03 · What You Need to Know
Access to Identifiers Should Follow Function, Not Academic Seniority
Start by separating linkage from analysis
A linked-data study usually contains at least two distinct tasks. Someone must determine which records correspond to the same individual. Someone must then analyze the resulting research variables.
Those tasks do not necessarily require the same information.
Linkage function
Uses the minimum identifying or matching information necessary to connect records belonging to the same individual.
Analytical function
Uses the linked research variables needed to answer the approved research question and may not require names or other direct identifiers.
Separating these functions can substantially reduce the number of people who handle identifiable information.
The principal investigator does not automatically need identifiers
Being responsible for a study does not mean the principal investigator must personally see every field used at every stage. If another authorized unit can perform linkage and release an appropriately coded analytical file, direct access to names or identification numbers may add privacy risk without adding scientific value.
The same logic applies to statisticians, research assistants, students, collaborators, and external consultants. Access should be justified by role and necessity rather than by membership in the project.
An honest broker can separate identities from research data
OHRP advisory material defines an honest broker as a neutral intermediary between the individual whose tissue and data are being studied and the researcher. In a linkage setting, an analogous intermediary can receive identifiers, perform or facilitate the match, assign project-specific codes, and provide researchers with the approved linked variables without direct identifiers.
OHRP's guidance on coded private information also gives examples in which investigators cannot readily ascertain identities because the holder of the code key is prohibited by agreement, repository procedures, or legal requirements from releasing it to them.
These arrangements demonstrate an important principle: a code key can exist without every researcher being entitled to possess it.
A trusted linkage unit can perform the matching centrally
For larger or repeated linkage projects, an institution may maintain a specialized linkage service or secure data environment. Source custodians provide the linkage unit with the minimum identifying information needed for matching. The linkage unit performs the match, removes or separates direct identifiers, and releases approved research variables under project-specific controls.
This can provide several advantages. It limits identifier exposure, concentrates technical linkage expertise, standardizes security practices, and creates clearer accountability for who handled identifying information.
It does not eliminate the need for authorization. The linkage unit itself must be permitted to receive and process the information.
Data custodians may have different responsibilities from researchers
The organization holding a source dataset may need to verify identities, prepare records, transfer approved fields, or maintain linkage keys without becoming part of the analytical research team in the ordinary sense.
OHRP's guidance distinguishes certain activities involving the provision of coded private information from participation in other research activities such as analysis and interpretation. Regulatory engagement depends on the specific activities performed rather than merely on appearing somewhere in the data flow.
Institutions should therefore map roles explicitly instead of assuming that everyone touching the project has the same responsibilities and permissions.
The minimum necessary identifier set should be used
Linkage accuracy often improves when more identifiers are available, but privacy risk also increases. The linkage design should therefore justify which matching variables are genuinely necessary.
A project may require a unique identification number, for example, without needing a full address. Another project may lack a common identifier and require combinations of name, date of birth, and location. The appropriate set depends on the data and linkage method.
The Philippine Data Privacy Act's implementing rules require proportionality in personal-data processing, including that information be adequate, relevant, necessary, and not excessive for the declared purpose. They also require reasonable and appropriate organizational, physical, and technical security measures and instruct organizations to ensure that people acting under their authority process personal data only under appropriate instructions.
Access to the linkage key deserves separate control
A linkage key can be unusually powerful because it reconnects project codes with identities. It should not simply sit beside the analytical dataset in the same shared folder.
Where feasible, the key should be stored separately, access should be limited to designated personnel, and the research team should have a documented rule governing whether and when identities may ever be recovered.
If investigators unexpectedly gain the ability to readily ascertain identities, the regulatory status of the research can change under the U.S. Common Rule framework. OHRP specifically advises that if researchers using coded information become able to readily ascertain identities, the activity may then involve human subjects and require the appropriate regulatory response.
Role-based access should be technically enforced where possible
A policy saying “only the linkage officer should open this file” is weaker than a system in which only the linkage officer's account can open it. Technical controls can include account permissions, restricted workspaces, multifactor authentication, logging, controlled exports, encryption, and separation of identifier files from analytical data.
The specific controls should be proportionate to the sensitivity and scale of the project. The underlying principle is straightforward: people should not receive identifiable information merely because preventing access would be administratively inconvenient.
Students and trainees require the same justification for access
Student status does not automatically prohibit access to identifiable research data, nor does inclusion on a research team automatically authorize it. Their access should be consistent with ethics approval, institutional policy, privacy requirements, supervision, training, and the actual tasks they need to perform.
If a student is conducting only statistical analysis on the linked dataset, there may be little reason to provide the identity key. Conversely, if the approved research specifically requires the student to perform linkage, the institution needs to establish whether that role and access are permissible and adequately supervised.
External collaborators should not inherit access automatically
A collaborator joining the analytical team later does not necessarily acquire every permission granted to the original institution. Data-use agreements, ethics approvals, privacy requirements, repository conditions, and cross-border transfer rules may restrict who can receive identifiable or linked information.
Before transferring data, determine whether the collaborator is an authorized recipient, what information they need, what safeguards their institution provides, and whether the existing approval covers the transfer.
Identifiable linkage data should not be retained merely for convenience
Once linkage is complete, researchers should determine whether direct identifiers or matching files still serve an approved purpose. Some longitudinal studies require repeated linkage and therefore need a controlled mechanism for maintaining a key. Other projects may have no scientific reason to retain identifying information after the final match.
Retention should follow the approved protocol, consent, legal requirements, data-use agreements, and institutional policy rather than the instinct that the file “might be useful someday.”
The person performing linkage should be competent as well as authorized
Privacy is not the only reason to control linkage roles. Record linkage can involve deterministic rules, probabilistic matching, clerical review, thresholds, and decisions about uncertain matches. Poor linkage can create false matches and missed matches that bias the study.
The person or unit performing linkage should therefore have the methodological competence required for the chosen procedure. Authorization without competence is not much of a safeguard.
Linkage architecture should anticipate the new privacy risks created by combination
Limiting access to identifiers is especially important because linking datasets can create privacy risks that neither source presented alone. The resulting resource may reveal more sensitive information or make individuals easier to distinguish.
The decision about who performs linkage should therefore be part of the project's privacy design from the beginning, not an operational detail delegated after the protocol has already been approved.
Watch Out
Do not give the entire research team identifiable data “just in case.” Every additional person, device, account, transfer, and copy with access to identifiers expands the surface on which confidentiality can fail.