Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

How Do You Protect Confidentiality When Participants Know Each Other?

Confidentiality becomes harder when participants already know one another. Even without names, insiders may recognize experiences, roles, relationships, or quotations that outsiders would never connect to a particular person.

302
Confidentiality When Participants Know Each Other Guide 302 of 398
01 · The Question

What changes when participants already know one another?

Imagine interviewing employees from one department, teachers from the same school, students from the same class, members of a small community, or relatives from the same family.

You remove their names. You use participant codes. You generalize some demographic details. Yet one participant describes a recent promotion, another mentions a recognizable disagreement, and someone else refers to "the only person in our office who..."

To an outside reader, the data may appear anonymous. To the other participants, the identities may be obvious. When people already know one another, confidentiality depends not only on removing direct identifiers but also on managing what insiders can infer from information they already possess.

02 · The Short Answer

Protect against recognition by insiders, not just identification by strangers

In Brief

When participants know one another, protect confidentiality by assessing what insiders already know, limiting unnecessary contextual details, avoiding combinations that reveal identities, carefully selecting quotations and attribution labels, separating participants where appropriate, and being explicit about any limits to confidentiality that the research design cannot eliminate.

The researcher may be able to protect records and publications, but cannot always prevent participants from recognizing one another's experiences or inferring who contributed particular information. These risks should be considered during study design and consent, not only when the manuscript is being anonymised.

03 · What You Need to Know

Insiders begin with information the researcher cannot remove

Confidentiality and anonymity are not the same thing

Confidentiality concerns how information known or collected in the research is protected from inappropriate disclosure. Anonymity concerns whether a person's identity is known or can be connected to the information.

These concepts become especially important when participants already know one another. A researcher may faithfully protect names, recordings, transcripts, and linkage files while participants remain identifiable to insiders from their roles, experiences, or relationships.

OHRP guidance emphasizes that research plans should make appropriate provisions for protecting participants' privacy and maintaining data confidentiality. It also cautions against promising absolute confidentiality and recommends explaining relevant limits during consent.

Insiders already possess pieces of the identification puzzle

An outside reader may see "Participant 4, senior employee" and learn very little. A coworker may know there are only two senior employees in the unit and that only one recently experienced the event described in the quotation.

This is why confidentiality cannot be evaluated solely from the perspective of someone unfamiliar with the research setting.

Research involving small or unusual samples, identifiable locations, or prominent participants has long been recognized as particularly challenging because local knowledge can make participants easier to identify. Qualitative research adds further difficulty because detailed accounts often contain precisely the contextual information insiders need to recognize someone.

Relationships themselves can identify participants

Suppose a study includes a supervisor and several employees. A quotation says, "My supervisor rejected my request to transfer after I returned from maternity leave."

The researcher may remove the employee's name and the supervisor's name. Yet coworkers may know who recently returned from maternity leave and who requested a transfer. The relationship and event together may reveal both people.

Family research creates similar problems. "My older sister who lives overseas" may effectively name a person within a family even though no conventional identifier appears.

Confidentiality reviews should therefore consider relational information such as reporting lines, family roles, friendships, conflicts, partnerships, and other connections among participants.

A small population magnifies otherwise ordinary details

Age, occupation, seniority, educational background, location, or family structure may seem harmless in a large population. In a small organization or community, the same details can dramatically narrow who the participant could be.

This is the broader problem in which several individually harmless details become identifying when combined.

When participants already know one another, the threshold for recognition can be even lower because they do not need to search public databases or reconstruct the entire profile. They may already know the relevant ages, jobs, events, relationships, and histories.

Quotations can be recognizable even after demographic details are removed

People can recognize stories as well as characteristics.

A participant may recount a meeting everyone attended, a workplace conflict, a family incident, a controversial decision, or an unusual event. Removing age, gender, and job title does little if the story itself identifies who was involved.

Likewise, distinctive expressions, habitual phrases, or recognizable ways of describing events may contribute to recognition in tightly connected groups.

This is why an apparently anonymous quotation may still reveal who said it, particularly to readers who already know the speaker or setting.

Repeated participant codes can build recognizable profiles

Researchers sometimes use consistent labels such as P01 throughout a publication so readers can follow one participant's perspective.

That can improve analytical coherence, but it also allows information to accumulate. One quotation reveals the participant's department. Another reveals a family circumstance. A third describes a recent dispute. By the fourth quotation, coworkers may have little difficulty recognizing P01.

Consider whether readers genuinely need to connect every quotation from the same participant. When continuity is not analytically important, reducing unnecessary linkability may help protect confidentiality.

Participants may reveal information about one another

When participants are socially connected, one person's interview can contain information about another participant.

An employee may describe a colleague's disciplinary issue. A family member may discuss another relative's health. A student may identify another participant's behavior. These disclosures create third-party confidentiality concerns even if the person being discussed never raised the information in their own interview.

Researchers should therefore review data not only for information that identifies the speaker but also for information that identifies other people mentioned in the account.

Separate interviews do not eliminate insider identification

Individual interviews can prevent participants from directly hearing what others say during data collection, which may make them preferable to group discussion for highly sensitive topics.

They do not, however, guarantee that participants will remain unrecognizable in the final report. If quotations or case descriptions contain distinctive experiences, coworkers or community members may still infer who contributed them.

The choice between individual interviews and group methods should therefore consider both immediate disclosure during data collection and later deductive disclosure in dissemination.

Focus groups create an additional confidentiality problem

In a focus group, participants directly hear what other participants say. The researcher can control how recordings, transcripts, and publications are handled, but cannot exercise equivalent control over what group members remember and repeat afterward.

HHS informed-consent models for sensitive focus-group research explicitly acknowledge a risk of unwanted or accidental disclosure and recommend telling participants that researchers will ask all group members to keep the discussion confidential. AHRQ focus-group materials similarly tell participants that, although everyone is asked to maintain confidentiality, the researchers cannot guarantee that another group member will not reveal a participant's name or comments.

This specific limitation deserves its own treatment because the question is not simply how the research team protects data but whether researchers can guarantee confidentiality in a focus group.

Recruitment can itself reveal participation

Confidentiality problems can arise before anyone answers a research question.

If a researcher sends a group email exposing all recipients, recruits employees through a supervisor, gathers participants visibly in a workplace conference room, or publicly identifies members of a small study, people may learn who participated.

This can matter when participation itself is sensitive. For example, being recruited into a study of workplace harassment, stigmatized health conditions, or controversial organizational practices may reveal information participants would prefer others not to infer.

Recruitment procedures should therefore consider privacy among participants as well as confidentiality of the eventual data.

Be careful with demographic tables in small samples

A participant table can unintentionally become an identification key.

Imagine a study of eight employees. The table reports each participant's age, gender, exact job title, years of service, and department. The results then attribute quotations using matching participant codes.

Even if the table contains no names, coworkers may recognize most rows immediately. Combining the table with quotations can make disclosure still easier.

Consider whether readers need participant-level demographic profiles or whether aggregated sample characteristics provide sufficient methodological transparency.

Consent should describe realistic limits rather than promise perfect secrecy

OHRP-related guidance recommends describing the extent to which confidentiality will be maintained and cautions that absolute confidentiality should not be guaranteed. Relevant limits should be explained when they may affect a participant's decision to participate.

For interconnected populations, this means being candid that the research team will take steps to protect identity but that people familiar with the participant or circumstances may sometimes recognize them from contextual information.

This is more informative than simply promising that "all information will be anonymous" when the study design cannot realistically support that promise.

Watch Out

Do not evaluate confidentiality only from the perspective of a journal reader who knows nobody in the study. The participant's coworker, sibling, classmate, neighbor, or fellow participant may need only one familiar detail to identify them.

04 · A Practical Example

A workplace study where everyone knows everyone

Hypothetical Example

Researchers interview employees from one small department

A qualitative study examines workload among 12 employees in one university office. Participants are interviewed individually. The researcher plans to use pseudonyms and quotations in the report.

Direct identifiers Names, email addresses, and exact job titles are removed from the publication.
Insider knowledge Employees already know who recently returned from parental leave, who was promoted, who supervises whom, and who manages a particular project.
Quotation risk One participant describes being denied a promotion immediately after taking parental leave. Coworkers could recognize the event even if the quotation is attributed only to "Participant 7."
Adjustment The researcher removes unnecessary chronology and organizational detail while preserving the information needed to support the theme of perceived career disadvantage.
Publication review The team checks quotations, participant labels, demographic tables, and methods descriptions together to determine whether combinations reconstruct identifiable profiles.

The challenge is not that the researcher failed to remove names. The challenge is that coworkers already know the stories behind the data.

05 · What Researchers Often Get Wrong

Common confidentiality mistakes in interconnected participant groups

Misconception

Pseudonyms are enough because nobody's real name appears

Pseudonyms conceal names but not recognizable experiences, relationships, roles, or contextual details. Insiders may identify participants without needing their names.

Misconception

Individual interviews solve the confidentiality problem

Individual interviews prevent participants from directly hearing one another during data collection, but later quotations and contextual descriptions may still allow insiders to identify speakers.

Misconception

If an outside reader cannot identify someone, the participant is anonymous

The most relevant identification risk may come from coworkers, relatives, classmates, community members, or other participants who already possess contextual information.

Misconception

A detailed demographic table demonstrates rigor without affecting confidentiality

In small samples, combinations of age, gender, department, occupation, seniority, and other characteristics may effectively identify individual participants. Methodological transparency does not require publishing every characteristic at participant level.

Misconception

The researcher only needs to protect what each participant says about themselves

Participants may disclose identifiable information about coworkers, relatives, supervisors, patients, students, or other participants. Third-party information also requires careful review.

06 · What This Means for You

Design confidentiality for the people who know the setting best

When participants are socially connected, build insider recognition into the confidentiality assessment from the beginning.

A simple insider-confidentiality framework

If participants belong to a small interconnected population
Assume that insiders possess background knowledge unavailable to ordinary readers and assess disclosure accordingly.
If a role, event, relationship, or chronology is recognizable
Remove or generalize unnecessary clues while preserving the information required for the analysis.
If repeated participant labels create identifiable profiles
Consider whether cross-quotation linkage is analytically necessary.
If participation itself is sensitive
Design recruitment and data collection so that participants are not unnecessarily exposed to one another or to gatekeepers.
If the research design cannot prevent participants from recognizing one another
Explain the relevant limits during consent rather than promising anonymity that cannot realistically be delivered.

The confidentiality standard should therefore reflect the actual social environment of the research. A quotation that looks beautifully anonymised to the research team may be practically signed and dated to the five people who know what happened.

07 · A Quick Checklist

Before reporting data from participants who know one another

Check whether insiders could identify participants through:
Distinctive workplace, family, school, community, or organizational roles.
Recent promotions, conflicts, absences, awards, illnesses, transfers, or other recognizable events.
Relationships among participants, such as supervisor and employee, parent and child, or colleagues in a small team.
Combinations of age, occupation, seniority, location, education, or other demographic characteristics.
Stories or quotations describing events already known within the group.
Repeated participant codes that allow readers to assemble identifying information across the report.
Participant-level demographic tables that effectively recreate the membership of a small group.
Information participants reveal about other participants or identifiable third parties.
Whether the consent process accurately describes limits to confidentiality and insider recognition.
08 · Frequently Asked Questions

Questions about confidentiality among participants who know each other

Can participants be anonymous if they work in the same small organization?

Sometimes complete anonymity may be difficult because coworkers already know one another's roles, histories, and experiences. Researchers can reduce identification risk through careful reporting, but should not promise anonymity that the design and setting cannot realistically support.

Are individual interviews more confidential than focus groups?

Individual interviews prevent other participants from directly hearing what someone says during data collection, which can provide an important confidentiality advantage. They do not eliminate later identification through quotations, contextual details, or research reports.

Should I avoid using quotations when participants know one another?

Not necessarily. Quotations can still be used when appropriate, but they should be reviewed for distinctive stories, roles, relationships, language, and combinations of details that insiders could recognize.

Can demographic tables identify participants in small samples?

Yes. Participant-level combinations of characteristics can make individuals recognizable even without names. Consider whether aggregated sample descriptions can provide the necessary methodological information with lower disclosure risk.

What if participants already know who else is in the study?

Knowing who participated can increase the ease of attributing quotations or experiences to particular people. The researcher should account for this smaller pool of possible speakers when anonymising and reporting the data.

Should I tell participants that other people may recognize them?

If insider recognition is a realistic limitation of confidentiality, it should be considered in the consent process according to the applicable ethics and institutional requirements. Avoid giving an absolute assurance of anonymity when the research setting makes that assurance unrealistic.

09 · The Bottom Line

Confidentiality is harder when readers already know half the story

The Bottom Line

When participants know one another, protect confidentiality by evaluating what insiders can infer from roles, relationships, events, quotations, demographic characteristics, and combinations of details, not merely by removing names.

Use careful recruitment, appropriate data-collection methods, selective contextual detail, manuscript-level disclosure review, and realistic consent language. The research team can reduce recognition risk substantially, but it should not promise anonymity when the social structure of the study makes participants recognizable to one another.

10 · Sources and Further Reading

Research and guidance on confidentiality in interconnected groups

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes