03 · What You Need to Know
Access Should Follow Function, Not Convenience
Start With What Each Role Actually Needs to Do
Access control becomes easier when researchers stop asking, "Who is on the project?" and instead ask, "What information does this person need for this task?"
A staff member recruiting participants may need names and contact details. Someone analysing coded survey responses may have no analytical reason to see those identifiers. A researcher conducting participant interviews will ordinarily know whom they are interviewing, while a statistician working later in the project may need only the study variables and a non-identifying study code.
This is an application of the broader principle of data minimisation: exposure to personal information should be limited to what is necessary for the relevant purpose. The ICO's research guidance identifies data minimisation and pseudonymisation among the safeguards applicable to research-related processing under the UK GDPR framework.
The precise legal requirements vary by jurisdiction, but function-based access is a useful research-governance principle even where that framework does not apply.
The Principal Investigator Does Not Automatically Need Every Identifier at Every Stage
The principal investigator is responsible for the study, but responsibility and routine access are not identical.
In some projects, the principal investigator legitimately needs identifiable information for participant communication, safety procedures, withdrawal requests, data linkage, or other study functions. In others, those functions may be delegated to authorised staff while the principal investigator works primarily with coded information.
The question is therefore not whether a particular job title deserves access. It is whether the person's responsibilities require the information and whether the access is consistent with the protocol, participant information, applicable agreements, institutional requirements, and law.
Research Assistants Should Not Receive Identifiers Merely Because They Are Research Assistants
Research assistants often perform highly varied tasks. One may recruit participants and therefore need contact information. Another may clean quantitative data and need no identities at all. A third may transcribe interviews containing inherently identifying narratives.
Treating all research assistants as one access category can therefore expose more information than necessary.
Where systems permit it, role-based access can separate functions. A recruitment assistant might access the contact list without the full analysis dataset, while a data analyst receives coded research records without names or contact details.
Analysts Often Do Not Need Direct Identifiers
Statistical analysis rarely requires a participant's name, email address, telephone number, or mailing address merely because those identifiers were collected elsewhere in the study.
If analysts need to connect observations across time or datasets, a study code may often serve that function. The code may preserve authorised linkage while reducing routine exposure of direct identifiers.
This is one reason researchers may separate participant identifiers from research data before routine analysis begins.
However, coded data are not necessarily anonymous. Under OHRP guidance for the US Common Rule, private information can remain individually identifiable when investigators can link it to specific people directly or indirectly through coding systems. The regulatory consequences depend on whether investigators can readily ascertain identities and on the circumstances of the research.
The Person Holding the Code Key Has a Different Access Function
A linkage key can reconnect coded research records to participant identities. Access to it therefore deserves particular attention.
Researchers may designate one person or a restricted group to maintain the key. The appropriate choice depends on why re-identification is needed. Someone responsible for longitudinal follow-up, participant withdrawal, safety procedures, or record linkage may need authorised access. Routine analysts may not.
The important point is not that one specific job title must always hold the key. It is that contact and linkage information can be separated from research responses and access granted according to purpose.
Collaborators Should Receive the Minimum Information Their Work Requires
Multi-institutional research creates another access question. A collaborator's legitimate involvement in a project does not automatically establish a need for participant identities.
If a collaborating team needs only to analyse outcomes, a coded, pseudonymized, de-identified, aggregated, or otherwise appropriately prepared dataset may be sufficient, depending on the study and governing requirements.
If collaborators genuinely need identifiable information, researchers should establish the basis for that access and address the relevant ethics approvals, institutional arrangements, data-sharing terms, security requirements, participant information, and applicable law.
OHRP guidance also illustrates why these relationships matter under the US Common Rule. It distinguishes circumstances in which investigators receive coded private information without the ability to readily ascertain identities from situations in which investigators can link information to individuals.
Service Providers Can Encounter Identifiable Research Information Too
Research information may pass through people or organisations that are not conventional members of the academic research team.
Examples include transcription services, survey platforms, cloud-storage providers, laboratories, data-management centres, technology vendors, and specialist consultants. Whether these parties can access identifiable information depends on the service and technical architecture.
Researchers should therefore map actual data access rather than listing only named investigators. If a transcription provider receives identifiable audio recordings, for example, the confidentiality analysis should account for that access even if the provider never appears as an author on the eventual paper.
Applicable contractual, institutional, data-protection, and security requirements should be checked before identifiable information is provided to external services.
Oversight Access Is Different From Routine Research Access
Some people may legitimately inspect identifiable information without using it to answer the research question.
Depending on the study and jurisdiction, authorised ethics bodies, institutional officials, sponsors, monitors, auditors, regulatory authorities, or other oversight entities may need access for compliance, safety, auditing, or verification.
OHRP's guidance on institutional engagement, for example, recognises circumstances in which identifiable private information may be accessed for study auditing or FDA reporting purposes. Such access serves a different function from ordinary research analysis.
This is one reason participant information should avoid simplistic statements such as "only the researchers will ever see your information" unless that statement is actually true under the study's oversight arrangements.
Access Should Be Limited by Both People and Data
Access control is not merely a list of authorised names. It can also determine what each authorised person can see.
| Role |
Information That May Be Needed |
Information That May Not Be Needed |
| Recruitment coordinator |
Names, eligibility information, contact details |
Complete analytical dataset, unless required for another authorised role |
| Interviewer |
Participant identity and interview information needed for the session |
Unrelated participant records |
| Data analyst |
Research variables and study codes needed for analysis |
Names and contact details when identity is analytically irrelevant |
| Linkage manager |
Study codes and information required to perform authorised linkage |
Unrelated research variables when not required for linkage |
| External collaborator |
Data necessary for the agreed research task |
Direct identifiers when the collaboration can proceed without them |
| Authorised auditor or monitor |
Information necessary for the specific oversight function |
Unrestricted access beyond the scope of that function |
These are illustrative arrangements rather than universal rules. A particular study may require different access because of its methodology, safety requirements, regulatory obligations, or organisational structure.
Access to Identifiable Information Should Not Be Permanent by Default
A person may need identifiable information during one stage of a study but not another.
Recruitment staff may need participant contact details while enrolment is open. A longitudinal coordinator may need them through the final follow-up. Once those functions end, continued access may no longer be necessary even if the information must still be retained under an approved retention policy.
Access should therefore have a lifecycle. Researchers can review permissions when personnel change roles, leave the project, complete their assigned tasks, or when the study moves into a new phase.
Shared Accounts Undermine Meaningful Access Control
Limiting access on paper is of little value if an entire research group uses the same account, password, shared drive permission, or unrestricted spreadsheet.
Where systems permit it, individual accounts and role-appropriate permissions can make access restrictions enforceable and auditable. They can also help determine who accessed or changed information when audit logging is available.
The appropriate technical controls depend on the institution, data sensitivity, study risk, and applicable requirements. Researchers should follow approved institutional systems rather than inventing their own security architecture from whatever cloud folder happens to be nearby.
Access Controls Do Not Replace Other Confidentiality Safeguards
Restricting access is only one layer of confidentiality protection. Appropriate safeguards may also include data minimisation, pseudonymization, secure transfer, encryption where required, controlled devices or environments, confidentiality agreements, staff training, retention controls, and procedures for responding to incidents.
Likewise, legal protections such as US Certificates of Confidentiality address particular forms of compelled disclosure but do not prevent every intentional or accidental confidentiality breach. OHRP guidance explicitly notes that other mechanisms remain necessary to protect identifiable private information.
Watch Out
Do not promise that identifiable information will be accessible "only to the research team" unless you have checked the actual study arrangements. Service providers, authorised monitors, regulators, auditors, institutional officials, or other parties may have legitimate access in particular studies, and applicable law may create additional disclosure circumstances.