Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Who Should Be Allowed to Perform Linkage Using Identifiable Data?

Identifiable data used for linkage should be accessible only to authorized people or systems that genuinely need the identifiers to perform an approved function. Separating linkage from analysis can reduce unnecessary exposure while preserving the scientific value of linked data.

373
Who Should Link Identifiable Research Data? Guide 373 of 398
01 · The Question

Does the Researcher Analyzing Linked Data Need to See Participants' Identities?

Linking two datasets often requires information that researchers would rather not expose: names, identification numbers, dates of birth, addresses, or other matching variables. Someone may need those fields to determine which records belong to the same person.

But does that person have to be the principal investigator? The statistician? Every member of the research team? Usually, the better question is not who would find identifiers convenient, but who genuinely needs them to perform an authorized linkage function.

02 · The Short Answer

Identifiable Linkage Data Should Be Restricted to Those Who Need Them

In Brief

Identifiable data used for linkage should generally be accessible only to specifically authorized people or systems that need those identifiers to perform an approved linkage or related function; analytical researchers do not automatically need access to identities.

Where feasible, linkage can be separated from analysis through a data custodian, trusted linkage unit, honest broker, or comparable intermediary. The appropriate arrangement depends on the research, governing law, institutional responsibilities, consent, and technical infrastructure.

03 · What You Need to Know

Access to Identifiers Should Follow Function, Not Academic Seniority

Start by separating linkage from analysis

A linked-data study usually contains at least two distinct tasks. Someone must determine which records correspond to the same individual. Someone must then analyze the resulting research variables.

Those tasks do not necessarily require the same information.

Linkage function Uses the minimum identifying or matching information necessary to connect records belonging to the same individual.
Analytical function Uses the linked research variables needed to answer the approved research question and may not require names or other direct identifiers.

Separating these functions can substantially reduce the number of people who handle identifiable information.

The principal investigator does not automatically need identifiers

Being responsible for a study does not mean the principal investigator must personally see every field used at every stage. If another authorized unit can perform linkage and release an appropriately coded analytical file, direct access to names or identification numbers may add privacy risk without adding scientific value.

The same logic applies to statisticians, research assistants, students, collaborators, and external consultants. Access should be justified by role and necessity rather than by membership in the project.

An honest broker can separate identities from research data

OHRP advisory material defines an honest broker as a neutral intermediary between the individual whose tissue and data are being studied and the researcher. In a linkage setting, an analogous intermediary can receive identifiers, perform or facilitate the match, assign project-specific codes, and provide researchers with the approved linked variables without direct identifiers.

OHRP's guidance on coded private information also gives examples in which investigators cannot readily ascertain identities because the holder of the code key is prohibited by agreement, repository procedures, or legal requirements from releasing it to them.

These arrangements demonstrate an important principle: a code key can exist without every researcher being entitled to possess it.

A trusted linkage unit can perform the matching centrally

For larger or repeated linkage projects, an institution may maintain a specialized linkage service or secure data environment. Source custodians provide the linkage unit with the minimum identifying information needed for matching. The linkage unit performs the match, removes or separates direct identifiers, and releases approved research variables under project-specific controls.

This can provide several advantages. It limits identifier exposure, concentrates technical linkage expertise, standardizes security practices, and creates clearer accountability for who handled identifying information.

It does not eliminate the need for authorization. The linkage unit itself must be permitted to receive and process the information.

Data custodians may have different responsibilities from researchers

The organization holding a source dataset may need to verify identities, prepare records, transfer approved fields, or maintain linkage keys without becoming part of the analytical research team in the ordinary sense.

OHRP's guidance distinguishes certain activities involving the provision of coded private information from participation in other research activities such as analysis and interpretation. Regulatory engagement depends on the specific activities performed rather than merely on appearing somewhere in the data flow.

Institutions should therefore map roles explicitly instead of assuming that everyone touching the project has the same responsibilities and permissions.

The minimum necessary identifier set should be used

Linkage accuracy often improves when more identifiers are available, but privacy risk also increases. The linkage design should therefore justify which matching variables are genuinely necessary.

A project may require a unique identification number, for example, without needing a full address. Another project may lack a common identifier and require combinations of name, date of birth, and location. The appropriate set depends on the data and linkage method.

The Philippine Data Privacy Act's implementing rules require proportionality in personal-data processing, including that information be adequate, relevant, necessary, and not excessive for the declared purpose. They also require reasonable and appropriate organizational, physical, and technical security measures and instruct organizations to ensure that people acting under their authority process personal data only under appropriate instructions.

Access to the linkage key deserves separate control

A linkage key can be unusually powerful because it reconnects project codes with identities. It should not simply sit beside the analytical dataset in the same shared folder.

