Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

When Can Researchers Break Participant Confidentiality?

Confidentiality does not mean researchers may disclose participant information whenever they believe disclosure is justified. Disclosure should have a defined basis, such as participant authorization, an applicable legal requirement, an approved research or oversight function, or another circumstance permitted by the rules governing the study.

286
When Can Researchers Break Confidentiality? Guide 286 of 398
01 · The Question

When Is a Researcher Allowed or Required to Disclose Confidential Participant Information?

A participant reveals something serious during an interview. A court requests research records. A regulator asks to inspect study documentation. A participant asks the researcher to send information to their physician.

Does confidentiality mean the researcher must refuse every disclosure?

No. But neither does a researcher's belief that disclosure would be sensible automatically create permission to disclose. Whether participant information may or must be released depends on the reason for disclosure, applicable law, the participant's authorization, the study's approved procedures, any specific legal protections, and the researcher's professional or institutional obligations.

02 · The Short Answer

Confidentiality Can Have Defined Exceptions, but Researchers Should Not Invent Them

In Brief

Researchers may disclose confidential participant information when a valid authority or permission applies, such as the participant's authorization, an applicable legal reporting requirement, an authorised research or oversight function, or another disclosure expressly permitted under the protections governing the study.

The rules are jurisdiction- and study-specific. Researchers should not assume there is a universal duty to report every disclosure involving harm, abuse, illegal activity, or other sensitive information; nor should they assume confidentiality always overrides applicable law. The correct response should be established before sensitive data are collected whenever foreseeable disclosure situations exist.

03 · What You Need to Know

Not Every Disclosure Is a Breach of Confidentiality

First Distinguish an Authorised Disclosure From a Confidentiality Breach

Researchers sometimes use "break confidentiality" to describe any occasion on which identifiable information leaves the immediate research team. That can obscure an important distinction.

If a participant authorizes a disclosure, a law requires particular reporting, or an authorised regulator inspects records under the conditions governing the study, disclosure may fall within an established limit of confidentiality rather than constitute an unauthorised breach.

Permitted or required disclosure Identifiable information is disclosed under a valid permission, legal requirement, approved research arrangement, or other applicable authority.
Confidentiality breach Information is accessed, used, or disclosed inconsistently with the permissions, protections, or obligations governing it.

The practical goal is therefore not simply to "never disclose." It is to prevent unauthorised disclosure while identifying legitimate exceptions accurately.

A Participant Can Authorize Disclosure

A participant may ask researchers to disclose particular information to another person or organisation. For example, a participant might authorize release of certain research information to a physician or another researcher.

The scope of that authorization matters. Permission to disclose one result to one person does not necessarily authorize release of the participant's entire research record to anyone who asks.

Where applicable, researchers should follow the documentation, consent, privacy, institutional, and legal requirements governing such disclosures.

NIH's current Certificate of Confidentiality policy, for example, permits disclosure of protected identifiable, sensitive research information when the individual consents.

Some Laws Can Require Disclosure

Researchers may be subject to reporting requirements established by law. The specific duties depend on jurisdiction, research setting, professional status, participant population, and the information involved.

NIH guidance concerning Certificates of Confidentiality illustrates this clearly. Although Certificates provide strong protection against disclosure of identifiable, sensitive research information, current NIH policy permits disclosure when required by applicable federal, state, or local law, with examples including certain communicable-disease and abuse-reporting requirements.

This should not be converted into a universal rule that every researcher everywhere must report the same categories. A psychologist conducting research, a university lecturer conducting interviews, a physician-investigator, and a researcher in another country may operate under different legal duties.

Watch Out

Do not write a generic protocol stating that researchers will disclose information whenever participants mention abuse, self-harm, harm to others, illegal conduct, or another sensitive issue unless you have verified the actual legal, professional, ethical, and institutional requirements governing that research. Reporting obligations vary.

Threats of Harm Do Not Create One Universal Research Rule

Statements suggesting serious harm to self or others are among the most difficult confidentiality scenarios. Researchers may have legal, professional, institutional, or protocol-specific responsibilities, particularly when they are also clinicians or other regulated professionals.

But there is no single international "researcher duty to warn" that can safely be applied to every project.

The appropriate response may depend on the jurisdiction, whether the researcher has a professional duty independent of the research role, the immediacy and specificity of the threat, institutional procedures, ethics approval, and any protections governing the data.

Researchers studying topics where such disclosures are reasonably foreseeable should establish a response protocol before recruitment begins rather than deciding during an interview under pressure.

Abuse and Safeguarding Disclosures Also Depend on Applicable Rules

Research involving children, older adults, vulnerable people, violence, abuse, neglect, or exploitation may encounter information that triggers safeguarding questions.

Again, the researcher should not assume either that all such information must remain confidential or that every disclosure automatically requires reporting.

Applicable reporting laws, institutional safeguarding procedures, professional duties, ethics requirements, and the participant's circumstances need to be established for the particular research setting.

Where reporting is foreseeable, the relevant limit should ordinarily be incorporated into the study's confidentiality plan and explained appropriately to participants rather than revealed only after sensitive information has been provided.

Illegal Activity Does Not Automatically Cancel Confidentiality

A participant may disclose illegal drug use, undocumented work, regulatory violations, criminal behaviour, or another potentially unlawful activity during research.

The mere fact that information concerns illegal conduct does not itself establish a universal permission or obligation for researchers to report it.

Indeed, research on sensitive or stigmatized behaviour often depends on strong confidentiality protections. US Certificates of Confidentiality were developed in part to protect identifiable, sensitive research information from compelled disclosure in legal proceedings. Current NIH policy generally prohibits disclosure of covered information in federal, state, or local civil, criminal, administrative, legislative, or other proceedings unless the participant consents, while permitting specified categories of disclosure outside that prohibition.

Researchers should therefore determine the actual legal position rather than treating "illegal" as synonymous with "reportable."

A Court Request Does Not Necessarily Mean Researchers Should Immediately Hand Over the Data

Subpoenas, court orders, law-enforcement requests, and other demands for research information require careful handling. The correct response can depend on jurisdiction, institutional policy, the form of the request, and whether a specific legal protection applies.

For research protected by a US Certificate of Confidentiality, federal law provides significant protection against compelled disclosure of identifiable, sensitive research information in legal and other proceedings. NIH states that institutions covered by a Certificate must uphold and defend those protections.

A researcher receiving a legal demand should therefore follow the institution's established legal and research-governance procedures rather than personally deciding that a document bearing legal language must automatically be obeyed or ignored.

Oversight Access May Be Part of the Study Rather Than an Exception Invented Later

Depending on the research, authorised monitors, regulators, institutional officials, sponsors, auditors, or ethics bodies may inspect records for compliance, verification, safety, or oversight.

If that access is part of the approved research arrangement, it should be treated as such and addressed appropriately in participant information where required.

This reinforces the distinction between confidentiality and secrecy. Confidential research information can have controlled authorised access without being publicly or indiscriminately disclosed.

Scientific Research Can Sometimes Permit Further Disclosure Under Specific Rules

Identifiable research information may sometimes be shared for additional scientific research, but the conditions depend on the applicable framework, consent, approvals, data-sharing arrangements, and legal protections.

For example, NIH's current Certificate policy permits disclosure for other scientific research conducted in compliance with applicable federal human-subjects regulations.

That does not create a general right to give identifiable data to another researcher. The original study's consent, ethics approval, applicable data-protection rules, agreements, and institutional requirements still matter.

Medical Treatment Can Create a Specific Disclosure Path in Some Research

Under NIH Certificate policy, identifiable, sensitive information protected by a Certificate may be disclosed when necessary for the participant's medical treatment and when the participant consents.

This is a specific feature of that US legal framework, not a universal research rule. Other studies and jurisdictions may have different requirements for returning clinically relevant information or communicating with healthcare professionals.

Voluntary Disclosure and Legally Required Disclosure Are Not the Same

Older OHRP guidance on Certificates of Confidentiality highlights an important conceptual distinction. Certificates protect against compelled disclosure, but researchers may face situations involving voluntary disclosure, such as information about abuse or threats of violence. OHRP states that if investigators intend to make such voluntary disclosures, the consent form should clearly indicate this.

Current NIH policy should be consulted for the operative Certificate rules, but the broader research-ethics lesson remains useful: a disclosure practice that the research team intends to follow should not be hidden from participants merely because disclosure is not legally compelled.

Disclosure Should Usually Be No Broader Than Necessary

When disclosure is required or authorised, that does not automatically justify releasing every piece of information the researcher holds.

The appropriate scope depends on the authority requiring or permitting disclosure. Researchers should follow applicable legal and institutional guidance concerning what information must be provided, to whom, and for what purpose.

This mirrors the broader principle of data minimisation: necessity should shape both collection and disclosure.

The Disclosure Plan Should Be Designed Before Data Collection

Studies involving foreseeable safeguarding, legal, clinical, or safety disclosures should establish procedures before participants begin providing information.

Possible Situation Question to Resolve in Advance Do Not Assume
Participant authorizes disclosure What exactly has the participant authorized, to whom, and how should it be documented? Permission for one disclosure authorizes every future disclosure
Suspected abuse or neglect What reporting laws, professional duties, and institutional procedures actually apply? Every researcher has the same mandatory-reporting duty
Threat of serious harm What legal, professional, ethics, and institutional response protocol governs the situation? There is one universal researcher duty to warn
Legal demand for records What legal protections apply and who within the institution handles the request? Every subpoena or request automatically overrides confidentiality
Regulatory or monitoring access Is the access authorised under the study and what records may be inspected? Any access outside the immediate research team is a breach
Further scientific research Do consent, approvals, law, agreements, and applicable protections permit the disclosure? Scientific usefulness alone creates permission
04 · A Practical Example

What Happens When a Participant Reveals Something the Researcher May Need to Report?

Hypothetical Example

An Interview Study About Family Experiences

A research team plans interviews that could reasonably elicit disclosures about abuse or serious threats of harm. Before recruitment, the team determines the applicable reporting laws, institutional safeguarding procedures, professional obligations of the interviewers, and ethics requirements.

Before recruitment The researchers identify exactly which circumstances, if any, would require or permit disclosure and establish whom staff should contact internally.
During consent Participants are told the relevant confidentiality limit in understandable terms before deciding whether to participate.
During an interview A participant provides information that appears to fall within the predetermined disclosure procedure.
Researcher response The interviewer follows the approved procedure rather than improvising a personal interpretation of the law or promising continued secrecy that the protocol cannot provide.
Disclosure If disclosure is required, the team follows the applicable institutional and legal process and limits the information disclosed to what that process requires or permits.

The important safeguard occurred before the difficult disclosure. The research team knew what confidentiality meant in that study, and the participant had been given an opportunity to understand the relevant limit before sharing sensitive information.

05 · What Researchers Often Get Wrong

Common Mistakes About Breaking Research Confidentiality

Misconception

Researchers Must Report Every Illegal Act Participants Mention

No universal research rule requires this. Reporting duties depend on applicable law, professional obligations, jurisdiction, study circumstances, and specific legal protections. Sensitive research may in fact have strong protections against compelled disclosure.

Misconception

Researchers Can Break Confidentiality Whenever They Think It Is Ethically Right

Personal ethical judgment does not automatically create legal or institutional authority to disclose identifiable information. Researchers should follow the requirements and procedures governing the study, seeking appropriate institutional or legal guidance when necessary.

Misconception

A Subpoena Always Means the Data Must Be Released

Not necessarily. Legal protections such as US Certificates of Confidentiality can restrict compelled disclosure. Researchers should route legal demands through appropriate institutional procedures rather than responding independently.

Misconception

A Certificate of Confidentiality Means Researchers Can Never Disclose Anything

No. Current NIH policy permits specified disclosures, including those required by certain laws, those made with participant consent, certain disclosures necessary for medical treatment with consent, and qualifying scientific research.

Misconception

If Disclosure Is Legally Permitted, Participants Do Not Need to Know About It

Where a disclosure limit is relevant to participation, informed-consent principles support explaining the extent of confidentiality accurately. HHS advisory guidance specifically states that participants should be informed about circumstances in which confidentiality will not be maintained.

06 · What This Means for You

Decide the Limits Before a Participant Tests Them

If the subject matter makes sensitive disclosures foreseeable, confidentiality planning should be part of protocol design rather than an emergency decision during data collection.

A simple decision framework

If you believe a law requires disclosure
Verify the actual requirement for your jurisdiction, role, participant population, and research context through appropriate institutional or legal channels.
If the participant requests disclosure
Confirm the scope and validity of the participant's authorization and follow the applicable documentation and institutional procedures.
If a court, law-enforcement agency, or other authority requests identifiable research records
Use the institution's established legal process and determine whether protections such as a Certificate of Confidentiality apply before releasing information.
If monitors, regulators, or auditors require access
Confirm that the access falls within the authorised oversight arrangement and limit it to the relevant function.
If a foreseeable confidentiality exception exists
Make sure participants receive an accurate explanation of that limit before providing the information to which it may apply.

Confidentiality should be strong enough that researchers do not disclose information casually, but precise enough that they know what to do when an actual exception arises. The next challenge is communicating those limits of confidentiality to participants without turning consent into a miniature statute book.

07 · A Quick Checklist

Before Disclosing Confidential Participant Information

Before making an identifiable disclosure, check:
Identify the specific authority, permission, legal requirement, or approved research function that permits or requires disclosure.
Verify jurisdiction-specific reporting obligations rather than relying on assumptions about abuse, harm, illegal conduct, or other sensitive disclosures.
If a participant authorizes disclosure, confirm what information may be released and to whom.
Route subpoenas, court orders, law-enforcement requests, and similar legal demands through appropriate institutional procedures.
Determine whether a Certificate of Confidentiality or another specific legal protection restricts disclosure.
Limit disclosure to the information and recipients authorised or required by the applicable rule or permission.
Document the disclosure according to institutional and study requirements where applicable.
Ensure foreseeable confidentiality limits were accurately addressed in participant information and consent materials.
08 · Frequently Asked Questions

Frequently Asked Questions About Breaking Participant Confidentiality

Must researchers report participants who admit committing a crime?

There is no universal rule requiring researchers to report every admission of illegal conduct. The answer depends on applicable law, professional obligations, the research context, jurisdiction, and any specific confidentiality protections.

Must researchers report threats of self-harm or harm to others?

Not under one universal research rule. Legal and professional duties vary by jurisdiction and by the researcher's role. Studies likely to encounter such disclosures should establish an institutionally approved response procedure before data collection begins.

Must researchers report suspected child abuse?

Potential reporting duties depend on the jurisdiction, the researcher's professional or institutional status, the participant population, and applicable law. Researchers should verify the rules governing their study rather than assume that all researchers have identical obligations.

Can researchers disclose information if the participant asks them to?

Potentially, yes. The participant may authorize a defined disclosure, subject to the applicable legal, ethical, institutional, and documentation requirements. Permission should not be interpreted more broadly than its actual scope.

Does a subpoena automatically override research confidentiality?

No universal answer applies. Specific legal protections may restrict compelled disclosure, including US Certificates of Confidentiality for qualifying research. Researchers should follow institutional legal procedures rather than responding independently.

Can information protected by a Certificate of Confidentiality ever be disclosed?

Yes, in specified circumstances. Current NIH policy permits certain disclosures required by law, disclosures made with participant consent, certain disclosures for medical treatment with consent, and qualifying scientific research, while providing strong protection against compelled disclosure in legal proceedings.

Is an authorised regulator viewing research records a breach of confidentiality?

Not necessarily. Where such access is authorised under the study's regulatory and oversight arrangements, it can fall within the defined extent of confidentiality rather than constitute an unauthorised breach.

09 · The Bottom Line

Confidentiality Has Rules, Not a Researcher's Personal Override Button

The Bottom Line

Researchers should disclose confidential participant information only when a valid authority or permission applies, such as participant authorization, an applicable legal requirement, an authorised oversight or research function, or another disclosure permitted by the protections governing the study.

Do not invent universal reporting duties, and do not assume confidentiality overrides every law or authorised disclosure. For foreseeable situations, determine the applicable rules before recruitment, build them into the protocol, and tell participants about meaningful limits before they decide what to disclose.

10 · Sources and Further Reading

Authoritative Sources on Disclosure and Research Confidentiality

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes