Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Happens When Research Data Are Accidentally Disclosed or Lost?

A lost laptop, misdirected email, exposed folder, or missing USB drive should be treated as a security incident immediately. Researchers should contain the problem and report it internally rather than deciding for themselves whether it is legally a reportable breach.

321
When Research Data Are Disclosed or Lost Guide 321 of 398
01 · The Question

You Sent, Lost, or Exposed Research Data by Mistake. What Now?

A spreadsheet goes to the wrong collaborator. A laptop containing interview transcripts disappears. A cloud folder is accidentally made public. A participant list is left in a meeting room. An encrypted USB drive cannot be found.

The first instinct may be to fix the problem quietly: recall the email, delete the sharing link, ask the unintended recipient to erase the file, and hope that nobody opened it.

Those actions may help contain the incident, but they should not replace formal reporting. When personal research data are accidentally lost, disclosed, altered, destroyed, or made accessible to someone who should not have them, researchers should follow the institution's security-incident procedure promptly so that the event can be assessed properly.

02 · The Short Answer

Contain the Incident and Report It Internally Without Delay

In Brief

If research data are accidentally disclosed, lost, or otherwise compromised, take reasonable immediate steps to contain the incident and report it through the institution's designated privacy, security, or breach-response process as soon as possible.

Do not wait until you know whether the event legally qualifies as a reportable personal data breach. The responsible organization needs the facts early enough to investigate, mitigate harm, document the incident, and determine whether regulators, participants, ethics bodies, sponsors, collaborators, or others must be informed.

03 · What You Need to Know

Not Every Incident Has the Same Consequences, but Every Incident Needs Assessment

Accidental disclosure can happen in very ordinary ways

Research data incidents do not require sophisticated hacking. Many begin with routine mistakes.

A researcher selects the wrong email address from autocomplete. A spreadsheet containing hidden identifying columns is shared instead of the intended analytical file. A cloud permission is set to "anyone with the link." A research assistant leaves a laptop on public transport. A paper participant list is discarded incorrectly. A collaborator forwards a dataset to someone outside the authorized team.

The technical simplicity of an incident does not determine its seriousness. What matters is what happened to the information and what consequences may follow.

Loss is not limited to someone reading the data

Privacy incidents can affect confidentiality, integrity, or availability.

Confidentiality is affected when personal data are disclosed or made accessible to someone who is not authorized to receive them.

Integrity is affected when data are changed, corrupted, or altered without authorization or in a way that makes them unreliable.

Availability is affected when authorized researchers lose access to data, for example because files are accidentally deleted, encrypted by ransomware, or stored only on a device that is lost.

A single incident can affect more than one of these dimensions. Losing the only copy of an encrypted research dataset may present little confidentiality risk if the encryption is robust, yet it can create a serious availability and research-integrity problem.

A security incident and a personal data breach are related but not always identical

The Philippine National Privacy Commission distinguishes security incidents from personal data breaches. NPC Circular No. 16-03 provides a breach-management framework intended to ensure timely discovery, containment, assessment, mitigation, documentation, and notification where required.

Not every security incident involving a research system necessarily becomes a personal data breach. Conversely, once personal data have been affected in the relevant way, the incident may require assessment under breach rules.

This distinction is useful because researchers should not spend valuable time attempting to make the final legal classification themselves. Report the event internally and allow the responsible privacy or incident-response personnel to determine whether it meets the applicable definition and notification threshold.

Containment comes first, but preserve the facts

Reasonable immediate containment depends on what happened. You might revoke a sharing link, disable a compromised account, retrieve a document, ask an unintended recipient not to access or further distribute a file, disconnect an affected system, or contact institutional IT to secure an account.

At the same time, avoid destroying information that may be needed to investigate the incident. Preserve relevant emails, timestamps, access logs, file names, recipient details, screenshots, system alerts, or other evidence according to institutional instructions.

The goal is to stop continuing exposure without erasing the trail needed to understand what occurred.

Report the incident even if you think you fixed it

Suppose you email a participant spreadsheet to the wrong colleague. Five minutes later, the colleague confirms that they deleted it without opening the attachment.

That information is relevant and may substantially reduce the assessed risk. It does not mean the incident should disappear from institutional view.

The responsible organization may need to document what happened, verify containment, assess whether additional copies exist, determine what personal data were involved, consider legal notification requirements, and identify whether a procedural or technical change could prevent recurrence.

Under the Philippine Data Privacy Act implementing rules, all security incidents and personal data breaches must be documented through written reports, including incidents that do not meet the threshold for mandatory breach notification.

Do not investigate indefinitely before reporting

Some legal frameworks impose short breach-notification timelines. Under the EU GDPR, for example, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a reportable personal data breach. Processors must notify controllers without undue delay after becoming aware of a breach.

Philippine breach rules likewise contain a 72-hour notification framework for breaches meeting the applicable notification criteria.

Individual researchers therefore should not consume much of that window conducting their own informal investigation before telling the institution. Report what you know, identify what remains uncertain, and continue gathering information through the designated response process.

Write down what you know, not what you assume

Useful early information can include when the incident occurred and when it was discovered, which systems or devices were involved, what files or records may be affected, approximately how many participants may be involved, what categories of information were present, who may have received or accessed the data, whether encryption or other protections were applied, and what containment actions have already been taken.

Distinguish confirmed facts from possibilities. "The attachment was sent to the wrong address" is a fact. "Nobody opened it" is not a fact unless there is evidence supporting that conclusion.

ICO breach-response guidance similarly recommends beginning a log immediately and recording facts as they emerge, including what happened, who was involved, the timeline, and actions taken.

The sensitivity and identifiability of the data matter

A misplaced file containing anonymous aggregate statistics creates a different risk from one containing participant names, health information, financial data, passwords, identification numbers, or detailed interview narratives.

Assessment may consider the nature and sensitivity of the information, the number and characteristics of affected people, how easily individuals can be identified, who received the information, whether it was encrypted, whether the data can be recovered, and the possible consequences of misuse or disclosure.

Philippine mandatory-notification rules specifically consider sensitive personal information and other information that may enable identity fraud, together with unauthorized acquisition and the likelihood of real risk of serious harm.

Encryption can materially change the risk assessment

If an encrypted laptop or USB drive is lost, effective encryption may make the personal data unintelligible to whoever obtains the device. That can substantially reduce confidentiality risk.

But do not decide from memory that the device was "probably encrypted." The incident team may need to confirm what encryption was enabled, whether the device was locked, whether credentials were stored with it, and whether remote access or synchronization creates additional exposure.

Under the EU GDPR, appropriate protection such as encryption can affect whether communication to affected individuals is required in particular circumstances.

Asking an unintended recipient to delete the data can help, but it is not the entire response

If information was sent to the wrong person, promptly contacting the recipient may help contain the disclosure. Depending on institutional advice, they may be asked not to open, copy, forward, or retain the information and to confirm deletion.

That confirmation becomes part of the risk assessment. It does not retroactively mean the disclosure never occurred.

Researchers should also avoid sending further sensitive information while trying to correct the first mistake. Incident response occasionally produces sequels nobody requested.

Participant welfare may require action before the legal analysis is complete

Some incidents create immediate risks to participants. Exposed credentials may need to be reset. A disclosure involving safety-sensitive information may require urgent protective measures. Financial or identity information may justify advice on protective steps.

The incident-response team should consider mitigation alongside legal notification. Philippine NPC breach-management guidance specifically includes actions to mitigate possible harm, limit damage or distress, recover compromised information, and prevent recurrence.

Do not contact participants independently unless the response plan calls for it

A researcher who discovers a mistake may understandably want to apologize to participants immediately. Premature notification can, however, provide incomplete or inaccurate information, interfere with an investigation, create inconsistent messages, or omit legally required content.

Report internally first unless there is an immediate safety reason requiring another response. The responsible organization can determine who should contact affected participants, when, through which channel, and with what information.

Research governance obligations may exist beyond privacy law

A serious incident can also affect ethics approval, sponsor obligations, contractual commitments, research integrity, clinical governance, institutional security, or the safety of continued data collection.

Depending on the study, the institution may need to inform an ethics committee, sponsor, collaborating institution, funder, data provider, information-security team, or another authority in addition to any privacy regulator.

Those obligations should be coordinated rather than handled independently by individual researchers.

Do Not Hide Small Mistakes

A seemingly minor incident can often be contained quickly when reported early. Delayed reporting can turn a manageable disclosure into a larger problem by allowing access, copying, forwarding, or regulatory deadlines to continue while the research team hopes the issue disappears.

The incident should lead to prevention, not only closure

Once the immediate problem is contained, determine why it occurred. Was autocomplete responsible? Were access permissions too broad? Did staff use an unapproved personal device? Was a dataset insufficiently minimized? Was sensitive information unnecessarily attached to email?

The response may involve technical changes, revised procedures, staff training, tighter permissions, new transfer tools, better labeling, encryption, or changes to the data management plan.

The aim is not merely to identify who clicked the wrong button. A useful investigation asks what made that button capable of causing so much damage.

04 · A Practical Example

A Participant Spreadsheet Goes to the Wrong Recipient

Hypothetical Example

An autocomplete mistake

A researcher intends to send an encrypted analytical file to an authorized collaborator but accidentally selects another person with a similar name. The message contains a spreadsheet attachment with participant study IDs, age, occupation, and sensitive questionnaire responses.

Contain The researcher follows institutional procedure to contact the unintended recipient, asks them not to open or distribute the attachment, and takes any available technical containment steps.
Report The researcher immediately reports the incident through the institution's privacy or security channel rather than waiting for the recipient to respond.
Preserve facts The original message, attachment details, recipient address, time sent, encryption status, and subsequent correspondence are retained for assessment.
Assess The institution determines what information was involved, whether the recipient accessed it, whether the encryption credentials were also disclosed, what risks participants face, and whether formal breach-notification requirements apply.
Prevent recurrence The team reviews whether an authenticated file-transfer system, recipient verification step, or reduced dataset would have prevented or reduced the incident.

The researcher's responsibility was not to make the final legal determination in the first five minutes. It was to stop further exposure where possible and get the incident into the hands of people who could make that determination before relevant deadlines expired.

05 · What Researchers Often Get Wrong

Common Mistakes After Research Data Go Missing or to the Wrong Place

Misconception

If I Recovered the File, Do I Still Need to Report the Incident?

Usually you should still follow the institutional incident-reporting process. Recovery is important evidence for assessing risk, but the organization may still need to document and investigate what happened.

Misconception

If the Recipient Says They Deleted It, Was There No Breach?

Not necessarily. Their response may reduce the assessed risk, but an unauthorized disclosure may already have occurred. The responsible organization should make the classification and determine whether further action is required.

Misconception

If the Data Were Pseudonymized, Is the Incident Harmless?

No. Pseudonymization can reduce risk, but pseudonymized information may remain personal data and may still reveal sensitive information. Assess the actual identifiability and consequences rather than relying on the label.

Misconception

Should I Investigate Fully Before Telling the Privacy Office?

No. Gather immediate facts and contain the incident, but report promptly. Short regulatory timelines can apply, and the institution may need to direct the investigation and preserve evidence.

Misconception

Should I Email Participants Immediately to Be Transparent?

Not independently unless the response procedure calls for it or an urgent safety need exists. Participant notification may have specific timing, content, and legal requirements and should normally be coordinated through the responsible organization.

06 · What This Means for You

Know the Incident Route Before You Need It

Every research team handling personal data should know whom to contact when something goes wrong. The middle of an incident is a poor time to discover that nobody knows the data protection officer's email address.

A simple incident framework

If data may still be exposed or accessible
Take reasonable immediate containment steps without destroying evidence or exceeding your authority.
If personal research data may have been lost, disclosed, altered, destroyed, or accessed improperly
Report the incident immediately through the designated institutional process.
If you are uncertain whether it qualifies as a personal data breach
Report it anyway and let the responsible privacy or incident-response personnel make the formal assessment.
If participants may face immediate harm
Escalate that risk clearly so appropriate mitigation can begin without waiting for the entire investigation to finish.
If the incident is contained
Continue documenting facts and cooperate with the assessment, notification, remediation, and prevention process.

Once the initial response is underway, the institution can determine whether the event meets the applicable definition of a research data breach and what should happen next.

07 · A Quick Checklist

What to Do Immediately After a Research Data Incident

As soon as you discover the incident:
Take reasonable steps to stop continuing disclosure, access, loss, alteration, or destruction where you can do so safely and within your authority.
Report the incident immediately through the institution's designated privacy, information-security, or breach-response channel.
Record when the incident happened, when it was discovered, and what actions have already been taken.
Identify the affected files, systems, devices, participant groups, and types of information as accurately as possible.
Preserve relevant emails, logs, messages, screenshots, file names, and other evidence according to institutional instructions.
State clearly what is confirmed and what remains uncertain rather than guessing whether anyone accessed the information.
Do not independently notify participants, regulators, media, or external parties unless authorized or required by the incident-response procedure.
Cooperate with mitigation, documentation, regulatory assessment, ethics review, and corrective actions after containment.
08 · Frequently Asked Questions

Common Questions After Research Data Are Lost or Disclosed

Is sending participant data to the wrong person a data breach?

It can be an unauthorized disclosure and may meet the applicable definition of a personal data breach. Report it immediately and allow the responsible organization to assess the event under the relevant law and institutional procedure.

Is losing an encrypted laptop a data breach?

It requires incident assessment. Effective encryption may substantially reduce confidentiality risk, but the institution should confirm the encryption, credentials, data involved, availability impact, and applicable breach rules rather than assuming there is nothing to report.

What if the wrong recipient confirms that they deleted the email?

Provide that information to the incident-response team. It may reduce the risk and influence notification decisions, but the event should still be documented and assessed.

Do all incidents have to be reported to the National Privacy Commission?

No. Philippine rules distinguish mandatory breach notification from broader incident documentation. The NPC states that not all personal data breaches require notification, while incidents that do not meet the mandatory threshold still need appropriate documentation and reporting through the applicable organizational process.

Should researchers notify the ethics committee after a data incident?

Possibly. The answer depends on the ethics approval, institutional rules, study risk, and seriousness of the incident. Coordinate with the responsible research-governance or ethics office rather than assuming privacy notification and ethics reporting are identical.

What if no personal data were involved?

The event may fall outside personal-data breach rules but can still be a research security, confidentiality, contractual, intellectual-property, or research-integrity incident. Follow the applicable institutional reporting procedure.

09 · The Bottom Line

Report First; Classify Carefully Afterward

The Bottom Line

When research data are accidentally disclosed, lost, altered, destroyed, or exposed, contain what you reasonably can and report the incident internally without waiting to decide whether it is legally a reportable breach.

Early reporting gives the responsible organization time to establish the facts, reduce participant harm, meet any applicable deadlines, and prevent recurrence. A quick mistake does not have to become a prolonged one.

10 · Sources and Further Reading

Authoritative Sources on Research Data Incidents

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes