Professional, Legal, and Ethical Responsibilities

Capstone projects involve working with community partners, research groups, companies, students, faculty, staff, and members of the public. As a result, project teams will encounter legal, ethical, and professional obligations related to privacy, confidentiality, intellectual property, data use, research ethics, and public communication.

These requirements are not intended to create barriers to collaboration. Rather, they exist to protect the rights of individuals, project teams, community partners, and the university while supporting responsible project work.

Understanding and following these obligations is an ongoing responsibility throughout the semester and an important part of professional practice.

Why These Requirements Exist

Successful projects balance the needs and rights of many different stakeholders, including:

Many of the policies, agreements, and procedures discussed in this course exist to protect these stakeholders while supporting collaboration, learning, assessment, and public engagement.

Common Agreements and Requirements

Depending on the project, students may be required to comply with one or more of the following requirements.

Non-Disclosure Agreements (NDAs)

NDAs protect confidential information shared by a community partner. These agreements may restrict how project information, data, documents, software, or discussions can be shared, stored, or published.

Intellectual Property (IP) Agreements

IP agreements establish expectations regarding ownership and use of software, designs, reports, data, inventions, and other project deliverables.

Some projects require students to sign NDAs, IP agreements, or both. Students should fully understand these agreements before signing them. If a student is unwilling or unable to accept a required agreement, an alternative project may be assigned.

FERPA

The Family Educational Rights and Privacy Act (FERPA) protects student education records and establishes important privacy rights for students.

Some projects may require students to complete FERPA training before working with educational data such as student records, advising information, learning analytics, or survey responses. At the same time, FERPA also protects your own information as a student. Course activities such as grading, assessment, and peer evaluation may require instructors to access certain information, but students retain important rights regarding how their educational records are used and disclosed.

When working with FERPA-protected information:

Protecting student information is both a legal obligation and a professional responsibility.

Institutional Review Board (IRB)

Institutional Review Boards (IRBs) exist to protect the rights, privacy, safety, and well-being of people participating in research.

Some projects may involve organizations that operate under IRB-approved protocols and may require training or additional restrictions regarding data collection, storage, analysis, and reporting.

Although classroom activities are not always considered research studies, this course generally takes a conservative approach whenever projects involve people, personal information, interviews, surveys, observations, or sensitive data. Students should not assume that collecting information from people is automatically permitted simply because it is being done for a class project.

Even when formal IRB review is not required, students should follow the same principles of respect, transparency, privacy, and informed participation.

Students are responsible for ensuring they have permission to use images, software, datasets, videos, documents, and other materials included in project deliverables.

Always verify that content can be legally used, shared, modified, or redistributed before including it in reports, presentations, websites, repositories, or promotional materials.

Media Releases and Public Communication

The course may provide opportunities to share project work through websites, presentations, hallway displays, project portfolios, conference presentations, social media, or other public-facing materials.

Media release procedures help ensure that names, photographs, recordings, and other identifying information are shared only with appropriate permission. Students are never required to publicly disclose personal information beyond what is necessary to participate in the course.

Sharing Information Responsibly

Many projects involve multiple and overlapping requirements. For example, information may be appropriate to share with instructors for grading purposes while remaining restricted from public release. Similarly, a team may be able to discuss a project publicly while still being prohibited from sharing data, source code, technical details, or other confidential information.

Before sharing information, ask yourself:

If the answer is unclear, ask before sharing.

Executing Agreements and Forms

Throughout the semester, students may be asked to complete agreements, acknowledgements, release forms, training certifications, or other official documents related to their projects and participation in the course.

Examples may include:

Students are responsible for carefully reviewing all documents before signing and ensuring that all required information is completed correctly.

When completing forms:

Students should never sign documents on behalf of another individual, organization, company, project team, or Michigan State University unless they have been explicitly authorized to do so.

A signature indicates that you have reviewed the document and understand the responsibilities associated with it.

If your project requires an NDA or IP agreement, the appropriate forms will be provided through your project materials.

When preparing these documents:

Incorrectly completed forms may delay project participation, prevent access to project resources, or require documents to be resubmitted.

If you are unsure how to complete a form, ask before submitting it.

The following video may be helpful if you are confused. Note that it was recorded during a previous semester, so some course procedures have changed. The discussion of D2L can be ignored. The remainder of the video demonstrates the document signing process.

Course Data and Resource Management

Many projects involve data, source code, documents, reports, and other digital resources that must be managed appropriately throughout the semester. The goal of these guidelines is to balance collaboration, security, legal obligations, and professional software development practices.

Unless otherwise specified by a community partner, legal agreement, university policy, or instructor, these guidelines apply to all course projects.

General Principles

Students should only access, store, and share project resources using approved systems and only with individuals authorized to receive those resources.

When handling project materials, consider:

Approved Collaboration Platforms

Microsoft Teams is the primary secure data platform for this course.

Unless otherwise specified, project data, documents, and communications may be shared through the private Teams spaces provided for the course. These university-supported systems have been approved for the types of project data typically encountered in CMSE capstone projects.

For similar reasons, the course uses Microsoft Teams rather than services such as Discord or Slack.

Data Storage

Project data should be stored only in locations appropriate for the sensitivity of the data.

Approved storage locations may include:

Students should NOT upload protected project data to external cloud services, AI systems, file-sharing platforms, or other third-party services unless those services have been specifically approved by the instructor and community partner.

Local Copies of Data

Project work often requires students to download data to their local computers.

Unless prohibited by an NDA, data-use agreement, or community partner requirement, local working copies are generally permitted when necessary for coursework.

Students are responsible for:

Students should never assume they may retain project data indefinitely after the project concludes.

Source Code Repositories

Source code should be managed using version control.

Projects involving confidential code, partner-owned software, or intellectual property agreements should use private repositories hosted on approved university systems such as:

unless other arrangements have been approved by the community partner .

Open-source projects may use public repositories such as GitHub when permitted by the community partner and team.

Data and Git Repositories

As a general software engineering practice, data should not be stored directly in Git repositories.

Git repositories are intended for source code and documentation, not large or frequently changing datasets.

Repositories may include:

Whenever possible, project data should be stored separately from source code.

External Services and FERPA Considerations

Students are not required to create accounts on third-party services in order to participate in this course.

For this reason, the course provides university-supported platforms such as GitLab and Microsoft Teams for project work and collaboration.

Students retain important privacy rights regarding their educational records and personal information. Course tools and workflows are selected in part to support those rights while still enabling collaboration, instruction, and assessment.

Artificial Intelligence and Cloud Services

Students should be particularly cautious when using AI systems, cloud services, and external analysis platforms.

Project data should not be uploaded to external AI tools, public chat systems, cloud notebooks, or other third-party services unless:

Many AI and cloud platforms retain submitted information or process data outside university-managed systems. Students are responsible for ensuring that data-sharing obligations are not violated.

Project-Specific Requirements

Some projects may have requirements that are more restrictive than the general course guidelines described here.

Examples include:

When project-specific requirements conflict with general course guidance, the more restrictive requirement should be followed.

Ongoing Responsibility

Compliance is not a one-time activity completed through a form or signature. Teams should periodically review their obligations throughout the semester, especially before:

When in Doubt

Professional project work often involves balancing technical goals with legal, ethical, and organizational responsibilities.

If you are uncertain whether information can be collected, stored, shared, analyzed, published, or uploaded to a particular system, do not guess.

Ask your community partner, instructor, or the appropriate university resource before proceeding.

Protecting people, data, and intellectual property is a shared responsibility and an important part of professional practice.

Video to help with signing documents

Some student’s struggled with signing documents. Here are some general guildlines on how to do this professionally. this video was made in a previous semester and some of it is out of date but many students have found this helpful: