Professional, Legal, and Ethical Responsibilities
Capstone projects involve working with community partners, research groups, companies, students, faculty, staff, and members of the public. As a result, project teams will encounter legal, ethical, and professional obligations related to privacy, confidentiality, intellectual property, data use, research ethics, and public communication.
These requirements are not intended to create barriers to collaboration. Rather, they exist to protect the rights of individuals, project teams, community partners, and the university while supporting responsible project work.
Understanding and following these obligations is an ongoing responsibility throughout the semester and an important part of professional practice.
Why These Requirements Exist
Successful projects balance the needs and rights of many different stakeholders, including:
- Individual students.
- Other members of the project team.
- Community partners.
- Michigan State University.
- Course instructors and staff.
- Research participants and members of the public.
Many of the policies, agreements, and procedures discussed in this course exist to protect these stakeholders while supporting collaboration, learning, assessment, and public engagement.
Common Agreements and Requirements
Depending on the project, students may be required to comply with one or more of the following requirements.
Non-Disclosure Agreements (NDAs)
NDAs protect confidential information shared by a community partner. These agreements may restrict how project information, data, documents, software, or discussions can be shared, stored, or published.
Intellectual Property (IP) Agreements
IP agreements establish expectations regarding ownership and use of software, designs, reports, data, inventions, and other project deliverables.
Some projects require students to sign NDAs, IP agreements, or both. Students should fully understand these agreements before signing them. If a student is unwilling or unable to accept a required agreement, an alternative project may be assigned.
FERPA
The Family Educational Rights and Privacy Act (FERPA) protects student education records and establishes important privacy rights for students.
Some projects may require students to complete FERPA training before working with educational data such as student records, advising information, learning analytics, or survey responses. At the same time, FERPA also protects your own information as a student. Course activities such as grading, assessment, and peer evaluation may require instructors to access certain information, but students retain important rights regarding how their educational records are used and disclosed.
When working with FERPA-protected information:
- Access only information necessary to complete project responsibilities.
- Follow all project, course, and university requirements regarding data access and storage.
- Do not share protected information with unauthorized individuals.
- Complete any required training before accessing restricted data.
- Ask questions whenever requirements are unclear.
Protecting student information is both a legal obligation and a professional responsibility.
Institutional Review Board (IRB)
Institutional Review Boards (IRBs) exist to protect the rights, privacy, safety, and well-being of people participating in research.
Some projects may involve organizations that operate under IRB-approved protocols and may require training or additional restrictions regarding data collection, storage, analysis, and reporting.
Although classroom activities are not always considered research studies, this course generally takes a conservative approach whenever projects involve people, personal information, interviews, surveys, observations, or sensitive data. Students should not assume that collecting information from people is automatically permitted simply because it is being done for a class project.
Even when formal IRB review is not required, students should follow the same principles of respect, transparency, privacy, and informed participation.
Copyright and Licensing
Students are responsible for ensuring they have permission to use images, software, datasets, videos, documents, and other materials included in project deliverables.
Always verify that content can be legally used, shared, modified, or redistributed before including it in reports, presentations, websites, repositories, or promotional materials.
Media Releases and Public Communication
The course may provide opportunities to share project work through websites, presentations, hallway displays, project portfolios, conference presentations, social media, or other public-facing materials.
Media release procedures help ensure that names, photographs, recordings, and other identifying information are shared only with appropriate permission. Students are never required to publicly disclose personal information beyond what is necessary to participate in the course.
Sharing Information Responsibly
Many projects involve multiple and overlapping requirements. For example, information may be appropriate to share with instructors for grading purposes while remaining restricted from public release. Similarly, a team may be able to discuss a project publicly while still being prohibited from sharing data, source code, technical details, or other confidential information.
Before sharing information, ask yourself:
- Do I have permission to share this information?
- Does this information contain personal, confidential, proprietary, or protected content?
- Does sharing this information violate an NDA, IP agreement, FERPA requirement, IRB protocol, copyright restriction, or other obligation?
- Does everyone represented in this content understand how it will be used?
- Would I be comfortable explaining this decision to my team, community partner, and instructor?
If the answer is unclear, ask before sharing.
Executing Agreements and Forms
Throughout the semester, students may be asked to complete agreements, acknowledgements, release forms, training certifications, or other official documents related to their projects and participation in the course.
Examples may include:
- Non-Disclosure Agreements (NDAs).
- Intellectual Property (IP) Agreements.
- Media Release Forms.
- Research participation documents.
- Community partner agreements.
- Course-related acknowledgements.
Students are responsible for carefully reviewing all documents before signing and ensuring that all required information is completed correctly.
When completing forms:
- Read the entire document before signing.
- Follow all instructions provided with the document.
- Complete all required fields unless instructed otherwise.
- Use your legal name when required.
- Verify dates, signatures, and contact information are accurate.
- Initial all required sections.
- Do not alter agreement language unless explicitly authorized.
- Retain a copy of any document you sign for your records.
Students should never sign documents on behalf of another individual, organization, company, project team, or Michigan State University unless they have been explicitly authorized to do so.
A signature indicates that you have reviewed the document and understand the responsibilities associated with it.
Digitally Signing Legal Documents
If your project requires an NDA or IP agreement, the appropriate forms will be provided through your project materials.
When preparing these documents:
- Remove any instructional highlighting before submitting.
- Complete all fields assigned to you.
- Type all information except your signature whenever possible.
- Ensure names, dates, and signatures are clearly visible.
- Use a professional-looking electronic signature or a clean scanned signature.
- Verify that formatting remains readable after editing.
- Avoid leaving unnecessary blank pages or incomplete sections.
Incorrectly completed forms may delay project participation, prevent access to project resources, or require documents to be resubmitted.
If you are unsure how to complete a form, ask before submitting it.
The following video may be helpful if you are confused. Note that it was recorded during a previous semester, so some course procedures have changed. The discussion of D2L can be ignored. The remainder of the video demonstrates the document signing process.
Course Data and Resource Management
Many projects involve data, source code, documents, reports, and other digital resources that must be managed appropriately throughout the semester. The goal of these guidelines is to balance collaboration, security, legal obligations, and professional software development practices.
Unless otherwise specified by a community partner, legal agreement, university policy, or instructor, these guidelines apply to all course projects.
General Principles
Students should only access, store, and share project resources using approved systems and only with individuals authorized to receive those resources.
When handling project materials, consider:
- Who owns the information?
- Who is authorized to access it?
- Where should it be stored?
- How long should it be retained?
- Are there legal, contractual, or ethical obligations that apply?
Approved Collaboration Platforms
Microsoft Teams is the primary secure data platform for this course.
Unless otherwise specified, project data, documents, and communications may be shared through the private Teams spaces provided for the course. These university-supported systems have been approved for the types of project data typically encountered in CMSE capstone projects.
For similar reasons, the course uses Microsoft Teams rather than services such as Discord or Slack.
Data Storage
Project data should be stored only in locations appropriate for the sensitivity of the data.
Approved storage locations may include:
- Microsoft Teams.
- MSU High Performance Computing (HPC) resources.
- Other MSU approved project infrastructure.
Students should NOT upload protected project data to external cloud services, AI systems, file-sharing platforms, or other third-party services unless those services have been specifically approved by the instructor and community partner.
Local Copies of Data
Project work often requires students to download data to their local computers.
Unless prohibited by an NDA, data-use agreement, or community partner requirement, local working copies are generally permitted when necessary for coursework.
Students are responsible for:
- Protecting downloaded data from unauthorized access.
- Following project-specific restrictions.
- Removing confidential or protected data when it is no longer needed.
- Deleting partner-provided data at the conclusion of the project when required by the community partner or applicable agreements.
Students should never assume they may retain project data indefinitely after the project concludes.
Source Code Repositories
Source code should be managed using version control.
Projects involving confidential code, partner-owned software, or intellectual property agreements should use private repositories hosted on approved university systems such as:
unless other arrangements have been approved by the community partner .
Open-source projects may use public repositories such as GitHub when permitted by the community partner and team.
Data and Git Repositories
As a general software engineering practice, data should not be stored directly in Git repositories.
Git repositories are intended for source code and documentation, not large or frequently changing datasets.
Repositories may include:
- Small example datasets.
- Synthetic datasets.
- Documentation about data access procedures.
- Scripts used to retrieve data.
Whenever possible, project data should be stored separately from source code.
External Services and FERPA Considerations
Students are not required to create accounts on third-party services in order to participate in this course.
For this reason, the course provides university-supported platforms such as GitLab and Microsoft Teams for project work and collaboration.
Students retain important privacy rights regarding their educational records and personal information. Course tools and workflows are selected in part to support those rights while still enabling collaboration, instruction, and assessment.
Artificial Intelligence and Cloud Services
Students should be particularly cautious when using AI systems, cloud services, and external analysis platforms.
Project data should not be uploaded to external AI tools, public chat systems, cloud notebooks, or other third-party services unless:
- The community partner has approved the use.
- Applicable agreements permit it.
- University policies allow it.
- The instructor has approved the workflow when necessary.
Many AI and cloud platforms retain submitted information or process data outside university-managed systems. Students are responsible for ensuring that data-sharing obligations are not violated.
Project-Specific Requirements
Some projects may have requirements that are more restrictive than the general course guidelines described here.
Examples include:
- NDA-protected projects.
- Industry projects.
- Healthcare-related projects.
- Projects involving educational records.
- Projects involving human-subject research.
- Projects with IRB requirements.
- Projects governed by specific data-use agreements.
When project-specific requirements conflict with general course guidance, the more restrictive requirement should be followed.
Ongoing Responsibility
Compliance is not a one-time activity completed through a form or signature. Teams should periodically review their obligations throughout the semester, especially before:
- Publishing content online.
- Presenting project work.
- Releasing code or data.
- Sharing reports outside the course.
- Using photographs, videos, or logos.
- Conducting interviews, surveys, or user studies.
- Submitting deliverables intended for public distribution.
When in Doubt
Professional project work often involves balancing technical goals with legal, ethical, and organizational responsibilities.
If you are uncertain whether information can be collected, stored, shared, analyzed, published, or uploaded to a particular system, do not guess.
Ask your community partner, instructor, or the appropriate university resource before proceeding.
Protecting people, data, and intellectual property is a shared responsibility and an important part of professional practice.
Video to help with signing documents
Some student’s struggled with signing documents. Here are some general guildlines on how to do this professionally. this video was made in a previous semester and some of it is out of date but many students have found this helpful: