Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Research Ethics vs. Data Protection Compliance: What’s the Difference?

Research ethics and data protection often address the same participant data, but they ask different questions. Understanding the distinction helps researchers avoid assuming that ethics approval automatically means their data practices are legally compliant.

306
Research Ethics vs. Data Protection Guide 306 of 398
01 · The Question

If Your Study Has Ethics Approval, Is Your Data Protection Covered?

You have ethics approval. Your participants signed the consent form. The protocol explains how confidentiality will be protected. Does that mean the study also complies with applicable data protection law?

Not necessarily. Research ethics and data protection frequently meet at the same practical issues, including consent, privacy, confidentiality, data collection, sharing, retention, and security. But they are not simply two names for the same set of requirements.

This distinction matters because a study can raise a data protection problem even when its overall research design is ethically acceptable. The reverse is also possible: technically lawful processing of personal data does not, by itself, establish that a study is ethically justified.

02 · The Short Answer

Research Ethics and Data Protection Are Related, but They Are Not Interchangeable

In Brief

Research ethics asks whether research involving people is designed and conducted responsibly, while data protection compliance asks whether personal data are processed in accordance with applicable data protection law and related institutional requirements.

The two overlap substantially, especially around privacy, confidentiality, consent, risk, and safeguards. However, ethics approval does not automatically establish data protection compliance, and data protection compliance does not by itself make a study ethically acceptable.

03 · What You Need to Know

Why the Two Systems Ask Different Questions

Research ethics is concerned with how people are treated through research

Research ethics provides principles for deciding whether research involving people can be justified and how participants should be treated. The Belmont Report, for example, organizes human-subject research ethics around respect for persons, beneficence, and justice. These principles inform questions about voluntary participation, informed consent, risk and benefit, participant selection, privacy, confidentiality, and protections for people who may be vulnerable to coercion or undue influence.

In medical research, the World Medical Association's Declaration of Helsinki similarly addresses participant rights and interests, scientific rigor, risk and burden, informed consent, privacy and confidentiality, vulnerable individuals and groups, and independent ethics review. Its 2024 version explicitly applies to medical research involving human participants, including research using identifiable human material or data.

Ethical assessment therefore extends well beyond what happens to a dataset. A study could use excellent encryption and collect very little personal information yet still be ethically problematic because, for example, participants are exposed to unjustified risk, recruitment is coercive, the participant population is unfairly selected, or the research lacks sufficient scientific value to justify its burdens.

Data protection focuses specifically on the processing of personal data

Data protection law is narrower in subject matter but often much more specific about what happens to personal data. Depending on the jurisdiction, it may regulate collection, recording, organization, use, disclosure, storage, transfer, retention, deletion, and other forms of processing.

Under the EU General Data Protection Regulation (GDPR), for example, organizations processing personal data must address principles including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Processing also requires an appropriate legal basis. Additional conditions may apply to particular categories of data.

Other jurisdictions use different statutory structures and terminology. In the Philippines, for example, the Data Privacy Act of 2012 regulates the processing of personal information and establishes obligations concerning privacy and the protection of personal data. Its implementing rules also contain provisions relevant to scientific and statistical research. Researchers should therefore determine which law actually applies rather than assuming that a familiar framework such as the GDPR governs every project.

Jurisdiction Matters

There is no single worldwide data protection rulebook for research. Applicable requirements can depend on where participants are located, where data are processed, which organizations are involved, and the reach of the relevant law. Institutional policies, contracts, funder requirements, and sector-specific rules may add further obligations.

The easiest way to distinguish them is by the question being asked

Issue Research ethics may ask Data protection may ask
Collecting participant information Is collecting this information ethically justified, and are the burdens or risks reasonable? Is there a valid basis for processing it, is the purpose sufficiently defined, and is the information necessary?
Consent Is participation genuinely informed and voluntary? If consent is being relied upon for data processing, does it satisfy the applicable legal requirements? If another legal basis applies, have the relevant requirements still been met?
Privacy and confidentiality Are participants' privacy interests respected and foreseeable harms appropriately minimized? Are appropriate legal, organizational, and technical safeguards applied to personal data?
Data collection Is asking for the information justified by the study and proportionate to its aims? Are the personal data adequate, relevant, and limited to what is necessary under applicable rules?
Sharing data Is the proposed sharing consistent with what participants were told and with the ethical commitments made to them? Is the disclosure or transfer lawful, appropriately governed, secure, and consistent with the stated purpose and applicable rights?
Overall study design Are the risks, benefits, recruitment, participant selection, scientific design, and treatment of participants ethically acceptable? Does the study's processing of personal data satisfy applicable data protection requirements?

The exact questions differ across ethical frameworks and legal systems, but the distinction is useful: ethics evaluates the responsibilities created by conducting research involving people, whereas data protection concentrates on responsibilities created by processing personal data.

Privacy and confidentiality belong to both conversations

The boundary is not clean because data practices can themselves create ethical risks. Disclosure of a participant's health condition, political views, immigration status, or other sensitive information might cause stigma, discrimination, embarrassment, financial loss, or other harm. Protecting personal information can therefore be both an ethical obligation and a legal one.

This is why research ethics frameworks explicitly address privacy and confidentiality. The Declaration of Helsinki requires precautions to protect participant privacy and the confidentiality of personal information. U.S. human-subject protections likewise include consideration of privacy and confidentiality where appropriate.

Data protection requirements approach some of the same risks through concepts such as purpose limitation, security, accountability, retention, and limiting personal data to what the research actually requires. The practical safeguards may overlap even though the underlying frameworks are not identical.

Ethics approval is not a legal compliance certificate

A research ethics committee or institutional review board evaluates matters within its remit. Depending on the institution and jurisdiction, its review may include detailed examination of data handling, or another office such as a data protection officer, privacy office, information security team, legal office, or research governance unit may have separate responsibilities.

An ethics committee's approval therefore should not be interpreted more broadly than the approval actually says. Researchers may still need to establish the applicable legal basis for processing, provide required privacy information, complete a privacy or data protection impact assessment when required, document responsibilities, implement security controls, establish appropriate arrangements with collaborators or service providers, and comply with rules governing transfers or breaches.

The reverse inference is equally unsafe. A project can satisfy data protection requirements while still raising ethical concerns unrelated to data protection. A legally permissible dataset does not answer whether recruitment is fair, risks are justified, participants are unduly influenced, or the study itself is ethically defensible.

Consent is one place where the distinction becomes especially important

A participant may be asked to agree to take part in research, and the project may also need to establish how personal data can lawfully be processed. These questions can interact, but they should not automatically be collapsed into one concept.

European data protection guidance explicitly distinguishes consent used as a legal basis for processing personal data from consent requirements that arise as an ethical standard or procedural obligation. A research project may, depending on the applicable law and circumstances, process personal data on a lawful basis other than data protection consent even though informed consent to research participation is still ethically or institutionally required.

That is why researchers should distinguish agreement to participate from permission or another legal basis for processing personal data rather than assuming that one signature automatically resolves both questions.

Data protection obligations can continue long after recruitment

Ethics is not confined to recruitment either, but researchers sometimes encounter data protection questions most visibly after participants have already enrolled. Who can access the dataset? Where will it be stored? How long will identifiers be retained? Can another institution receive a copy? What happens when a cloud provider is used? What if a laptop containing participant information is stolen?

These are not administrative details to postpone until data collection has finished. They form part of responsible research planning. Clarifying who is responsible for protecting personal research data early can prevent the familiar situation in which everyone on a collaboration assumes someone else has handled privacy compliance.

De-identification does not always remove the issue

Removing names from a spreadsheet does not automatically make data anonymous. A coded or pseudonymized dataset may still be personal data when an individual can be reidentified using additional information available to the relevant party. Whether information is legally anonymous depends on the applicable framework and the circumstances.

This matters because researchers may reduce privacy risks substantially through de-identification while still remaining subject to data protection requirements. Ethical duties may also persist even where information falls outside a particular data protection law. The correct question is not simply, "Did I delete the names?" but whether individuals remain identifiable and what obligations still apply.

04 · A Practical Example

One Study, Two Different Reviews

Hypothetical Example

A university survey about student mental health

A research team plans an online survey examining student mental health and academic experiences. Participants will provide demographic information and responses about psychological well-being. Email addresses will be collected separately for participants who want to enter a prize draw.

Ethics question The team considers whether the questions could cause distress, whether recruitment creates pressure to participate, whether incentives are appropriate, whether potentially vulnerable participants need additional protections, what support information should be provided, and whether the expected knowledge justifies the burdens and risks.
Data protection question The team determines which information constitutes personal data, why each variable is necessary, what legal basis and any additional conditions apply, what privacy information must be provided, who can access the data, where it will be stored, how identifiers will be separated, and when identifiable information will be deleted or anonymized.
Overlap Both reviews may examine confidentiality, unnecessary collection, access controls, disclosure risks, and what participants are told about their information.
Result Approval from the ethics committee addresses the ethical review process, but the team still needs to satisfy any separate data protection and institutional requirements that apply to the processing.

Suppose the ethics committee approves the study, but the research team later decides to upload identifiable responses to a commercial platform that was never assessed or described in the approved data-management arrangements. The existence of ethics approval would not automatically make that new processing arrangement compliant. The team would need to examine the platform, contractual arrangements, security, access, location of processing, applicable transfer rules, and institutional requirements before proceeding.

Conversely, suppose every technical and legal data protection requirement is satisfied, but students are recruited by an instructor who strongly implies that participation will improve their standing in the course. Good data security would not resolve the ethical concern about voluntariness and undue influence.

05 · What Researchers Often Get Wrong

Where Ethics and Data Protection Are Commonly Confused

Misconception

Does Ethics Approval Mean the Study Is Data Protection Compliant?

No. Ethics approval confirms the outcome of an ethics review within that committee's remit. Separate privacy, legal, information-security, contractual, or governance requirements may still apply. Researchers should verify their institution's process rather than treating ethics approval as universal clearance.

Misconception

If Participants Consented, Can You Do Anything Described Somewhere in the Form?

No. Consent is not a waiver of all ethical or data protection obligations. The processing still has to satisfy the applicable requirements, and researchers should not collect unnecessary information merely because participants agreed to provide it. The precise legal role of consent also varies by jurisdiction and context.

Misconception

If the Data Are Secure, Is the Research Ethically Acceptable?

Not necessarily. Security addresses an important class of risk, but research ethics also considers matters such as scientific validity, proportionality of risk and benefit, voluntariness, participant selection, fairness, and protection of vulnerable participants. An encrypted unethical study is still an unethical study.

Misconception

Is Data Protection Just About Keeping Information Confidential?

No. Confidentiality and security are important, but modern data protection frameworks can also regulate why personal data are processed, what information is collected, how transparent the processing is, how long information is retained, who receives it, what rights individuals have, and how compliance is demonstrated.

Misconception

Do You Need Every Piece of Information That Might Be Useful Later?

Usually that is a poor starting assumption. Researchers should be able to justify which personal data the study actually needs. Collecting extra variables "just in case" can increase privacy and security risks and may conflict with data minimization requirements under applicable law.

06 · What This Means for You

Treat Ethics and Data Protection as Parallel Requirements

When a study involves personal data, do not ask only whether you have ethics approval. Ask separately whether you have identified and satisfied the data protection requirements that apply to the project.

A simple decision framework

If your study involves human participants
Determine what ethical review, exemption, or other research-governance process your institution and jurisdiction require.
If you collect or otherwise process personal data
Identify the applicable data protection framework, purposes, legal basis or bases, safeguards, transparency requirements, retention arrangements, and participant rights.
If both apply
Address them together during study design, but document and obtain any required approvals or reviews separately rather than assuming one process satisfies the other.
If the data plan changes after approval
Check whether the change requires an ethics amendment, privacy review, security assessment, contractual change, participant notification, or another institutional action before implementing it.

Early planning is especially useful because many good practices serve both purposes. Collecting less unnecessary personal information can reduce participant risk and support data minimization. Restricting access can protect confidentiality and improve security. Clear participant information can support meaningful decision-making and transparency. Those common benefits should not obscure the fact that the underlying requirements remain distinct.

Responsibility may also be distributed across several people or organizations. A principal investigator, university, sponsor, collaborator, service provider, ethics committee, privacy office, and data protection officer can have different roles. Before sharing or transferring participant information, researchers should establish who determines how the data are processed and who manages or safeguards them.

For studies involving multiple institutions or countries, resolve these questions before data begin moving between organizations. A collaborator's scientific involvement does not automatically answer whether they may access every participant-level dataset, and international transfers may introduce additional requirements.

07 · A Quick Checklist

Before You Start Processing Participant Data

Before data collection begins, check:
Determine whether the project requires ethics review, approval, exemption, or another research-governance determination.
Identify which data protection law or laws and institutional privacy policies apply to the project.
Document why each category of personal data is needed rather than collecting potentially useful information by default.
Determine the applicable legal basis and, where relevant, any additional condition required for sensitive or special-category data.
Make sure participant information distinguishes research participation from personal-data processing where the applicable framework requires that distinction.
Specify who may access identifiable or pseudonymized data and what each person or organization is permitted to do with them.
Verify storage, security, retention, deletion, sharing, and transfer arrangements with the appropriate institutional office rather than relying solely on the ethics application.
Check whether a privacy or data protection impact assessment, data-sharing agreement, processor agreement, or other documentation is required.
Establish what happens if the protocol, data collected, collaborators, software, storage location, or sharing plan changes during the study.
08 · Frequently Asked Questions

Common Questions About Research Ethics and Data Protection

Does ethics approval mean my study complies with privacy law?

Not automatically. Ethics review and data protection compliance have overlapping concerns but different purposes and requirements. Your institution may require separate privacy, legal, security, or governance checks.

Can a study comply with data protection law and still be unethical?

Yes. Data protection compliance does not resolve every ethical question. A study could process personal data lawfully yet still raise concerns about coercion, participant selection, disproportionate risk, inadequate scientific justification, or other ethical issues.

Can an ethically approved study still violate data protection requirements?

Yes. For example, a project could later process personal data in a way that lacks an appropriate legal basis, collect unnecessary information, use an unapproved storage arrangement, retain identifiable information improperly, or make an unlawful disclosure. Whether a particular action violates the law depends on the applicable jurisdiction and facts.

Is informed consent the same as data protection consent?

Not necessarily. Informed consent to participate in research serves an ethical and sometimes regulatory function, while consent under a data protection law is one possible legal basis for processing personal data and has its own requirements. Some research processing may rely on another lawful basis. The applicable framework must be checked for the particular study.

Does anonymized research data still fall under data protection law?

That depends on whether the data are genuinely anonymous under the applicable legal standard. Pseudonymized or coded data can remain personal data when reidentification is reasonably possible using additional information. Ethical and institutional responsibilities may also continue even when a particular data protection law no longer applies.

Who should I contact about data protection requirements at my institution?

Institutional arrangements differ. Depending on your organization, the appropriate contact may be a data protection officer, privacy office, research governance office, information security team, legal office, or another designated unit. Check local policy rather than assuming that the ethics committee handles every privacy requirement.

Do data protection rules apply only to sensitive research topics?

No. Their application generally depends on whether personal data are being processed and on the relevant law, not simply on whether the research topic appears sensitive. The sensitivity of the information may, however, affect the requirements, risks, and safeguards that apply.

09 · The Bottom Line

Passing One Test Does Not Automatically Mean You Have Passed the Other

The Bottom Line

Research ethics and data protection compliance overlap, but they answer different questions: ethics considers whether research involving people is responsibly designed and conducted, while data protection addresses whether personal data are being processed in accordance with applicable requirements.

Build both into the study from the beginning. Ethics approval should not be treated as blanket privacy clearance, and legal data processing should not be treated as proof that the research itself is ethically acceptable.

10 · Sources and Further Reading

Authoritative Sources on Research Ethics and Data Protection

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes