Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Research Data Be Sent by Email?

Email can be used for some research data transfers, but ordinary email attachments can create avoidable disclosure and security risks. The appropriate method depends on the data, recipient, encryption, institutional policy, and available secure alternatives.

315
Sending Research Data by Email Guide 315 of 398
01 · The Question

Can You Just Attach the Dataset and Click Send?

A collaborator asks for the latest dataset. It is only one spreadsheet, so attaching it to an email seems much easier than setting up another transfer system.

Then comes the uncomfortable part. The spreadsheet contains participant-level information. Perhaps the data are pseudonymized. Perhaps they include names, contact details, interview transcripts, health information, or other sensitive material.

Email is not automatically prohibited for research data, but sending participant information as an ordinary attachment can create risks involving interception, incorrect recipients, compromised accounts, uncontrolled copies, forwarding, retention, and inadequate encryption. The correct question is not simply whether email works, but whether it provides an appropriate transfer mechanism for the particular data.

02 · The Short Answer

Email May Be Appropriate, but the Data Need Appropriate Protection

In Brief

Research data can sometimes be sent by email when institutional policy permits it and the transmission provides safeguards appropriate to the sensitivity of the information, but sensitive or identifiable participant data should not simply be attached to an ordinary unprotected email.

Depending on the data and institutional requirements, appropriate protection may involve encrypted email, an encrypted attachment with the password communicated separately, or preferably an approved secure file-transfer or authenticated sharing service that avoids placing the dataset directly in multiple email accounts.

03 · What You Need to Know

Email Creates More Than One Kind of Data-Transfer Risk

Email is a transfer mechanism, not a research data repository

Email was designed primarily for communication. It can move files conveniently, but convenience should not be confused with controlled research data management.

When a dataset is attached to an email, copies may remain in the sender's mailbox, the recipient's mailbox, sent folders, synchronized devices, server backups, archives, and potentially forwarded messages. Researchers may lose practical control over where the attachment exists.

If the purpose is ongoing collaborative access rather than a one-time message, an approved research storage or sharing environment may provide more appropriate access control, version management, logging, revocation, and retention.

The wrong recipient is one of the simplest ways to disclose data

Encryption discussions can make email security sound highly technical, but one of the most ordinary risks is typing or selecting the wrong address.

The UK Information Commissioner's Office identifies sending personal information to the wrong recipient as a common disclosure scenario. The Philippine National Privacy Commission has similarly warned that human errors involving email, including inappropriate use of the CC function, have resulted in unintended exposure of personal information.

Autocomplete makes this particularly easy when people have similar names or addresses. Distribution lists and reply-all chains can expand the number of recipients further.

Before sending participant information, verify the recipients rather than relying solely on autocomplete. Where the message is going to multiple people, check whether every recipient actually needs the data.

CC and BCC can create their own privacy problem

The data at risk may not even be in the attachment. Email addresses themselves can constitute personal information.

The Philippine National Privacy Commission specifically warns that using CC exposes each recipient's email address to all other recipients and can unintentionally disclose personal, sensitive, confidential, or restricted information contained in the email or its attachments.

If researchers communicate with groups of participants by email, they should consider whether recipients are supposed to know one another's identities or addresses. BCC or an appropriate mailing system may be required where addresses should not be mutually visible, subject to institutional procedures.

Encryption can protect the contents during transfer and storage

Encryption can make email content or attachments unreadable to people who do not possess the necessary key or credentials.

The Philippine National Privacy Commission advises organizations transferring personal data by email to ensure that the information is encrypted or to use a secure email facility that facilitates encryption. Its work-from-home guidance specifically recommends encrypting files and attachments when sensitive data are transferred by email.

For Philippine government agencies, NPC Circular 16-01 expressly requires personal data transferred by email either to be encrypted or sent using a secure email facility that facilitates encryption of the data and attachments.

ICO guidance likewise identifies encryption of email content and attachments as an important control, especially when sensitive personal information is involved.

An encrypted attachment can be useful, but password handling matters

One common approach is to encrypt a file before attaching it to an ordinary email. The recipient then needs a password or cryptographic key to open it.

Sending the password in the same message largely defeats the point if an unintended recipient receives both. ICO guidance recommends communicating the key through a separate channel to obtain the strongest benefit from encrypted attachments. Philippine government guidance similarly states that passwords should be sent separately.

The separate channel might be an approved messaging system, telephone call, or another institutionally authorized method, depending on the organization's security procedures.

Watch Out

Encryption does not fix an incorrect recipient if that recipient also receives the password or otherwise has the ability to decrypt the attachment. Recipient verification remains necessary even when files are encrypted.

Transport encryption and attachment encryption are not identical

Modern email systems often encrypt connections between devices and servers or between mail servers. That protects information while it travels across particular parts of the network, but it does not necessarily mean that only the intended human recipient can access the message after delivery.

An encrypted attachment provides a different layer of protection because the file itself remains encrypted unless opened with the appropriate credentials.

Researchers should follow the encryption method approved by their institution rather than assuming that seeing a padlock icon somewhere in the email interface answers every security question.

A secure link may be preferable to an attachment

Instead of sending the dataset itself, some institutional systems allow researchers to send an authenticated link to an approved storage or file-transfer environment.

This can provide practical advantages. Access may expire, permissions can sometimes be revoked, authentication can be required, large files need not be duplicated across mailboxes, and the authoritative copy can remain within an approved environment.

The Philippine National Privacy Commission's data-security guidance recommends identity authentication when online links are used to provide access to personal data.

A secure link is not automatically safe merely because it begins with HTTPS. The underlying storage, access permissions, recipient authentication, provider, expiration settings, and institutional approval still matter.

Send only what the recipient actually needs

If a statistician needs selected pseudonymized variables, do not email the entire identifiable master dataset simply because it is easier than making an export.

Apply data minimization before the transfer. Remove unnecessary variables, identifiers, records, and supporting files. If direct identifiers are not required, keep them out of the transfer.

The same reasoning applies to recipients. Before sending participant-level information to a collaborator, determine whether that collaborator is actually authorized to receive the data.

Verify what the recipient will do with the attachment

Sending a file securely is only half of the transfer. What happens after receipt?

Will the recipient download the attachment to a personal computer? Forward it to another team member? Upload it to a different cloud service? Leave it indefinitely in the mailbox? Use a personal email application that synchronizes attachments to multiple devices?

Where research data are shared under an agreement or defined collaboration, the recipient's storage, access, onward sharing, retention, and deletion arrangements should be consistent with that authorization.

Email creates retention issues

Attachments can survive long after the research team believes a working copy has been deleted. Email archives and backups may be subject to organizational retention systems outside the researcher's direct control.

This does not necessarily mean email can never be used. It means the research team should understand whether sending the data by email creates additional copies that conflict with the project's retention, minimization, contractual, or data-management requirements.

Highly sensitive datasets may warrant a different transfer method

The more serious the potential consequences of unauthorized disclosure, the stronger the justification should be for the chosen transfer method.

Identifiable health data, genetic information, detailed financial information, highly sensitive interview material, reidentification keys, credentials, or large identifiable datasets may be inappropriate for ordinary email even where less sensitive information can legitimately be sent that way.

Use the transfer mechanism approved for the project's data classification. If the appropriate method is unclear, ask the institutional privacy, information-security, research IT, or data-governance office before sending the file.

Using email does not eliminate transfer-governance requirements

If data are being sent to another institution or organization, the fact that the technical transfer occurs by email does not determine whether the disclosure itself is authorized.

You may still need to address purpose, recipient role, legal basis, ethics commitments, confidentiality, security, retention, and whether a data-sharing or data-transfer agreement is required.

Email answers only the question of how the bits move. It does not answer whether they should move.

04 · A Practical Example

A Collaborator Requests the Latest Participant Dataset

Hypothetical Example

Sending data for statistical analysis

A researcher at University A needs to provide a collaborator at University B with participant-level data for an agreed statistical analysis. The master dataset contains names, email addresses, demographic variables, and outcome measurements. The collaborator does not need participant identities.

Confirm authorization The research team verifies that University B and the named collaborator are authorized to receive the required participant-level information.
Minimize the dataset Names, email addresses, and variables unrelated to the agreed analysis are removed. Participants are represented using the appropriate study identifiers.
Choose the transfer method Institutional policy provides an approved authenticated file-transfer service. The team uses that system rather than attaching the dataset directly to an ordinary email.
Send notification Email is used to tell the collaborator that the dataset is available and to provide the appropriate access instructions, without placing the participant dataset itself in the mailbox.
Confirm handling The collaborator accesses the dataset under the agreed storage, access, use, and retention arrangements.

If the institution instead permits email transfer for this type of data, the researchers might use an approved encrypted-email system or encrypted attachment. The correct method depends on institutional policy and the risk presented by the particular dataset.

05 · What Researchers Often Get Wrong

Common Mistakes When Emailing Research Data

Misconception

If I Use My University Email, Is Every Attachment Automatically Secure?

