How to protect participant confidentiality when doing research

Confidentiality refers to your obligation as a researcher to prevent unauthorised access to data collected from your participants. In this blog, we discuss how to protect participant confidentiality when doing research.

The concepts

A core tenet of confidentiality is that you only rely on participant data for the purpose consented to. You only divulge it with prior, and preferably written, agreement. Disclosing information about participants to others for reasons outside of the intended scope of your study is not ethical. You must give assurances that after gathering, analysing and interpreting your data, and publishing the ensuing results and findings, its sources remain private and untraceable.

Participant confidentiality is thus closely related to the concepts of privacy and anonymity. Privacy is based on the belief that people have the right, as far as is practicable, to decide what should happen to their personal information. This means that they should be able to control the degree to which their information will be shared, and by what means. Anonymity refers to the practice of ensuring participants are not recognisable from the way you present your raw data, results and findings. It involves eliminating, or hiding, any private information that could possibly identify your participants.

The experiences

One of our former students, Tomas Bhagwan, reminded us of the importance of putting a human face on these seemingly abstract concepts. “Remember, you are dealing with real people, who live real lives and have real experiences. You have real responsibilities to protect your real-life participants.”

Tomas took the rather unusual decision for an aspiring data scientist completing a BSc Data Sciences to do a qualitative study. After conducting his interviews, he assigned pseudonyms to his participants. He also checked his transcripts and removed details potentially connecting what interviewees said with the organisations they worked for. Such as references to proprietary software. This contrasted to the approach taken by most of Tomas’s class colleagues, who did quantitative research. They administered questionnaires, so any personal information was collected in aggregate and did not reveal the identities of any one individual who participated. Regardless of the approach adopted, all these final year students had to comply with their institution’s code of ethics. They also had to abide by the safeguards they had agreed to observe when signing their ethics declaration form.

It is worth noting that confidentiality, privacy and anonymity are not absolutes. You have a duty not to make unrealistic promises or watertight guarantees that might be challenging and impracticable to keep or tempting to break. For example, you might have to contemplate releasing information you have received despite providing explicit, or implicit, undertakings of confidentiality. Like when confronted with a situation of illegality, injustice or wrongdoing.

The laws

Increasingly, how researchers manage confidentiality, privacy and anonymity is prescribed by legislation. The treatment of participant data depends on the geographic jurisdiction that applies to you and your research. Legislative examples include:

  • Canada’s Personal Information Protection and Electronic Documents Act 2000 (PIPEDA).
  • EU’s General Data Protection Regulation 2016/679 (GDPR).
  • India’s Digital Personal Data Protection Rules 2025 (DPDP).
  • UK’s Data (Use and Access) Act 2025 and the General Data Protection Regulation 2018 (UK GDPR).

To illustrate, take the EU’s General Data Protection Regulation (GDPR). This became law for all member states in May 2018. Personal data is information that relates to, or can identify an EU citizen, either by itself or together with other available information. It can include, for example, an internet address, location data and audio or audio-visual recordings.

Data can only be utilised, or kept, where there is lawful reason. The GDPR sets out six lawful reasons, including that consent is freely given, specific, informed and unambiguous, and can be withdrawn. This unequivocally indicates that consent cannot be assumed, so silence, pre-ticked boxes or inactivity does not equate to consent. EU citizens also have the right to request access to their data, and ask for it to be corrected, erased and restricted.

The implications

There is a salutary lesson to be learned for all researchers. Failure to protect participant confidentiality has legal consequences, not just educational ones. Failing your thesis, dissertation or capstone project because of not protecting participant confidentiality is beyond the scope of just being a research issue. So, satisfy your institution’s requirements and conform to local, national and international data protection laws.

Leave a Reply

Your email address will not be published. Required fields are marked *