03 · What You Need to Know
Participants Need to Understand What "Confidential" Means in This Study
Start With the Actual Information Flow
Good confidentiality language cannot be written accurately until researchers know how participant information moves through the study.
Before drafting consent materials, determine:
- what identifying information is collected;
- which research personnel can access it;
- whether identifiers are separated from research responses;
- whether external providers process identifiable information;
- whether collaborators receive data;
- whether monitors, regulators, or institutional officials may inspect records;
- whether information will be reused or shared for future research;
- how findings will be reported; and
- which circumstances, if any, require or permit identifiable disclosure.
The consent explanation should then describe the parts of this architecture that are material to a participant's decision.
Explain the Extent of Confidentiality, Not Merely the Word
Under the US Common Rule, informed consent includes, when applicable, a statement describing the extent to which confidentiality of records identifying the participant will be maintained. OHRP's informed-consent materials repeat this requirement.
The wording "extent" is useful beyond the US context because confidentiality is rarely binary. Participants need to understand its boundaries.
A study might say that identifiable records are accessible only to specified authorised research personnel, that names are stored separately from responses, that findings will ordinarily be reported without direct identifiers, and that specified oversight or legal circumstances can permit disclosure.
The appropriate details depend on the research.
Do Not Promise Absolute Confidentiality
HHS advisory guidance is explicit that absolute confidentiality should not be guaranteed and that participants should be informed of relevant circumstances in which confidentiality will not be maintained, including applicable legal requirements and mandated reporting.
This does not mean every consent form should contain a frightening statement that confidentiality "cannot be guaranteed." Such generic language may tell participants almost nothing.
A more useful approach is to identify the actual protections and actual limits.
Vague disclaimer
"We cannot guarantee confidentiality under any circumstances."
Study-specific explanation
Describe who normally has access, how records are protected, and the particular situations in which identifiable information may be disclosed.
Tell Participants Who May Access Identifiable Information
Participants may reasonably interpret "only the research team will see your information" literally.
If identifiable records may also be accessed by an approved transcription service, sponsor, monitor, regulator, auditor, institutional official, laboratory, data centre, or other authorised party, the consent process should reflect the access arrangements required to be disclosed for that study.
The level of detail should be meaningful rather than encyclopedic. It may be more useful to describe categories and purposes of access than to list the names of every employee who might perform an authorised task.
The underlying access plan should follow the principle that identifiable information is available only where an authorised function requires it.
Explain Relevant Legal or Safeguarding Limits Before Sensitive Information Is Disclosed
If the research team may or must disclose particular information under applicable law or an approved safeguarding procedure, participants should ordinarily learn about that limit before deciding whether to provide the affected information.
This is particularly important when research intentionally asks about topics likely to trigger the limit.
For example, if applicable law and institutional policy require a particular category of abuse to be reported, explaining that only after the participant has disclosed it undermines the participant's ability to make an informed decision about what to reveal.
The exact reporting categories should be verified for the jurisdiction and research setting. Researchers should not copy a generic list of child abuse, elder abuse, self-harm, violence, illegal activity, and communicable disease into every consent form. Those obligations are not universal.
Do Not Invent a Universal "Danger to Self or Others" Clause
Consent templates sometimes include language stating that confidentiality will be broken whenever a participant poses a danger to themselves or someone else.
Such a clause may be appropriate in a particular jurisdiction, profession, clinical setting, or approved protocol. It should not be inserted automatically into unrelated research.
The researcher's professional status matters. A clinician conducting research may have obligations arising from a professional relationship that do not automatically apply to every social scientist conducting an interview.
Researchers should verify when confidential participant information may actually be disclosed before drafting the corresponding consent language.
Explain Research Data Sharing When It Changes Who Can Receive the Information
Modern research data may move beyond the original team. Data may be deposited in repositories, shared with approved researchers, transferred to collaborators, or retained for future studies.
The confidentiality explanation should be consistent with those plans.
Participants do not necessarily need the technical mechanics of every repository. They do need an accurate understanding of whether their information will remain within the immediate study team, be shared in identifiable or coded form, be made available under controlled access, or be released in a form intended to be anonymous.
For stored data and biospecimens, OHRP guidance has long emphasized describing conditions under which materials will be released to recipient investigators and procedures used to protect privacy and confidentiality.
Be Precise About Anonymization and Coding
If names are replaced with study codes but a key remains, do not tell participants that their information is anonymous.
A more accurate explanation is that direct identifiers will be stored separately, replaced with a study code in working data, and accessible only to authorised people, if that is in fact what the study does.
HHS guidance concerning internet research specifically recommends accurate use of terms such as "anonymous" and "confidential" and suggests explaining how data move from identifiable to aggregate forms and what linkage or re-identification remains possible.
This distinction helps participants understand whether researchers themselves can still connect responses to them.
Tell Participants About Group-Based Limits That Researchers Cannot Control
Focus groups and other group methods create a special problem. Researchers can protect their recordings, transcripts, and reports, but they cannot fully control what other participants repeat outside the research setting.
Participants should therefore understand that the research team will protect the information it controls while confidentiality among participants cannot necessarily be guaranteed.
Similar issues can arise in group interviews, participatory workshops, online group discussions, or other settings in which participants can see or hear one another.
Explain Publication Risks When Context May Reveal Identity
"Your name will not appear in publications" can be true while still giving an incomplete picture.
A distinctive quotation, job title, event, demographic profile, or institutional description may allow recognition even after names are removed. This risk becomes more important in small or distinctive samples.
Researchers need not describe every conceivable inference, but where contextual identification is a meaningful foreseeable risk, participants should receive an appropriate explanation of how quotations, case descriptions, or other outputs will be handled.
Certificates of Confidentiality Need Accurate Explanations Too
When a US Certificate of Confidentiality applies, participants should not simply be told that "the government can never obtain your data."
NIH provides example consent language explaining that Certificates protect identifiable, sensitive research information from disclosure in legal proceedings while also identifying important limits. Current NIH guidance notes that Certificates do not prevent disclosures required by certain laws, disclosures made with participant consent, certain disclosures for medical treatment with consent, or qualifying scientific research.
The NIH example language is explicitly optional rather than mandatory, so researchers should use the consent language approved for their study and institution.
Do Not Overstate Legal Protections
The same principle applies to other legal protections. OHRP's guidance concerning the US Genetic Information Nondiscrimination Act states that investigators and IRBs should ensure consent descriptions do not overstate the protections GINA provides.
That is a useful general lesson: naming a law is not a substitute for explaining what it actually protects and what it does not.
Participants Usually Do Not Need the Technical Security Manual
Consent forms can become unreadable when researchers attempt to prove security competence by listing every technical measure.
HHS advisory guidance states that detailed technical descriptions such as encrypted transfer mechanisms or locked file cabinets are generally not useful to participants under most circumstances.
The participant needs the practical consequence: who can access identifiable information, whether identifiers are separated, how broadly data may be shared, and what meaningful limits apply.
Specific technical information may be appropriate where it materially affects the participant's decision, but the consent form should not double as the IT department's configuration documentation.
The Level of Detail Should Follow the Confidentiality Risk
A brief anonymous questionnaire about an innocuous topic does not require the same confidentiality discussion as identifiable interviews about criminalized behaviour, genomic data, workplace misconduct, immigration status, or highly sensitive health information.
The explanation should therefore be proportionate to:
- how identifiable the information is;
- how sensitive it is;
- the consequences of disclosure;
- how many parties may access it;
- whether disclosure exceptions are foreseeable;
- whether data will be shared or reused; and
- the characteristics of the participant population.
More confidentiality risk can justify more explanation, but more words are useful only if they improve understanding.
A Useful Confidentiality Explanation Answers Concrete Participant Questions
| Participant Question |
What the Study Should Clarify When Relevant |
| Will you know which answers are mine? |
Whether responses are anonymous, coded, pseudonymized, or directly identifiable |
| Who can see my identifiable information? |
Relevant authorised research personnel and other categories of authorised access |
| Will my employer, school, family, or another organisation see it? |
Whether such disclosure is planned, permitted, required, or not part of the study |
| Could you ever be required to report something I tell you? |
The actual legal or institutional reporting limits applicable to the research |
| Will my data be shared with other researchers? |
The form of sharing, level of identifiability, and applicable access controls |
| Could someone recognise me in a publication? |
How quotations, cases, demographic details, and other potentially identifying outputs will be handled |
| Is there any special legal protection? |
What that protection actually does and its relevant limitations |