No. An institutional account may provide important organizational protections, but the security of a particular transfer also depends on the email system, recipient, encryption, attachment, data sensitivity, and institutional requirements.

Misconception

If I Encrypt the File, Can I Stop Checking the Recipient?

No. Recipient errors still matter, particularly if the unintended recipient also receives the password or otherwise gains access. Always verify addresses and recipients before sending.

Misconception

Can I Put the Password in the Same Email?

That weakens the protection considerably if the email reaches the wrong person or account. Where encrypted attachments are used, follow institutional guidance for communicating credentials separately.

Misconception

Does Pseudonymization Mean the Dataset Is Safe to Email Normally?

Not automatically. Pseudonymized information can remain personal data. Its appropriate transfer method depends on the residual identification risk, sensitivity, institutional requirements, and other safeguards.

Misconception

If the Recipient Is a Co-Author, Can I Email Them the Full Dataset?

No automatic entitlement follows from authorship. Share only information the recipient is authorized to access and actually needs for the agreed research purpose.

06 · What This Means for You

Decide Whether Email Is the Right Transfer Tool Before Attaching the File

A simple decision framework

If the information is public or genuinely anonymous
Ordinary email may be acceptable, subject to confidentiality, intellectual-property, contractual, and institutional requirements.
If the file contains personal or confidential research data
Check whether email is permitted and what encryption or secure-transfer controls are required.
If an approved secure file-sharing or transfer system is available
Consider using it instead of creating persistent attachment copies in multiple mailboxes.
If encrypted attachments are permitted
Use approved encryption and communicate the password or key through a separate authorized channel.
If the dataset is highly sensitive or the transfer arrangement is unclear
Confirm the approved method with the relevant institutional privacy, security, research IT, or governance office before sending it.

Also distinguish the security of the transfer from the account being used. Even where email itself is an acceptable channel, using a personal email account for research data raises additional governance and control questions.

07 · A Quick Checklist

Before Sending Research Data by Email

Check:
Email is an institutionally permitted transfer method for the type of research data involved.
Every recipient is authorized to receive the information and actually needs it.
The recipient addresses, CC, and BCC fields have been checked carefully before sending.
Only the records and variables required for the transfer are included.
Required encryption is applied to the message, attachment, or approved transfer environment.
Any attachment password or encryption key is communicated through a separate approved channel where required.
A secure authenticated link or institutional transfer service has been considered where it would provide better control than an attachment.
The transfer is consistent with applicable ethics approval, participant information, agreements, institutional policy, and data protection requirements.
08 · Frequently Asked Questions

Common Questions About Emailing Research Data

Can I email a research dataset to a collaborator?

Possibly, but first confirm that the collaborator is authorized to receive it and that email is an approved transfer method for the data involved. Sensitive or identifiable datasets may require encryption or an approved secure transfer service.

Should research data attachments be encrypted?

Where personal or sensitive information is transferred by email, authoritative privacy guidance supports appropriate encryption. The precise requirements depend on the applicable law, institution, email system, and data sensitivity.

Can I send the password in another email?

A genuinely separate communication channel generally provides stronger protection than sending the encrypted attachment and password through the same email account. Follow your institution's approved procedure for exchanging encryption credentials.

Is sending a secure link better than an attachment?

It can be. An approved authenticated sharing service may allow access to expire or be revoked and can avoid leaving persistent dataset copies in several mailboxes. The service itself still needs to be appropriate for the research data.

Can I email anonymized research data normally?

If the information is genuinely anonymous under the applicable standard, personal-data requirements may no longer apply to that dataset. Confidentiality, contractual, intellectual-property, research-integrity, or institutional restrictions may nevertheless remain.

What if I accidentally email participant data to the wrong person?

Follow your institution's incident procedure immediately. Do not rely solely on asking the recipient to delete the message. The organization needs to assess what information was disclosed, whether it was accessed, what safeguards were present, and what further action is required.

09 · The Bottom Line

Email the Message, but Think Carefully Before Emailing the Dataset

The Bottom Line

Research data can sometimes be sent by email, but identifiable or sensitive participant information should be transferred only through an institutionally permitted method with safeguards appropriate to the data and recipients.

Verify the recipient, minimize the dataset, use required encryption, protect credentials separately, and consider whether an approved secure sharing service gives you better control than an attachment. The easiest way to avoid an email disclosure is often not to put the dataset in the email at all.

10 · Sources and Further Reading

Authoritative Sources on Email and Personal Data Security

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes