specialized software and required versions in a README file.  Section 5.4 discusses assigning a unique and persistent identifier to datasets. It asks whether the selected repository provides a persistent identifier such as a DOI (Digital Object Identifier). The infographic notes that the RODBUK repository is one example because it guarantees DOI assignment for deposited datasets.  Icons throughout the graphic represent data sharing, calendars, retention periods, restrictions, file formats, computer access, checklists, and DOI registration. The overall message emphasizes making research data openly available, preserved for the long term, reusable, and uniquely identifiable.
Orange and light-beige infographic labeled “6. Data Management Responsibilities and Resources.” The infographic is divided into two sections addressing responsibility for data management and the resources needed to support FAIR data practices.  Section 6.1 asks who will be responsible for data management (data steward). It identifies three key areas:  Data management responsibility, for example assignment to the Principal Investigator (PI). Roles and responsibilities for data collection, analysis, and management, assigned to relevant research team members where applicable. Responsibility for Data Management Plan (DMP) implementation and updates, often assigned to the Principal Investigator.  A separate support panel lists institutional and project support resources, including:  KUE IT Team, KUE Data Protection Officer (DPO), KUE legal advisors, KUE patent attorney, KUE librarians and the Cyfronet AGH team responsible for the RODBUK repository, Other relevant stakeholders such as project partners.  A key issue highlighted at the bottom states that in projects involving multiple institutions, the roles and responsibilities of each partner related to data management should be clearly defined.  Section 6.2 asks what resources will be dedicated to data management and ensuring that data are FAIR (Findable, Accessible, Interoperable, and Reusable). The section lists possible project costs, including:  Equipment such as laptops, Digitization of analogue data, External hard drives for backups, Repository fees for data storage.  Funding options under NCN (National Science Centre) include:  Open Access indirect costs (2% of direct costs), Other indirect costs (up to 20% of direct costs).  The infographic also recommends:  Using existing university infrastructure for data storage, management, security, and sharing, Depositing data in a trusted and free repository such as RODBUK.  Icons depict project management, teamwork, a DMP document, support services, funding, and repository infrastructure. The overall message emphasizes assigning clear responsibility for data management and allocating adequate resources to support long-term, FAIR research data management..
An orange and light-beige informational graphic titled “Good to Know” with a warning icon containing an exclamation mark. The graphic explains that research data management costs can be covered by indirect project costs.  The text lists two funding categories:  Open Access indirect costs, up to 2% of allocated direct costs, which may be used only for expenses related to making publications or research data openly accessible. Other indirect costs, up to 20% of used direct costs, which may be allocated to expenses indirectly related to the project, including costs associated with providing open access to publications or research data.  On the right side, a large orange banner titled “More information about the repository:” displays the name “RODBUK”, directing users to the repository as a source of further information about research data storage and sharing.  The graphic uses orange accents and a caution-style icon to highlight practical guidance on funding and repository resources for research data management.

For detailed information on the Data Management Plan, please download the document available here.

Data Management Plan and reporting:

DMP may change during project development (recommended).

Throughout the project, a note should be made of all changes that have occurred compared to the original content of the DMP.

There is no obligation to communicate changes to the DMP to NCN on a regular basis.

Annual report – you report on issues related to the release of publication-related data (if applicable).

Final Report:
– you have to provide a Data Management Plan that is in accordance with the current state of the project at the end of implementation and explain the differences that occurred compared to the original version of the plan;
– you should provide deposited datasets, together with metadata, even when the data has not (yet) been released (e.g., embargo);
– DMP is subject to the evaluation of the Expert Teams. Rating: satisfactory (2 points), partially satisfactory (1 point), unsatisfactory (0 points: call for clarification/completion, in the case of failure to do so, sanctions will be applied).

The information on this site was prepared mainly based on the guidelines and presentations of the National Science Center:

– Guidelines for applicants to complete the Data Management Plan form in the proposal, https://pg.edu.pl/documents/84578476/98747041/wytyczne_zarzadzanie_danymi_ang.pdf
– Czarny G., Wskazówki dot. weryfikacji planów zarzadzania danymi i otwartych (meta)danych badawczych, (prezentacja PDF).
– Galica N., Research Data Management in the Open Access Policy  of the National Science Centre Poland (04.10.2024), https://web.archive.org/web/20250417173558mp_/https://ncn.gov.pl/sites/default/files/pliki/04102024_RDM_Webinar_4_October_2024_v_2.pdf

Tools supporting the preparation of a Data Management Plan (DMP):

  • DMP Tool – a tool that prepares DMP templates tailored to the requirements of US grantors
  • DMP online – a tool very similar to DMPtool containing the UK science funding body database
  • The Digital Curation Centre (DDC) – a UK-based service specializing in research data management