Version: 1.0.0
Aligned with: Horizon Europe DMP requirements, FAIR Guiding Principles, NIH Data Management and Sharing Policy, OpenAIRE RDM best practices, HIPAA Security Rule
Applicable to: All Cytognosis Foundation research projects generating, reusing, or processing research data
[!NOTE]
Implementation status: This template is complete and ready for use.
The first DMP to be written from this template will be for the Neuroverse program.
See Neuroverse datasets for the cohorts
that will populate sections 2.1 and 2.3 of the DMP.
This template follows the European Commission Horizon Europe DMP template structure and integrates guidance from the OpenAIRE RDM compliance guide, the OpenAIRE FAIR data guide, and the Utrecht University DMP planning guide.
Complete each section below. Replace [placeholder] text with project-specific information. Sections marked with (HIPAA) require additional review by the HIPAA Security Officer. Sections marked with (FAIR) map directly to FAIR sub-principles.
A DMP is a living document. Update it whenever significant changes arise (new data types, revised access conditions, repository changes). At minimum:
| Field | Value |
| --- | --- |
| Project title | [title] |
| Project acronym | [acronym] |
| Grant/funding reference | [grant number, funder name] |
| Project start date | [YYYY-MM-DD] |
| Project end date | [YYYY-MM-DD] |
| DMP version | [e.g. 1.0] |
| DMP last updated | [YYYY-MM-DD] |
| Principal investigator | [name, ORCID iD, affiliation] |
| Data steward / contact | [name, email] |
| HIPAA Security Officer | [name, email] |
Provide a brief description (3-5 sentences) of the project, its objectives, and the role of data in achieving them.
[project summary]
For each dataset or data category the project will generate or reuse, complete the table below.
| Dataset ID | Name / Description | Type | Format(s) | Estimated Size | Origin | Sensitivity Level |
| --- | --- | --- | --- | --- | --- | --- |
| DS-001 | [e.g. Single-cell RNA-seq] | [Genomic] | [AnnData (.h5ad), FASTQ] | [~500 GB] | [Generated / Reused] | [Public / Internal / Controlled / PHI] |
| DS-002 | [e.g. Clinical phenotypes] | [Clinical] | [FHIR R4 JSON, CSV] | [~2 GB] | [Reused from NDA] | [PHI] |
| DS-003 | [e.g. Trained ML models] | [Model] | [ONNX, PyTorch .pt] | [~50 GB] | [Generated] | [Internal] |
Guidance: Use open, non-proprietary formats where possible (CSV/TSV, JSON, HDF5, Parquet, ONNX). If proprietary formats are required for collection (e.g., vendor instrument output), document the conversion pipeline to an open format. See the Cytognosis Multimodal Health Data Schema for canonical format specifications and the Tools Catalog — L1 Storage for approved storage formats (TileDB, Zarr v3, AnnData/h5ad, Safetensors, GGUF, Parquet). The Storage Hierarchy and Dataset Versioning by Scale tables specify which tools to use at each data-lifecycle stage.
All data must be classified according to the Cytognosis Data Governance Policy:
| Level | Definition | Examples | Storage Requirement |
| --- | --- | --- | --- |
| Public | No restrictions on access or sharing | Published datasets, open-source code, aggregated statistics | Any approved storage |
| Internal | For internal use; no PHI or PII | Intermediate analysis results, draft manuscripts, internal reports | Cytognosis-controlled infrastructure |
| Controlled | Subject to access agreements (DUA, MTA) | NIH NDA datasets, dbGaP, UK Biobank extracts | Isolated GCP project with audit logging |
| PHI | Protected Health Information under HIPAA | Patient records, identifiable genomic data, clinical notes | cytognosis-phi-prod with full HIPAA controls |
For each reused dataset, document:
| Dataset | Source | Access mechanism | License / DUA | Restrictions |
| --- | --- | --- | --- | --- |
| [e.g. ADNI neuroimaging] | [LONI portal] | [Approved DUA #XYZ] | [ADNI DUA v3] | [No redistribution; derived data inherits restrictions] |
| Dataset ID | Contains PHI? | Contains PII? | GDPR applies? | Genetic data? | Requires IRB? | Requires DUA/MTA? |
| --- | --- | --- | --- | --- | --- | --- |
| DS-001 | [Yes/No] | [Yes/No] | [Yes/No] | [Yes/No] | [Yes/No] | [Yes/No] |
For datasets containing sensitive information, describe the privacy protection strategy:
| Data class | Storage location | Access method | Responsible party |
| --- | --- | --- | --- |
| Public / Internal | [e.g. GCS cytognosis-data project, regional buckets] | [HTTPS, gsutil, programmatic API] | [Data steward name] |
| Controlled | [e.g. GCS cytognosis-data isolated project with VPC-SC] | [Authenticated API, audit-logged] | [Data steward name] |
| PHI | [e.g. GCS cytognosis-phi-prod with HIPAA BAA] | [VPN + MFA + IAM roles] | [HIPAA Security Officer] |
| Code / pipelines | [GitHub cytognosis org, private repos] | [Git + SSH/HTTPS] | [Engineering lead] |
Describe which data will be shared, with whom, when, and how, following the principle "as open as possible, as closed as necessary."
