01 · The Question
If Your Study Has Ethics Approval, Is Your Data Protection Covered?
You have ethics approval. Your participants signed the consent form. The protocol explains how confidentiality will be protected. Does that mean the study also complies with applicable data protection law?
Not necessarily. Research ethics and data protection frequently meet at the same practical issues, including consent, privacy, confidentiality, data collection, sharing, retention, and security. But they are not simply two names for the same set of requirements.
This distinction matters because a study can raise a data protection problem even when its overall research design is ethically acceptable. The reverse is also possible: technically lawful processing of personal data does not, by itself, establish that a study is ethically justified.
03 · What You Need to Know
Why the Two Systems Ask Different Questions
Research ethics is concerned with how people are treated through research
Research ethics provides principles for deciding whether research involving people can be justified and how participants should be treated. The Belmont Report, for example, organizes human-subject research ethics around respect for persons, beneficence, and justice. These principles inform questions about voluntary participation, informed consent, risk and benefit, participant selection, privacy, confidentiality, and protections for people who may be vulnerable to coercion or undue influence.
In medical research, the World Medical Association's Declaration of Helsinki similarly addresses participant rights and interests, scientific rigor, risk and burden, informed consent, privacy and confidentiality, vulnerable individuals and groups, and independent ethics review. Its 2024 version explicitly applies to medical research involving human participants, including research using identifiable human material or data.
Ethical assessment therefore extends well beyond what happens to a dataset. A study could use excellent encryption and collect very little personal information yet still be ethically problematic because, for example, participants are exposed to unjustified risk, recruitment is coercive, the participant population is unfairly selected, or the research lacks sufficient scientific value to justify its burdens.
Data protection focuses specifically on the processing of personal data
Data protection law is narrower in subject matter but often much more specific about what happens to personal data. Depending on the jurisdiction, it may regulate collection, recording, organization, use, disclosure, storage, transfer, retention, deletion, and other forms of processing.
Under the EU General Data Protection Regulation (GDPR), for example, organizations processing personal data must address principles including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Processing also requires an appropriate legal basis. Additional conditions may apply to particular categories of data.
Other jurisdictions use different statutory structures and terminology. In the Philippines, for example, the Data Privacy Act of 2012 regulates the processing of personal information and establishes obligations concerning privacy and the protection of personal data. Its implementing rules also contain provisions relevant to scientific and statistical research. Researchers should therefore determine which law actually applies rather than assuming that a familiar framework such as the GDPR governs every project.
Jurisdiction Matters
There is no single worldwide data protection rulebook for research. Applicable requirements can depend on where participants are located, where data are processed, which organizations are involved, and the reach of the relevant law. Institutional policies, contracts, funder requirements, and sector-specific rules may add further obligations.
The easiest way to distinguish them is by the question being asked
| Issue |
Research ethics may ask |
Data protection may ask |
| Collecting participant information |
Is collecting this information ethically justified, and are the burdens or risks reasonable? |
Is there a valid basis for processing it, is the purpose sufficiently defined, and is the information necessary? |
| Consent |
Is participation genuinely informed and voluntary? |
If consent is being relied upon for data processing, does it satisfy the applicable legal requirements? If another legal basis applies, have the relevant requirements still been met? |
| Privacy and confidentiality |
Are participants' privacy interests respected and foreseeable harms appropriately minimized? |
Are appropriate legal, organizational, and technical safeguards applied to personal data? |
| Data collection |
Is asking for the information justified by the study and proportionate to its aims? |
Are the personal data adequate, relevant, and limited to what is necessary under applicable rules? |
| Sharing data |
Is the proposed sharing consistent with what participants were told and with the ethical commitments made to them? |
Is the disclosure or transfer lawful, appropriately governed, secure, and consistent with the stated purpose and applicable rights? |
| Overall study design |
Are the risks, benefits, recruitment, participant selection, scientific design, and treatment of participants ethically acceptable? |
Does the study's processing of personal data satisfy applicable data protection requirements? |
The exact questions differ across ethical frameworks and legal systems, but the distinction is useful: ethics evaluates the responsibilities created by conducting research involving people, whereas data protection concentrates on responsibilities created by processing personal data.
Privacy and confidentiality belong to both conversations
The boundary is not clean because data practices can themselves create ethical risks. Disclosure of a participant's health condition, political views, immigration status, or other sensitive information might cause stigma, discrimination, embarrassment, financial loss, or other harm. Protecting personal information can therefore be both an ethical obligation and a legal one.
This is why research ethics frameworks explicitly address privacy and confidentiality. The Declaration of Helsinki requires precautions to protect participant privacy and the confidentiality of personal information. U.S. human-subject protections likewise include consideration of privacy and confidentiality where appropriate.
Data protection requirements approach some of the same risks through concepts such as purpose limitation, security, accountability, retention, and limiting personal data to what the research actually requires. The practical safeguards may overlap even though the underlying frameworks are not identical.
Ethics approval is not a legal compliance certificate
A research ethics committee or institutional review board evaluates matters within its remit. Depending on the institution and jurisdiction, its review may include detailed examination of data handling, or another office such as a data protection officer, privacy office, information security team, legal office, or research governance unit may have separate responsibilities.
An ethics committee's approval therefore should not be interpreted more broadly than the approval actually says. Researchers may still need to establish the applicable legal basis for processing, provide required privacy information, complete a privacy or data protection impact assessment when required, document responsibilities, implement security controls, establish appropriate arrangements with collaborators or service providers, and comply with rules governing transfers or breaches.
The reverse inference is equally unsafe. A project can satisfy data protection requirements while still raising ethical concerns unrelated to data protection. A legally permissible dataset does not answer whether recruitment is fair, risks are justified, participants are unduly influenced, or the study itself is ethically defensible.
Consent is one place where the distinction becomes especially important
A participant may be asked to agree to take part in research, and the project may also need to establish how personal data can lawfully be processed. These questions can interact, but they should not automatically be collapsed into one concept.
European data protection guidance explicitly distinguishes consent used as a legal basis for processing personal data from consent requirements that arise as an ethical standard or procedural obligation. A research project may, depending on the applicable law and circumstances, process personal data on a lawful basis other than data protection consent even though informed consent to research participation is still ethically or institutionally required.
That is why researchers should distinguish agreement to participate from permission or another legal basis for processing personal data rather than assuming that one signature automatically resolves both questions.
Data protection obligations can continue long after recruitment
Ethics is not confined to recruitment either, but researchers sometimes encounter data protection questions most visibly after participants have already enrolled. Who can access the dataset? Where will it be stored? How long will identifiers be retained? Can another institution receive a copy? What happens when a cloud provider is used? What if a laptop containing participant information is stolen?
These are not administrative details to postpone until data collection has finished. They form part of responsible research planning. Clarifying who is responsible for protecting personal research data early can prevent the familiar situation in which everyone on a collaboration assumes someone else has handled privacy compliance.
De-identification does not always remove the issue
Removing names from a spreadsheet does not automatically make data anonymous. A coded or pseudonymized dataset may still be personal data when an individual can be reidentified using additional information available to the relevant party. Whether information is legally anonymous depends on the applicable framework and the circumstances.
This matters because researchers may reduce privacy risks substantially through de-identification while still remaining subject to data protection requirements. Ethical duties may also persist even where information falls outside a particular data protection law. The correct question is not simply, "Did I delete the names?" but whether individuals remain identifiable and what obligations still apply.
04 · A Practical Example
One Study, Two Different Reviews
Hypothetical Example
A university survey about student mental health
A research team plans an online survey examining student mental health and academic experiences. Participants will provide demographic information and responses about psychological well-being. Email addresses will be collected separately for participants who want to enter a prize draw.
Ethics question
The team considers whether the questions could cause distress, whether recruitment creates pressure to participate, whether incentives are appropriate, whether potentially vulnerable participants need additional protections, what support information should be provided, and whether the expected knowledge justifies the burdens and risks.
Data protection question
The team determines which information constitutes personal data, why each variable is necessary, what legal basis and any additional conditions apply, what privacy information must be provided, who can access the data, where it will be stored, how identifiers will be separated, and when identifiable information will be deleted or anonymized.
Overlap
Both reviews may examine confidentiality, unnecessary collection, access controls, disclosure risks, and what participants are told about their information.
Result
Approval from the ethics committee addresses the ethical review process, but the team still needs to satisfy any separate data protection and institutional requirements that apply to the processing.
Suppose the ethics committee approves the study, but the research team later decides to upload identifiable responses to a commercial platform that was never assessed or described in the approved data-management arrangements. The existence of ethics approval would not automatically make that new processing arrangement compliant. The team would need to examine the platform, contractual arrangements, security, access, location of processing, applicable transfer rules, and institutional requirements before proceeding.
Conversely, suppose every technical and legal data protection requirement is satisfied, but students are recruited by an instructor who strongly implies that participation will improve their standing in the course. Good data security would not resolve the ethical concern about voluntariness and undue influence.
06 · What This Means for You
Treat Ethics and Data Protection as Parallel Requirements
When a study involves personal data, do not ask only whether you have ethics approval. Ask separately whether you have identified and satisfied the data protection requirements that apply to the project.
A simple decision framework
If your study involves human participants
Determine what ethical review, exemption, or other research-governance process your institution and jurisdiction require.
If you collect or otherwise process personal data
Identify the applicable data protection framework, purposes, legal basis or bases, safeguards, transparency requirements, retention arrangements, and participant rights.
If both apply
Address them together during study design, but document and obtain any required approvals or reviews separately rather than assuming one process satisfies the other.
If the data plan changes after approval
Check whether the change requires an ethics amendment, privacy review, security assessment, contractual change, participant notification, or another institutional action before implementing it.
Early planning is especially useful because many good practices serve both purposes. Collecting less unnecessary personal information can reduce participant risk and support data minimization. Restricting access can protect confidentiality and improve security. Clear participant information can support meaningful decision-making and transparency. Those common benefits should not obscure the fact that the underlying requirements remain distinct.
Responsibility may also be distributed across several people or organizations. A principal investigator, university, sponsor, collaborator, service provider, ethics committee, privacy office, and data protection officer can have different roles. Before sharing or transferring participant information, researchers should establish who determines how the data are processed and who manages or safeguards them.
For studies involving multiple institutions or countries, resolve these questions before data begin moving between organizations. A collaborator's scientific involvement does not automatically answer whether they may access every participant-level dataset, and international transfers may introduce additional requirements.
07 · A Quick Checklist
Before You Start Processing Participant Data
Before data collection begins, check:
Determine whether the project requires ethics review, approval, exemption, or another research-governance determination.
Identify which data protection law or laws and institutional privacy policies apply to the project.
Document why each category of personal data is needed rather than collecting potentially useful information by default.
Determine the applicable legal basis and, where relevant, any additional condition required for sensitive or special-category data.
Make sure participant information distinguishes research participation from personal-data processing where the applicable framework requires that distinction.
Specify who may access identifiable or pseudonymized data and what each person or organization is permitted to do with them.
Verify storage, security, retention, deletion, sharing, and transfer arrangements with the appropriate institutional office rather than relying solely on the ethics application.
Check whether a privacy or data protection impact assessment, data-sharing agreement, processor agreement, or other documentation is required.
Establish what happens if the protocol, data collected, collaborators, software, storage location, or sharing plan changes during the study.