Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Who Must Be Told When a Research Data Breach Occurs?

A research data breach may need to be reported internally and, depending on its seriousness and the applicable rules, externally to regulators, affected participants, ethics bodies, sponsors, or partner institutions. These notification routes are related but not interchangeable.

323
Reporting a Research Data Breach Guide 323 of 398
01 · The Question

A Research Data Breach Happened. Who Needs to Know?

You have reported a suspected breach to your institution. The immediate exposure has been contained, and the investigation has begun.

Who gets told next? The affected participants? The privacy regulator? The research ethics committee? Your sponsor? A collaborating university? Everyone?

There is no single notification list that applies to every research data breach. Different recipients are notified for different reasons, under different rules, and sometimes at different thresholds. Internal escalation should happen promptly, while external notification depends on the applicable data protection law, research oversight arrangements, contracts, and seriousness of the incident.

02 · The Short Answer

Internal Reporting Comes First; External Notification Depends on the Breach

In Brief

A suspected research data breach should be reported immediately through the institution's designated privacy or security process; after assessment, the responsible organization determines whether regulators, affected participants, research ethics bodies, sponsors, collaborators, funders, or other parties must also be notified.

Not every personal data breach requires notification to every external party. The threshold for notifying a privacy regulator can differ from the threshold for notifying participants or an ethics committee, so these decisions should be coordinated rather than made independently by individual researchers.

03 · What You Need to Know

Different Notifications Serve Different Purposes

The first notification is usually internal

When a researcher discovers that personal research data may have been lost, disclosed, altered, destroyed, or accessed without authorization, the first step is normally to activate the institution's incident-response process.

Depending on the organization, the relevant contact may be a data protection officer, privacy office, information-security team, incident-response team, research governance office, or another designated unit.

The researcher should not wait until the event has been fully investigated. External notification deadlines can be short, and the institution needs enough time to determine what happened, assess the risk, and decide which reporting obligations apply.

This is why the immediate response to a suspected research data breach emphasizes rapid internal escalation even when the final legal classification remains uncertain.

The privacy regulator is notified only when the applicable threshold is met

Data protection laws use different tests for regulatory notification.

Under the EU GDPR, a controller must notify the competent supervisory authority of a personal data breach unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where notification is required, it must occur without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.

The Philippine framework uses a different test. The Data Privacy Act implementing rules require notification to the National Privacy Commission and affected data subjects when specified information is reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to give rise to a real risk of serious harm.

The NPC explicitly states that not all personal data breaches require notification. Its current breach-reporting guidance identifies mandatory notification criteria and requires qualifying notifications through its Data Breach Notification Management System.

In the Philippines, the personal information controller carries the notification obligation

The NPC states that the obligation to notify remains with the personal information controller even where processing has been outsourced or subcontracted to a personal information processor.

This matters in research involving cloud providers, survey platforms, transcription companies, laboratories, and other service providers. A vendor may be required to alert the institution quickly, but researchers should not assume the vendor will take over the institution's regulatory obligations.

Internally, this reinforces the importance of knowing who is responsible for protecting personal research data and who has authority to make breach-notification decisions.

Affected participants may have to be told

Regulatory notification and participant notification are related but separate questions.

Under the EU GDPR, affected individuals generally must be informed without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms, subject to the Regulation's conditions and exceptions.

Under the Philippine breach framework, affected data subjects must be notified when the applicable mandatory-notification requirements are met. NPC guidance states that qualifying notifications should be made individually through written or electronic means and should explain how affected individuals can obtain further information and what they can do to minimize resulting risks.

Participant notification is therefore not simply an apology email. Its content and timing may be regulated.

Participants should receive useful information, not institutional fog

When notification is required, affected people need enough information to understand what happened and what they can do.

Depending on the governing law, relevant information may include the nature of the breach, the types of information involved, likely consequences, actions already taken, protective steps the participant can take, and how to contact the responsible organization or data protection officer.

If credentials were exposed, participants may need to change passwords. If financial or identity information was compromised, different protective measures may be appropriate. If highly sensitive research information was disclosed, the institution may need to consider context-specific safety or confidentiality risks.

Good notification should help participants act. A paragraph explaining that the organization "takes privacy very seriously" is not, by itself, a mitigation strategy.

The ethics committee may need to know even when the privacy regulator does not

A research data incident can raise ethical issues independently of whether it meets a statutory privacy-notification threshold.

Loss of confidentiality may expose participants to psychological, social, economic, physical, or other harms that were not previously anticipated. It may also reveal that the study's approved privacy protections are inadequate.

Under U.S. HHS human-subject protections, unanticipated problems involving risks to participants or others must be reported promptly through the relevant institutional process. OHRP guidance specifically gives the example of an unencrypted laptop containing identifiable sensitive research data being stolen and treats the event as an unanticipated problem requiring reporting because it increased participants' risk of harm.

OHRP has also treated inadvertent disclosure of research participants' email addresses as a confidentiality breach constituting an unanticipated problem in a specific enforcement case.

The exact reporting requirements depend on the ethics framework governing the study. Researchers should therefore check the conditions of their own ethics approval rather than assuming that regulator notification and ethics reporting use the same threshold.

Research ethics committees can have authority to require changes or suspend research

The 2024 Declaration of Helsinki states that research ethics committees must have authority to monitor research, recommend changes, withdraw approval, and suspend ongoing research. It also requires researchers to provide relevant monitoring information, particularly regarding serious adverse events, where monitoring is required.

Although the Declaration applies specifically to medical research involving human participants, it illustrates why a confidentiality breach can become more than a privacy-office matter. A serious incident may alter the ethical acceptability of continuing the approved protocol unchanged.

Sponsors and funders may have separate reporting requirements

Research contracts, grant conditions, clinical trial agreements, data-use agreements, or sponsor policies may require notification of security incidents or confidentiality breaches.

The contractual threshold may not be identical to the legal threshold for regulator notification. A sponsor might require notification of any suspected breach affecting sponsored data, even where the incident ultimately does not meet the regulator's mandatory reporting criteria.

Researchers should therefore check project-specific agreements rather than assuming the privacy office's regulator decision resolves every reporting obligation.

Collaborating institutions may need immediate notice

If data originated from another institution, are jointly controlled, or are processed under a collaboration or data-sharing arrangement, the partner organization may need to be informed promptly.

Agreements should ideally specify who reports incidents to whom, within what period, and what information must be provided. This is particularly important because one institution may need information from another to meet its own regulatory deadline.

A collaborator discovering a breach should therefore follow the reporting provisions established when the data-sharing or transfer arrangement was documented.

A processor should tell the controller, not independently improvise the whole response

Where a service provider acts as a processor, it generally needs to notify the controller according to applicable law and contract so that the controller can perform its breach assessment.

Under the GDPR, processors must notify controllers without undue delay after becoming aware of a personal data breach.

Researchers using external services should know the contractual incident-notification route and should immediately escalate any provider notification to the institutional privacy or security team.

Other regulators or authorities may apply in specialized research

Health research, clinical trials, government research, education records, financial data, national-security research, or other regulated areas may involve additional authorities and sector-specific reporting obligations.

For HHS-regulated human-subject research in the United States, institutional procedures must provide for prompt reporting of relevant unanticipated problems, serious or continuing noncompliance, and suspensions or terminations to the IRB, appropriate institutional officials, and, where applicable, agencies such as OHRP or FDA.

Researchers should not generalize those U.S. requirements to studies in other jurisdictions. The useful principle is that privacy regulation may be only one reporting layer.

Law enforcement notification is situation-specific

A breach involving theft, extortion, ransomware, fraud, physical danger, or other suspected criminal activity may justify involvement of law enforcement or cybercrime authorities.

That decision should normally be coordinated through institutional security, legal, privacy, or senior management channels. Researchers should preserve evidence and avoid actions that could interfere with a forensic or criminal investigation.

Do not notify the media simply because the incident feels serious

Public communication may sometimes become necessary, particularly for large incidents or where individual notification is impossible, but media communication is normally an institutional function.

Researchers should not post about an active breach on social media, contact journalists independently, or discuss identifiable details publicly. Apart from creating additional disclosure risk, premature public statements may contain facts that later prove inaccurate.

Notification can be phased when the investigation is incomplete

Short deadlines do not always mean the organization must know everything within 72 hours.

Philippine NPC guidance states that where complete information cannot reasonably be provided within the prescribed period, the PIC should still submit the available information through the breach-notification process and may supplement it later.

GDPR Article 33 similarly allows information to be provided in phases where it cannot all be supplied at the same time.

The practical lesson is important: uncertainty is not a reason to remain silent until day four.

Notification can sometimes be delayed, but researchers should not make that decision alone

Philippine NPC guidance permits limited delay of data-subject notification where necessary to determine the scope of the breach, prevent further disclosure, or restore reasonable integrity to the system, subject to the applicable conditions. It also identifies circumstances in which delay is not allowed and provides a process for requesting postponement.

Other jurisdictions have their own rules and exceptions. Decisions to delay notification should therefore be made through the formal breach-response process, not because the research team would prefer to finish the paper first.

Different Thresholds

A breach can require reporting to an ethics committee without requiring notification to a privacy regulator, or require contractual notice to a partner before the regulator assessment is complete. Never assume that one "not reportable" decision answers every reporting obligation.

04 · A Practical Example

One Breach, Several Possible Notification Routes

Hypothetical Example

A stolen laptop containing sensitive interview data

A research assistant's laptop is stolen. It contains locally stored identifiable interview transcripts concerning participants' mental health and workplace experiences. The study is led by University A, funded by an external sponsor, and includes a collaborating researcher at University B.

Internal response The research assistant immediately reports the theft to University A's designated privacy and information-security process and informs the PI according to institutional procedure.
Privacy assessment University A determines whether the device was encrypted, what information was stored locally, how many participants are affected, and whether the applicable legal threshold for regulator and participant notification is met.
Research ethics assessment The institution reviews whether the loss constitutes an unanticipated confidentiality risk requiring reporting to the ethics committee and whether changes to the study's data-handling procedures are necessary.
Contractual assessment The sponsor agreement and collaboration arrangement are reviewed to determine whether the sponsor or University B must be notified and within what timeframe.
Participant notification If the applicable threshold is met, affected participants receive coordinated notification explaining what happened, the information involved, potential consequences, mitigation measures, and where they can obtain assistance.

There is no contradiction if one route requires notification while another does not. Each decision answers a different regulatory, ethical, or contractual question.

05 · What Researchers Often Get Wrong

Common Misconceptions About Breach Notification

Misconception

Does Every Breach Have to Be Reported to the Privacy Regulator?

No. Notification thresholds differ by jurisdiction. The Philippines and GDPR frameworks both distinguish personal data breaches from breaches that meet the threshold for mandatory regulator notification.

Misconception

If the Regulator Does Not Need to Be Told, Does Nobody Else Need to Know?

No. Internal reporting, ethics reporting, sponsor notification, contractual notice, or partner-institution reporting may still be required even when the privacy regulator threshold is not met.

Misconception

Should the Researcher Personally Notify Participants Immediately?

Usually not independently. Participant notification should be coordinated through the responsible organization so that timing, content, risk information, assistance, and legal requirements are handled consistently.

Misconception

Does the 72-Hour Rule Mean the Investigation Must Be Finished in 72 Hours?

No. Applicable frameworks allow initial notification based on available information in circumstances where complete information cannot yet be provided. The deadline is a reason to escalate early, not a requirement to complete every forensic question before reporting.

Misconception

If a Vendor Caused the Breach, Does the Vendor Handle All Notification?

Not necessarily. Under the Philippine framework, the PIC retains the notification obligation for qualifying breaches even where processing is outsourced. Processor-controller responsibilities under other frameworks likewise need to be followed according to law and contract.

06 · What This Means for You

Think in Notification Routes, Not One Master Recipient List

A simple notification framework

If you discover or suspect a breach
Notify the designated institutional privacy or security route immediately.
If the applicable legal threshold for regulator notification is met
The responsible controller or PIC should notify the relevant authority within the required timeframe and procedure.
If the applicable threshold for notifying affected people is met
Provide coordinated participant notification containing the required information and useful risk-mitigation advice.
If the incident creates an unanticipated or materially increased research risk
Follow the applicable ethics or human-subject protection reporting procedure.
If sponsors, collaborators, funders, processors, or data providers are contractually involved
Check and satisfy their incident-notification provisions as part of the coordinated response.

Once the required parties have been identified, another decision may become urgent: whether continuing the study could expose additional participants or data to the same unresolved problem.

07 · A Quick Checklist

Who Might Need to Be Told After a Research Data Breach?

Check each applicable notification route:
The institution's designated privacy, data protection, information-security, or incident-response team has been informed immediately.
The applicable privacy regulator notification threshold and deadline have been assessed by the responsible organization.
The separate threshold for notifying affected participants or data subjects has been assessed.
The research ethics committee or human-subject protection reporting requirements have been checked.
Sponsor, funder, clinical governance, or research-contract notification requirements have been reviewed.
Collaborating institutions, data providers, controllers, processors, or other contractual parties have been notified where required.
Any sector-specific regulator, government agency, or law-enforcement reporting requirement has been considered where relevant.
All notifications and decisions not to notify are documented with the applicable reasoning and timeline.
08 · Frequently Asked Questions

Common Questions About Research Data Breach Notification

Do all Philippine data breaches have to be reported to the NPC?

No. The NPC states that mandatory notification applies only when all applicable criteria are present. Incidents that do not meet the mandatory threshold still need appropriate documentation under the Philippine breach-management framework.

Who reports a qualifying breach to the NPC?

The notification obligation rests with the personal information controller, including where processing has been outsourced to a personal information processor. Researchers should therefore escalate promptly through their institution rather than attempting to file independently unless they are specifically authorized to do so.

Do affected participants always have to be notified?

No. The applicable threshold depends on the governing law. Under GDPR, communication generally turns on high risk to individuals, while the Philippine framework applies its own mandatory-notification criteria. The organization should make the assessment from the actual breach facts.

Does a confidentiality breach need to be reported to the ethics committee?

Potentially. If the incident creates an unanticipated or materially increased risk to participants, applicable ethics rules may require reporting. OHRP guidance, for example, specifically recognizes certain confidentiality breaches as reportable unanticipated problems in HHS-regulated research.

Can participant notification be delayed while the breach is investigated?

Sometimes, within the conditions of the applicable law. Philippine NPC guidance permits limited delay for purposes such as determining scope, preventing further disclosure, or restoring system integrity, while also identifying circumstances where delay is restricted.

Who should communicate with participants?

The responsible organization should coordinate the communication through its breach-response process. The message may involve the research team, privacy office, institutional leadership, communications personnel, or others depending on the incident, but it should not be improvised independently by whichever researcher discovered the breach.

Should a collaborating university be told about a breach?

Potentially, especially where it is a controller, source of the data, recipient, processor, or party to an agreement requiring incident notification. Review the actual institutional relationship and contractual terms.

09 · The Bottom Line

A Research Data Breach Can Have More Than One Reporting Route

The Bottom Line

Report a suspected research data breach internally immediately, then determine through the institutional response process which external parties must be told under privacy law, research ethics requirements, contracts, sponsorship arrangements, and other applicable rules.

Do not assume that notifying one party satisfies everyone else, or that a decision not to notify the privacy regulator ends the analysis. Breach notification is better understood as several overlapping reporting routes, each triggered by its own purpose and threshold.

10 · Sources and Further Reading

Authoritative Sources on Breach Notification

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes