03 · What You Need to Know
Not Every Disclosure Is a Breach of Confidentiality
First Distinguish an Authorised Disclosure From a Confidentiality Breach
Researchers sometimes use "break confidentiality" to describe any occasion on which identifiable information leaves the immediate research team. That can obscure an important distinction.
If a participant authorizes a disclosure, a law requires particular reporting, or an authorised regulator inspects records under the conditions governing the study, disclosure may fall within an established limit of confidentiality rather than constitute an unauthorised breach.
Permitted or required disclosure
Identifiable information is disclosed under a valid permission, legal requirement, approved research arrangement, or other applicable authority.
Confidentiality breach
Information is accessed, used, or disclosed inconsistently with the permissions, protections, or obligations governing it.
The practical goal is therefore not simply to "never disclose." It is to prevent unauthorised disclosure while identifying legitimate exceptions accurately.
A Participant Can Authorize Disclosure
A participant may ask researchers to disclose particular information to another person or organisation. For example, a participant might authorize release of certain research information to a physician or another researcher.
The scope of that authorization matters. Permission to disclose one result to one person does not necessarily authorize release of the participant's entire research record to anyone who asks.
Where applicable, researchers should follow the documentation, consent, privacy, institutional, and legal requirements governing such disclosures.
NIH's current Certificate of Confidentiality policy, for example, permits disclosure of protected identifiable, sensitive research information when the individual consents.
Some Laws Can Require Disclosure
Researchers may be subject to reporting requirements established by law. The specific duties depend on jurisdiction, research setting, professional status, participant population, and the information involved.
NIH guidance concerning Certificates of Confidentiality illustrates this clearly. Although Certificates provide strong protection against disclosure of identifiable, sensitive research information, current NIH policy permits disclosure when required by applicable federal, state, or local law, with examples including certain communicable-disease and abuse-reporting requirements.
This should not be converted into a universal rule that every researcher everywhere must report the same categories. A psychologist conducting research, a university lecturer conducting interviews, a physician-investigator, and a researcher in another country may operate under different legal duties.
Watch Out
Do not write a generic protocol stating that researchers will disclose information whenever participants mention abuse, self-harm, harm to others, illegal conduct, or another sensitive issue unless you have verified the actual legal, professional, ethical, and institutional requirements governing that research. Reporting obligations vary.
Threats of Harm Do Not Create One Universal Research Rule
Statements suggesting serious harm to self or others are among the most difficult confidentiality scenarios. Researchers may have legal, professional, institutional, or protocol-specific responsibilities, particularly when they are also clinicians or other regulated professionals.
But there is no single international "researcher duty to warn" that can safely be applied to every project.
The appropriate response may depend on the jurisdiction, whether the researcher has a professional duty independent of the research role, the immediacy and specificity of the threat, institutional procedures, ethics approval, and any protections governing the data.
Researchers studying topics where such disclosures are reasonably foreseeable should establish a response protocol before recruitment begins rather than deciding during an interview under pressure.
Abuse and Safeguarding Disclosures Also Depend on Applicable Rules
Research involving children, older adults, vulnerable people, violence, abuse, neglect, or exploitation may encounter information that triggers safeguarding questions.
Again, the researcher should not assume either that all such information must remain confidential or that every disclosure automatically requires reporting.
Applicable reporting laws, institutional safeguarding procedures, professional duties, ethics requirements, and the participant's circumstances need to be established for the particular research setting.
Where reporting is foreseeable, the relevant limit should ordinarily be incorporated into the study's confidentiality plan and explained appropriately to participants rather than revealed only after sensitive information has been provided.
Illegal Activity Does Not Automatically Cancel Confidentiality
A participant may disclose illegal drug use, undocumented work, regulatory violations, criminal behaviour, or another potentially unlawful activity during research.
The mere fact that information concerns illegal conduct does not itself establish a universal permission or obligation for researchers to report it.
Indeed, research on sensitive or stigmatized behaviour often depends on strong confidentiality protections. US Certificates of Confidentiality were developed in part to protect identifiable, sensitive research information from compelled disclosure in legal proceedings. Current NIH policy generally prohibits disclosure of covered information in federal, state, or local civil, criminal, administrative, legislative, or other proceedings unless the participant consents, while permitting specified categories of disclosure outside that prohibition.
Researchers should therefore determine the actual legal position rather than treating "illegal" as synonymous with "reportable."
A Court Request Does Not Necessarily Mean Researchers Should Immediately Hand Over the Data
Subpoenas, court orders, law-enforcement requests, and other demands for research information require careful handling. The correct response can depend on jurisdiction, institutional policy, the form of the request, and whether a specific legal protection applies.
For research protected by a US Certificate of Confidentiality, federal law provides significant protection against compelled disclosure of identifiable, sensitive research information in legal and other proceedings. NIH states that institutions covered by a Certificate must uphold and defend those protections.
A researcher receiving a legal demand should therefore follow the institution's established legal and research-governance procedures rather than personally deciding that a document bearing legal language must automatically be obeyed or ignored.
Oversight Access May Be Part of the Study Rather Than an Exception Invented Later
Depending on the research, authorised monitors, regulators, institutional officials, sponsors, auditors, or ethics bodies may inspect records for compliance, verification, safety, or oversight.
If that access is part of the approved research arrangement, it should be treated as such and addressed appropriately in participant information where required.
This reinforces the distinction between confidentiality and secrecy. Confidential research information can have controlled authorised access without being publicly or indiscriminately disclosed.
Scientific Research Can Sometimes Permit Further Disclosure Under Specific Rules
Identifiable research information may sometimes be shared for additional scientific research, but the conditions depend on the applicable framework, consent, approvals, data-sharing arrangements, and legal protections.
For example, NIH's current Certificate policy permits disclosure for other scientific research conducted in compliance with applicable federal human-subjects regulations.
That does not create a general right to give identifiable data to another researcher. The original study's consent, ethics approval, applicable data-protection rules, agreements, and institutional requirements still matter.
Medical Treatment Can Create a Specific Disclosure Path in Some Research
Under NIH Certificate policy, identifiable, sensitive information protected by a Certificate may be disclosed when necessary for the participant's medical treatment and when the participant consents.
This is a specific feature of that US legal framework, not a universal research rule. Other studies and jurisdictions may have different requirements for returning clinically relevant information or communicating with healthcare professionals.
Voluntary Disclosure and Legally Required Disclosure Are Not the Same
Older OHRP guidance on Certificates of Confidentiality highlights an important conceptual distinction. Certificates protect against compelled disclosure, but researchers may face situations involving voluntary disclosure, such as information about abuse or threats of violence. OHRP states that if investigators intend to make such voluntary disclosures, the consent form should clearly indicate this.
Current NIH policy should be consulted for the operative Certificate rules, but the broader research-ethics lesson remains useful: a disclosure practice that the research team intends to follow should not be hidden from participants merely because disclosure is not legally compelled.
Disclosure Should Usually Be No Broader Than Necessary
When disclosure is required or authorised, that does not automatically justify releasing every piece of information the researcher holds.
The appropriate scope depends on the authority requiring or permitting disclosure. Researchers should follow applicable legal and institutional guidance concerning what information must be provided, to whom, and for what purpose.
This mirrors the broader principle of data minimisation: necessity should shape both collection and disclosure.
The Disclosure Plan Should Be Designed Before Data Collection
Studies involving foreseeable safeguarding, legal, clinical, or safety disclosures should establish procedures before participants begin providing information.
| Possible Situation |
Question to Resolve in Advance |
Do Not Assume |
| Participant authorizes disclosure |
What exactly has the participant authorized, to whom, and how should it be documented? |
Permission for one disclosure authorizes every future disclosure |
| Suspected abuse or neglect |
What reporting laws, professional duties, and institutional procedures actually apply? |
Every researcher has the same mandatory-reporting duty |
| Threat of serious harm |
What legal, professional, ethics, and institutional response protocol governs the situation? |
There is one universal researcher duty to warn |
| Legal demand for records |
What legal protections apply and who within the institution handles the request? |
Every subpoena or request automatically overrides confidentiality |
| Regulatory or monitoring access |
Is the access authorised under the study and what records may be inspected? |
Any access outside the immediate research team is a breach |
| Further scientific research |
Do consent, approvals, law, agreements, and applicable protections permit the disclosure? |
Scientific usefulness alone creates permission |