03 · What You Need to Know
How to Respond to Accidental Pre-Approval Data Collection
First, Stop the Unapproved Activity
Once you discover that covered research activity began before the required approval, do not allow the same activity to continue simply because some data have already been collected.
Disable the survey link if necessary. Pause interviews. Stop research-specific record extraction. Tell research staff not to enroll or collect further information from participants until the appropriate institutional authority advises that the research may proceed.
The immediate objective is to prevent an isolated error from becoming a continuing practice.
Protect Participants Before Solving the Administrative Problem
If stopping an activity would itself create an immediate hazard to participants, participant safety comes first. Research regulations recognize narrow circumstances in which changes can be implemented without prior IRB approval when necessary to eliminate apparent immediate hazards to human subjects.
That exception should not be stretched into a general permission to continue unapproved research. It addresses protection from immediate hazards, not project convenience.
If participants may require clinical follow-up, safety monitoring, support, or another protective response because of what has already occurred, contact the appropriate institutional and clinical authorities promptly.
Do Not Delete the Evidence of What Happened
Researchers sometimes react to accidental early data collection by immediately deleting the responses. The instinct is understandable: if the data disappear, perhaps the problem disappears too.
That can make matters worse. The institution may need to determine what information was collected, how many participants were involved, whether anyone was exposed to risk, whether consent was obtained, whether confidentiality was compromised, and whether the data can or cannot be retained or used.
Deleting records before obtaining instructions can destroy information needed to reconstruct the incident.
Watch Out
Do not destroy, modify, backdate, relabel, or selectively remove research records merely to make the incident disappear. Secure the information against further unauthorized use and ask the appropriate institutional authority what should happen to it.
Preserving the Data Does Not Mean You Are Allowed to Analyze Them
There is an important distinction between retaining information temporarily so the incident can be assessed and using that information as research data.
Preserving records
Maintaining an accurate and secure record of what occurred while the institution evaluates the incident.
Using data for research
Analyzing, combining, reporting, publishing, or otherwise using the information to answer the study's research question.
The first may be necessary for compliance assessment. It does not automatically authorize the second.
Document Exactly What Happened
Create a factual chronology while events are still clear. Avoid defensiveness and speculation. Record what happened, when it happened, how it was discovered, and what immediate action was taken.
Useful information can include:
- the date and time the unapproved activity began and stopped;
- how many people were approached, screened, enrolled, or otherwise involved;
- what information, specimens, measurements, or recordings were obtained;
- whether participants received a consent process and which version was used;
- whether any intervention or research procedure occurred;
- whether the data contain direct or indirect identifiers;
- whether any information was accessed, shared, analyzed, downloaded, or disclosed;
- what risks or harms may have arisen;
- how the error occurred;
- what was done immediately after discovery.
OHRP's incident-reporting guidance similarly expects reports of noncompliance to include a detailed description of the incident and the corrective actions the institution has taken or plans to take.
Report Through the Institution's Actual Process
The investigator should contact the REC, IRB, research-compliance office, Human Research Protection Program, research office, or other body designated by institutional policy.
Do not assume that telling a thesis adviser, department chair, collaborator, or sponsor is equivalent to reporting to the authority responsible for research ethics. Those people may also need to know, but institutional procedures determine who receives and evaluates the incident.
Under HHS requirements, institutions conducting covered research must maintain procedures for prompt reporting of serious or continuing noncompliance, unanticipated problems involving risks to participants or others, and suspensions or terminations of IRB approval.
Is Accidental Early Data Collection a Protocol Deviation?
Terminology varies among institutions. Terms such as protocol deviation, protocol violation, noncompliance, and incident can be defined differently.
U.S. advisory guidance describes protocol deviations broadly as departures from procedures specified in an IRB-approved protocol and notes that deviations can be intentional or unintentional. It also emphasizes institutional variation in how deviations are classified and reviewed.
When data collection begins before initial approval exists, however, there may be no approved protocol from which to “deviate.” The institution may instead characterize the activity as unapproved human-subject research or another form of noncompliance. Let the responsible institutional authority apply its terminology rather than choosing the least alarming label yourself.
Not Every Mistake Has the Same Seriousness
Accidentally receiving one response to a minimal-risk questionnaire is not factually identical to enrolling multiple participants into an unapproved invasive intervention. Institutions should consider the circumstances rather than treating every incident as interchangeable.
Relevant factors can include the number of participants, nature and sensitivity of information, physical or nonphysical risks, whether participants were properly informed, whether vulnerable populations were involved, whether the activity was intentional, whether similar problems have happened before, and whether anyone experienced harm.
Under HHS oversight, serious or continuing noncompliance and unanticipated problems involving risks to subjects or others have specific reporting implications. Institutions and IRBs evaluate incidents against those standards.
An Error Does Not Automatically Mean an Unanticipated Problem
The terms should not be collapsed. OHRP generally considers an unanticipated problem involving risks to subjects or others to involve an event that is unexpected, related or possibly related to the research, and suggests greater risk of harm than was previously known or recognized.
An incident can therefore constitute noncompliance without necessarily satisfying all criteria for an unanticipated problem. The IRB or institution determines which reporting categories apply.
Do Not Decide for Yourself That the Incident Is Too Minor to Report
Institutions differ in what investigators must report and on what timetable. Some distinguish minor deviations from reportable noncompliance; others require investigators to report specified categories through formal systems.
If data collection occurred before required initial approval, guessing that “it was only three responses” is a poor substitute for checking the institution's policy. Contact the appropriate office and let it determine the required reporting and corrective process.
Do Not Backdate Consent or Approval Documents
Research records should reflect what actually happened. Changing a date so that consent appears to have occurred after approval, or presenting a later approval letter as though it existed earlier, would obscure rather than correct the incident.
Accurate chronology is essential for determining participant protections, compliance, data status, and any corrective action.
Later Ethics Approval Does Not Automatically Validate Earlier Data Collection
An REC or IRB may subsequently approve the protocol for prospective research. That does not mean the earlier unapproved activity automatically becomes approved retroactively.
The ethics body or institution may need to decide separately whether previously collected information can be retained, analyzed, or otherwise used. That decision can depend on the applicable regulatory framework, consent, risk, institutional policy, and what occurred during the unapproved period.
This is why retrospective ethics approval should not be treated as the default solution.
Do Not Assume the Data Must Automatically Be Destroyed Either
The opposite automatic reaction can also be problematic. Whether information must be destroyed, retained for compliance documentation, returned, isolated, or potentially used under specified conditions is not a decision researchers should improvise.
There can be legal, institutional, sponsor, safety, scientific-integrity, and participant-welfare considerations. Preserve the status quo as safely as possible and obtain instructions.
Data Security Still Matters During the Investigation
While the incident is being assessed, protect the information already obtained. Restrict access, preserve audit trails where available, prevent unnecessary copying, and avoid sharing or analyzing the data beyond what is necessary to address the incident.
If the mistake involved a confidentiality or security breach, additional institutional privacy or data-protection reporting may also be required.
Participants May Need to Be Informed, but Do Not Improvise the Message
Depending on what happened, the institution or ethics committee may determine that affected participants should be informed, re-consented, given additional information, offered follow-up, or otherwise contacted.
Do not automatically email participants with an improvised explanation before consulting the responsible office. A poorly designed message can create confusion, reveal additional information, or interfere with the institution's corrective plan.
Conversely, do not conceal the event from participants when the institution determines that disclosure is ethically required.
The Response Should Address Why the Error Happened
Corrective action is not limited to dealing with the existing data. The institution may also need to prevent recurrence.
Possible contributing factors include unclear approval dates, poor staff training, misunderstanding of an exemption determination, automated survey activation, miscommunication between collaborators, inadequate version control, or confusion about which site had authorization to begin.
OHRP's incident-reporting process considers corrective actions such as staff education, revised procedures, protocol suspension, increased monitoring, and other institutional responses depending on the incident.
Intent Matters, but Accident Does Not Erase the Event
An accidental error is ethically and administratively different from deliberately ignoring an ethics requirement. Nevertheless, describing something as accidental does not mean no response is needed.
The appropriate authority needs enough information to assess the incident, participant impact, and corrective action. Transparency helps distinguish an isolated mistake from a pattern of disregard for research protections.
Do Not Continue Because You Have Already Started
Researchers occasionally reason that once five participants have already provided data, stopping would only make the dataset less useful. That is precisely the wrong incentive.
Continuing after discovering the problem can transform an accidental event into knowing continuation of unapproved activity. Stop, report, and wait for instructions about what may proceed.
Watch Out
The discovery of accidental early data collection is the point to contain the problem, not normalize it. Continuing after you know approval is missing can materially change how the institution views the incident.