| Dataset ID | Shareable? | Access level | Repository | License | Embargo | Justification for restrictions |
| --- | --- | --- | --- | --- | --- | --- |
| DS-001 | Yes (processed) | Open | [Zenodo / GEO] | CC BY 4.0 | [None / 12 mo] | [N/A] |
| DS-002 | Partial (aggregated) | Controlled | [NDA] | Custom DUA | None | PHI; individual-level data restricted per consent |
| DS-003 | Yes | Open | [HuggingFace / Zenodo] | Apache 2.0 | None | N/A |
For any data not shared openly, document the legitimate exception:
Guidance: Even when data cannot be shared, metadata describing the dataset must be made openly accessible (CC0). Deposit a metadata-only record in the repository describing what the data contains, how it was generated, and how to request access.
cytognosis organization, public repos]| Role | Person | Responsibilities |
| --- | --- | --- |
| Principal Investigator | [name] | Overall accountability for DMP compliance; approves data sharing decisions |
| Data Steward | [name] | Day-to-day data management; metadata curation; repository deposits; DMP updates |
| HIPAA Security Officer | [name] | PHI access controls; security incident response; quarterly HIPAA reviews |
| Privacy Officer | [name] | GDPR/privacy compliance; consent management; DPIA coordination |
| IT / Infrastructure Lead | [name] | Storage provisioning; backup verification; access control implementation |
| Research Lead(s) | [name(s)] | Data collection protocols; quality control; documentation of methods |
| Item | Estimated Cost | Funding Source | Notes |
| --- | --- | --- | --- |
| Cloud storage (GCS) | [$/year] | [Grant / operational budget] | [Tiered: standard for active, nearline for archive] |
| Repository deposit fees | [$ or free] | [Grant] | [Zenodo: free; domain repos may charge] |
| Personnel (data steward) | [% FTE] | [Grant / institutional] | [Ongoing throughout project lifecycle] |
| Compliance (HIPAA audit) | [$/year] | [Operational budget] | [Annual third-party assessment] |
| Software licenses | [$ or open-source] | [Grant] | [List any commercial tools required] |
| Data anonymization tools | [$ or free] | [Grant] | [e.g., Amnesia (free), ARX (free)] |
Guidance: RDM costs are eligible under Horizon Europe grants (Article 6.2). Plan early to reduce costs. Use the OpenAIRE RDM costing tool for estimation.
| Version | Date | Author | Changes |
| --- | --- | --- | --- |
| 0.1 | [YYYY-MM-DD] | [name] | Initial draft (proposal stage) |
| 1.0 | [YYYY-MM-DD] | [name] | Full DMP (month 6 deliverable) |
Use this checklist (adapted from Jones & Grootveld, 2017) to evaluate each dataset:
| Standard | URL | Applicability |
| --- | --- | --- |
| FAIR Guiding Principles | https://doi.org/10.1038/sdata.2016.18 | All research data |
| Horizon Europe DMP Template | https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/temp-form/report/data-management-plan_he_en.docx | EU-funded projects |
| NIH Data Management and Sharing Policy | https://sharing.nih.gov/data-management-and-sharing-policy | NIH-funded projects |
| HIPAA Security Rule | https://www.hhs.gov/hipaa/for-professionals/security/ | All PHI handling |
| GA4GH Framework | https://www.ga4gh.org/genomic-data-toolkit/ | Genomic data exchange |
| BIDS Specification | https://bids-specification.readthedocs.io/ | Neuroimaging data |
| CELLxGENE Schema | https://github.com/chanzuckerberg/single-cell-curation | Single-cell data |
| OpenAIRE ARGOS | https://argos.openaire.eu/ | DMP creation and publishing |
| CoreTrustSeal | https://www.coretrustseal.org/ | Repository certification |
| FAIRsharing | https://fairsharing.org/ | Standards and repository registry |
| re3data | https://www.re3data.org/ | Repository discovery |
© 2026 Cytognosis Foundation. All rights reserved.
This template is reviewed annually. Domain-specific annexes (genomics, neuroimaging, clinical) may be appended as the project portfolio grows.This appendix maps DMP sections to the relevant layers of the Cytognosis Tools Catalog to help project teams select approved tools.
| DMP Section | Catalog Layer(s) | Key Primary Picks |
| --- | --- | --- |
| 2.1 Data Types and Formats | L1-storage | TileDB, Zarr v3, Parquet, AnnData/h5ad, Safetensors, GGUF |
| 2.1 Preprocessing pipelines | L2-preprocessing | fMRIPrep, Docling, GROBID, PLINK2, Scanpy, scVI |
| 3.1 Findable (PIDs, metadata) | L6-fair | Zenodo (DOI), SWHID, ARK (FAIRSCAPE), CITATION.cff |
| 3.3 Interoperable (schemas) | L9-standard | LinkML, BIDS, NWB, GA4GH VRS, Biolink Model, CELLxGENE |
| 3.4 Reusable (provenance) | L7-provenance | LaminDB, redun, DVC, DataLad, MLflow, Aim |
| 3.4 FAIR packaging | L6-fair | RO-Crate (WRROC), FAIRSCAPE |
| 4.2 Security controls | L13-net | Tailscale, WireGuard, NATS+JetStream |
| 5.1 Storage infrastructure | L1-storage | GCS, TileDB, AIStor (MinIO), DuckDB |
| 5.3 Long-term preservation | L3-repository | Zenodo, DANDI, OpenNeuro, Software Heritage |
| 6.1 Data sharing (repositories) | L3-repository | GitHub, HuggingFace Hub, Zenodo, OpenNeuro |
| 6.3 Code sharing | L4-meta | Zoekt, GitNexus, CITATION.cff |
| 8 Costs (open-source stack) | Cross-cutting themes | All primary picks permissively licensed |