Skip to content
NBDC Human Database

No datasets in the cart.

Due to system maintenance, the application system, application review by the Data Access Committee will be unavailable during the following period.
Schedule: October 5th (Mon), 2026, 9:00 - October 7th (Wed), 2026, 15:00 (JST)
We apologize for any inconvenience this may cause and appreciate your understanding.

We are currently receiving a large number of applications for data submission, and the review process is taking longer than usual.We sincerely apologize for the delay and kindly ask for your understanding. When submitting an application, we would greatly appreciate it if you could allow sufficient time for the processing.

Following a change to our organizational structure effective April 1, 2026, this division has been renamed from the "Database Center for Life Science, Joint Support-Center for Data Science Research" to the "Database Division for Life Science (DBCLS), BioData Science Initiative (BSI), National Institute of Genetics (NIG)". Where the former name still appears in the guidelines, please read it as the new name.

NBDC Security Guidelines for Human Data (for Database Centers)

Click to Latest version.

2013.4.25
Ver. 1.0 

#Introduction

The National Bioscience Database Center (NBDC) of the Japan Science and Technology Agency (JST) develops and operates the NBDC Human Database in accordance with the NBDC Guidelines for Human Data Sharing (hereinafter, the Data Sharing Guidelines). For data users, we have the NBDC Security Guidelines for Human Data (for Data Users)" (hereinafter, the User Security Guidelines). For database centers, which receive data from data submitters and offer them to data users, security measures that are stronger than those taken by data users are required because database centers handle not only controlled-access data, which are defined in the Data Sharing Guidelines, but also data for future release (data held prior to publication of a paper or acquisition of a patent). Based on the User Security Guidelines, this document sets forth the security measures to be taken by database centers.

#1. Application of the User Security Guidelines

When controlled-access data or data for future release are handled, in principle the standard-level (Type I) security measures, which are listed in the User Security Guidelines, must be put in place, and high-level (Type II) security measures are implemented as needed. All data offered must be de-identified.

Some definitions in Section 1 (Definitions) of the User Security Guidelines are changed as follows, and the sections starting with Section 2 (Measures to Be Taken under Standard-Level (Type I) Security) apply to this document.

  • Data
    • Controlled-access data and data for future release that are handled at the database center.
  • Principal Investigator (PI)
    • The person in charge of the database center.
  • Data user
    • The PI the database center or staff who accesses data at the database center.

#2. Security Measures Additionally Taken by the Database Center

  1. The database center must be audited by system security experts when a system is built and once every several years.
  2. With regard to open data, the servers and network devices that handle them must be properly maintained in order to avoid unauthorized access and malicious data alteration.