When working on your degree project, you will often encounter two important concepts: GDPR and Ethics. GDPR stands for the EU's General Data Protection Regulation. It regulates how personal data may be collected, stored, used and protected. GDPR is a set of regulations that you need to follow when collecting, storing or using personal data. Personal data is all information that can be linked to a living person. It can include, for example, name, email address, audio recordings or responses to surveys.
Ethics is about moral principles: what is right, respectful and responsible in our interactions with people. In a degree project, ethics means, for example, informed consent and confidentiality; it also means that the work follows good research practice. Reflection on responsibility and respect in scientific work is also included in the learning outcomes for degree project courses.
In short, GDPR is about how you manage data. Ethics is about how you take responsibility for people and knowledge. Remember that both are needed in a well-considered and responsible degree project.
If your work involves the processing of personal data, follow the eight-step guide below. The other parts apply to the writing of all academic papers. In the first instance, you must follow the instructions stated in your course syllabus and provided by your supervisor.
Templates for degree projects or academic papers
You should choose a template for "examensarbete" when the course/module you are taking is called "examensarbete" and/or has the code G1E, G2E, A1E or A2E, depending on the level and type of degree. If you are taking a vocational programme (yrkesprogram) that leads to a professional qualification (yrkesexamen) (midwife, engineer, teacher, social worker, nurse, specialist nurse), then the course will be called "Examensarbete för … (name of the specific profession)".
If your course includes an academic paper (uppsats), this is not the same as a degree project (examensarbete). Use the template for an uppsats.
Student templates - Microsoft Word
Before you begin
When writing an academic paper (uppsats) and handling personal data, you must comply with the General Data Protection Regulation (GDPR). It exists to protect people's privacy. Dalarna University is responsible for how personal data is managed, including in degree projects.
What is considered personal data?
Personal data is anything that can be linked to a living person, for example:
- Name, email address, phone number
- Personnummer or ID number
- Photo, audio recording or IP address
Collecting, storing or using such information is considered to be processing personal data.
What is considered sensitive personal data?
There are special rules for sensitive personal data. As a general rule, you may not use such information in academic papers (uppsatser) at the undergraduate (first-cycle) level. Sensitive personal data is:
- Race or ethnic background
- Political views
- Religious or philosophical convictions
- Trade union membership
- Health
- Sex life or sexual orientation
- Genetic data
- Biometric data
Personal data in academic papers – an eight-step guide
For more in-depth information about personal data processing, see Personuppgiftsbehandling i självständiga studentarbeten - en handledning (pdf) (Swedish text)
Think carefully about and clearly describe why you are collecting personal data; this is the purpose of processing personal data. This helps determine which information is necessary to achieve that purpose.
It is often these that are used:
- Consent: when participants provide information themselves.
- Most frequently, the legal basis on which personal data processing is based is consent.
- Public interest: when the personal data is not collected from the data subject directly, for example, in internet studies or register-based studies.
- It is often not possible to inform and collect consent from each individual.
Only collect personal data if it is truly necessary.
Ask yourself:
- Can I do the study without personal data?
- Can I use less personal data?
You may never collect and process more personal data than is necessary for the purpose. Your supervisor will help you assess the processing of personal data in the intended work.
In independent academic papers at the undergraduate level (first cycle), it is not permitted to:
- Process sensitive personal data
- Process extra sensitive personal data
The examiner has the right to decide on exceptions.
If sensitive personal data is to be processed, see: Sensitive personal data and research projects
Personal data must be protected from unauthorised access and must not be disseminated to more people than necessary.
Keep in mind that:
- Only those who need it should have access.
- Computers should be password protected and have antivirus and firewalls.
- The computer's operating system and software that are used should be up to date with necessary security updates.
- You should use the university's central storage system (H: or home directory on your computer).
- When processing sensitive personal data, you must use H:/home directory.
- When storing locally on a computer or on mobile devices such as a mobile phone or USB, you must ensure that personal data is protected and that a back-up copy is made.
- External cloud services may not be used for processing personal data.
- Printouts should be stored safely and be destroyed in a secure manner.
- Personal data may not be stored longer than necessary.
- In most cases, it should be deleted when the work with the academic paper is completed and has received a passing grade.
- If the data is to be used in further studies, it needs to be saved, and the participants in the study need to consent to this.
Before the practical work begins, it is important to decide what will happen to the collected personal data. If the academic paper is part of a research project, see this heading further down: Sensitive personal data and research projects
According to GDPR, personal data may only be processed if there is a legal basis for the processing. You can read about how the legal basis is assessed in step 1 of the guide: “Step 1: Determine purpose and legal basis”.
If the personal data is collected directly from study participants, the legal basis is consent. Consent is needed from each individual participating in the study.
If you collect consent directly from individuals, you must, in writing:
- explain the purpose of the study
- tell us what data you want to collect
- explain how the personal data will be used and how long it will be stored
Participants must approve this before you begin.
Samtyckesmall och informationsbrev, studentarbeten (doc)
If major deviations from the template need to be made in a specific case, it is recommended that the supervisor contact the university's data protection group dataskydd@du.se or FER fer@du.se.
When your academic paper contains personal data:
- You must register the academic paper with the university's behandlingsregister.
- This is done so that the university can control the ongoing processing of personal data.
- Your supervisor is responsible for checking that the structure and planning comply with legislation and internal rules. This includes ethical considerations.
After you have submitted it for registration:
- You will receive an automatic response.
- You will not receive any further feedback.
If something changes in your work
You must re-register if:
- The purpose of your academic paper changes
- You start processing other categories of personal data.
You also need to register a change if:
- You change supervisor
Follow what you have planned and registered. You may only use the personal data in the manner you have informed us about.
When you have completed your academic paper and been examined in the module and your results have been registered in Ladok, you must:
- Delete personal data (including obtained consent)
- Or archive the personal data according to what you decided in “Step 4: decide what to delete”
The same personal data may be used for a maximum of five examination occasions within the space of no more than three years from the date on which the data collection began. If it has not been possible to offer five occasions within three years, the examiner may decide on a limited time extension.
If you are a student, you are responsible for ensuring that the personal data material is deleted when the work with your academic paper is completed or when three years have elapsed.
Sensitive personal data and research projects
According to GDPR, it is generally prohibited to process sensitive personal data. However, there are exceptions.
For research, special rules apply. The Ethical Review Act (Etikprövningslagen) makes it possible to process sensitive personal data if the research has been approved in an ethics review. However, education at the first-cycle and second-cycle levels is not counted as research. Therefore, these rules do not apply to degree projects at these levels.
The university has decided that the processing of sensitive personal data is, as a general rule, not permitted at the first-cycle level. Exceptions may be made in individual cases if the examiner deems it necessary for you to achieve the course's learning outcomes.
If you are a student and plan to process sensitive personal data, this applies regardless of whether you are covered by an exemption according to the above or are studying at the second-cycle level. You then need to take special requirements into account.
Below is a description of what applies to academic papers that are part of research projects and that process personal data.
For more in-depth information about personal data processing. see: Personuppgiftsbehandling i självständiga studentarbeten - en handledning (pdf)
If you are writing your academic paper as part of a research project where Dalarna University is the research principal (huvudman), the following applies:
- Your personal data will be processed within the framework of the research project.
- The project's principal researcher (huvudansvariga forskare) is responsible for how personal data and research data are managed.
- You use the same legal basis as the research project, usually public interest.
Managing personal data and research data
- You must follow the rules that apply to the current research project.
- You will use the project's IT solution for all processing of research data.
- The IT solution must meet requirements for secure data processing.
In order to process sensitive personal data or information about violations of the law in research, approval from the Swedish Ethical Review Authority is required.
Independent academic papers at the bachelor’s (first-cycle) and master’s (second-cycle) levels do not count as research. They cannot therefore obtain their own ethics approval.
When your work is part of an ethics-approved research project
A degree project can be part of a research project that is led by a principal researcher and that has already received ethical approval. The following then applies:
- You follow the research plan and ethics approval that exist for the project.
- You process personal data with the same conditions as other researchers in the project.
- All processing of research data must take place in the project's IT solution with secure processing.
Keep in mind that:
- If you collect data directly from people, they must have been informed about how the data will be used, including in your degree project.
- The processing of personal data that you do within the project must already be included in the ethics application.
Processing of collected data
- Research data that you collect within the project becomes public.
- It is considered primary material in research.
- It should be archived, not deleted as is usually the case with a degree project.
Therefore, the recommendation is that if you, as a student, need to process sensitive personal data, do so within the framework of an ethics-approved research project where Dalarna University is the research principal (huvudman).
The circumstances under which you may process sensitive personal data in an independent academic paper that is not part of a research project are very limited. This is because students’ academic papers that are not part of a research project cannot receive ethics approval.
In order for it still to be permissible to process sensitive personal data in your independent academic paper, it is required that:
- There is a clear and documented need.
- There are procedures in place to protect the privacy of data subjects.
Based on the developed procedures, a general needs and risk analysis needs to be carried out by the institution as a basis for decisions on exceptions.
Specific for educational level:
- At the undergraduate (first-cycle) level, the processing is considered necessary for you to achieve the learning outcomes.
- The assessment must be documented and registered in the diariet.
- The same principle should also be used at the master’s (second-cycle) level.
In addition, it must be ensured that:
- The work is carried out in an ethically acceptable manner.
- Personal data is handled and protected securely.
It may also be appropriate to submit an application to FER.
Needs and risk analysis
Before you are allowed to process sensitive personal data within the framework of an independent academic paper (regardless of level), a needs and risk analysis must be conducted. It should contain:
Needs
- Why do you need to process sensitive personal data?
- Is it necessary to achieve the learning outcomes?
- Are there alternatives that you can use instead?
Education
- Get in-depth information about personal data processing: Personuppgiftsbehandling i självständiga studentarbeten - en handledning (pdf)
- GDPR training, for example, via the student website
IT security
- You may only use IT solutions that the university has approved.
- Sensitive personal data should be stored in your computer's home directory (H:)
Procedures for suitability assessment
- Consider whether the academic paper should be sent to FER and, through documentation, be able to demonstrate that the work involved with it complies with good practice and is ethically defensible.
- Personal data in academic papers – an eight-step guide to follow
- The suitability assessment should be made for each academic paper using FER's questions: Research Ethics Council (FER) - Dalarna University
Documentation
- The assessment must be documented and registered in the diariet.
The university advises students not to participate in research projects where Dalarna University is not the research principal (huvudman).
This is because:
- The university then lacks control over how the project is conducted.
- It is not possible to ensure that the work is carried out in a legally secure manner.
- It is unclear what responsibility the university can take for your participation in the project.
If external actors process personal data
This is unusual in degree projects, but can occur. If an external party (for example, a supplier of an IT service) processes personal data on behalf of the university, the following applies:
- A personal data processing agreement must be drawn up.
This applies to you as a student:
- In the first instance, use the IT services provided by the university.
- If you want to use other services, an agreement may be required.
- Contact data protection support if this may be relevant: dataskydd@du.se
Ethical considerations
In degree projects that involve people and/or sensitive personal data, support and advice can be sought from the Research Ethics Council (FER); you can also ask to have your academic paper reviewed.
Seek support from your supervisor to determine whether you need to contact FER to ensure that your academic paper is completed under ethically acceptable conditions.
Below are examples of two common situations where both ethics and data protection issues are relevant to consider.
In its review, the council often focuses on four main issues:
- Is the research ethically acceptable in accordance with current regulations?
- Can the harm that the study may cause be outweighed by the benefit (knowledge gains) it may result in?
- Is the information provided to the people being researched and the manner in which their informed consent is obtained appropriate?
- Have personal data issues been handled correctly?
You are a student in a teacher training programme and for your degree project, you plan to interview pupils at a school about their experience of the grades they received in the subject of Swedish. During one of the interviews, a pupil becomes sad and starts crying when the question about their grade comes up.
You are a student in a nursing programme. You are planning to conduct interviews with staff in a department about the work environment, stress and burnout. There is no plan to collect sensitive personal data.
Questions to reflect on: Even if you do not collect sensitive personal data, what risks to the research subjects do you consider there to be? What can happen during the interviews? What steps should you take BEFORE data collection to reduce or avoid harm to research subjects? Why should you do this?
If your academic paper needs to be reviewed by FER
Before you submit your application to FER, all steps need to be completed:
- Complete project description with relevant attachments (for example, interview guide, questionnaire, etc.)
- Information to study participants/researchers in accordance with FER's instructions
- Separate consent form
- Notification of personal data processing according to GDPR and compliance with "Personal data in academic papers - an eight-step guide", which you can find further up on this page
Submit your application: Application to FER for students | Forms
| Statement for degree projects* | What should students do? |
| Complies with good research practice | No further revisions or actions are required. |
| Student revision | There are revisions described in the statement that should be made in consultation with your supervisor. |
| Recommend resubmission to the chairperson | FER recommends that you submit the revisions described in the statement to the FER chairperson for a renewed review. |
|
Recommend resubmission to FER |
FER recommends that you submit the revisions described in the statement to the next FER meeting for a renewed review. |
|
Advice against proceeding |
FER recommends that you do not proceed with your study plan. Reconsider your study in consultation with your supervisor. |
|
Not eligible for an FER statement |
For the reason(s) described in the statement, the application is not eligible for review by FER. |
* Note that the statement usually contains more specific comments and instructions.
FER normally has four meetings each semester. FER must receive applications no later than eight days in advance of a meeting, by 12 noon.
2026
| Meeting date | Deadline for submission |
|---|---|
| 11 February | 3 February |
| 10 March | 2 March |
| 7 April | 30 March |
| 13 May | 5 May |
| 9 June | 1 June – current cases only; no new submissions accepted |
| 8 September | 31 August |
| 14 October | 6 October |
| 10 November | 2 November |
| 8 December | 30 November |
If a problem arises
If personal data is misplaced or lost:
- Contact your supervisor directly.
- The matter may need to be investigated and reported.
Support and advice
- If you have questions about personal data processing, contact the university's data protection office: dataskydd@du.se
- If you have questions about the university's compliance with GDPR, contact the university's data protection officer: frida.sjokvist@arkivit.se
- If you have questions of an ethical nature, contact FER: fer@du.se
During the work process
Security, storage and transmission
If your degree project contains personal data, please refer to the step-by-step guide above.
The university recommends that collected data be stored on its central storage system (called H: or home directory on your computer).
If you are not on campus, you must first connect your computer to the university network via EduVPN. There, data is protected, and a backup copy is made. When storing it locally on a computer or on mobile devices such as a mobile phone or USB, you must ensure that the personal data is protected and that a back-up copy has been made.
In the university's rules for storing digital information at Dalarna University, you can see what type of data can be stored and where. See, in particular, the matrix on the last page of the rules.
- Regler för lagring av digital information vid Högskolan Dalarna (pdf)
- How do I connect my home directory to an external Windows computer - faq.du.se
- How do I connect my home directory on Mac? - faq.du.se
References and copyright
Reference style manuals are available to help you with your academic writing and to inform you about how to avoid plagiarism. Programs are also available that can help you reference correctly. The Swedish Copyright Act (1960:729) explains what to think about when you are copying so as to protect both your work and that of others.
Referencing, reference style guides, plagiarism, copyright, etc.
After work has been completed and approved
Digitala Vetenskapliga Arkivet (DiVA)
Academic papers, degree projects (theses/examensarbeten) for 90/120 credits or equivalent (previously C-level and above) must be archived and preserved in DiVA. If you do not want to publish the degree project in full text, an archival copy should still be preserved in DiVA. Academic papers for 60 credits or equivalent (up to the previous B-level) are not archived in DiVA. They are stored in the university's learning platform and can usually be deleted after 5 years.
For the degree project to be published in full text in DiVA, the author (the student) must give their consent. You give your consent when you use the university's template for degree projects (examensarbeten).
Is your degree project (examensarbete) not available in full text in DiVA? If this is the case, write to publexarb@du.se to consent to its publication.
For other questions about degree projects (examensarbeten), contact: support@du.se.
GDPR training
- Grundläggande utbildning om GDPR för medarbetare och studenter på grundnivå
Datum: 20 september 2023, klockan 09:00 - 10:00
Inspelad föreläsning av utbildningstillfället om GDPR
- Fördjupad utbildning om GDPR för forskare och studenter på avancerad nivå
Datum: 4 oktober 2023, klockan 09:00 - 10:00
Plats: Digitalt via Zoom
Inspelad föreläsning av utbildningstillfället om GDPR för forskare och studenter på avancerad nivå
- Course in the GDPR (General Data Protection Regulation) for Researchers and Students
Datum: 11 oktober 2023, klockan 09:00 - 10:00
Engelsk version med sammanfattning av det viktigaste från främst tillfälle 1 och 3
Plats: Digitalt via Zoom
Inspelad föreläsning av utbildningstillfället "Course in the GDPR (General Data Protection Regulation) for Researchers and Students"