Research funders spent a decade encouraging data sharing. The next phase is checking whether anyone did it. The National Institutes of Health's Data Management and Sharing Policy, in force for every award that generates scientific data since January 25, 2023, makes an approved Data Management Plan a term and condition of the grant. The European Commission's Horizon Europe programme does the same through Article 17 of its Model Grant Agreement. The language is not new. The enforcement machinery around it has started to move.
Investigators who treat a data management plan as boilerplate will now meet the policy during a progress report or a closeout. Grantee institutions can be asked to show that repository records match the approved plan, that metadata includes licence and access terms, and that the data connect to the published findings. The expansion comes from audit practice as much as from stricter language. The plans are being read.
From policy text to audit practice
The NIH policy captures scientific data from most grants, including bench experiments, clinical studies, field work, and computational projects. The Data Management and Sharing Plan must cover data types, standards, metadata, preservation, sharing timelines, access controls, and reuse licences. Deposit in a recognised repository is expected at publication or by the end of the performance period, whichever comes first. If a plan calls for an embargo, that must be written down. Costs for curation and sharing can be included in the grant budget, but they have to be tied to the plan.
Horizon Europe grantees face a similar obligation with more paperwork. The first Data Management Plan is due within six months of a project's start and gets updated at reporting checkpoints. Data should follow the FAIR principles, short for Findable, Accessible, Interoperable, and Reusable. The Commission requires deposit in a trusted repository and says data should be as open as possible and as closed as necessary, with exceptions for security, confidentiality, legitimate commercial interest, or personal data protection. The European Research Council uses the same Model Grant Agreement obligations for its grantees. The enforcement lever sits in the grant contract: the Commission can suspend payments, reduce the grant in proportion to the breach, or recover sums already paid for serious failures. NIH's grants policy has parallel remedies, from added conditions to termination.
Why enforcement feels different now
The change research administrators describe is procedural. NIH program staff have clearer instructions to raise data management at progress reviews and to compare the approved plan with what actually enters a repository. Horizon Europe carries the same check through technical reviews and Data Management Plan updates. For many labs, the first signal is an email asking for the repository DOI, a licence statement, a corrected version number, or the embargo date listed in the plan. That is compliance, and it fails even well-funded labs when nobody owns the files.
One recurring problem is the gap between a Data Management and Sharing Plan and what a lab actually does. A genomicist, call her Dr. K, wrote a careful plan for a five-year multi-site study. At closeout, the raw sequencing files were complete, but the phenotype metadata lived in a hospital's clinical system and a collaborator's spreadsheet. The only complete merged file sat on a departed postdoc's laptop. Reassembling the deposit took five weeks. The plan was approved. The habit of naming and storing files coherently was not.
The base rate and the exception
Dr. K's case is not exotic. Across biomedical and computational fields, studies of data availability consistently find that requested or repository-linked datasets are usable somewhere between a third and half of the time. A 2021 analysis in Scientific Data found that requests for data from authors often went unanswered or produced incomplete files, even when papers carried availability statements. The base rate gets worse when researchers rely on "available upon request" statements. The exception is labs that treat the repository record as part of publication, with a named person responsible for transferring files, checking checksums, and recording a DOI before the manuscript is submitted.
What this means for your lab
The first operational fix is to stop treating data management as an administrative afterthought at closeout. Assign one person, even a graduate student with protected time, to own the repository record from month one. Use one shared folder structure and one README per dataset. A README that lists units, missing codes, and version history takes half an hour, and it is the document most likely to save a later compliance conversation.
Budget line items matter. Timid investigators ask for nothing and then rely on goodwill. The better approach is to put repository fees, curation time, metadata help, and a data steward's protected hours into the original budget, because funders said they will pay for them. NIH and the European Commission both allow these costs; omitting them does not make you look frugal when an audit sits in your inbox.
- Name a data steward for each funded project, not each lab.
- Keep a README file beside each dataset from the first experiment, not the last.
- Pick a repository early and confirm its metadata requirements before data arrive.
- Record the DOI and licence in the project file and in the final report.
The external check that follows
Once a dataset is in a repository, external parties verify it. Funders audit the grant file; journals and readers check the DOI. That matters because a data record with no licence or with "on request" as the only access route can fail both a grant audit and a journal check. The NIH Data Management and Sharing Policy makes the accepted plan a condition of award. Horizon Europe open science guidance maps the same logic across European grants. Read both alongside your next grant application, not after the closeout letter arrives.
The European angle, especially for ERC grantees
ERC grant holders are not exempt. The ERC's open science pages require grantees to follow the Model Grant Agreement, which includes the same data deposit rules and Data Management Plan timelines as Horizon Europe. A researcher with an ERC Starting Grant who moves institutions between reporting periods often discovers that the Data Management Plan and the repository access lists need to be updated; this site's earlier guide on ERC open access mandates and grantee rules covers the publication side in detail. The data side tends to trip people when a collaborator leaves and an institutional account closes, taking the linked storage with it.
UK-funded researchers should watch the same pattern. UK Research and Innovation requires data management plans and expects shared data to be as open as possible, with metadata that supports reuse. The earlier piece on the Nelson Memo public access update tracks a parallel US policy discussion, and the current NIH enforcement posture sits against the wider funding turbulence covered in this site's reporting on NIH grant terminations. The throughline remains the same: grant documents now carry data obligations with consequences.
The first concrete next step
Do not fix the archive you already dread. Start with the next grant you will submit. Before the deadline, open the repository you intend to use, read its metadata form, and write a one-paragraph deposit test with ten files from a pilot experiment. That small step exposes most compliance failures: absent licence fields, unnamed variables, missing version numbers. If you can complete a test deposit now, the closeout email later becomes routine. If you cannot, you have just identified the line item to put in the budget.
Photo by Mika Baumeister on Unsplash

Discussion
Be the first to comment on this article!
You’ll be asked to sign in before your comment is posted.