Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Researchers Promise Participants Complete Confidentiality?

Researchers can make strong commitments to protect participant information, but an absolute promise of complete confidentiality is usually difficult to justify. Legal requirements, authorised oversight, study procedures, and the possibility of accidental disclosure can create limits that participants should understand.

285
Can Researchers Promise Complete Confidentiality? Guide 285 of 398
01 · The Question

Can You Tell Participants Their Information Will Never Be Disclosed?

"Everything you tell us will remain completely confidential."

It sounds reassuring. It may also promise more than the research team can actually guarantee.

A study may use strong security, restrict access, separate identifiers, train staff, and avoid publishing identifiable information. Yet particular laws may require disclosure in some circumstances. Authorised monitors or regulators may inspect records. Participants may consent to particular disclosures. Human error and security incidents cannot be made physically impossible.

The challenge is not to make confidentiality sound weak. It is to describe its strength and its boundaries accurately.

02 · The Short Answer

A Strong Confidentiality Commitment Is Different From an Absolute Guarantee

In Brief

Researchers should generally avoid promising complete or absolute confidentiality unless they can genuinely guarantee that no circumstance permits or could result in disclosure, which is rarely a defensible promise for identifiable research information.

Instead, tell participants what information will be protected, who may access it, how confidentiality will be maintained, and the circumstances in which disclosure may occur. The exact limits depend on the study, jurisdiction, applicable law, institutional requirements, and any special legal protections.

03 · What You Need to Know

Confidentiality Is a Commitment With Defined Boundaries

Confidentiality Does Not Mean Nobody Can Ever See the Information

In confidential research, identifiable information may legitimately be accessed by authorised people for approved purposes. Researchers may need participant identities for recruitment, interviews, follow-up, linkage, clinical procedures, withdrawal requests, or data verification.

Depending on the study, authorised monitors, auditors, regulators, institutional officials, sponsors, laboratories, or service providers may also have particular access functions.

This does not mean confidentiality has failed. Confidentiality concerns controlling access, use, and disclosure according to legitimate purposes and the commitments governing the research.

The relevant question is therefore who should have access to identifiable research information, not whether the information can literally be seen by no one.

US Human-Subjects Guidance Explicitly Warns Against Absolute Guarantees

US HHS advisory guidance concerning research consent forms states that, when appropriate, consent forms should explain that research records will be kept confidential and may describe general confidentiality measures. It also states that absolute confidentiality should not be guaranteed and that participants should be informed about circumstances in which confidentiality will not be maintained, such as applicable legal requirements or mandated reporting.

This is US guidance rather than a universal international rule. Nevertheless, it captures an important informed-consent principle: participant information should describe the protection researchers can actually provide rather than the protection they would ideally like participants to hear.

Legal Duties Can Create Limits to Confidentiality

Whether researchers are legally required or permitted to disclose particular information depends on jurisdiction, participant population, professional role, institution, study type, and the information involved.

Examples can include particular statutory reporting requirements, regulatory obligations, or other legally defined circumstances. These should not be guessed from general ethical intuition. Researchers should determine which requirements actually apply to their study with appropriate institutional or legal guidance.

This is why a generic statement such as "we will never disclose your information under any circumstances" can be risky. The researcher may not possess legal authority to make that promise.

Not Every Possible Disclosure Is a "Breach" of Confidentiality

If participants are accurately told that particular authorised people may inspect research records for monitoring or regulatory purposes, access by those people within that defined function is not the same as an unauthorised disclosure.

Likewise, information may be shared for an approved research purpose under applicable governance arrangements without necessarily violating the confidentiality commitment.

The distinction is between authorised, disclosed uses of information and disclosures inconsistent with the study's commitments or applicable requirements.

Authorised access or disclosure Information is accessed or disclosed for a purpose permitted by the study arrangements, participant information, applicable law, or other governing requirements.
Confidentiality breach Information is accessed, used, or disclosed contrary to the protections, permissions, or obligations governing it.

Certificates of Confidentiality Provide Strong Protection, but They Are Not a Promise That Nothing Can Ever Be Disclosed

In the United States, NIH Certificates of Confidentiality provide substantial protection for identifiable, sensitive research information. NIH states that Certificates prohibit disclosure to people not connected with the research except in specified situations, and qualifying NIH-funded research has been automatically deemed to have a Certificate since 2017.

Current NIH policy identifies limited circumstances in which protected information may be disclosed, including when required by certain federal, state, or local laws, with the individual's consent, for medical treatment with consent, or for other scientific research conducted in compliance with applicable federal human-subjects regulations.

Certificates also do not eliminate the possibility of accidental or improper disclosure. OHRP's guidance emphasizes that confidentiality protections still require other appropriate mechanisms and procedures.

Watch Out

Do not describe a Certificate of Confidentiality as making research information absolutely undisclosable. It provides specific statutory protections against disclosure, subject to defined exceptions and responsibilities. Researchers should use current NIH guidance when explaining what a Certificate actually protects.

A Certificate of Confidentiality Is Not a General International Research Protection

Certificates of Confidentiality arise from US federal law. Researchers outside that legal context should not imply that their data receive the same protection merely because the study promises confidentiality.

Other countries may provide different legal protections, duties, privileges, disclosure rules, or data-protection regimes. Multi-country studies may therefore require separate analysis of the limits applying in each relevant jurisdiction.

The safest approach is to identify the actual authority protecting the information rather than borrowing terminology from another regulatory system.

Confidentiality Can Also Be Limited by the Research Method Itself

Not every limit comes from law.

Focus groups are a classic example. Researchers can instruct participants to respect the confidentiality of what others say, but researchers generally cannot guarantee that every participant will comply after leaving the session.

Research involving participant observation, group activities, online communities, or settings where participation is visible may create similar practical constraints.

The confidentiality statement should therefore reflect what the research team controls and what it does not.

Small Samples Can Make Confidentiality Difficult Even Without Names

A researcher may keep the participant list secure and publish no names, yet a reader may recognise a participant from a distinctive quotation, demographic combination, job role, or event.

This is particularly important in small or distinctive research samples.

Confidentiality therefore extends into analysis and dissemination. Researchers should assess whether published descriptions, tables, case narratives, quotations, or supplementary data could reveal identities indirectly.

Security Reduces Risk but Cannot Create an Absolute Guarantee

Encryption, access controls, pseudonymization, secure storage, approved platforms, staff training, and other safeguards can materially reduce confidentiality risk.

They cannot make human error, credential compromise, technical failure, malicious access, or every other security incident logically impossible.

This does not justify vague warnings that "anything could happen." Participants need useful information, not cybersecurity existentialism. The appropriate approach is to explain meaningful foreseeable confidentiality risks and the safeguards used to reduce them.

Good Consent Language Describes the Extent of Confidentiality

US informed-consent regulations require, when appropriate, a statement describing the extent to which confidentiality of records identifying the participant will be maintained. OHRP guidance likewise advises explaining confidentiality protections and their relevant limits rather than giving an absolute guarantee.

A useful confidentiality explanation may address:

  • what identifiable information is collected;
  • who can access it;
  • how direct identifiers are separated or otherwise protected;
  • whether data will be shared with other researchers;
  • how findings will be reported;
  • what legal or regulatory disclosures may apply;
  • whether a Certificate of Confidentiality or another specific protection applies; and
  • any study-specific circumstances in which confidentiality cannot be guaranteed.

The exact content should match the study rather than becoming a boilerplate paragraph copied into every consent form.

Do Not Confuse Confidentiality With Anonymity

If researchers know participants' identities, the study may still provide strong confidentiality protections. Calling it anonymous merely because identities will not be published is inaccurate.

Likewise, promising "complete confidentiality" does not make identifiable information anonymous.

The distinction between anonymous and confidential research matters because participants should understand whether the research team itself can connect their responses to them.

The Strength of the Promise Should Match the Strength of the Architecture

Study Arrangement What Researchers May Reasonably Explain What to Avoid
Identifiable data with restricted access Who can access the information and how access is limited Calling the responses anonymous
Coded data with a retained key Identifiers are stored separately and authorised linkage remains possible Claiming identity can never be restored
Focus group Researchers will protect records and ask participants to respect confidentiality Guaranteeing that other participants will never repeat what they hear
Research protected by a US Certificate of Confidentiality Describe the applicable statutory protections and permitted disclosures accurately Claiming the Certificate prevents every possible disclosure
Publication using de-identified quotations Explain how identities will be protected in dissemination Assuming removal of names prevents all contextual recognition
04 · A Practical Example

Why "Completely Confidential" Can Be Less Accurate Than a More Specific Promise

Hypothetical Example

An Interview Study About Workplace Harassment

A researcher interviews employees about experiences of workplace harassment. Because the topic is sensitive, the draft participant information says, "Everything you tell us will remain completely confidential and will never be disclosed to anyone."

Check actual access The interviewer and principal investigator can identify participants. An approved transcription service will process the recordings under the study's confidentiality arrangements.
Check dissemination The researchers plan to publish de-identified quotations but recognise that unusually distinctive experiences may require additional editing or omission to reduce recognition risk.
Check applicable requirements The institution determines whether any legal reporting duties, authorised oversight access, or other study-specific disclosure circumstances apply.
Revise the promise Instead of guaranteeing absolute secrecy, participant information explains who may access identifiable records, how the information will be protected, how quotations will be handled, and the specific limits that actually apply.
Result Participants receive a more accurate description of a strong confidentiality plan without being promised something the researchers cannot guarantee.

The revised explanation may sound less absolute, but it is more informative. In informed consent, precision is usually a better reassurance than superlatives.

05 · What Researchers Often Get Wrong

Common Mistakes When Promising Research Confidentiality

Misconception

A Strong Ethics Protocol Means Complete Confidentiality Can Be Guaranteed

Strong safeguards can substantially reduce risk, but they do not necessarily eliminate authorised disclosures, legal obligations, oversight access, contextual identification, or the possibility of an information-security incident.

Misconception

Confidential Means Only the Principal Investigator Can See the Data

Confidential research may involve several authorised people or organisations. What matters is whether access is necessary, controlled, and consistent with what participants were told and with the requirements governing the research.

Misconception

A Certificate of Confidentiality Prevents Every Disclosure

NIH Certificates provide specific statutory protections for identifiable, sensitive research information, but current policy also specifies permitted disclosure circumstances. They should be explained according to the actual legal protection rather than as an absolute secrecy guarantee.

Misconception

If Names Are Removed From the Paper, Confidentiality Is Guaranteed

Participants may still be recognisable from quotations, demographic combinations, distinctive roles, events, or contextual details. Confidentiality must be considered during dissemination as well as storage.

Misconception

Listing Every Theoretical Risk Makes Consent More Honest

Consent information should communicate meaningful protections and relevant limits in understandable terms. Exhaustive speculation about implausible events can obscure the risks participants actually need to understand.

06 · What This Means for You

Promise What Your Study Can Defend

Before writing the confidentiality section of a protocol or participant information sheet, map the actual information flow and disclosure rules.

A simple decision framework

If identifiable information is collected
Explain the protections that apply rather than describing the study as anonymous.
If authorised people outside the immediate research team may access records
Determine whether and how that access should be explained to participants under the applicable requirements.
If particular laws or professional duties can require disclosure
State the relevant limits accurately rather than promising disclosure will never occur.
If a Certificate of Confidentiality applies
Use current NIH guidance to explain its protections and permitted disclosure circumstances accurately.
If other participants can hear what someone says
Distinguish what the research team can protect from what it cannot guarantee other participants will keep confidential.

The next step is to tell participants about the limits of confidentiality that actually apply to the study. A narrow, accurate limitation is preferable to a sweeping disclaimer, just as a defensible promise is preferable to "complete confidentiality" printed in bold and hoped for afterward.

07 · A Quick Checklist

Before Promising Confidentiality to Participants

Check what your confidentiality promise actually covers:
Identify who can access identifiable participant information during each stage of the research.
Determine whether external service providers, collaborators, monitors, auditors, regulators, sponsors, or institutional officials may have authorised access.
Verify any applicable legal or professional disclosure requirements rather than relying on generic assumptions.
If a Certificate of Confidentiality applies, verify its current protections and permitted disclosures using NIH guidance.
Assess whether group research methods limit what the research team can guarantee about other participants' behaviour.
Review publications, quotations, tables, and shared datasets for indirect identification as well as names.
Describe safeguards accurately without implying that security controls make a breach impossible.
Ensure participant materials explain meaningful confidentiality limits in language appropriate to the study and population.
08 · Frequently Asked Questions

Frequently Asked Questions About Complete Confidentiality

Can I tell participants their responses are completely confidential?

Absolute language is generally best avoided unless it is genuinely supportable. Describe who can access identifiable information, what safeguards apply, and any relevant limits to confidentiality instead.

Does confidential mean nobody except the researcher can see the data?

No. Other authorised research personnel, service providers, collaborators, monitors, regulators, or institutional officials may have legitimate access in particular studies. Confidentiality concerns controlled access and disclosure rather than access by exactly one person.

Can researchers ever be legally required to disclose participant information?

Potentially, depending on the jurisdiction, study, information involved, professional role, and any specific legal protections. Researchers should verify the requirements applicable to their project rather than assume one universal disclosure rule.

Does a Certificate of Confidentiality guarantee complete secrecy?

No. US Certificates of Confidentiality provide strong statutory protection for identifiable, sensitive research information but permit disclosure in specified circumstances. Researchers must also maintain other confidentiality safeguards.

Can confidentiality be guaranteed in a focus group?

Researchers can protect their own records and ask participants not to repeat what others say, but they generally cannot guarantee the behaviour of every group member after the session. That limitation should be considered when explaining confidentiality.

If data are encrypted, can I promise complete confidentiality?

No. Encryption can be an important security safeguard, but confidentiality also depends on access, disclosure rules, research procedures, human behaviour, legal obligations, and other controls. No single technical safeguard creates an absolute guarantee.

Does removing names from quotations guarantee confidentiality?

No. Participants may still be recognisable through distinctive experiences, occupations, demographic combinations, locations, or other contextual information. Qualitative outputs should be assessed for contextual identification.

09 · The Bottom Line

Strong Confidentiality Does Not Require an Impossible Promise

The Bottom Line

Researchers should protect participant information rigorously but generally should not promise complete confidentiality when authorised access, legal obligations, methodological limits, or residual disclosure risks mean absolute secrecy cannot genuinely be guaranteed.

Tell participants what will be protected, who may access identifiable information, what safeguards apply, and which meaningful limits exist. A precise confidentiality commitment gives participants more useful protection than an absolute promise the research design cannot keep.

10 · Sources and Further Reading

Authoritative Sources on Research Confidentiality

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes