Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

When Does Confidentiality Give Way to a Duty to Act or Report?

Research confidentiality is a substantive obligation, but it is not always absolute. Disclosure may be required or permitted by specific laws, safety duties, participant consent, or other governing rules, and those limits should be identified before sensitive data are collected.

397
When Confidentiality Has Limits Guide 397 of 398
01 · The Question

Researchers Promise Confidentiality, but What Happens When Someone May Be in Danger?

A participant discloses possible child abuse. Another reports suicidal intent. Someone makes a serious threat toward another person. A dataset contains information that may be legally reportable. Police request records from a study involving illegal behavior.

Each situation places pressure on confidentiality, but they do not all produce the same answer.

Research confidentiality protects participants from social, legal, economic, psychological, and other harms. Weakening it casually can damage participants and make sensitive research impossible. Yet particular laws and safety obligations can require or permit action that involves disclosure. The difficult task is determining when that boundary has actually been crossed.

02 · The Short Answer

Confidentiality Gives Way Only When a Valid Exception or Obligation Applies

In Brief

Research confidentiality should be maintained unless disclosure has a valid basis under the participant's consent, applicable law, an approved safety or reporting procedure, or another governing ethical or professional obligation. Seriousness alone does not authorize unrestricted disclosure, and confidentiality alone does not nullify a genuine legal duty.

The relevant threshold varies by situation and jurisdiction. Researchers should identify foreseeable limits before data collection, explain them accurately during consent, disclose no more information than the applicable purpose requires, and seek appropriate ethics, institutional, professional, or legal guidance when the boundary is uncertain.

03 · What You Need to Know

Confidentiality Is a Rule With Defined Boundaries, Not a Promise of Absolute Secrecy

Why confidentiality matters so much in research

Research participants often reveal information they would not disclose publicly: health conditions, sexuality, substance use, illegal behavior, immigration circumstances, traumatic experiences, family conflict, financial information, political activity, or stigmatized behavior.

If disclosure could expose participants to prosecution, discrimination, stigma, retaliation, relationship harm, or economic loss, confidentiality is part of participant protection rather than administrative housekeeping.

It can also be necessary for scientific validity. Participants who reasonably fear disclosure may decline research or systematically withhold sensitive information.

Confidentiality is not the same as anonymity

An anonymous dataset cannot readily be linked to an identifiable participant in the relevant research context. Confidential research information, by contrast, may be identifiable but is protected against unauthorized disclosure.

Anonymous or non-identifiable information The research team cannot reasonably connect the information to a particular participant within the relevant context.
Confidential identifiable information The information can be connected to a participant, but access and disclosure are restricted by research, ethical, institutional, and sometimes legal protections.

This distinction matters because researchers cannot disclose an identity they genuinely cannot determine, while identifiable information creates a different set of confidentiality obligations.

There is no single “duty to report” covering every dangerous or unlawful disclosure

Researchers sometimes speak as though confidentiality disappears whenever information is serious. That is too broad.

Different situations can invoke different legal doctrines and ethical processes:

Situation Possible confidentiality limit What must be checked
Possible child or protected-adult abuse Mandatory safeguarding report Applicable reporting statute, participant status, researcher's professional role
Suicide or serious self-harm risk Safety-related disclosure or intervention Approved safety protocol, professional duties, applicable law
Serious threat toward another person Duty to warn, protect, or another permitted or required disclosure Jurisdiction, professional role, seriousness and characteristics of the threat
Reportable communicable disease Public-health reporting requirement Applicable public-health law
Possible illegal activity without another trigger Often no automatic reporting duty Whether a specific law or obligation actually requires disclosure
Court, police, or administrative demand Potential compelled disclosure Applicable privilege, Certificate of Confidentiality, statute, court process, and institutional legal advice
Participant authorizes disclosure Consent-based disclosure Scope and validity of the participant's authorization

The relevant question is therefore not “Is confidentiality absolute?” but “Which rule governs this particular proposed disclosure?”

Consent should identify foreseeable limits

A confidentiality exception that researchers know about before enrollment should not be kept secret from participants until it occurs.

Participants in research likely to elicit abuse disclosures, serious threats, suicide risk, or legally reportable information should be told about relevant limits in understandable language. The exact wording depends on the study and jurisdiction.

Canada's TCPS 2 explicitly states that incidental findings can sometimes trigger legal reporting obligations and that researchers should be aware of those obligations and inform participants of limits to confidentiality during the initial consent process.

Certificates of Confidentiality create strong but defined protections

In qualifying U.S. research, Certificates of Confidentiality prohibit disclosure of identifiable sensitive research information outside the research except in specified circumstances. NIH-funded research meeting the statutory criteria receives this protection automatically.

Current NIH policy permits disclosure when required by federal, state, or local law, with participant consent, for certain medical treatment with consent, or for qualifying scientific research. It separately prohibits use of protected identifiable information in specified legal proceedings without participant consent.

This is why researchers should not summarize Certificates as either “absolute secrecy” or “useless if someone asks.” Both descriptions are wrong.

Mandatory reporting and compelled disclosure are different

This distinction is easy to miss.

A law may affirmatively require a researcher or professional to report a defined circumstance, such as particular abuse or public-health information. Separately, police, litigants, regulators, or courts may seek access to research records for an investigation or proceeding.

Under the modern U.S. Certificate framework, those situations are not interchangeable. Certificates can strongly protect covered information against compelled use in proceedings while still permitting disclosure required by another applicable federal, state, or local law.

A safety exception should be no broader than necessary

Even when disclosure is justified, confidentiality does not necessarily vanish for the participant's entire research record.

If a particular safety or reporting purpose requires communicating defined information to a safeguarding agency, clinician, potential victim, public-health authority, or another recipient, researchers should ordinarily limit disclosure to information appropriate to that purpose, subject to applicable law and institutional procedure.

A valid reason to disclose one safety-critical fact is not automatically permission to send an entire interview transcript or dataset.

Possible abuse requires its own reporting analysis

A disclosure of possible abuse during research may trigger mandatory-reporting rules, particularly for children or protected adults. The rules vary by jurisdiction and professional role.

The researcher should not decide based solely on whether the allegation sounds credible enough personally. The study should have a safeguarding pathway identifying the reporting threshold and designated consultation route.

Self-harm and suicide risk require a safety protocol

When a participant discloses self-harm or suicide risk, confidentiality may intersect with the need to protect the participant. The response should depend on an appropriate assessment and the approved safety framework rather than an automatic rule that every mention of suicide is either confidential or immediately reportable.

Threats toward others raise jurisdiction-specific duties

The legal rules surrounding a serious risk of harm to another person vary substantially. Duties to warn or protect may depend on professional status, jurisdiction, specificity of the threat, identifiability of the potential victim, and other factors.

A researcher should therefore not invoke “Tarasoff” as though it were a universal international research rule.

Illegal activity does not automatically defeat confidentiality

Research confidentiality protections have particular importance precisely because sensitive studies can concern illicit or stigmatized behavior. A participant's admission of possible unlawful conduct does not, by itself, establish a general duty to report.

The appropriate analysis for possible illegal activity discovered during research is whether a specific disclosure obligation applies, not simply whether the behavior may violate law.

Uncertainty should trigger consultation, not casual disclosure

Researchers are not expected to memorize every reporting statute, privilege, professional rule, and confidentiality law that could arise. They are expected to know where to obtain timely guidance.

A protocol involving sensitive information should identify a rapid consultation pathway involving, as appropriate, the principal investigator, safeguarding lead, research ethics committee or IRB, privacy office, institutional counsel, clinical professional, or other designated authority.

Watch Out

When you are uncertain whether disclosure is legally required, do not solve the uncertainty by disclosing “just to be safe.” Disclosure itself can seriously harm participants and may violate applicable protections. Escalate the question through the appropriate institutional process.

Confidentiality failures can themselves harm participants

OHRP treats certain unexpected breaches of identifiable sensitive information as reportable unanticipated problems when they increase risks to participants. Its examples include theft of unencrypted identifiable research data concerning illegal behavior.

This reinforces the larger point: protecting confidentiality is itself part of protecting participant welfare. Exceptions should therefore be justified, bounded, and planned rather than treated casually.

04 · A Practical Example

One Sensitive Interview Produces Three Different Disclosure Questions

Hypothetical Example

Not every sensitive disclosure has the same confidentiality rule

A qualitative study asks adults about difficult life experiences. During different interviews, three participants disclose different kinds of sensitive information.

Participant A The participant describes past illegal drug use with no apparent current safety issue. The researcher protects the information under the study's confidentiality procedures rather than assuming it must be reported.
Participant B The participant describes circumstances suggesting abuse of a child. The researcher activates the study's safeguarding pathway to determine and fulfill the applicable reporting duty.
Participant C The participant makes a statement suggesting a serious current threat toward another person. The researcher activates the threat-escalation procedure and obtains the qualified and legal assessment required by the protocol.

All three disclosures are sensitive. Only examining the specific rule governing each situation reveals whether confidentiality remains intact, is limited, or requires a protective disclosure.

05 · What Researchers Often Get Wrong

Common Mistakes About Confidentiality and Reporting

Misconception

Confidential means researchers can never disclose anything

Confidentiality can have defined exceptions arising from consent, law, safety obligations, and other governing rules. Participants should be informed about foreseeable limits rather than promised absolute secrecy.

Misconception

Safety concerns automatically override all confidentiality

Safety can justify or require particular disclosures, but the scope of disclosure should follow the applicable rule. A concern about one risk does not necessarily authorize release of unrelated research information.

Misconception

Anything illegal must be reported

No general research principle makes every suspected legal violation reportable. Researchers should identify the actual reporting requirement rather than infer one from illegality alone.

Misconception

A subpoena means the researcher has no choice but to hand over the data

Sensitive research information may have legal protections, including Certificates of Confidentiality. External legal demands should be handled through institutional counsel and the applicable confidentiality framework.

Misconception

If the consent form mentions a confidentiality exception, disclosure is automatically appropriate

Consent language informs participants about the framework; it does not eliminate the need to determine whether the actual threshold for disclosure has been met.

06 · What This Means for You

Know the Exception Before You Promise the Rule

Before collecting sensitive information, map the circumstances in which confidentiality might be limited. Determine which are legally required, which are ethically or professionally permitted, who decides that the threshold has been reached, and what information can be disclosed.

A practical confidentiality framework

If no specific exception or disclosure obligation applies
Maintain confidentiality according to the approved protocol and applicable protections.
If a defined mandatory-reporting law applies
Follow the legally required reporting pathway and institutional procedure.
If a serious safety concern may justify disclosure but the threshold is uncertain
Use the designated urgent clinical, safeguarding, ethics, or legal consultation process before disclosing when circumstances permit.
If an outside party demands identifiable research information
Invoke institutional legal review and applicable confidentiality protections rather than responding independently.
If disclosure is validly required or authorized
Limit the information shared to what is appropriate for that purpose, subject to the applicable law and procedure.

Researchers should not have to choose between confidentiality and safety from scratch during an emergency. The study should already define the decision pathway.

07 · A Quick Checklist

Before Promising Confidentiality

For sensitive research, verify:
Which foreseeable disclosures could trigger mandatory reporting or protective action.
Which laws apply where participants and research personnel are located.
Whether professional obligations differ among members of the research team.
Whether a Certificate of Confidentiality or another legal protection applies.
Whether consent materials explain genuine confidentiality protections and foreseeable limits accurately.
Who determines whether a reporting or safety threshold has been met.
How staff obtain rapid ethics, safeguarding, clinical, privacy, or legal advice.
How external demands for research information will be handled.
How any necessary disclosure will be limited and documented.
08 · Frequently Asked Questions

Questions About the Limits of Research Confidentiality

Is research confidentiality legally absolute?

No. The applicable protections and exceptions depend on jurisdiction, research context, consent, specific confidentiality statutes or protections, and other legal obligations.

Does immediate danger always permit disclosure?

Potentially serious danger can activate safety and protective duties, but the legal basis and appropriate recipient of disclosure vary. Researchers should follow the approved urgent safety procedure and applicable law.

Must researchers report illegal activity?

Not merely because the activity may be illegal. A specific reporting requirement or other valid basis for disclosure must be identified.

What does a Certificate of Confidentiality protect?

In qualifying U.S. research, it provides strong statutory protection for identifiable sensitive research information, including protection against specified compelled disclosures. It operates subject to defined statutory rules and exceptions.

Should confidentiality limits be stated in consent forms?

Foreseeable and relevant limits should be communicated accurately so participants understand the circumstances in which identifiable information may need to be disclosed.

What if researchers are unsure whether they must report?

They should promptly use the institution's designated ethics, legal, safeguarding, privacy, or professional consultation pathway rather than either disclosing reflexively or ignoring a possible duty.

09 · The Bottom Line

Confidentiality Has Limits, but Those Limits Need a Defensible Basis

The Bottom Line

Research confidentiality gives way when a valid consent-based, legal, professional, safety, or other governing rule requires or permits an appropriate disclosure, not simply whenever information is troubling, illegal, or potentially important.

The strongest protection is prospective clarity: determine the applicable reporting duties, safety exceptions, legal protections, and consultation procedures before collecting sensitive information. When disclosure is justified, preserve confidentiality as far as possible by sharing only what the protective or legal purpose appropriately requires.

10 · Sources and Further Reading

Sources and Further Reading

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes