Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Participants Withdraw Data That Have Already Been Anonymized?

Once research data have been genuinely anonymized so that researchers can no longer identify which records belong to a participant, individual withdrawal may no longer be technically possible. This differs from coded or pseudonymized data that can still be linked back to a person.

136
Withdrawing Anonymized Research Data Guide 136 of 398
01 · The Question

What If the Participant Withdraws After Their Identity Has Been Removed?

A participant contacts the research team and asks for their data to be removed. There is just one problem: the dataset has already been anonymized, and the research team says it can no longer tell which record belongs to that participant.

Does the right to withdraw require researchers to find and delete the record anyway? Or has anonymization created a point after which individual removal is no longer possible?

The answer depends first on what researchers mean by anonymized. Data that are genuinely no longer linkable to an individual create a very different withdrawal problem from data that merely have names replaced with participant codes.

02 · The Short Answer

True Anonymization Can Make Individual Withdrawal Impossible

In Brief

If research data have been genuinely anonymized so that researchers can no longer identify which information belongs to a particular participant, removing that participant's individual data may no longer be technically possible.

Do not assume that coded, pseudonymized, or de-identified data are necessarily anonymous. If researchers can still reconnect a record to the participant, withdrawal may remain technically possible and must be handled according to the consent terms, approved protocol, and applicable ethics, privacy, and regulatory requirements.

03 · What You Need to Know

The First Question Is Whether the Data Are Actually Anonymous

Removing a Name Does Not Necessarily Make Data Anonymous

Research teams sometimes use anonymous, de-identified, coded, and pseudonymized as though they were interchangeable. They are not.

A dataset may display only participant numbers while another file still links those numbers to names. In that situation, the research team or another authorized party may still be able to determine which record belongs to a particular participant.

By contrast, if identifiers and linkage information have been irreversibly removed so that the participant's record can no longer be identified, an individual withdrawal request creates a practical problem: researchers cannot remove a record they cannot locate.

Coded or pseudonymized data Direct identifiers have been replaced, but a code, key, or other mechanism still allows the information to be linked to the participant under specified conditions.
Genuinely anonymized data The information can no longer be linked back to the participant using the means retained or reasonably available under the applicable framework.

The terminology varies among jurisdictions and regulatory frameworks, so researchers should use the definitions applicable to their study rather than relying only on a database label.

Why Anonymization Changes the Withdrawal Question

Withdrawal of identifiable data requires researchers to know which information belongs to the participant. Once that link has genuinely disappeared, the mechanism needed to execute individual removal has disappeared with it.

SACHRP has explicitly recognized this limitation. Its recommendations note that withdrawal would not be feasible once biospecimens or data have already been fully de-identified, and it recommends informing participants of this limitation in advance when de-identification will prevent later withdrawal.

Data status Can the participant's record still be located? Withdrawal implication
Directly identifiable data Yes Individual removal may be technically possible, subject to applicable rules and retention requirements.
Coded data with an accessible linkage key Potentially yes Do not describe withdrawal as impossible merely because names were replaced with codes.
Coded data where researchers cannot access the key Depends on who controls linkage and the applicable framework Determine whether an authorized entity can still identify and act on the participant's record.
Irreversibly anonymized data No Individual withdrawal may no longer be technically possible.
Aggregate results Individual observations may no longer exist as separable records Withdrawal ordinarily cannot mean extracting one person's contribution from the aggregate result.

Common Rule Status and Ethical Commitments Are Not Always the Same Question

Under OHRP's interpretation of the U.S. Common Rule, research using fully de-identified or fully anonymized information does not involve human subjects as defined by that regulatory framework. SACHRP similarly explains that certain coded information may fall outside human-subject research when investigators cannot readily ascertain participants' identities.

That regulatory conclusion does not mean researchers can ignore promises made during consent. SACHRP specifically notes that even when a secondary use of de-identified or coded material is not human-subject research under the Common Rule, researchers and institutions still have an obligation to honor agreements made with participants about how their information or specimens would be used.

Researchers should therefore distinguish “the Common Rule no longer treats this as identifiable human-subject information” from “we are ethically free to disregard everything we promised.”

Anonymization Should Not Be Used to Defeat a Withdrawal Request

Timing matters. Suppose identifiable data remain linkable when a participant asks to withdraw them. Researchers should not simply erase the identifiers immediately and then announce that withdrawal is impossible because the data are now anonymous.

SACHRP has specifically described that strategy as ethically suspect when de-identification is performed in response to a withdrawal request solely to avoid honoring it. If researchers intend from the outset to anonymize withdrawn data and continue using them, SACHRP recommends that this possibility be disclosed during the original consent process, while also cautioning that an IRB should scrutinize such an approach carefully.

Watch Out

“We anonymized it after you asked to withdraw” is very different from “your data had already been irreversibly anonymized before we received your request.” Anonymization should not be used strategically to eliminate a participant's withdrawal option after that option has already been exercised.

The Consent Process Should Explain the Point of No Return

If a study intends to anonymize data permanently, participants should understand what that means for later withdrawal. A statement such as “you may withdraw your data at any time” may be misleading if, after anonymization, the research team will be unable to identify which data belong to them.

SACHRP recommends explaining processes for and limitations to withdrawal when information or specimens will be retained for research. If anonymization will make later withdrawal infeasible, that is a consequential limitation rather than a technical footnote.

A clearer consent process might explain that participants may request withdrawal while information remains linkable, but after irreversible anonymization the researchers may no longer be able to identify and remove an individual's contribution.

Anonymization Is Different From Analysis

Researchers should not confuse two different reasons why withdrawal may become difficult. One concerns identity: the data can no longer be connected to the participant. The other concerns research progression: the data may already have been incorporated into analyses or derived results.

A dataset can remain identifiable even after analysis begins, and a dataset can be anonymized before substantial analysis occurs. The question of whether data can be withdrawn after analysis has begun therefore requires a separate assessment.

FDA-Regulated Trial Data Create a Different Limitation

In an FDA-regulated clinical trial, the inability to remove accrued data does not depend on anonymization. FDA policy requires already-accrued trial data from participants who discontinue participation to remain part of the study data.

Researchers should therefore identify why withdrawal is limited. “We cannot identify your data anymore” and “the regulatory framework requires us to retain the data” are not interchangeable explanations.

Do Not Promise More Control Than the Data Architecture Can Deliver

The withdrawal language in a consent form should reflect the actual data workflow. If a linkage key will be destroyed after quality control, say what that means. If data will remain coded for years, do not describe them as permanently anonymous. If copies will be shared with approved secondary researchers, explain relevant limits on retrieving those copies.

This is one reason the broader question of what happens to data after participant withdrawal should be considered during study design rather than improvised when the first withdrawal occurs.

04 · A Practical Example

When the Link to the Participant Has Already Been Destroyed

Hypothetical Example

A Participant Requests Removal After Irreversible Anonymization

Imagine an observational study in which identifiable survey records are initially stored under participant codes. The approved protocol states that after data cleaning, the linkage file connecting those codes to participant identities will be permanently destroyed. Participants are informed during consent that individual withdrawal will no longer be possible after that stage.

Before anonymization The research team can identify which coded record belongs to each participant using the linkage file.
Anonymization occurs After the approved quality-control process, the linkage file is permanently destroyed and the remaining research dataset cannot be connected back to named participants.
A later request arrives One participant subsequently asks for their individual responses to be removed.
Check whether identification is possible The team confirms that no retained linkage mechanism allows it to determine which anonymous record belongs to that person.
Explain the limitation The researcher explains that individual removal is no longer technically possible because the research team cannot identify the participant's record, consistent with the limitation disclosed during consent.

The limitation is genuine because anonymization occurred according to the approved process before the withdrawal request. The result would be ethically different if the team still had identifiable data when the participant requested withdrawal and anonymized them specifically to avoid acting on the request.

05 · What Researchers Often Get Wrong

Common Mistakes About Withdrawing Anonymized Data

Misconception

If Names Are Removed, Are the Data Automatically Anonymous?

No. A code, linkage key, combination of variables, or other mechanism may still permit the record to be connected to an individual. Researchers should apply the definitions and identifiability standards relevant to their jurisdiction and study.

Misconception

Can Participants Always Withdraw Their Data Because They Can Withdraw From the Study?

No. The right to stop future participation does not guarantee that individually identifiable data can be removed indefinitely. Once genuine anonymization has made a participant's record unidentifiable, individual removal may no longer be possible.

Misconception

Can Researchers Anonymize Data Immediately After a Withdrawal Request and Keep Them?

Researchers should not assume so. SACHRP has characterized de-identification performed solely to circumvent a participant's withdrawal request as ethically suspect, particularly when that consequence was not disclosed during consent.

Misconception

If Anonymous Data Are Not Human-Subject Research Under the Common Rule, Do Consent Promises Stop Mattering?

No. SACHRP distinguishes regulatory status from commitments made to participants. An institution may still have an ethical obligation to honor restrictions it promised even when a later use does not constitute human-subject research under the Common Rule.

Misconception

Is Anonymization the Same as Aggregating Data?

No. Anonymization concerns whether information can be linked to an individual. Aggregation combines observations into summaries or results. Either process can make individual withdrawal difficult, but for different reasons.

06 · What This Means for You

Know Whether You Can Still Find the Participant's Data

When someone asks to withdraw anonymized data, do not answer from the dataset's filename. Trace the actual data architecture and determine whether any retained mechanism can still connect the participant to their information.

A simple decision framework

If the data remain directly identifiable
Individual removal is technically possible, but whether it is permitted or required depends on the applicable research and data-retention framework.
If the data are coded or pseudonymized and can still be linked
Do not claim that withdrawal is technically impossible merely because direct identifiers have been removed.
If the data were genuinely anonymized before the withdrawal request
Individual removal may no longer be possible because the research team cannot identify the participant's contribution.
If identifiable data still exist when the withdrawal request arrives
Do not anonymize them merely to defeat the request. Apply the consent, protocol, ethics, privacy, and regulatory requirements governing withdrawal.
If anonymization will eventually prevent withdrawal
Describe that limitation clearly during the original consent process.
07 · A Quick Checklist

When Someone Asks to Withdraw Anonymized Data

Before saying removal is impossible, check:
Determine what “anonymized” means under the framework applicable to the study.
Check whether a participant code, linkage key, identifier file, or other re-identification mechanism still exists.
Identify who, if anyone, can access that linkage mechanism.
Establish whether anonymization occurred before or after the participant's withdrawal request.
Review what the consent materials told participants about anonymization and limits on later withdrawal.
Distinguish technical impossibility of identifying the record from a regulatory requirement to retain identifiable data.
Check whether the information has also been shared, aggregated, analyzed, or incorporated into other research outputs.
Explain the result to the participant accurately without calling coded data anonymous when they remain linkable.
08 · Frequently Asked Questions

Questions About Withdrawal After Anonymization

Can participants withdraw data after they have been fully anonymized?

Often not on an individual basis if the research team can no longer identify which record belongs to that participant. SACHRP has specifically recognized that withdrawal may no longer be feasible once data or biospecimens have already been fully de-identified.

Are coded data anonymous?

Not necessarily. If a code can still be connected to the participant through a retained key or another mechanism, the data remain linkable even though names and other direct identifiers may not appear in the research dataset.

Can researchers destroy the code key after someone asks to withdraw?

Researchers should not destroy linkage solely to circumvent a withdrawal request. SACHRP has cautioned that deliberately de-identifying identifiable material after a withdrawal request for the purpose of continuing its use is ethically suspect.

Should participants be told that anonymization will prevent later withdrawal?

Yes, when that is how the study will operate. SACHRP recommends informing participants when complete de-identification will make later consent withdrawal infeasible.

What if researchers can identify the participant indirectly?

Then the information may not be genuinely anonymous under the applicable framework. Researchers should assess actual identifiability rather than relying on whether direct identifiers such as names have been removed.

What if the participant's data have already been combined into aggregate statistics?

Individual removal may no longer be meaningful or technically straightforward once the person's contribution exists only within an aggregate or derived result. The stage of analysis and governing research requirements should be considered separately from anonymization.

09 · The Bottom Line

You Cannot Remove a Record You Can No Longer Identify

The Bottom Line

Once research data have been genuinely and irreversibly anonymized so that the participant's record can no longer be identified, individual withdrawal may no longer be technically possible.

Before reaching that conclusion, verify that the data are truly unlinked rather than merely coded or pseudonymized. Researchers should disclose foreseeable limits on withdrawal before anonymization occurs and should not anonymize still-identifiable data after a withdrawal request merely to avoid honoring that request.

10 · Sources and Further Reading

Authoritative Guidance and Further Reading

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes