This document discusses managing sensitive data in repositories. It notes that repositories can support fully open, mediated access, or closed/private data, and most contain a combination of open and mediated access data. Sensitive health data can be managed in repositories by de-identifying data where possible, restricting access otherwise, and ensuring proper licensing, metadata, and identifiers are included to aid discovery and reuse while maintaining privacy. The biggest challenge is having longitudinal individual data needed for research while maintaining privacy through de-identification, as some data may need to be omitted from datasets as a result.