03 · What You Need to Know
Confidentiality Is a Commitment With Defined Boundaries
Confidentiality Does Not Mean Nobody Can Ever See the Information
In confidential research, identifiable information may legitimately be accessed by authorised people for approved purposes. Researchers may need participant identities for recruitment, interviews, follow-up, linkage, clinical procedures, withdrawal requests, or data verification.
Depending on the study, authorised monitors, auditors, regulators, institutional officials, sponsors, laboratories, or service providers may also have particular access functions.
This does not mean confidentiality has failed. Confidentiality concerns controlling access, use, and disclosure according to legitimate purposes and the commitments governing the research.
The relevant question is therefore who should have access to identifiable research information, not whether the information can literally be seen by no one.
US Human-Subjects Guidance Explicitly Warns Against Absolute Guarantees
US HHS advisory guidance concerning research consent forms states that, when appropriate, consent forms should explain that research records will be kept confidential and may describe general confidentiality measures. It also states that absolute confidentiality should not be guaranteed and that participants should be informed about circumstances in which confidentiality will not be maintained, such as applicable legal requirements or mandated reporting.
This is US guidance rather than a universal international rule. Nevertheless, it captures an important informed-consent principle: participant information should describe the protection researchers can actually provide rather than the protection they would ideally like participants to hear.
Legal Duties Can Create Limits to Confidentiality
Whether researchers are legally required or permitted to disclose particular information depends on jurisdiction, participant population, professional role, institution, study type, and the information involved.
Examples can include particular statutory reporting requirements, regulatory obligations, or other legally defined circumstances. These should not be guessed from general ethical intuition. Researchers should determine which requirements actually apply to their study with appropriate institutional or legal guidance.
This is why a generic statement such as "we will never disclose your information under any circumstances" can be risky. The researcher may not possess legal authority to make that promise.
Not Every Possible Disclosure Is a "Breach" of Confidentiality
If participants are accurately told that particular authorised people may inspect research records for monitoring or regulatory purposes, access by those people within that defined function is not the same as an unauthorised disclosure.
Likewise, information may be shared for an approved research purpose under applicable governance arrangements without necessarily violating the confidentiality commitment.
The distinction is between authorised, disclosed uses of information and disclosures inconsistent with the study's commitments or applicable requirements.
Authorised access or disclosure
Information is accessed or disclosed for a purpose permitted by the study arrangements, participant information, applicable law, or other governing requirements.
Confidentiality breach
Information is accessed, used, or disclosed contrary to the protections, permissions, or obligations governing it.
Certificates of Confidentiality Provide Strong Protection, but They Are Not a Promise That Nothing Can Ever Be Disclosed
In the United States, NIH Certificates of Confidentiality provide substantial protection for identifiable, sensitive research information. NIH states that Certificates prohibit disclosure to people not connected with the research except in specified situations, and qualifying NIH-funded research has been automatically deemed to have a Certificate since 2017.
Current NIH policy identifies limited circumstances in which protected information may be disclosed, including when required by certain federal, state, or local laws, with the individual's consent, for medical treatment with consent, or for other scientific research conducted in compliance with applicable federal human-subjects regulations.
Certificates also do not eliminate the possibility of accidental or improper disclosure. OHRP's guidance emphasizes that confidentiality protections still require other appropriate mechanisms and procedures.
Watch Out
Do not describe a Certificate of Confidentiality as making research information absolutely undisclosable. It provides specific statutory protections against disclosure, subject to defined exceptions and responsibilities. Researchers should use current NIH guidance when explaining what a Certificate actually protects.
A Certificate of Confidentiality Is Not a General International Research Protection
Certificates of Confidentiality arise from US federal law. Researchers outside that legal context should not imply that their data receive the same protection merely because the study promises confidentiality.
Other countries may provide different legal protections, duties, privileges, disclosure rules, or data-protection regimes. Multi-country studies may therefore require separate analysis of the limits applying in each relevant jurisdiction.
The safest approach is to identify the actual authority protecting the information rather than borrowing terminology from another regulatory system.
Confidentiality Can Also Be Limited by the Research Method Itself
Not every limit comes from law.
Focus groups are a classic example. Researchers can instruct participants to respect the confidentiality of what others say, but researchers generally cannot guarantee that every participant will comply after leaving the session.
Research involving participant observation, group activities, online communities, or settings where participation is visible may create similar practical constraints.
The confidentiality statement should therefore reflect what the research team controls and what it does not.
Small Samples Can Make Confidentiality Difficult Even Without Names
A researcher may keep the participant list secure and publish no names, yet a reader may recognise a participant from a distinctive quotation, demographic combination, job role, or event.
This is particularly important in small or distinctive research samples.
Confidentiality therefore extends into analysis and dissemination. Researchers should assess whether published descriptions, tables, case narratives, quotations, or supplementary data could reveal identities indirectly.
Security Reduces Risk but Cannot Create an Absolute Guarantee
Encryption, access controls, pseudonymization, secure storage, approved platforms, staff training, and other safeguards can materially reduce confidentiality risk.
They cannot make human error, credential compromise, technical failure, malicious access, or every other security incident logically impossible.
This does not justify vague warnings that "anything could happen." Participants need useful information, not cybersecurity existentialism. The appropriate approach is to explain meaningful foreseeable confidentiality risks and the safeguards used to reduce them.
Good Consent Language Describes the Extent of Confidentiality
US informed-consent regulations require, when appropriate, a statement describing the extent to which confidentiality of records identifying the participant will be maintained. OHRP guidance likewise advises explaining confidentiality protections and their relevant limits rather than giving an absolute guarantee.
A useful confidentiality explanation may address:
- what identifiable information is collected;
- who can access it;
- how direct identifiers are separated or otherwise protected;
- whether data will be shared with other researchers;
- how findings will be reported;
- what legal or regulatory disclosures may apply;
- whether a Certificate of Confidentiality or another specific protection applies; and
- any study-specific circumstances in which confidentiality cannot be guaranteed.
The exact content should match the study rather than becoming a boilerplate paragraph copied into every consent form.
Do Not Confuse Confidentiality With Anonymity
If researchers know participants' identities, the study may still provide strong confidentiality protections. Calling it anonymous merely because identities will not be published is inaccurate.
Likewise, promising "complete confidentiality" does not make identifiable information anonymous.
The distinction between anonymous and confidential research matters because participants should understand whether the research team itself can connect their responses to them.
The Strength of the Promise Should Match the Strength of the Architecture
| Study Arrangement |
What Researchers May Reasonably Explain |
What to Avoid |
| Identifiable data with restricted access |
Who can access the information and how access is limited |
Calling the responses anonymous |
| Coded data with a retained key |
Identifiers are stored separately and authorised linkage remains possible |
Claiming identity can never be restored |
| Focus group |
Researchers will protect records and ask participants to respect confidentiality |
Guaranteeing that other participants will never repeat what they hear |
| Research protected by a US Certificate of Confidentiality |
Describe the applicable statutory protections and permitted disclosures accurately |
Claiming the Certificate prevents every possible disclosure |
| Publication using de-identified quotations |
Explain how identities will be protected in dissemination |
Assuming removal of names prevents all contextual recognition |