Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Researchers Create Vulnerability Through the Way a Study Is Designed?

Vulnerability is not always something participants bring into a study. Recruitment methods, incentives, privacy practices, authority relationships, and other design choices can create or intensify vulnerabilities that might otherwise have been absent.

210
Can Research Design Create Vulnerability? Guide 210 of 398
01 · The Question

Can the study itself make participants vulnerable?

Researchers often begin vulnerability assessments by describing the participants: children, patients, employees, economically disadvantaged people, migrants, or people with impaired decision-making capacity. That approach can overlook another possible source of vulnerability sitting much closer to home: the protocol.

A participant may enter a study fully capable of making decisions and facing no unusual research-related disadvantage. Then the study recruits them through someone who controls their employment, asks for unnecessary identifying information about sensitive behavior, offers participation as the only route to something they need, or conducts an interview where others can overhear.

In these situations, vulnerability is not merely a characteristic discovered in the participant. Part of it may have been created by the way the research was designed.

02 · The Short Answer

Yes, research design can create or amplify vulnerability

In Brief

Yes. Researchers can create or intensify participant vulnerability when recruitment, consent procedures, incentives, data collection, authority relationships, privacy practices, or other features of a study make participants more susceptible to pressure, exploitation, disclosure, or other harms and wrongs.

This does not mean every research-created risk makes someone ethically vulnerable. The important question is whether a design choice unnecessarily changes participants' ability to protect their interests or exposes them to greater susceptibility to harm or wrong, and whether that feature can reasonably be redesigned.

03 · What You Need to Know

Sometimes the ethical problem is not who you recruit but how you recruit and study them

Vulnerability can emerge from an interaction between people and research

CIOMS defines vulnerable persons as those who may have an increased likelihood of being wronged or incurring additional harm in research. Its guidance emphasizes characteristics and circumstances that produce vulnerability rather than treating vulnerability solely as a fixed property of particular groups.

The 2024 Declaration of Helsinki likewise recognizes factors producing vulnerability that may be fixed or contextual and dynamic. This contextual approach has an important implication: researchers need to examine not only what circumstances participants bring into research but also what circumstances the research creates.

A useful vulnerability assessment therefore asks two questions. What could make these participants more susceptible to harm or wrong before the study begins? And what features of this study could create or increase that susceptibility?

Recruitment can create vulnerability through authority

Consider a researcher who wants to recruit university employees. Simply being employed does not necessarily make participants vulnerable in every study. Now suppose their immediate supervisors personally invite them, repeatedly remind them to participate, and receive a list showing who enrolled.

The design has introduced a hierarchical relationship directly into recruitment.

CIOMS identifies subordinate relationships as a potential source of diminished voluntariness. People may agree because they expect favorable treatment or because they fear disapproval or retaliation if they refuse.

Researchers may sometimes reduce that vulnerability by changing who approaches participants, who knows their participation decision, or how recruitment is separated from relationships involving employment, education, healthcare, or services.

Researchers can create privacy vulnerability by collecting more data than they need

Imagine an anonymous survey about attitudes toward workplace technology. If the research question does not require names, employee numbers, exact job titles, precise work locations, or IP addresses, collecting them anyway creates information that could connect responses to individuals.

If the survey also asks participants to criticize supervisors, report misconduct, or describe stigmatized experiences, those identifiers can transform the consequences of a data breach.

The ethical problem is not solved merely by telling participants that disclosure is a risk. Researchers should first ask whether the identifying information needs to exist.

Watch Out

Informed consent does not turn an avoidable design risk into a good design choice. Disclosing a risk is important, but researchers should still minimize unnecessary risks where reasonably possible.

The setting can change what participation reveals

Where research occurs can itself disclose information.

Suppose a researcher interviews members of a stigmatized population in a room clearly identified for that study. Even if the interview data are stored securely, simply being seen entering the room may reveal something sensitive about a participant.

Similarly, calling a participant from a recognizable research center, leaving detailed voicemail messages, sending mail with revealing labels, or conducting interviews within hearing distance of relatives or colleagues can create exposure before the formal data-security plan becomes relevant.

For research involving stigma or legally sensitive information, confidentiality therefore begins with recruitment and contact procedures, not only with the database.

Incentive design can alter the conditions of choice

Payment for research participation is not inherently unethical. Participants may reasonably be compensated for time, inconvenience, expenses, or other contributions. But incentives form part of the environment in which consent occurs.

The Belmont Report distinguishes coercion from undue influence. Coercion involves an overt threat of harm used to obtain compliance, whereas undue influence can arise through an excessive, unwarranted, inappropriate, or improper reward or other overture. It also recognizes that an inducement ordinarily considered acceptable may operate differently when a prospective participant is especially vulnerable.

The design question is therefore not simply whether participants are paid. Researchers should examine the amount, structure, timing, conditions of payment, consequences of withdrawal, alternatives available to participants, and context in which the offer is made.

This becomes especially important when financial need may affect how an incentive is experienced.

Access to valued benefits can become part of the vulnerability

Money is not the only inducement that matters. Research may intersect with healthcare, educational credit, institutional privileges, services, or other things participants value.

OHRP uses the example of students being offered extra credit for research participation. If participation is the only way to earn that credit, the arrangement may create undue influence. Providing a comparable non-research alternative can reduce that concern.

The broader lesson is that researchers should examine what participation controls. If saying “no” means losing access to something participants reasonably need or value, the study may have changed the practical meaning of voluntary choice.

Study procedures can unnecessarily expose participants to harm

A protocol may ask participants to disclose traumatic experiences, illegal behavior, immigration status, sexual behavior, workplace misconduct, or other sensitive information. Sometimes those questions are necessary to answer the research question. Sometimes they are merely interesting.

The distinction matters ethically.

Every additional sensitive question can introduce burdens or consequences. Researchers should be able to explain why collecting the information is scientifically necessary and what protections correspond to its sensitivity.

The same principle applies to physical procedures, repeated assessments, travel requirements, lengthy interviews, digital tracking, biological samples, and other burdens. A procedure should not survive ethical scrutiny simply because it would produce an interesting additional variable.

Digital research can create vulnerabilities that are easy to overlook

Online and technology-mediated research can collect information beyond what participants consciously type into a form. Depending on the platform and configuration, researchers may encounter IP addresses, device information, timestamps, location data, contact information, account identifiers, or other metadata.

The relevant protections depend on the actual technology and data flow. Researchers should determine what information is collected, where it goes, who can access it, how long it is retained, and whether third-party platforms introduce additional privacy considerations.

A promise that a study is “anonymous” should therefore reflect the actual data architecture rather than the researcher's intention not to look at identifiers.

Researcher-created vulnerability can sometimes be removed rather than merely managed

This is perhaps the most practical consequence of viewing vulnerability contextually. If a design choice creates the problem, changing the design may be more effective than adding another warning to the consent form.

Design feature Potential vulnerability created or intensified Possible redesign
Supervisor recruits employees Pressure or fear of employment consequences Use independent recruitment and limit supervisor knowledge of participation
Unnecessary identifiers collected with sensitive responses Greater consequences if confidentiality is breached Remove identifiers or collect only the minimum necessary information
Sensitive interviews conducted where others can hear Unintended disclosure Provide an appropriately private setting
Research participation is the only way to obtain course credit Undue influence Provide a comparable non-research alternative where appropriate
Payment depends on completing every study visit Pressure to remain when a participant wishes to withdraw Consider payment arrangements that appropriately recognize participation already completed
Unnecessary sensitive questions are included Additional psychological, social, legal, or privacy risk Remove questions that are not necessary for the research objectives

These are examples rather than universal prescriptions. The appropriate redesign depends on the study and governing requirements. The central principle is to consider whether vulnerability can be reduced at its source.

04 · A Practical Example

A low-risk survey becomes ethically different after a few design decisions

Hypothetical Example

An employee survey about workplace misconduct

A researcher proposes an online survey asking hospital employees about bullying, unsafe practices, and misconduct they have witnessed.

Initial design Department heads distribute personalized survey links to their staff. Employees are asked for their unit, exact job title, years of service, and supervisor. Managers receive weekly information showing which employees have completed the survey.
What the design creates Employees may fear that declining will be visible. Combinations of demographic information may also make respondents recognizable even if names are removed. The sensitive topic increases the consequences of identification.
Redesign Recruitment is separated from supervisors. Managers do not receive participation lists. Unnecessary identifying variables are removed or made less granular, and the research team reviews whether quotations or small subgroups could reveal individuals.
Result The employees and research question have not changed. The redesigned protocol has reduced vulnerabilities that the original study itself helped create.

This is the practical value of understanding vulnerability as partly situational. Ethical protection can sometimes be achieved by changing the research environment rather than changing who is allowed to participate.

05 · What Researchers Often Get Wrong

Design-created vulnerability is easy to miss when attention stays on participant characteristics

Misconception

Participants are either vulnerable before the study or they are not

Research procedures and relationships can alter participants' susceptibility to harm or wrong. Vulnerability may emerge because of how recruitment, consent, data collection, incentives, or confidentiality are designed.

Misconception

If participants consent to a risk, the design no longer needs to minimize it

Consent and risk minimization serve different ethical functions. Informing participants about a reasonably necessary risk may support autonomous choice, but disclosure does not justify avoidable risks that could be reduced without undermining the research.

Misconception

Removing names makes sensitive data anonymous

Participants may remain identifiable through combinations of variables, codes, metadata, quotations, small subgroup characteristics, or other information. Researchers should evaluate the actual possibility of identification rather than relying solely on removal of names.

Misconception

Pressure matters only when someone explicitly threatens participants

Explicit threats concern coercion, but undue influence and hierarchical pressure can be subtler. Participants may infer consequences from relationships of authority even when researchers never state them.

Misconception

More safeguards are always the answer

Sometimes the better solution is fewer risky design features. Removing unnecessary identifiers, changing recruiters, eliminating an unnecessary sensitive question, or providing a genuine alternative may address the problem more directly than adding procedural layers after the vulnerability has been created.

06 · What This Means for You

Audit the protocol for vulnerability before assigning it to the participant

When you identify a vulnerability, ask whether it would still exist if the study were designed differently. That question can reveal problems that a participant-focused assessment misses.

A design-focused vulnerability check

If participants may feel unable to refuse
Examine who recruits them, what authority that person holds, and what participants believe will happen if they decline.
If disclosure could cause serious harm
Ask whether every identifier and sensitive data element is necessary before deciding how to protect it.
If an incentive raises concerns
Examine its amount, structure, alternatives, participant circumstances, and withdrawal arrangements rather than treating payment itself as the problem.
If participation exposes people publicly
Review recruitment, contact, study location, communications, and reporting for less revealing alternatives.
If a safeguard seems complicated
Ask whether redesigning the procedure could remove the source of vulnerability altogether.

The goal is not to eliminate every possible research risk. Research often involves legitimate burdens and uncertainties. The more precise question is whether the protocol creates avoidable susceptibility to harm or wrong and whether the remaining vulnerability has appropriate protections.

07 · A Quick Checklist

Before finalizing the protocol, check whether the study creates vulnerability

Audit these design choices:
Could the person recruiting participants exercise authority or control over them outside the research?
Could anyone important to participants learn whether they accepted or declined?
Are you collecting identifiers or sensitive variables that are not necessary to answer the research question?
Could the location, communication method, or act of participating itself reveal sensitive information?
Could incentives or access to valued benefits affect voluntariness in the circumstances of the target population?
Are withdrawal and payment arrangements designed so participants can leave according to the applicable consent and protocol requirements without unnecessary financial pressure?
Does every sensitive question or burdensome procedure have a defensible research purpose?
Have you examined what information any digital platform collects beyond participants' direct responses?
Can any identified vulnerability be reduced by redesigning the protocol rather than adding restrictions on participants?
08 · Frequently Asked Questions

Frequently asked questions about research-created vulnerability

Can a study make someone vulnerable who was not previously vulnerable?

Yes. Research can introduce authority relationships, disclosure risks, incentives, dependency, or other circumstances that make participants more susceptible to harm or wrong. Vulnerability can therefore arise partly from the interaction between the participant and the protocol.

Does every research risk create vulnerability?

No. Research can involve risk without necessarily placing participants in a situation of particular vulnerability. Vulnerability concerns heightened susceptibility to being wronged or harmed, so the participant's circumstances and the nature of the research both matter.

Can recruitment methods create undue influence?

Yes. Authority relationships, exclusive rewards, repeated pressure, or other features of recruitment can affect voluntariness. OHRP emphasizes that undue influence is contextual and can be subtle.

Can collecting unnecessary data be an ethical problem even if the data are useful?

Potential usefulness does not by itself establish that collection is justified. Researchers should consider whether the information is necessary for the research aims and whether its collection creates additional privacy, confidentiality, psychological, social, or legal risks.

Can changing the study design remove vulnerability?

Sometimes. Independent recruitment, removal of unnecessary identifiers, more private data collection, different incentive arrangements, or eliminating unnecessary procedures may substantially reduce a vulnerability created by the original design.

Should researchers mention design-created vulnerabilities in an ethics application?

Where they are relevant, researchers should describe foreseeable ethical concerns and the measures used to minimize them according to the requirements of the reviewing ethics committee. A strong protocol explains not only participant characteristics but also how research procedures affect participant welfare and voluntariness.

09 · The Bottom Line

Before protecting participants from vulnerability, make sure the protocol is not creating it

The Bottom Line

Researchers can create or intensify vulnerability through choices about recruitment, authority, incentives, privacy, data collection, study settings, and other features of the protocol, so vulnerability assessment should examine the study as closely as it examines the participant.

When the research itself contributes to the problem, the strongest safeguard may be redesign. Removing an unnecessary source of pressure, exposure, or dependency can protect participants more directly than asking them to accept that avoidable vulnerability through a consent form.

10 · Sources and Further Reading

Authoritative guidance on research design, vulnerability, and voluntariness

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes