03 · What You Need to Know
Confidentiality Is a Rule With Defined Boundaries, Not a Promise of Absolute Secrecy
Why confidentiality matters so much in research
Research participants often reveal information they would not disclose publicly: health conditions, sexuality, substance use, illegal behavior, immigration circumstances, traumatic experiences, family conflict, financial information, political activity, or stigmatized behavior.
If disclosure could expose participants to prosecution, discrimination, stigma, retaliation, relationship harm, or economic loss, confidentiality is part of participant protection rather than administrative housekeeping.
It can also be necessary for scientific validity. Participants who reasonably fear disclosure may decline research or systematically withhold sensitive information.
Confidentiality is not the same as anonymity
An anonymous dataset cannot readily be linked to an identifiable participant in the relevant research context. Confidential research information, by contrast, may be identifiable but is protected against unauthorized disclosure.
Anonymous or non-identifiable information
The research team cannot reasonably connect the information to a particular participant within the relevant context.
Confidential identifiable information
The information can be connected to a participant, but access and disclosure are restricted by research, ethical, institutional, and sometimes legal protections.
This distinction matters because researchers cannot disclose an identity they genuinely cannot determine, while identifiable information creates a different set of confidentiality obligations.
There is no single “duty to report” covering every dangerous or unlawful disclosure
Researchers sometimes speak as though confidentiality disappears whenever information is serious. That is too broad.
Different situations can invoke different legal doctrines and ethical processes:
| Situation |
Possible confidentiality limit |
What must be checked |
| Possible child or protected-adult abuse |
Mandatory safeguarding report |
Applicable reporting statute, participant status, researcher's professional role |
| Suicide or serious self-harm risk |
Safety-related disclosure or intervention |
Approved safety protocol, professional duties, applicable law |
| Serious threat toward another person |
Duty to warn, protect, or another permitted or required disclosure |
Jurisdiction, professional role, seriousness and characteristics of the threat |
| Reportable communicable disease |
Public-health reporting requirement |
Applicable public-health law |
| Possible illegal activity without another trigger |
Often no automatic reporting duty |
Whether a specific law or obligation actually requires disclosure |
| Court, police, or administrative demand |
Potential compelled disclosure |
Applicable privilege, Certificate of Confidentiality, statute, court process, and institutional legal advice |
| Participant authorizes disclosure |
Consent-based disclosure |
Scope and validity of the participant's authorization |
The relevant question is therefore not “Is confidentiality absolute?” but “Which rule governs this particular proposed disclosure?”
Consent should identify foreseeable limits
A confidentiality exception that researchers know about before enrollment should not be kept secret from participants until it occurs.
Participants in research likely to elicit abuse disclosures, serious threats, suicide risk, or legally reportable information should be told about relevant limits in understandable language. The exact wording depends on the study and jurisdiction.
Canada's TCPS 2 explicitly states that incidental findings can sometimes trigger legal reporting obligations and that researchers should be aware of those obligations and inform participants of limits to confidentiality during the initial consent process.
Certificates of Confidentiality create strong but defined protections
In qualifying U.S. research, Certificates of Confidentiality prohibit disclosure of identifiable sensitive research information outside the research except in specified circumstances. NIH-funded research meeting the statutory criteria receives this protection automatically.
Current NIH policy permits disclosure when required by federal, state, or local law, with participant consent, for certain medical treatment with consent, or for qualifying scientific research. It separately prohibits use of protected identifiable information in specified legal proceedings without participant consent.
This is why researchers should not summarize Certificates as either “absolute secrecy” or “useless if someone asks.” Both descriptions are wrong.
Mandatory reporting and compelled disclosure are different
This distinction is easy to miss.
A law may affirmatively require a researcher or professional to report a defined circumstance, such as particular abuse or public-health information. Separately, police, litigants, regulators, or courts may seek access to research records for an investigation or proceeding.
Under the modern U.S. Certificate framework, those situations are not interchangeable. Certificates can strongly protect covered information against compelled use in proceedings while still permitting disclosure required by another applicable federal, state, or local law.
A safety exception should be no broader than necessary
Even when disclosure is justified, confidentiality does not necessarily vanish for the participant's entire research record.
If a particular safety or reporting purpose requires communicating defined information to a safeguarding agency, clinician, potential victim, public-health authority, or another recipient, researchers should ordinarily limit disclosure to information appropriate to that purpose, subject to applicable law and institutional procedure.
A valid reason to disclose one safety-critical fact is not automatically permission to send an entire interview transcript or dataset.
Possible abuse requires its own reporting analysis
A disclosure of possible abuse during research may trigger mandatory-reporting rules, particularly for children or protected adults. The rules vary by jurisdiction and professional role.
The researcher should not decide based solely on whether the allegation sounds credible enough personally. The study should have a safeguarding pathway identifying the reporting threshold and designated consultation route.
Self-harm and suicide risk require a safety protocol
When a participant discloses self-harm or suicide risk, confidentiality may intersect with the need to protect the participant. The response should depend on an appropriate assessment and the approved safety framework rather than an automatic rule that every mention of suicide is either confidential or immediately reportable.
Threats toward others raise jurisdiction-specific duties
The legal rules surrounding a serious risk of harm to another person vary substantially. Duties to warn or protect may depend on professional status, jurisdiction, specificity of the threat, identifiability of the potential victim, and other factors.
A researcher should therefore not invoke “Tarasoff” as though it were a universal international research rule.
Illegal activity does not automatically defeat confidentiality
Research confidentiality protections have particular importance precisely because sensitive studies can concern illicit or stigmatized behavior. A participant's admission of possible unlawful conduct does not, by itself, establish a general duty to report.
The appropriate analysis for possible illegal activity discovered during research is whether a specific disclosure obligation applies, not simply whether the behavior may violate law.
Uncertainty should trigger consultation, not casual disclosure
Researchers are not expected to memorize every reporting statute, privilege, professional rule, and confidentiality law that could arise. They are expected to know where to obtain timely guidance.
A protocol involving sensitive information should identify a rapid consultation pathway involving, as appropriate, the principal investigator, safeguarding lead, research ethics committee or IRB, privacy office, institutional counsel, clinical professional, or other designated authority.
Watch Out
When you are uncertain whether disclosure is legally required, do not solve the uncertainty by disclosing “just to be safe.” Disclosure itself can seriously harm participants and may violate applicable protections. Escalate the question through the appropriate institutional process.
Confidentiality failures can themselves harm participants
OHRP treats certain unexpected breaches of identifiable sensitive information as reportable unanticipated problems when they increase risks to participants. Its examples include theft of unencrypted identifiable research data concerning illegal behavior.
This reinforces the larger point: protecting confidentiality is itself part of protecting participant welfare. Exceptions should therefore be justified, bounded, and planned rather than treated casually.