Unfortunately, download is a requirement. I just used pivot table as an example as someone mentioned it, but others have mentioned the Faculty may want to put in into tools to run queries using those tools, outside of Google (ie. a database tool, or a reporting tool like IBM Cognos, etc.).
I'm thinking a DLP rule looking for a unique string that we enter into the Sheet and hope they don't remove those unique strings, that should catch external email sharing or Drive sharing (tested).
I understand once we allow download (nothing stops someone from taking a screenshot either), we lose control/visibility without the proper DLP tools or extensive work on the backend (gpo's restricting all Windows devices from only signing in with thier Org gmail but that doesn't stop Mac users, etc.). I've let my VP of IT know and she's aware and has reiterated this to the Administration. We do have auditing at least to know who downloads/copies the file.