Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Who Should Have Access to Identifiable Research Information?

Being part of a research project does not automatically mean needing access to participant identities. Access to identifiable information should be tied to specific research, operational, oversight, or regulatory functions and limited accordingly.

282
Access to Identifiable Research Information Guide 282 of 398
01 · The Question

Does Everyone on the Research Team Need to Know Who the Participants Are?

A principal investigator may need to contact participants. A research assistant may schedule interviews. A statistician may analyse outcomes. A transcriptionist may process recordings. A collaborator may receive a dataset for secondary analysis.

All of them contribute to the research, but that does not necessarily mean all of them need the same information.

When identifiable information is required, one of the most useful confidentiality safeguards is to limit access according to what each person actually needs to perform an authorised function. "Part of the research team" is a role description, not a universal access credential.

02 · The Short Answer

Give Identifiable Information Only to People Who Need It for an Authorised Purpose

In Brief

Access to identifiable research information should generally be limited to people who need that information to perform a legitimate and authorised research, operational, oversight, or regulatory function.

Different people may need different levels of access. A recruiter may need contact details, an analyst may need only coded data, and authorised monitors or regulators may require access for particular oversight functions. The appropriate arrangement depends on the study, applicable law, institutional requirements, agreements, and the sensitivity of the information.

03 · What You Need to Know

Access Should Follow Function, Not Convenience

Start With What Each Role Actually Needs to Do

Access control becomes easier when researchers stop asking, "Who is on the project?" and instead ask, "What information does this person need for this task?"

A staff member recruiting participants may need names and contact details. Someone analysing coded survey responses may have no analytical reason to see those identifiers. A researcher conducting participant interviews will ordinarily know whom they are interviewing, while a statistician working later in the project may need only the study variables and a non-identifying study code.

This is an application of the broader principle of data minimisation: exposure to personal information should be limited to what is necessary for the relevant purpose. The ICO's research guidance identifies data minimisation and pseudonymisation among the safeguards applicable to research-related processing under the UK GDPR framework.

The precise legal requirements vary by jurisdiction, but function-based access is a useful research-governance principle even where that framework does not apply.

The Principal Investigator Does Not Automatically Need Every Identifier at Every Stage

The principal investigator is responsible for the study, but responsibility and routine access are not identical.

In some projects, the principal investigator legitimately needs identifiable information for participant communication, safety procedures, withdrawal requests, data linkage, or other study functions. In others, those functions may be delegated to authorised staff while the principal investigator works primarily with coded information.

The question is therefore not whether a particular job title deserves access. It is whether the person's responsibilities require the information and whether the access is consistent with the protocol, participant information, applicable agreements, institutional requirements, and law.

Research Assistants Should Not Receive Identifiers Merely Because They Are Research Assistants

Research assistants often perform highly varied tasks. One may recruit participants and therefore need contact information. Another may clean quantitative data and need no identities at all. A third may transcribe interviews containing inherently identifying narratives.

Treating all research assistants as one access category can therefore expose more information than necessary.

Where systems permit it, role-based access can separate functions. A recruitment assistant might access the contact list without the full analysis dataset, while a data analyst receives coded research records without names or contact details.

Analysts Often Do Not Need Direct Identifiers

Statistical analysis rarely requires a participant's name, email address, telephone number, or mailing address merely because those identifiers were collected elsewhere in the study.

If analysts need to connect observations across time or datasets, a study code may often serve that function. The code may preserve authorised linkage while reducing routine exposure of direct identifiers.

This is one reason researchers may separate participant identifiers from research data before routine analysis begins.

However, coded data are not necessarily anonymous. Under OHRP guidance for the US Common Rule, private information can remain individually identifiable when investigators can link it to specific people directly or indirectly through coding systems. The regulatory consequences depend on whether investigators can readily ascertain identities and on the circumstances of the research.

The Person Holding the Code Key Has a Different Access Function

A linkage key can reconnect coded research records to participant identities. Access to it therefore deserves particular attention.

Researchers may designate one person or a restricted group to maintain the key. The appropriate choice depends on why re-identification is needed. Someone responsible for longitudinal follow-up, participant withdrawal, safety procedures, or record linkage may need authorised access. Routine analysts may not.

The important point is not that one specific job title must always hold the key. It is that contact and linkage information can be separated from research responses and access granted according to purpose.

Collaborators Should Receive the Minimum Information Their Work Requires

Multi-institutional research creates another access question. A collaborator's legitimate involvement in a project does not automatically establish a need for participant identities.

If a collaborating team needs only to analyse outcomes, a coded, pseudonymized, de-identified, aggregated, or otherwise appropriately prepared dataset may be sufficient, depending on the study and governing requirements.

If collaborators genuinely need identifiable information, researchers should establish the basis for that access and address the relevant ethics approvals, institutional arrangements, data-sharing terms, security requirements, participant information, and applicable law.

OHRP guidance also illustrates why these relationships matter under the US Common Rule. It distinguishes circumstances in which investigators receive coded private information without the ability to readily ascertain identities from situations in which investigators can link information to individuals.

Service Providers Can Encounter Identifiable Research Information Too

Research information may pass through people or organisations that are not conventional members of the academic research team.

Examples include transcription services, survey platforms, cloud-storage providers, laboratories, data-management centres, technology vendors, and specialist consultants. Whether these parties can access identifiable information depends on the service and technical architecture.

Researchers should therefore map actual data access rather than listing only named investigators. If a transcription provider receives identifiable audio recordings, for example, the confidentiality analysis should account for that access even if the provider never appears as an author on the eventual paper.

Applicable contractual, institutional, data-protection, and security requirements should be checked before identifiable information is provided to external services.

Oversight Access Is Different From Routine Research Access

Some people may legitimately inspect identifiable information without using it to answer the research question.

Depending on the study and jurisdiction, authorised ethics bodies, institutional officials, sponsors, monitors, auditors, regulatory authorities, or other oversight entities may need access for compliance, safety, auditing, or verification.

OHRP's guidance on institutional engagement, for example, recognises circumstances in which identifiable private information may be accessed for study auditing or FDA reporting purposes. Such access serves a different function from ordinary research analysis.

This is one reason participant information should avoid simplistic statements such as "only the researchers will ever see your information" unless that statement is actually true under the study's oversight arrangements.

Access Should Be Limited by Both People and Data

Access control is not merely a list of authorised names. It can also determine what each authorised person can see.

Role Information That May Be Needed Information That May Not Be Needed
Recruitment coordinator Names, eligibility information, contact details Complete analytical dataset, unless required for another authorised role
Interviewer Participant identity and interview information needed for the session Unrelated participant records
Data analyst Research variables and study codes needed for analysis Names and contact details when identity is analytically irrelevant
Linkage manager Study codes and information required to perform authorised linkage Unrelated research variables when not required for linkage
External collaborator Data necessary for the agreed research task Direct identifiers when the collaboration can proceed without them
Authorised auditor or monitor Information necessary for the specific oversight function Unrestricted access beyond the scope of that function

These are illustrative arrangements rather than universal rules. A particular study may require different access because of its methodology, safety requirements, regulatory obligations, or organisational structure.

Access to Identifiable Information Should Not Be Permanent by Default

A person may need identifiable information during one stage of a study but not another.

Recruitment staff may need participant contact details while enrolment is open. A longitudinal coordinator may need them through the final follow-up. Once those functions end, continued access may no longer be necessary even if the information must still be retained under an approved retention policy.

Access should therefore have a lifecycle. Researchers can review permissions when personnel change roles, leave the project, complete their assigned tasks, or when the study moves into a new phase.

Shared Accounts Undermine Meaningful Access Control

Limiting access on paper is of little value if an entire research group uses the same account, password, shared drive permission, or unrestricted spreadsheet.

Where systems permit it, individual accounts and role-appropriate permissions can make access restrictions enforceable and auditable. They can also help determine who accessed or changed information when audit logging is available.

The appropriate technical controls depend on the institution, data sensitivity, study risk, and applicable requirements. Researchers should follow approved institutional systems rather than inventing their own security architecture from whatever cloud folder happens to be nearby.

Access Controls Do Not Replace Other Confidentiality Safeguards

Restricting access is only one layer of confidentiality protection. Appropriate safeguards may also include data minimisation, pseudonymization, secure transfer, encryption where required, controlled devices or environments, confidentiality agreements, staff training, retention controls, and procedures for responding to incidents.

Likewise, legal protections such as US Certificates of Confidentiality address particular forms of compelled disclosure but do not prevent every intentional or accidental confidentiality breach. OHRP guidance explicitly notes that other mechanisms remain necessary to protect identifiable private information.

Watch Out

Do not promise that identifiable information will be accessible "only to the research team" unless you have checked the actual study arrangements. Service providers, authorised monitors, regulators, auditors, institutional officials, or other parties may have legitimate access in particular studies, and applicable law may create additional disclosure circumstances.

04 · A Practical Example

One Study Does Not Require One Level of Data Access

Hypothetical Example

A Longitudinal Study of Nurse Burnout

A university follows 600 nurses for two years. Participants complete surveys every six months, so the study needs continued contact and must link responses across waves.

Recruitment team Authorised staff use names and contact information to invite participants and send follow-up reminders.
Linkage function Each participant receives a random study code. A restricted file connects the code to participant identity so longitudinal records can be managed.
Analysis team Statisticians receive study codes, survey variables, and analytically necessary demographics but not names, email addresses, or telephone numbers.
External collaborator A collaborator performing a specialised analysis receives only the variables required for that agreed task, subject to the project's approved sharing arrangements.
Access review When recruitment ends or staff roles change, the team reviews whether existing permissions remain necessary rather than leaving every account unchanged until project closure.

Everyone contributes to the same study, but their informational needs differ. The access design reflects those functions rather than treating membership in the project as permission to see everything.

05 · What Researchers Often Get Wrong

Common Mistakes When Granting Access to Identifiable Research Information

Misconception

Everyone Listed on the Protocol Should Have Full Data Access

Protocol involvement does not necessarily create a need for every category of information. Access can be matched to the functions each person performs, subject to the study's approved arrangements and governing requirements.

Misconception

Only the Principal Investigator Should Ever See Identifiers

That is not a universal rule either. Recruitment staff, interviewers, clinical personnel, linkage managers, or other authorised people may legitimately require identifiable information. The relevant criterion is justified function, not academic rank.

Misconception

Coded Data Mean Analysts Have Anonymous Data

If the research organisation retains a linkage mechanism or the data remain otherwise identifiable, coding does not necessarily create anonymity. It can still reduce unnecessary exposure of direct identifiers to analysts.

Misconception

External Vendors Do Not Count as Access Because They Are Not Researchers

If a provider can access identifiable recordings, files, or other participant information, that access matters to confidentiality and data governance regardless of whether the provider participates in scientific analysis.

Misconception

Once Someone Is Authorised, Their Access Can Remain Forever

Access needs can change as research tasks and personnel change. Permissions should be reviewed and withdrawn when they are no longer necessary, while any continuing retention of the underlying data follows the applicable requirements.

06 · What This Means for You

Build an Access Map Before You Build a Shared Folder

For each category of identifiable information, identify who needs it, why they need it, when they need it, and what happens when that need ends.

A simple decision framework

If someone needs only research outcomes or analytical variables
Consider whether coded or otherwise appropriately prepared data can support the task without direct identifiers.
If someone needs participant contact information but not sensitive responses
Consider restricting access to the contact function rather than granting access to the complete research dataset.
If someone must be able to re-identify coded records
Document the purpose and restrict access to the linkage information accordingly.
If an external collaborator or service provider needs identifiable information
Verify the applicable ethics, institutional, contractual, security, and legal requirements before providing access.
If a person's authorised function ends
Review and remove access that is no longer necessary rather than relying on permanent project-wide permissions.

For studies with substantial identifiable information, an access matrix can make this explicit: roles down one side, data categories across the top, and only the permissions that have a defensible purpose in the cells between them. It is not glamorous methodology, but neither is explaining an unnecessary disclosure to an ethics committee.

07 · A Quick Checklist

Review Who Can See Identifiable Research Information

Before granting access to identifiable research information, check:
Identify the specific research, operational, oversight, or regulatory function requiring access.
Give each role only the categories of information necessary for that function where systems and study requirements permit.
Determine whether analysts can work with coded or otherwise appropriately prepared information instead of direct identifiers.
Restrict access to code keys and other re-identification mechanisms to people with an authorised need.
Include external collaborators, transcription services, technology providers, laboratories, and other relevant third parties in the access assessment.
Account for legitimate monitoring, auditing, regulatory, and institutional access required by the study.
Use individual accounts and appropriate permissions rather than shared credentials where approved systems support them.
Review access when personnel join, change roles, complete their tasks, or leave the project.
Ensure participant information and consent materials accurately describe confidentiality and relevant access arrangements.
08 · Frequently Asked Questions

Frequently Asked Questions About Access to Identifiable Research Data

Should every co-author have access to identifiable participant data?

No universal rule requires authorship to entail access to participant identities. Access should follow the person's authorised research function and the requirements governing the project. Many collaborators can analyse, interpret, or write about appropriately prepared data without needing direct identifiers.

Should the principal investigator be the only person with access to participant identities?

Not necessarily. Other authorised personnel may need identities for recruitment, interviewing, follow-up, clinical procedures, linkage, withdrawal requests, or other legitimate functions. Access should reflect study needs rather than title alone.

Can research assistants access identifiable data?

They may when their authorised duties require it and the study's approvals, training, institutional policies, and applicable rules permit that access. A research assistant performing only data analysis may not need the same identifiers as one recruiting participants.

Can a statistician work without participant names?

Often, yes. Statistical analysis commonly requires study variables and possibly participant codes for linkage rather than names or contact information. Some analyses may have different requirements, so the actual analytical purpose should determine access.

Can an external collaborator receive identifiable research information?

Potentially, when identifiable information is necessary for the collaboration and the relevant ethics, institutional, contractual, security, and legal requirements are satisfied. If the collaboration can proceed without identities, providing less identifying information may reduce unnecessary exposure.

Can auditors or regulators see identifiable research records?

In some studies, authorised monitors, auditors, regulators, sponsors, or institutional officials may require access for oversight, verification, safety, or compliance purposes. The applicable requirements and participant information should be checked for the specific study.

Should former team members retain access to research data?

Access should be reviewed when someone leaves the project or no longer performs the function that justified it. Continued access should have an explicit basis rather than persisting simply because an old account remains active.

09 · The Bottom Line

Access Should Be Necessary, Authorised, and No Broader Than the Task Requires

The Bottom Line

Identifiable research information should generally be accessible only to people who need it for a legitimate and authorised function, with the scope and duration of access matched to that function.

Map roles to information rather than granting the entire project team the same permissions by default. Recruitment, analysis, linkage, collaboration, service provision, and oversight may each require different access, and those needs can change as the study progresses.

10 · Sources and Further Reading

Authoritative Sources on Access to Identifiable Research Information

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes