Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should Researchers Tell Participants About the Limits of Confidentiality?

Participants should understand both how researchers will protect their information and the meaningful circumstances in which confidentiality may be limited. The explanation should be specific to the study rather than an absolute promise or a generic legal disclaimer.

287
Explaining the Limits of Confidentiality Guide 287 of 398
01 · The Question

How Much Should Participants Be Told About Confidentiality?

A consent form says, "Your responses will be kept confidential."

But who can see them? Will a transcription service process the interview? Can regulators inspect the records? Will identifiable data be shared with collaborators? What happens if the participant discloses information the researcher is legally required to report?

"Confidential" is not enough if participants would reasonably understand the word to mean something different from what the study actually does.

At the same time, a consent form does not need a technical inventory of encryption protocols, server configurations, and every remote hypothetical disclosure. The aim is informed decision-making, not making participants defend a dissertation on the data-management plan.

02 · The Short Answer

Explain Both the Protection and Its Meaningful Limits

In Brief

Researchers should tell participants the extent to which identifiable information will be kept confidential, including who may access it, how it may be used or shared, and any meaningful circumstances in which confidentiality will not be maintained.

The explanation should be specific enough to support an informed decision but proportionate to the study. HHS advisory guidance states that absolute confidentiality should not be guaranteed and that participants should be informed about relevant limits, while detailed technical descriptions of routine security measures are often unnecessary.

03 · What You Need to Know

Participants Need to Understand What "Confidential" Means in This Study

Start With the Actual Information Flow

Good confidentiality language cannot be written accurately until researchers know how participant information moves through the study.

Before drafting consent materials, determine:

  • what identifying information is collected;
  • which research personnel can access it;
  • whether identifiers are separated from research responses;
  • whether external providers process identifiable information;
  • whether collaborators receive data;
  • whether monitors, regulators, or institutional officials may inspect records;
  • whether information will be reused or shared for future research;
  • how findings will be reported; and
  • which circumstances, if any, require or permit identifiable disclosure.

The consent explanation should then describe the parts of this architecture that are material to a participant's decision.

Explain the Extent of Confidentiality, Not Merely the Word

Under the US Common Rule, informed consent includes, when applicable, a statement describing the extent to which confidentiality of records identifying the participant will be maintained. OHRP's informed-consent materials repeat this requirement.

The wording "extent" is useful beyond the US context because confidentiality is rarely binary. Participants need to understand its boundaries.

A study might say that identifiable records are accessible only to specified authorised research personnel, that names are stored separately from responses, that findings will ordinarily be reported without direct identifiers, and that specified oversight or legal circumstances can permit disclosure.

The appropriate details depend on the research.

Do Not Promise Absolute Confidentiality

HHS advisory guidance is explicit that absolute confidentiality should not be guaranteed and that participants should be informed of relevant circumstances in which confidentiality will not be maintained, including applicable legal requirements and mandated reporting.

This does not mean every consent form should contain a frightening statement that confidentiality "cannot be guaranteed." Such generic language may tell participants almost nothing.

A more useful approach is to identify the actual protections and actual limits.

Vague disclaimer "We cannot guarantee confidentiality under any circumstances."
Study-specific explanation Describe who normally has access, how records are protected, and the particular situations in which identifiable information may be disclosed.

Tell Participants Who May Access Identifiable Information

Participants may reasonably interpret "only the research team will see your information" literally.

If identifiable records may also be accessed by an approved transcription service, sponsor, monitor, regulator, auditor, institutional official, laboratory, data centre, or other authorised party, the consent process should reflect the access arrangements required to be disclosed for that study.

The level of detail should be meaningful rather than encyclopedic. It may be more useful to describe categories and purposes of access than to list the names of every employee who might perform an authorised task.

The underlying access plan should follow the principle that identifiable information is available only where an authorised function requires it.

Explain Relevant Legal or Safeguarding Limits Before Sensitive Information Is Disclosed

If the research team may or must disclose particular information under applicable law or an approved safeguarding procedure, participants should ordinarily learn about that limit before deciding whether to provide the affected information.

This is particularly important when research intentionally asks about topics likely to trigger the limit.

For example, if applicable law and institutional policy require a particular category of abuse to be reported, explaining that only after the participant has disclosed it undermines the participant's ability to make an informed decision about what to reveal.

The exact reporting categories should be verified for the jurisdiction and research setting. Researchers should not copy a generic list of child abuse, elder abuse, self-harm, violence, illegal activity, and communicable disease into every consent form. Those obligations are not universal.

Do Not Invent a Universal "Danger to Self or Others" Clause

Consent templates sometimes include language stating that confidentiality will be broken whenever a participant poses a danger to themselves or someone else.

Such a clause may be appropriate in a particular jurisdiction, profession, clinical setting, or approved protocol. It should not be inserted automatically into unrelated research.

The researcher's professional status matters. A clinician conducting research may have obligations arising from a professional relationship that do not automatically apply to every social scientist conducting an interview.

Researchers should verify when confidential participant information may actually be disclosed before drafting the corresponding consent language.

Explain Research Data Sharing When It Changes Who Can Receive the Information

Modern research data may move beyond the original team. Data may be deposited in repositories, shared with approved researchers, transferred to collaborators, or retained for future studies.

The confidentiality explanation should be consistent with those plans.

Participants do not necessarily need the technical mechanics of every repository. They do need an accurate understanding of whether their information will remain within the immediate study team, be shared in identifiable or coded form, be made available under controlled access, or be released in a form intended to be anonymous.

For stored data and biospecimens, OHRP guidance has long emphasized describing conditions under which materials will be released to recipient investigators and procedures used to protect privacy and confidentiality.

Be Precise About Anonymization and Coding

If names are replaced with study codes but a key remains, do not tell participants that their information is anonymous.

A more accurate explanation is that direct identifiers will be stored separately, replaced with a study code in working data, and accessible only to authorised people, if that is in fact what the study does.

HHS guidance concerning internet research specifically recommends accurate use of terms such as "anonymous" and "confidential" and suggests explaining how data move from identifiable to aggregate forms and what linkage or re-identification remains possible.

This distinction helps participants understand whether researchers themselves can still connect responses to them.

Tell Participants About Group-Based Limits That Researchers Cannot Control

Focus groups and other group methods create a special problem. Researchers can protect their recordings, transcripts, and reports, but they cannot fully control what other participants repeat outside the research setting.

Participants should therefore understand that the research team will protect the information it controls while confidentiality among participants cannot necessarily be guaranteed.

Similar issues can arise in group interviews, participatory workshops, online group discussions, or other settings in which participants can see or hear one another.

Explain Publication Risks When Context May Reveal Identity

"Your name will not appear in publications" can be true while still giving an incomplete picture.

A distinctive quotation, job title, event, demographic profile, or institutional description may allow recognition even after names are removed. This risk becomes more important in small or distinctive samples.

Researchers need not describe every conceivable inference, but where contextual identification is a meaningful foreseeable risk, participants should receive an appropriate explanation of how quotations, case descriptions, or other outputs will be handled.

Certificates of Confidentiality Need Accurate Explanations Too

When a US Certificate of Confidentiality applies, participants should not simply be told that "the government can never obtain your data."

NIH provides example consent language explaining that Certificates protect identifiable, sensitive research information from disclosure in legal proceedings while also identifying important limits. Current NIH guidance notes that Certificates do not prevent disclosures required by certain laws, disclosures made with participant consent, certain disclosures for medical treatment with consent, or qualifying scientific research.

The NIH example language is explicitly optional rather than mandatory, so researchers should use the consent language approved for their study and institution.

Do Not Overstate Legal Protections

The same principle applies to other legal protections. OHRP's guidance concerning the US Genetic Information Nondiscrimination Act states that investigators and IRBs should ensure consent descriptions do not overstate the protections GINA provides.

That is a useful general lesson: naming a law is not a substitute for explaining what it actually protects and what it does not.

Participants Usually Do Not Need the Technical Security Manual

Consent forms can become unreadable when researchers attempt to prove security competence by listing every technical measure.

HHS advisory guidance states that detailed technical descriptions such as encrypted transfer mechanisms or locked file cabinets are generally not useful to participants under most circumstances.

The participant needs the practical consequence: who can access identifiable information, whether identifiers are separated, how broadly data may be shared, and what meaningful limits apply.

Specific technical information may be appropriate where it materially affects the participant's decision, but the consent form should not double as the IT department's configuration documentation.

The Level of Detail Should Follow the Confidentiality Risk

A brief anonymous questionnaire about an innocuous topic does not require the same confidentiality discussion as identifiable interviews about criminalized behaviour, genomic data, workplace misconduct, immigration status, or highly sensitive health information.

The explanation should therefore be proportionate to:

  • how identifiable the information is;
  • how sensitive it is;
  • the consequences of disclosure;
  • how many parties may access it;
  • whether disclosure exceptions are foreseeable;
  • whether data will be shared or reused; and
  • the characteristics of the participant population.

More confidentiality risk can justify more explanation, but more words are useful only if they improve understanding.

A Useful Confidentiality Explanation Answers Concrete Participant Questions

Participant Question What the Study Should Clarify When Relevant
Will you know which answers are mine? Whether responses are anonymous, coded, pseudonymized, or directly identifiable
Who can see my identifiable information? Relevant authorised research personnel and other categories of authorised access
Will my employer, school, family, or another organisation see it? Whether such disclosure is planned, permitted, required, or not part of the study
Could you ever be required to report something I tell you? The actual legal or institutional reporting limits applicable to the research
Will my data be shared with other researchers? The form of sharing, level of identifiability, and applicable access controls
Could someone recognise me in a publication? How quotations, cases, demographic details, and other potentially identifying outputs will be handled
Is there any special legal protection? What that protection actually does and its relevant limitations
04 · A Practical Example

Turning a Vague Confidentiality Statement Into Useful Participant Information

Hypothetical Example

A Study of Workplace Discrimination

The first draft of a consent form says only: "All information obtained in this study will remain strictly confidential."

Map the study Interviews are recorded. The interviewer and principal investigator know participant identities. An approved transcription provider processes recordings. Coded transcripts are later analysed by two additional researchers.
Map dissemination The researchers plan to publish quotations after removing or altering unnecessary identifying details, but some participants hold unusual organisational roles that could make contextual recognition possible.
Map disclosure limits The institution determines the specific legal and safeguarding obligations that apply in the jurisdiction and research setting.
Revise the explanation The participant information explains who can access recordings, that working transcripts use study codes, how quotations will be handled, and the specific circumstances in which identifiable information may be disclosed.
Remove unnecessary detail The form does not list encryption algorithms, server configurations, every staff member's name, or speculative legal scenarios that do not apply to the study.

The revised explanation is longer than "strictly confidential," but considerably more useful. Participants can now understand what confidentiality means before deciding whether to discuss a sensitive workplace experience.

05 · What Researchers Often Get Wrong

Common Mistakes When Explaining Confidentiality to Participants

Misconception

"Your Data Will Be Confidential" Is Enough

The statement does not explain who can identify participants, who may access records, whether information will be shared, or which relevant disclosure limits apply. The appropriate level of detail depends on the study's actual confidentiality arrangements.

Misconception

Every Consent Form Needs the Same Mandatory-Reporting Paragraph

Reporting obligations vary by jurisdiction, research setting, participant population, and the researcher's professional role. Include the limits that actually apply rather than importing a generic list from another protocol.

Misconception

More Technical Detail Always Means Better Informed Consent

Not necessarily. Participants need information relevant to their decision. HHS advisory guidance notes that detailed technical descriptions of confidentiality measures are often unnecessary.

Misconception

Saying "We Cannot Guarantee Confidentiality" Covers Every Possible Problem

A generic disclaimer can be too vague to support an informed decision. Participants benefit more from knowing the protections the study actually provides and the meaningful circumstances in which those protections have limits.

Misconception

If Names Will Not Be Published, There Is Nothing Else to Explain

Participants may still be identifiable to researchers, collaborators, service providers, or through contextual details in outputs. Publication anonymity is only one part of the confidentiality arrangement.

06 · What This Means for You

Write the Confidentiality Section From the Participant's Point of View

After mapping the study's data flow, decide which aspects could reasonably affect a person's decision to participate or what they choose to disclose.

A simple decision framework

If researchers can connect responses to participants
Explain the study as confidential or coded as appropriate rather than implying that responses are anonymous.
If people outside the immediate research team may access identifiable information
Explain the relevant categories and purposes of access when material to consent and required by the governing framework.
If particular disclosures may or must occur
State the actual circumstances clearly enough that participants understand the limit before providing affected information.
If data will be reused or shared
Describe the planned form of sharing and the level of identifiability rather than treating future research as invisible to the participant.
If a technical safeguard does not materially affect the participation decision
Keep the consent explanation focused on its practical effect rather than filling it with implementation detail.

The goal is calibrated transparency. Participants should not receive an impossible promise of complete confidentiality, but neither should they encounter a legal disclaimer so broad that it effectively says, "We will protect your information, except perhaps when we don't." Specificity is what makes the distinction meaningful.

07 · A Quick Checklist

Before Finalising the Confidentiality Section of Participant Materials

Check whether participants can understand:
Whether researchers can connect their identity to their responses or research records.
Which categories of authorised people or organisations may access identifiable information when relevant.
How identifiers are separated, coded, or otherwise protected when that information materially clarifies confidentiality.
Whether identifiable, coded, de-identified, or anonymous information will be shared or reused for other research.
Which specific legal, safeguarding, clinical, or other disclosure limits actually apply to the study.
Any limitations created by focus groups or other research settings in which participants can observe one another.
How quotations, case descriptions, small samples, or other outputs will be handled when contextual recognition is a meaningful risk.
What any Certificate of Confidentiality or other legal protection actually covers and what its limits are.
Whether unnecessary technical detail can be removed without reducing the participant's understanding of the actual protection.
08 · Frequently Asked Questions

Frequently Asked Questions About Explaining Confidentiality Limits

Should a consent form say confidentiality cannot be guaranteed?

It may be appropriate to acknowledge meaningful limits, but a generic disclaimer is less informative than explaining the actual protections and relevant circumstances in which identifiable information may be disclosed. HHS advisory guidance recommends against guaranteeing absolute confidentiality.

Do I need to list every person who can access participant data?

Not necessarily. Depending on the applicable requirements, describing relevant categories and purposes of authorised access may be clearer than listing individual names. The explanation should accurately reflect the study's access arrangements.

Should every consent form mention mandatory reporting?

No universal reporting paragraph applies to every study. Include disclosure limits that actually apply under the relevant law, professional duties, institutional requirements, and approved research procedures.

Should participants be told about transcription services or outside providers?

Where an outside provider can access identifiable or sensitive research information, that access should be considered when designing confidentiality protections and determining what participants need to know under the applicable consent and institutional requirements.

Should participants be told that other researchers may use their data?

When future sharing or secondary research is planned or otherwise relevant to consent, participant information should accurately describe those arrangements at the level required by the governing framework, including the form in which information will be shared where appropriate.

How much security detail belongs in a consent form?

Usually enough to explain the practical confidentiality protection, not a technical implementation manual. HHS advisory guidance notes that detailed descriptions of measures such as encrypted transfer systems or locked cabinets are often unnecessary for participants.

Should participants be told about a Certificate of Confidentiality?

Where a Certificate applies, the consent process should accurately reflect its protections and relevant limits under the study's approved requirements. NIH provides optional example consent language for this purpose.

09 · The Bottom Line

Tell Participants What Confidentiality Protects and Where Its Boundary Actually Lies

The Bottom Line

Participants should receive an accurate, understandable explanation of the extent of confidentiality, including who may access identifiable information, how it may be used or shared, and the meaningful circumstances in which confidentiality may be limited.

Do not promise absolute secrecy, copy reporting clauses that do not apply, or bury the participant in technical detail. Start with the study's real data flow and disclosure rules, then explain the parts that matter to an informed decision in language a participant can actually use.

10 · Sources and Further Reading

Authoritative Sources on Explaining Research Confidentiality

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes