03 · What You Need to Know
Access Should Follow Function, Not Status
Start with what the collaborator actually needs to do
A research team can contain people performing very different tasks. Someone recruits participants. Someone schedules interviews. Someone transcribes recordings. Someone analyzes numerical data. Someone verifies coding. Someone supervises the project without directly handling participant-level information.
Those roles do not require identical access.
A statistician may need pseudonymized outcome variables but not participant names or email addresses. A research assistant arranging appointments may need contact information but not sensitive interview transcripts. A transcription service may need audio recordings but no demographic spreadsheet. A supervisor may need to review analytical outputs without needing the raw identifiable dataset.
The useful question is therefore not "Are they on the team?" but "What information does this person need to perform their authorized function?"
Access is itself a form of processing
Data protection frameworks generally define processing broadly. The Philippine Data Privacy Act implementing rules, for example, include retrieval, consultation, use, consolidation, storage, and other operations within processing.
Allowing someone to open a participant dataset is therefore not a neutral administrative act. The person is processing personal data, and that processing should fit the project's lawful, ethical, and institutional arrangements.
The same applies when a collaborator can remotely view information without downloading it. Access can matter even when no new file is physically created.
Apply least privilege to research access
A useful information-security principle is least privilege: users receive only the access needed for their assigned functions.
In research, this can mean controlling both which datasets someone can access and what they can do with them. One researcher may be allowed to view pseudonymized data but not download them. Another may update participant contact information but have no access to outcome data. A data manager may control the reidentification key while analysts work only with study IDs.
The Philippine National Privacy Commission's data-security guidance emphasizes authorization and access control, including defining which users are permitted to access particular resources and limiting access to those authorized to perform relevant functions.
Good access design does not imply that collaborators are untrustworthy. It reduces unnecessary exposure and makes responsibilities clearer.
Data minimization applies to access as well as collection
Researchers often understand data minimization as collecting fewer variables. The same reasoning can be applied when distributing access.
If a collaborator needs 12 variables, providing 60 additional personal-data fields because they happen to exist in the same spreadsheet increases exposure without serving the stated purpose.
Minimization can therefore occur vertically by reducing variables, horizontally by limiting records, temporally by limiting how long access remains active, and organizationally by limiting the people who can reach the information.
Identifiers deserve particular attention
A collaborator may genuinely need participant-level data without needing to know who the participants are.
Where appropriate, direct identifiers can be removed or separated before access is provided. The collaborator may work with study IDs while a reidentification key remains under restricted control elsewhere.
Pseudonymization does not necessarily make information anonymous under applicable data protection law, but it can reduce the consequences of unauthorized access and help separate research functions.
Before providing names, contact details, student numbers, patient identifiers, exact addresses, or a reidentification key, ask what task specifically requires them.
Sensitive information may warrant narrower access
Some research datasets contain health information, genetic or biometric data, political or religious information, information about sexual life, financial information, disciplinary records, or other sensitive material.
The exact legal categories differ among jurisdictions, but higher-risk information often warrants stronger access controls. The fact that a collaborator needs one sensitive variable does not necessarily mean they need all other sensitive information collected by the project.
Internal team members and external collaborators may raise different governance questions
A researcher employed by the same institution and working under its authority may fit within an organization's internal access structure. A collaborator employed by another university may represent a disclosure or sharing of data between separate organizations.
Current ICO data-sharing guidance distinguishes internal organizational access from data sharing between controllers. The Philippine National Privacy Commission likewise distinguishes different processing relationships according to whether information is shared between personal information controllers or processed on a controller's instructions.
External collaboration may therefore require additional analysis of institutional roles, agreements, transfer mechanisms, and recipient safeguards. Before giving another institution access, consider the broader requirements for transferring research data between institutions.
A collaborator can be scientifically essential without needing the master dataset
Authorship, intellectual contribution, and data access are separate issues.
A senior investigator may make a major conceptual contribution while working only with aggregate results. A statistician may perform a sophisticated analysis using pseudonymized variables. A qualitative-methods expert may advise on coding without receiving participants' contact information.
Conversely, a junior research assistant may legitimately require identifiable information because they are responsible for participant scheduling.
Academic seniority is therefore a poor access-control model. Access should follow function.
Ethics approval does not necessarily give everyone named in the protocol identical access
An ethics application may identify investigators and describe who will handle data. That does not necessarily mean every named researcher is authorized to access every form of information collected.
The approved protocol, participant information, institutional policies, confidentiality commitments, data management plan, and applicable agreements should be read together to determine appropriate access.
If a new collaborator joins later or someone's role changes substantially, determine whether ethics, privacy, contractual, or governance amendments are required before granting access.
Access should end when the need ends
Research access should not quietly become permanent because nobody remembered to remove an account.
When a student graduates, a research assistant leaves, a consultant finishes an analysis, or a collaborator's work package ends, review whether continued access remains justified.
Appropriate systems should allow access to be revoked without requiring deletion of the entire research environment. This is one advantage of managed institutional repositories over uncontrolled copies distributed by email or portable media.
Downloading creates another problem: a new copy
Granting access to a controlled research environment and sending someone a downloadable copy are not operationally identical.
A controlled environment may support logging, authentication, permissions, expiry, and revocation. Once a collaborator downloads a dataset, the receiving copy must be governed on their systems as well.
Researchers should therefore ask whether the collaborator genuinely needs possession of a copy or merely needs controlled access to perform the task.
Access decisions should be documented
For higher-risk research, maintaining a record of who has access to what can support accountability and incident response. It can also prevent the rather awkward post-breach meeting in which nobody can remember who received the identifiable spreadsheet eighteen months earlier.
Documentation may include named users, roles, datasets, permission levels, approval dates, expiry dates, and changes to access. The level of formality should reflect the sensitivity and complexity of the project.
Access Is Not a Perk
Do not grant participant-data access as a courtesy, sign of seniority, or default benefit of being listed on the project. Personal data should be accessible because a defined research function requires them.