Where feasible, the key should be stored separately, access should be limited to designated personnel, and the research team should have a documented rule governing whether and when identities may ever be recovered.

If investigators unexpectedly gain the ability to readily ascertain identities, the regulatory status of the research can change under the U.S. Common Rule framework. OHRP specifically advises that if researchers using coded information become able to readily ascertain identities, the activity may then involve human subjects and require the appropriate regulatory response.

Role-based access should be technically enforced where possible

A policy saying “only the linkage officer should open this file” is weaker than a system in which only the linkage officer's account can open it. Technical controls can include account permissions, restricted workspaces, multifactor authentication, logging, controlled exports, encryption, and separation of identifier files from analytical data.

The specific controls should be proportionate to the sensitivity and scale of the project. The underlying principle is straightforward: people should not receive identifiable information merely because preventing access would be administratively inconvenient.

Students and trainees require the same justification for access

Student status does not automatically prohibit access to identifiable research data, nor does inclusion on a research team automatically authorize it. Their access should be consistent with ethics approval, institutional policy, privacy requirements, supervision, training, and the actual tasks they need to perform.

If a student is conducting only statistical analysis on the linked dataset, there may be little reason to provide the identity key. Conversely, if the approved research specifically requires the student to perform linkage, the institution needs to establish whether that role and access are permissible and adequately supervised.

External collaborators should not inherit access automatically

A collaborator joining the analytical team later does not necessarily acquire every permission granted to the original institution. Data-use agreements, ethics approvals, privacy requirements, repository conditions, and cross-border transfer rules may restrict who can receive identifiable or linked information.

Before transferring data, determine whether the collaborator is an authorized recipient, what information they need, what safeguards their institution provides, and whether the existing approval covers the transfer.

Identifiable linkage data should not be retained merely for convenience

Once linkage is complete, researchers should determine whether direct identifiers or matching files still serve an approved purpose. Some longitudinal studies require repeated linkage and therefore need a controlled mechanism for maintaining a key. Other projects may have no scientific reason to retain identifying information after the final match.

Retention should follow the approved protocol, consent, legal requirements, data-use agreements, and institutional policy rather than the instinct that the file “might be useful someday.”

The person performing linkage should be competent as well as authorized

Privacy is not the only reason to control linkage roles. Record linkage can involve deterministic rules, probabilistic matching, clerical review, thresholds, and decisions about uncertain matches. Poor linkage can create false matches and missed matches that bias the study.

The person or unit performing linkage should therefore have the methodological competence required for the chosen procedure. Authorization without competence is not much of a safeguard.

Linkage architecture should anticipate the new privacy risks created by combination

Limiting access to identifiers is especially important because linking datasets can create privacy risks that neither source presented alone. The resulting resource may reveal more sensitive information or make individuals easier to distinguish.

The decision about who performs linkage should therefore be part of the project's privacy design from the beginning, not an operational detail delegated after the protocol has already been approved.

Watch Out

Do not give the entire research team identifiable data “just in case.” Every additional person, device, account, transfer, and copy with access to identifiers expands the surface on which confidentiality can fail.

04 · A Practical Example

Separating the Person Who Links Records From the People Who Analyze Them

Hypothetical Example

Linking a student survey with administrative academic records

A research team wants to link survey responses from 5,000 students with university academic records. Names and student numbers are available in the original survey system, but the analytical researchers do not need to know which named student corresponds to each linked record.

Source preparation Authorized custodians prepare only the identifiers and approved variables needed for the linkage under the project's approved data-flow plan.
Linkage A designated institutional linkage unit receives the matching fields, performs the approved linkage, and assigns a project-specific research identifier.
Separation The linkage key connecting research identifiers to named students is stored separately and is not released to the analytical team.
Analysis Researchers receive the approved survey and academic variables attached only to the project identifier and conduct their statistical analyses without direct identifiers.
Retention The linkage unit retains or destroys the key according to the approved protocol, applicable rules, and whether legitimate future linkage is part of the study design.

This arrangement does not make the project risk-free, but it avoids exposing identities to researchers whose scientific task does not require them.

05 · What Researchers Often Get Wrong

Common Mistakes When Deciding Who May Access Linkage Identifiers

Misconception

“The principal investigator should have access to everything.”

Research responsibility does not create a scientific need for every data field. If the investigator can conduct the approved analysis without identities, withholding the linkage key can reduce unnecessary exposure.

Misconception

“Everyone named on the ethics application can see the identifiers.”

Not necessarily. Access should follow the approved roles, institutional controls, privacy requirements, and actual need to know. Being listed on a project does not automatically authorize every type of data access.

Misconception

“Once linkage is approved, the identity key is just another project file.”

The key can reconnect research records to named individuals and deserves separate access, storage, and retention controls.

Misconception

“An honest broker removes the need for ethics and privacy review.”

No. An intermediary is a privacy architecture, not an exemption. The intermediary must itself be authorized to receive and process the identifying information, and the overall study remains subject to applicable requirements.

Misconception

“A research assistant can do the linkage because it is mostly clerical.”

Some linkage is straightforward, but many projects require methodological judgment and secure handling of sensitive identifiers. Anyone performing linkage needs appropriate authorization, training, supervision, and technical competence.

Misconception

“Deleting identifiers after analysis makes broad access harmless.”

Deletion reduces future exposure but cannot undo unauthorized access, disclosure, copying, or processing that already occurred. Access minimization should begin before linkage, not after the project ends.

06 · What This Means for You

Map Roles Before You Move Identifiable Data

Before transferring any identifiers, draw the project's data flow. Identify who holds each source dataset, who will receive identifying fields, who performs matching, who holds the linkage key, what analysts receive, and what happens to each file after linkage.

A simple decision framework

If an analyst does not need identities to answer the research question
Do not provide them merely for convenience. Supply an appropriately coded analytical dataset instead where feasible.
If linkage requires identifiable information
Restrict it to an authorized and appropriately trained person, linkage unit, custodian, or intermediary with the necessary technical safeguards.
If a linkage key must be retained
Store it separately, limit access, document its purpose, and define when re-identification is permitted.
If a new collaborator later requests identifiable access
Treat that as a new access decision and verify that the existing consent, approval, agreements, and privacy requirements actually permit it.

When linkage itself has not yet been authorized, first establish whether the datasets may be linked without recontacting participants. Access controls cannot legitimize a linkage that was never permissible in the first place.

07 · A Quick Checklist

Before Giving Anyone Access to Identifiable Linkage Data

For each person or system requesting access, check:
Identify the specific linkage or research task that requires access to identifying information.
Confirm that the person, institution, or system is authorized under the applicable ethics approval, privacy framework, and data-use arrangements.
Determine whether the same task can be performed without giving the analytical research team direct identifiers.
Use only the minimum identifying fields necessary for reliable linkage.
Separate identifiers and linkage keys from analytical research variables wherever feasible.
Use role-based technical access controls rather than relying only on verbal instructions.
Verify appropriate confidentiality, privacy, security, and linkage-method training for personnel handling identifiers.
Log or otherwise document access when required or proportionate to the sensitivity of the data.
Define how long identifiers and linkage keys will be retained and who can authorize any later re-identification.
08 · Frequently Asked Questions

Frequently Asked Questions About Access to Identifiable Linkage Data

Does the principal investigator need access to the linkage key?

Not automatically. If the principal investigator can oversee and conduct the research without knowing participants' identities, keeping the key with an authorized custodian or linkage unit may reduce unnecessary privacy risk.

Can a student perform identifiable data linkage?

Potentially, if the student's role is authorized, necessary, appropriately supervised, and consistent with ethics approval, institutional policy, privacy requirements, data agreements, and required training. Student status alone neither authorizes nor prohibits access.

What is an honest broker?

OHRP advisory material defines an honest broker as a neutral intermediary between the person whose tissue or data are studied and the researcher. Such an intermediary can help prevent analytical researchers from receiving identities they do not need.

Can an automated system perform linkage instead of a person?

Yes, linkage may be automated or partly automated, but the system still needs appropriate authorization, security, validation, access controls, and accountable human oversight. Automation does not remove the privacy obligations associated with processing identifiers.

Should the person linking data also analyze the linked dataset?

Not necessarily. Separating those roles can reduce unnecessary access to identifiers. In some projects the same authorized person may legitimately perform both functions, but that arrangement should be justified rather than assumed.

Can the linkage key be stored with the analytical dataset?

Usually, separation provides stronger protection. The appropriate storage design depends on the project and governing requirements, but keeping the identity key separately with tightly restricted access reduces the chance that compromise of the analytical file immediately reveals participants' identities.

What happens if an analyst unexpectedly learns a participant's identity?

Follow the approved protocol and institutional procedures. Under OHRP guidance, if investigators using coded information become able to readily ascertain identities, the activity may then involve human subjects under the Common Rule and require an appropriate regulatory determination.

09 · The Bottom Line

Give Identifiers to the Linkage Function, Not Automatically to the Whole Team

The Bottom Line

Access to identifiable data used for linkage should be limited to authorized people or systems that genuinely need the identifiers for an approved function; being part of the research team does not automatically create that need.

Where feasible, separate linkage from analysis, restrict and isolate the identity key, use the minimum identifying information required, and enforce access through technical as well as administrative controls. Good linkage design asks not merely who can see the identifiers, but why they need to.

10 · Sources and Further Reading

Authoritative Guidance on Identifiable Data and Linkage Access

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes