Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Happens If You Accidentally Collect Research Data Before Ethics Approval?

Accidental data collection before required ethics approval should be addressed promptly and transparently. Stop further unapproved activity, document what happened, protect participants and data, and contact the appropriate institutional ethics authority for instructions.

42
Accidental Data Collection Before Approval Guide 42 of 398
01 · The Question

You Collected Data Too Early. What Should You Do Now?

You discover that a survey link went live before approval. A research assistant interviewed a participant using the wrong start date. Someone began extracting records because they misunderstood the ethics status. Perhaps a few responses arrived before anyone noticed.

The mistake has already happened. The useful question is no longer what should have happened prospectively, but how to protect participants, preserve an accurate record, and allow the appropriate institutional authority to determine what happens next.

02 · The Short Answer

Stop, Document, Protect, and Report

In Brief

If research data were accidentally collected before required ethics approval, stop further unapproved research activity, preserve an accurate record of what occurred, protect the participants and information already involved, and promptly contact the REC, IRB, or institutional office responsible for research ethics and compliance.

Do not conceal the incident, alter dates, quietly delete data, continue collecting because “the damage is done,” or assume that later approval automatically authorizes earlier activity. The appropriate response depends on what happened, the risks involved, the applicable rules, and the institution's procedures for deviations or noncompliance.

03 · What You Need to Know

How to Respond to Accidental Pre-Approval Data Collection

First, Stop the Unapproved Activity

Once you discover that covered research activity began before the required approval, do not allow the same activity to continue simply because some data have already been collected.

Disable the survey link if necessary. Pause interviews. Stop research-specific record extraction. Tell research staff not to enroll or collect further information from participants until the appropriate institutional authority advises that the research may proceed.

The immediate objective is to prevent an isolated error from becoming a continuing practice.

Protect Participants Before Solving the Administrative Problem

If stopping an activity would itself create an immediate hazard to participants, participant safety comes first. Research regulations recognize narrow circumstances in which changes can be implemented without prior IRB approval when necessary to eliminate apparent immediate hazards to human subjects.

That exception should not be stretched into a general permission to continue unapproved research. It addresses protection from immediate hazards, not project convenience.

If participants may require clinical follow-up, safety monitoring, support, or another protective response because of what has already occurred, contact the appropriate institutional and clinical authorities promptly.

Do Not Delete the Evidence of What Happened

Researchers sometimes react to accidental early data collection by immediately deleting the responses. The instinct is understandable: if the data disappear, perhaps the problem disappears too.

That can make matters worse. The institution may need to determine what information was collected, how many participants were involved, whether anyone was exposed to risk, whether consent was obtained, whether confidentiality was compromised, and whether the data can or cannot be retained or used.

Deleting records before obtaining instructions can destroy information needed to reconstruct the incident.

Watch Out

Do not destroy, modify, backdate, relabel, or selectively remove research records merely to make the incident disappear. Secure the information against further unauthorized use and ask the appropriate institutional authority what should happen to it.

Preserving the Data Does Not Mean You Are Allowed to Analyze Them

There is an important distinction between retaining information temporarily so the incident can be assessed and using that information as research data.

Preserving records Maintaining an accurate and secure record of what occurred while the institution evaluates the incident.
Using data for research Analyzing, combining, reporting, publishing, or otherwise using the information to answer the study's research question.

The first may be necessary for compliance assessment. It does not automatically authorize the second.

Document Exactly What Happened

Create a factual chronology while events are still clear. Avoid defensiveness and speculation. Record what happened, when it happened, how it was discovered, and what immediate action was taken.

Useful information can include:

  • the date and time the unapproved activity began and stopped;
  • how many people were approached, screened, enrolled, or otherwise involved;
  • what information, specimens, measurements, or recordings were obtained;
  • whether participants received a consent process and which version was used;
  • whether any intervention or research procedure occurred;
  • whether the data contain direct or indirect identifiers;
  • whether any information was accessed, shared, analyzed, downloaded, or disclosed;
  • what risks or harms may have arisen;
  • how the error occurred;
  • what was done immediately after discovery.

OHRP's incident-reporting guidance similarly expects reports of noncompliance to include a detailed description of the incident and the corrective actions the institution has taken or plans to take.

Report Through the Institution's Actual Process

The investigator should contact the REC, IRB, research-compliance office, Human Research Protection Program, research office, or other body designated by institutional policy.

Do not assume that telling a thesis adviser, department chair, collaborator, or sponsor is equivalent to reporting to the authority responsible for research ethics. Those people may also need to know, but institutional procedures determine who receives and evaluates the incident.

Under HHS requirements, institutions conducting covered research must maintain procedures for prompt reporting of serious or continuing noncompliance, unanticipated problems involving risks to participants or others, and suspensions or terminations of IRB approval.

Is Accidental Early Data Collection a Protocol Deviation?

Terminology varies among institutions. Terms such as protocol deviation, protocol violation, noncompliance, and incident can be defined differently.

U.S. advisory guidance describes protocol deviations broadly as departures from procedures specified in an IRB-approved protocol and notes that deviations can be intentional or unintentional. It also emphasizes institutional variation in how deviations are classified and reviewed.

When data collection begins before initial approval exists, however, there may be no approved protocol from which to “deviate.” The institution may instead characterize the activity as unapproved human-subject research or another form of noncompliance. Let the responsible institutional authority apply its terminology rather than choosing the least alarming label yourself.

Not Every Mistake Has the Same Seriousness

Accidentally receiving one response to a minimal-risk questionnaire is not factually identical to enrolling multiple participants into an unapproved invasive intervention. Institutions should consider the circumstances rather than treating every incident as interchangeable.

Relevant factors can include the number of participants, nature and sensitivity of information, physical or nonphysical risks, whether participants were properly informed, whether vulnerable populations were involved, whether the activity was intentional, whether similar problems have happened before, and whether anyone experienced harm.

Under HHS oversight, serious or continuing noncompliance and unanticipated problems involving risks to subjects or others have specific reporting implications. Institutions and IRBs evaluate incidents against those standards.

An Error Does Not Automatically Mean an Unanticipated Problem

The terms should not be collapsed. OHRP generally considers an unanticipated problem involving risks to subjects or others to involve an event that is unexpected, related or possibly related to the research, and suggests greater risk of harm than was previously known or recognized.

An incident can therefore constitute noncompliance without necessarily satisfying all criteria for an unanticipated problem. The IRB or institution determines which reporting categories apply.

Do Not Decide for Yourself That the Incident Is Too Minor to Report

Institutions differ in what investigators must report and on what timetable. Some distinguish minor deviations from reportable noncompliance; others require investigators to report specified categories through formal systems.

If data collection occurred before required initial approval, guessing that “it was only three responses” is a poor substitute for checking the institution's policy. Contact the appropriate office and let it determine the required reporting and corrective process.

Do Not Backdate Consent or Approval Documents

Research records should reflect what actually happened. Changing a date so that consent appears to have occurred after approval, or presenting a later approval letter as though it existed earlier, would obscure rather than correct the incident.

Accurate chronology is essential for determining participant protections, compliance, data status, and any corrective action.

Later Ethics Approval Does Not Automatically Validate Earlier Data Collection

An REC or IRB may subsequently approve the protocol for prospective research. That does not mean the earlier unapproved activity automatically becomes approved retroactively.

The ethics body or institution may need to decide separately whether previously collected information can be retained, analyzed, or otherwise used. That decision can depend on the applicable regulatory framework, consent, risk, institutional policy, and what occurred during the unapproved period.

This is why retrospective ethics approval should not be treated as the default solution.

Do Not Assume the Data Must Automatically Be Destroyed Either

The opposite automatic reaction can also be problematic. Whether information must be destroyed, retained for compliance documentation, returned, isolated, or potentially used under specified conditions is not a decision researchers should improvise.

There can be legal, institutional, sponsor, safety, scientific-integrity, and participant-welfare considerations. Preserve the status quo as safely as possible and obtain instructions.

Data Security Still Matters During the Investigation

While the incident is being assessed, protect the information already obtained. Restrict access, preserve audit trails where available, prevent unnecessary copying, and avoid sharing or analyzing the data beyond what is necessary to address the incident.

If the mistake involved a confidentiality or security breach, additional institutional privacy or data-protection reporting may also be required.

Participants May Need to Be Informed, but Do Not Improvise the Message

Depending on what happened, the institution or ethics committee may determine that affected participants should be informed, re-consented, given additional information, offered follow-up, or otherwise contacted.

Do not automatically email participants with an improvised explanation before consulting the responsible office. A poorly designed message can create confusion, reveal additional information, or interfere with the institution's corrective plan.

Conversely, do not conceal the event from participants when the institution determines that disclosure is ethically required.

The Response Should Address Why the Error Happened

Corrective action is not limited to dealing with the existing data. The institution may also need to prevent recurrence.

Possible contributing factors include unclear approval dates, poor staff training, misunderstanding of an exemption determination, automated survey activation, miscommunication between collaborators, inadequate version control, or confusion about which site had authorization to begin.

OHRP's incident-reporting process considers corrective actions such as staff education, revised procedures, protocol suspension, increased monitoring, and other institutional responses depending on the incident.

Intent Matters, but Accident Does Not Erase the Event

An accidental error is ethically and administratively different from deliberately ignoring an ethics requirement. Nevertheless, describing something as accidental does not mean no response is needed.

The appropriate authority needs enough information to assess the incident, participant impact, and corrective action. Transparency helps distinguish an isolated mistake from a pattern of disregard for research protections.

Do Not Continue Because You Have Already Started

Researchers occasionally reason that once five participants have already provided data, stopping would only make the dataset less useful. That is precisely the wrong incentive.

Continuing after discovering the problem can transform an accidental event into knowing continuation of unapproved activity. Stop, report, and wait for instructions about what may proceed.

Watch Out

The discovery of accidental early data collection is the point to contain the problem, not normalize it. Continuing after you know approval is missing can materially change how the institution views the incident.

04 · A Practical Example

A Survey Accidentally Goes Live Before Approval

Hypothetical Example

Seven Responses Arrive Too Early

A researcher programs an online questionnaire and schedules it to open on the anticipated approval date. Ethics review takes longer than expected, but the automated survey opens anyway. Seven participants respond before the researcher notices.

Stop The researcher immediately closes the survey and suspends recruitment rather than allowing additional responses to accumulate.
Secure The seven responses are placed under restricted access. The researcher does not analyze, delete, alter, or merge them with later data.
Document The researcher records when the survey opened, when the error was discovered, how many responses were received, what information was collected, what participant information was displayed, and why the automated activation occurred.
Report The researcher contacts the designated institutional ethics office and follows its incident-reporting procedure.
Correct The institution determines the appropriate handling of the seven responses and any corrective actions. The researcher also changes the survey workflow so that activation requires manual confirmation of effective ethics approval.

The researcher's task is not to decide privately whether seven responses are “too few to matter.” It is to give the institution an accurate record from which the appropriate determination can be made.

05 · What Researchers Often Get Wrong

Common Mistakes After Accidental Pre-Approval Data Collection

Misconception

“I'll Delete the Data and Say Nothing”

Deleting the information may destroy evidence needed to assess what occurred and does not necessarily erase the underlying unapproved research activity. Secure the records and obtain institutional instructions before deciding their disposition.

Misconception

“It Was an Accident, So It Isn't Noncompliance”

Intent can affect how an incident is assessed, but accidental conduct can still depart from applicable requirements. Institutional procedures determine how the event should be classified and reported.

Misconception

“I'll Keep Collecting Since We've Already Started”

Continuing after discovering the missing approval can compound the problem. Stop further unapproved activity and seek instructions.

Misconception

“Once Approval Arrives, the Earlier Data Become Approved Too”

Do not assume so. Prospective approval ordinarily governs the research according to its effective authorization. The institution may need to determine separately whether information collected earlier can be used.

Misconception

“The Data Must Automatically Be Destroyed”

Not necessarily. Data disposition can depend on the incident, applicable regulations, consent, institutional policy, participant welfare, and compliance requirements. Let the authorized body determine what should happen.

Misconception

“I Should Change the Dates So the Records Match the Approval”

No. Research and compliance records should accurately reflect the chronology. Backdating or altering documentation conceals the incident rather than correcting it.

06 · What This Means for You

Respond to the Incident Before Trying to Rescue the Dataset

The first question should not be “Can I still publish these data?” Participant protection, accurate documentation, and institutional reporting come first. Data usability is a later determination.

A simple response framework

If unapproved data collection is still occurring
Stop the activity unless immediate participant safety requires another action.
If data or records have already been obtained
Secure and preserve them without conducting unnecessary analysis, alteration, deletion, or dissemination.
If you can reconstruct what happened
Create an accurate chronology including participants affected, information collected, consent status, risks, and immediate corrective actions.
If the institution has an incident, deviation, or noncompliance procedure
Report through that process promptly and provide the requested information.
If you want to retain or use the accidentally collected data
Wait for the authorized institutional determination rather than deciding that later approval automatically permits their use.

If the incident is discovered only after substantial data collection has occurred, the next question becomes what to do when you discover after data collection that ethics approval was required.

07 · A Quick Checklist

What to Do After Accidental Pre-Approval Data Collection

As soon as you discover the incident:
Stop further unapproved recruitment, screening, intervention, or data collection unless immediate participant safety requires another action.
Secure the information already collected and restrict unnecessary access or analysis.
Do not delete, alter, backdate, or conceal research records before receiving appropriate institutional instructions.
Document when the activity began, when it stopped, who was affected, what was collected, and how the error occurred.
Identify any immediate physical, psychological, social, informational, legal, economic, or other risks to participants.
Contact the REC, IRB, research-compliance office, or other institutional authority designated to handle the incident.
Follow instructions concerning participant notification, data disposition, corrective action, and any additional reporting.
Correct the process that allowed the incident to occur before restarting research when authorization is eventually granted.
08 · Frequently Asked Questions

Frequently Asked Questions About Accidental Data Collection Before Approval

Should I delete data accidentally collected before ethics approval?

Do not automatically delete them. Secure the information and contact the appropriate institutional authority. The records may be needed to assess the incident, and the REC, IRB, or institution should determine their appropriate disposition.

Can I use the data once ethics approval is eventually granted?

Do not assume so. Later prospective approval does not automatically authorize earlier unapproved data collection. The appropriate authority should determine whether previously collected data can be retained or used.

Is accidental data collection automatically serious noncompliance?

Not every incident receives the same classification. Seriousness can depend on the applicable rules, risks, number of participants, intent, recurrence, and other circumstances. Institutions and IRBs determine whether an event constitutes serious or continuing noncompliance and whether additional reporting is required.

Is accidental pre-approval data collection an unanticipated problem?

Not automatically. Under OHRP guidance, an unanticipated problem generally must be unexpected, related or possibly related to the research, and suggest greater risk of harm than previously known or recognized. An incident can be noncompliance without satisfying all of those criteria.

Should I tell participants what happened?

Possibly, depending on the incident. Contact the ethics or compliance authority first so that participant communication, if required, is accurate and appropriately coordinated. Immediate safety needs should of course be addressed without delay.

What if only one participant was affected?

Do not assume the event is irrelevant because the number is small. Follow your institution's reporting procedure and allow the authorized body to assess the incident in context.

Can I continue collecting data while the incident is being reviewed?

Not merely because the study has already started. Stop the unapproved activity and wait for the authorization or instructions required by your institution, except where action is necessary to protect participants from an immediate hazard.

What if the mistake was caused by a research assistant rather than the principal investigator?

The incident still needs to be handled according to the institution's procedures. Document how it occurred and identify training, supervision, communication, or workflow changes needed to prevent recurrence rather than treating delegation as removing the study team's responsibility.

09 · The Bottom Line

An Honest, Prompt Response Matters More Than Trying to Hide the Mistake

The Bottom Line

If research data were accidentally collected before required ethics approval, stop further unapproved activity, protect participants and the information already obtained, document the incident accurately, and report it promptly through the appropriate institutional process.

Do not assume that deleting the data, continuing the study, or receiving approval later automatically resolves what happened. The REC, IRB, or responsible institutional authority should determine the incident's classification, corrective actions, and whether the previously collected data can be retained or used.

10 · Sources and Further Reading

Authoritative Sources on Research Noncompliance and Incident Reporting

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes