The Independent Verification Address (IVA) and how it is used in GHGA¶
What Is an IVA?¶
An Independent Verification Address (IVA) is an alternative contact method (usually a mobile phone number) used to verify personal accounts in the GHGA Data Portal. It aims to ensure that the LS ID used for authorisation in the portal is not compromised, thereby implementing an additional security layer. An IVA is also used by GHGA Data Stewards to validate decisions on Data Access Requests that are communicated to GHGA by Research Data Controller Representatives.
IVAs must be able to receive a one-time verification code via SMS, and so normally a mobile phone number is used.
Why Is an IVA Needed?¶
IVAs are an additional safety measure used to identify individuals either when they communicate with GHGA or during communication of the Research Data Controllers with Data Requesters.
An IVA is needed during the following processes:
- Data Submission to GHGA: During the establishment of a Data Processing Contract (DPC) with GHGA Central the Data Submitter must specify IVAs for the Persons authorised to act on behalf of the Research Data Controller (RDC) in the DPC. Further information here.
- Making a Data Access Request: When filing a Data Access Request (DAR) to a study listed on GHGA, the Data Requester Representative (DRR) creates an account on the GHGA Portal. Initial authentication is done via LS ID. However, in order to be able to download data from an approved DAR, a verified IVA is needed. Importantly, the Research Data Controller must instruct GHGA to use the same IVA for the DRR so we are sure that the Research Data Controller has verified the IVA independently. Further information here.
- Negotiating a Data Transfer Agreement (DTA): Once a Data Access Request (DAR) is filed in the GHGA Data Portal, it is the duty of the Research Data Controller to negotiate a suitable Data Transfer Agreement (DTA) with the Data Requester. Importantly, GHGA is not involved in this process. During this negotiations, the controller needs to confirm the IVA provided by the Data Requester in order to ensure the identity of the data requester. Further information here.
General Usage Instructions for the IVA¶
How to Verify an IVA¶
GHGA offers two types of IVAs: Mobile Phones and in Person validation. A new IVA can be added to your profile in the GHGA Data Portal.
For practicability mobile phones are recommended but please note that Research Data Controller (RDC) might demand alternative means during negotiation of a Data Transfer Agreement (DTA).
-
To create and verify a contact navigate to the GHGA Data Portal.
-
After logging in, visit "Your GHGA account page" by clicking on your profile on the top right corner.

-
Here the menu "Independent Verification Addresses (IVAs)", lists all registered contact addresses. To add a new one, click "Add an IVA":

-
Select an IVA type from SMS, or In-Person. Please note, in person verification is only offered for personnel located at a GHGA Data Hub. The fastest verification can be performed via SMS.

-
Enter the required information for the chosen type and confirm them by clicking on "Submit".

-
The menu "Independent Verification Addresses (IVAs)" will add the unverified address. A code for this address can be requested by clicking "Request verification".

-
A code will be transmitted if "SMS" was selected. Upon receival of the code, click on "Enter verification code", enter the code and confirm the transmission.

The contact address will then be shown as "Address has been verified".
If a code is not working or lost, the address can be deleted and added again to generate a new code. In case of issues, please contact the GHGA Helpdesk.
Important Notes¶
- IVAs will never be shared publicly by GHGA.
- Only verified IVAs that have been approved by the Research Data Controller can be used for accessing data.
- If you reset your second factor, all IVAs require re-verification.
- An incorrect or unverified IVA will prevent you from downloading data.
- You can submit a Data Access Request without an IVA, but cannot download data until it’s verified.