03 · What You Need to Know
A closed community creates an audience boundary that researchers should take seriously
What counts as a closed or private online community?
Restricted online spaces take many forms. Access might require a password, invitation, administrator approval, paid membership, institutional affiliation, acceptance of a follow request, answers to screening questions, or membership in a particular organization.
The restriction does not have to provide perfect security to matter ethically. Its existence communicates something about the intended audience.
| Online setting |
Access structure |
Ethical question |
| Unrestricted public forum |
Anyone can read discussions without approval |
Do users nevertheless have reasonable privacy expectations because of context or sensitivity? |
| Registration-only forum |
An account is required, but admission is automatic |
Is registration merely technical, or does it create a meaningful community boundary? |
| Moderator-approved group |
Membership requires approval |
What do members understand admission to mean about who can observe their discussions? |
| Invitation-only community |
Existing members or administrators control entry |
Would research observation violate the audience expectations created by restricted membership? |
| Private direct-message group |
Only specifically included accounts can view messages |
What consent and privacy protections are required for highly bounded communications? |
Researchers should describe the actual access architecture rather than labeling the setting simply “online.”
Restricted membership usually strengthens privacy expectations
Canada's current guidance on social media research states that identifiable information from digital sites involving online groups with restricted membership carries a much higher expectation of privacy. Under TCPS 2, research involving information from such sources is to be submitted for research ethics board review.
The guidance provides a particularly clear example: research involving a password-protected forum discussing depression and suicide, where registration requires approval by an administrator, requires REB review because the platform is private and the discussions are sensitive.
This illustrates why the general distinction between public accessibility and ethically public information becomes even more consequential once researchers cross an explicit access boundary.
Private does not necessarily mean secret
Members of closed groups may know that other members can copy messages, take screenshots, or disclose information elsewhere. They may also understand that administrators can inspect content.
That does not necessarily mean they have no privacy expectations.
Privacy is rarely an all-or-nothing condition. A person can understand that information is visible to hundreds of group members while still expecting it not to be systematically archived by an outside research institution or reproduced in a journal.
The appropriate question is therefore not whether members believed confidentiality was technologically guaranteed. It is what audience and uses they could reasonably anticipate within the particular setting.
Joining the community does not settle research permission
A researcher may obtain membership honestly and without circumventing any security measure. That establishes legitimate access as a member. It does not necessarily establish authorization to conduct research.
The distinction matters because community membership usually grants access for the purposes for which the community exists. Research involves additional activities such as systematic observation, copying, coding, archiving, analysis, and publication.
Whether joining a private online group gives permission to study it therefore requires separate analysis.
Gatekeeper permission may be necessary without being sufficient
Administrators and moderators often control access to closed communities. Researchers may need their permission to enter or conduct research there.
UKRI identifies research involving gatekeepers as potentially requiring fuller ethics review, particularly when access to participants depends on another person or organization. It also specifically identifies closed social media discussions involving sensitive issues and potentially identifiable quotations or images as circumstances warranting careful review.
Yet a moderator's authority over the platform does not necessarily mean the moderator can provide informed consent on behalf of every member.
Gatekeeper permission
Authorization from the person or organization controlling access to the research setting.
Participant consent
Agreement by the individual whose participation or information is involved, where consent is required under the applicable framework.
A study may require one, both, or neither depending on the circumstances and governing requirements. Researchers should not assume they are interchangeable.
Researcher identity becomes particularly important in bounded spaces
Members of a closed group may reasonably assume that other accounts are present for the group's stated purpose. A researcher who joins under an ordinary member identity while secretly collecting data may therefore create a different ethical situation from a researcher observing unrestricted public posts.
UKRI's current framework emphasizes voluntary and appropriately informed participation, respect for individuals and groups, and integrity and transparency throughout research.
Researchers should therefore determine whether they should identify themselves when observing the group. If disclosure would undermine a necessary research design, the protocol should address the requirements for ethically defensible covert observation rather than treating silence as the default.
Sensitivity can make restricted data substantially higher risk
Many private online communities exist precisely because people want to discuss topics they are reluctant to discuss openly.
Examples include health conditions, infertility, sexuality, abuse, bereavement, addiction, financial hardship, immigration status, workplace conflicts, disability, political organizing, religious experiences, and family problems.
The sensitivity of such material affects both the consequences of identification and the justification required for collecting it without members' knowledge.
UKRI specifically identifies closed online discussions of sensitive issues where quotations or images may identify people as situations that may require full ethics review.
Quotations can breach the boundary even after usernames are removed
Private-community data can be especially difficult to quote safely.
If a paper names the group and reproduces an exact statement, other members may recognize the author even when outsiders cannot. If the material has leaked or been reposted elsewhere, a search engine may also locate it.
The question of how online quotations can identify their authors therefore includes both public searchability and recognition by insiders.
Researchers should consider whether exact quotation is necessary and whether paraphrasing can reduce traceability without compromising the analysis.
The community itself may need protection
A paper can conceal every username while still exposing a small private community.
Naming the group, describing its membership criteria, reproducing recognizable discussions, or providing detailed contextual information may allow readers to identify the community. Publication could then attract unwanted outsiders, journalists, platform administrators, hostile groups, or others whose attention changes the community.
Researchers should therefore assess both individual and collective consequences, consistent with broader ethics principles requiring respect for the rights and dignity of individuals, groups, and communities.
Researchers should minimize what they extract
Membership in a group may technically provide access to years of discussions, member lists, photographs, reactions, timestamps, files, and profile information. Research rarely requires all of it.
Data minimization is especially valuable in private settings because unnecessary collection expands the number of people and types of information exposed if research files are lost, breached, subpoenaed, shared incorrectly, or reused beyond the original purpose.
Researchers should define the unit of analysis before collection and avoid downloading entire communities merely because the interface or software makes doing so easy.
Data security should reflect the sensitivity of the original environment
Researchers effectively create a second copy of community information when they download, screenshot, transcribe, scrape, or otherwise record it.
That copy may no longer benefit from the platform's access controls.
A private discussion protected by account authentication can become an ordinary spreadsheet, screenshot folder, transcript, or qualitative-analysis project file on a researcher's computer. Researchers should therefore specify access controls, encryption where appropriate, retention periods, sharing arrangements, deletion procedures, and whether direct identifiers need to be retained at all.
International online communities can create overlapping legal obligations
Members of an online group may reside in multiple countries, while the researcher and platform are located elsewhere. UKRI notes that internet-mediated research can cross national boundaries and that researchers need to consider relevant legal and ethics requirements across jurisdictions.
Ethics approval from one institution should therefore not be assumed to settle every privacy, data-protection, recording, copyright, or other legal issue that may apply.
Watch Out
Do not describe private-community data as “publicly available” merely because you personally gained access to them. Access granted to an account is not the same as unrestricted public availability.