This document outlines the steps and requirements for obtaining and managing data from dbGaP, as well as the associated security protocols mandated by NIH.
Key Updates:
New security requirements effective January 25, 2025 mandate that Approved Users of NIH controlled-access data utilize institutional IT systems and compliant third-party computing infrastructures, adhering to the cybersecurity standards specified in NIST SP 800-171 .
Compliance and Security
Granite System
Granite: This secure computing environment at Dartmouth College, Hanover, NH, supports projects requiring compliance with the controls in NIST 800-171 and NIST 800-53 Moderate, making it the appropriate platform for dbGaP data management.
Information on Granite Services: Detailed services and fees for Granite can be found here .
Process for Accessing dbGaP Data
Step 1 - Project Creation and Application Submission
Create a Project: The investigator must create a project and complete the online application through the dbGaP Authorized Access System as a “Principal Investigator” using their eRA Commons account.
Investigators without an eRA Commons account should coordinate with the Office of Sponsored Projects (OSP) to set up an account.
Application Routing: Once submitted, the application will be routed to the Dartmouth Institutional Signing Official in the Office of Sponsored Projects for approval after completion of necessary steps.
Step 2 - Data Use Agreement (DUA) Request
DUA Submission:
The investigator or representative must request a Data Use Agreement (DUA) in eRA.
Specify either Stephanie Morgan or Jill Mortali as the contact, avoiding your assigned Pre-award or Post-Award contact.
Required Information for DUA: Include the following in your ERA submission:
Dataset being requested (including version numbers)
dbGaP project number
Storage location: Indicate Granite, as administered by Research Computing.
Note: All stakeholders involved in managing dbGaP data are encouraged to stay updated on NIH policy changes and security requirements to ensure ongoing compliance.