Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can a Collaborator Receive Participant Data Simply Because They Are a Member of the Research Team?

Being named as a collaborator does not automatically entitle someone to every participant-level dataset. Access should follow the collaborator's authorized role, purpose, institutional relationship, and actual need for the information.

319
Collaborator Access to Participant Data Guide 319 of 398
01 · The Question

If Someone Is on the Research Team, Can They See the Participant Data?

A statistician is listed as a co-investigator. A doctoral student is helping with analysis. A collaborator at another university is a co-author. A research assistant helps administer the project.

They are all members of the research team. Does that mean they can receive the complete participant dataset?

No. Research-team membership establishes a relationship to the project, but it does not automatically establish a need or authorization to access every piece of participant information. Access should be connected to what the person is actually expected and permitted to do.

02 · The Short Answer

Team Membership Is Not Blanket Data Access

In Brief

A collaborator should receive participant data only when access is authorized, necessary for a defined research role or purpose, and limited to the information required to perform that role.

Being a co-investigator, co-author, student researcher, statistician, or other team member does not by itself justify access to identifiers, contact information, sensitive variables, reidentification keys, or the entire master dataset.

03 · What You Need to Know

Access Should Follow Function, Not Status

Start with what the collaborator actually needs to do

A research team can contain people performing very different tasks. Someone recruits participants. Someone schedules interviews. Someone transcribes recordings. Someone analyzes numerical data. Someone verifies coding. Someone supervises the project without directly handling participant-level information.

Those roles do not require identical access.

A statistician may need pseudonymized outcome variables but not participant names or email addresses. A research assistant arranging appointments may need contact information but not sensitive interview transcripts. A transcription service may need audio recordings but no demographic spreadsheet. A supervisor may need to review analytical outputs without needing the raw identifiable dataset.

The useful question is therefore not "Are they on the team?" but "What information does this person need to perform their authorized function?"

Access is itself a form of processing

Data protection frameworks generally define processing broadly. The Philippine Data Privacy Act implementing rules, for example, include retrieval, consultation, use, consolidation, storage, and other operations within processing.

Allowing someone to open a participant dataset is therefore not a neutral administrative act. The person is processing personal data, and that processing should fit the project's lawful, ethical, and institutional arrangements.

The same applies when a collaborator can remotely view information without downloading it. Access can matter even when no new file is physically created.

Apply least privilege to research access

A useful information-security principle is least privilege: users receive only the access needed for their assigned functions.

In research, this can mean controlling both which datasets someone can access and what they can do with them. One researcher may be allowed to view pseudonymized data but not download them. Another may update participant contact information but have no access to outcome data. A data manager may control the reidentification key while analysts work only with study IDs.

The Philippine National Privacy Commission's data-security guidance emphasizes authorization and access control, including defining which users are permitted to access particular resources and limiting access to those authorized to perform relevant functions.

Good access design does not imply that collaborators are untrustworthy. It reduces unnecessary exposure and makes responsibilities clearer.

Data minimization applies to access as well as collection

Researchers often understand data minimization as collecting fewer variables. The same reasoning can be applied when distributing access.

If a collaborator needs 12 variables, providing 60 additional personal-data fields because they happen to exist in the same spreadsheet increases exposure without serving the stated purpose.

Minimization can therefore occur vertically by reducing variables, horizontally by limiting records, temporally by limiting how long access remains active, and organizationally by limiting the people who can reach the information.

Identifiers deserve particular attention

A collaborator may genuinely need participant-level data without needing to know who the participants are.

Where appropriate, direct identifiers can be removed or separated before access is provided. The collaborator may work with study IDs while a reidentification key remains under restricted control elsewhere.

Pseudonymization does not necessarily make information anonymous under applicable data protection law, but it can reduce the consequences of unauthorized access and help separate research functions.

Before providing names, contact details, student numbers, patient identifiers, exact addresses, or a reidentification key, ask what task specifically requires them.

Sensitive information may warrant narrower access

Some research datasets contain health information, genetic or biometric data, political or religious information, information about sexual life, financial information, disciplinary records, or other sensitive material.

The exact legal categories differ among jurisdictions, but higher-risk information often warrants stronger access controls. The fact that a collaborator needs one sensitive variable does not necessarily mean they need all other sensitive information collected by the project.

Internal team members and external collaborators may raise different governance questions

A researcher employed by the same institution and working under its authority may fit within an organization's internal access structure. A collaborator employed by another university may represent a disclosure or sharing of data between separate organizations.

Current ICO data-sharing guidance distinguishes internal organizational access from data sharing between controllers. The Philippine National Privacy Commission likewise distinguishes different processing relationships according to whether information is shared between personal information controllers or processed on a controller's instructions.

External collaboration may therefore require additional analysis of institutional roles, agreements, transfer mechanisms, and recipient safeguards. Before giving another institution access, consider the broader requirements for transferring research data between institutions.

A collaborator can be scientifically essential without needing the master dataset

Authorship, intellectual contribution, and data access are separate issues.

A senior investigator may make a major conceptual contribution while working only with aggregate results. A statistician may perform a sophisticated analysis using pseudonymized variables. A qualitative-methods expert may advise on coding without receiving participants' contact information.

Conversely, a junior research assistant may legitimately require identifiable information because they are responsible for participant scheduling.

Academic seniority is therefore a poor access-control model. Access should follow function.

Ethics approval does not necessarily give everyone named in the protocol identical access

An ethics application may identify investigators and describe who will handle data. That does not necessarily mean every named researcher is authorized to access every form of information collected.

The approved protocol, participant information, institutional policies, confidentiality commitments, data management plan, and applicable agreements should be read together to determine appropriate access.

If a new collaborator joins later or someone's role changes substantially, determine whether ethics, privacy, contractual, or governance amendments are required before granting access.

Access should end when the need ends

Research access should not quietly become permanent because nobody remembered to remove an account.

When a student graduates, a research assistant leaves, a consultant finishes an analysis, or a collaborator's work package ends, review whether continued access remains justified.

Appropriate systems should allow access to be revoked without requiring deletion of the entire research environment. This is one advantage of managed institutional repositories over uncontrolled copies distributed by email or portable media.

Downloading creates another problem: a new copy

Granting access to a controlled research environment and sending someone a downloadable copy are not operationally identical.

A controlled environment may support logging, authentication, permissions, expiry, and revocation. Once a collaborator downloads a dataset, the receiving copy must be governed on their systems as well.

Researchers should therefore ask whether the collaborator genuinely needs possession of a copy or merely needs controlled access to perform the task.

Access decisions should be documented

For higher-risk research, maintaining a record of who has access to what can support accountability and incident response. It can also prevent the rather awkward post-breach meeting in which nobody can remember who received the identifiable spreadsheet eighteen months earlier.

Documentation may include named users, roles, datasets, permission levels, approval dates, expiry dates, and changes to access. The level of formality should reflect the sensitivity and complexity of the project.

Access Is Not a Perk

Do not grant participant-data access as a courtesy, sign of seniority, or default benefit of being listed on the project. Personal data should be accessible because a defined research function requires them.

04 · A Practical Example

Four Collaborators Do Not Need the Same Dataset

Hypothetical Example

A mixed-methods longitudinal study

A project collects participant names, email addresses, demographic variables, survey responses, interview recordings, transcripts, and six-month follow-up outcomes. Four researchers perform different functions.

Participant coordinator The coordinator needs names, contact information, appointment status, and study IDs to arrange follow-up but does not need access to the complete analytical dataset.
Statistician The statistician receives study IDs, required demographic variables, survey measures, and outcome variables. Names, email addresses, recordings, and the reidentification key are unnecessary.
Qualitative analyst The analyst receives appropriately prepared transcripts and relevant contextual variables but does not need participant contact information or unrelated survey fields.
External methodological adviser The adviser reviews the analytical approach using aggregate outputs and example materials that do not require access to the participant-level master dataset.

All four people contribute legitimately to the same project. Their membership in the team is identical in one sense, but their information needs are not.

05 · What Researchers Often Get Wrong

Common Mistakes When Giving Collaborators Data Access

Misconception

If Someone Is a Co-Investigator, Can They Access Everything?

No. Co-investigator status describes a research role, not universal authorization to access every personal-data field. Access should match the person's actual responsibilities and the project's governance arrangements.

Misconception

If Everyone Signed a Confidentiality Agreement, Can Everyone Receive the Full Dataset?

No. Confidentiality obligations can be valuable safeguards, but they do not establish necessity. Someone can promise to protect information they never needed to receive in the first place.

Misconception

If Data Are Pseudonymized, Can Every Collaborator Access Them?

Not automatically. Pseudonymization reduces identifiability but does not remove the need for authorization, purpose limitation, access control, and other applicable safeguards.

Misconception

If a Collaborator Might Need a Variable Later, Should You Give Them Access Now?

Not merely for convenience. Access can be expanded later if a legitimate, authorized need arises. Granting broad access in advance creates unnecessary exposure.

Misconception

If the Collaborator Works at the Same University, Is Access Automatically Internal and Permitted?

No. Being employed by the same organization does not mean every employee is authorized to access every research dataset. Internal access should still reflect role, purpose, confidentiality, institutional policy, and the project's approved arrangements.

06 · What This Means for You

Build Access Around Tasks Rather Than Team Membership

For each collaborator, define the task first. Then determine the information and permissions necessary to perform it.

A simple access framework

If the collaborator can perform the task using aggregate or genuinely anonymous information
Do not provide participant-level personal data merely because they are available.
If participant-level data are necessary but identity is not
Consider appropriately pseudonymized data and keep direct identifiers or reidentification information separately controlled.
If identifiable information is genuinely necessary
Document the purpose and provide only the identifiers and other fields required for that function.
If the collaborator belongs to another organization
Determine the institutional data-sharing relationship and any agreement or transfer requirements before granting access.
If the collaborator's task ends
Review and remove access that is no longer required and address any copies already held under the agreed retention or deletion arrangements.

Where external access is involved, clarify whether a data-sharing, processing, or transfer agreement is needed before providing the information.

07 · A Quick Checklist

Before Giving a Collaborator Participant-Data Access

Confirm:
The collaborator has a defined and authorized research function requiring access.
Participant-level data are actually necessary rather than aggregate or genuinely anonymous information.
Only the records, variables, identifiers, and level of detail needed for the person's role will be accessible.
The access is consistent with ethics approval, participant information, confidentiality commitments, institutional policy, and applicable data protection requirements.
Any interinstitutional sharing, processing, or transfer agreement required for external collaborators is in place.
The collaborator will use an approved storage and access environment appropriate to the data.
Downloading, copying, onward sharing, and secondary use are restricted appropriately.
There is a process for reviewing and removing access when the collaborator's role changes or ends.
08 · Frequently Asked Questions

Common Questions About Collaborator Access

Can every co-author access the raw research data?

No. Authorship does not automatically create authorization to access participant-level personal data. Determine what information each co-author needs for their legitimate research function.

Can my statistician receive the full participant dataset?

Only if the full dataset is genuinely necessary and authorized. Often a statistician can work with a reduced pseudonymized analytical dataset that excludes contact information, direct identifiers, and variables unrelated to the planned analysis.

Can a student researcher access identifiable data?

Potentially, when identifiable information is required for the student's authorized role and the access complies with the project's ethics, supervision, confidentiality, security, and institutional requirements. Student status alone neither grants nor prohibits access.

Does a confidentiality agreement authorize access?

No. A confidentiality agreement governs how information must be protected after authorized access is provided. The underlying need, purpose, legal basis, and authorization for access still need to exist.

Can collaborators access data remotely instead of receiving a copy?

Potentially. A controlled research environment can sometimes reduce unnecessary copies and allow access to be restricted or revoked. Remote access still constitutes processing and may trigger interinstitutional or international-transfer requirements depending on the arrangement.

Should collaborators lose access when the study ends?

Access should be reviewed when its purpose ends. Whether particular researchers retain access for approved archiving, verification, follow-up, or other legitimate purposes depends on the project's retention and governance arrangements.

09 · The Bottom Line

Being on the Team Does Not Mean Seeing Everything

The Bottom Line

A collaborator should receive participant data because a defined, authorized research function requires those data, not simply because their name appears on the research team.

Match access to purpose. Give each person the records, variables, identifiers, and permissions they actually need, then review that access when their role changes or ends. A research team can share responsibility without sharing every spreadsheet.

10 · Sources and Further Reading

Authoritative Sources on Research Data Access and Sharing

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes