01 · The Question
How should you handle research materials that can reveal who a participant is?
Interviews, focus groups, observations, photo elicitation, ethnographic fieldwork, and many other methods can produce more than written responses. You may end up with voice recordings, videos, photographs, screen recordings, or other files that preserve characteristics of the people who participated.
These materials create a particular confidentiality problem. Removing a participant's name may not be enough. A familiar voice, visible face, distinctive tattoo, workplace, home interior, uniform, location, or combination of contextual details may still make someone recognizable. The question is therefore not simply whether a file contains a name, but whether a person's identity can reasonably be connected to the material.
That distinction matters throughout the research lifecycle. What you collect affects what must be protected, what participants should understand during consent, who may access the original files, whether they can be shared or shown, and when they should eventually be deleted or retained.
03 · What You Need to Know
Identifiable research materials require more than removing names
Identifiability is about whether a person can be connected to the data
A useful starting point is to distinguish a direct identifier from identifiability more broadly. A participant's name is an obvious direct identifier, but it is not the only way a person can be recognized.
Under the U.S. Common Rule, identifiable private information is private information for which the participant's identity is or may readily be ascertained by the investigator or associated with the information. This illustrates an important principle that extends beyond any one regulatory system: you need to consider whether identity can actually be connected to the material, not merely whether a name appears in it.
Multimedia files deserve particular attention because the content itself may carry identifying information. A participant may never state their name in an interview, yet their audio recording may still be identifiable. Similarly, a face, voice, recognizable environment, location, or other characteristic can contribute to identifiability.
Directly identified material
The material explicitly contains information such as a participant's name or another direct identifier.
Identifiable material
The person's identity can still reasonably be ascertained or connected to the material, even if a direct identifier has been removed.
Pseudonymised material
Identifiers have been replaced or separated, but additional information still exists that can reconnect the material to the person.
Anonymised material
The information has been processed so that individuals are no longer identifiable under the applicable standard and circumstances.
These categories should not be treated as interchangeable. For example, the UK Information Commissioner's Office distinguishes pseudonymisation from anonymisation: pseudonymised data remain personal data because additional separately held information can permit identification. The exact legal terminology and threshold for identifiability can differ by jurisdiction, so researchers should apply the rules governing their institution and study rather than assuming that one definition is universal.
Audio, video, and photographs can contain identifiers within the material itself
With a spreadsheet, removing a column containing names may eliminate one obvious identifier. Multimedia data are less cooperative. The identifying feature may be inseparable from what makes the material analytically useful.
A voice can convey accent, speech patterns, age-related characteristics, or other recognizable features. Video can capture faces, voices, clothing, mobility, workplaces, homes, bystanders, computer screens, and documents in the background. Photographs may reveal faces, distinctive physical features, locations, possessions, uniforms, or other contextual information. File metadata may also contain information that deserves review.
This is why researchers should assess voice, face, location, and other identifying characteristics rather than treating "name removed" as a synonym for anonymous.
Start with data minimisation, not with fixing the problem later
Before recording anything, ask what the research question actually requires. If audio is sufficient, recording video may create additional privacy risk without corresponding analytical value. If a photograph needs to show an object rather than the participant, framing the image to exclude the participant's face may avoid collecting an identifier in the first place.
This is data minimisation in practical terms: collect the identifiable material you genuinely need rather than collecting everything because storage is cheap or because it might become useful someday. The principle also applies during recording. Researchers can sometimes avoid capturing unnecessary bystanders, computer screens, name badges, addresses, or other incidental information through careful positioning and data-collection procedures.
Consent should reflect what you actually plan to do with the material
Participants should understand relevant recording procedures and the confidentiality protections and limitations associated with their participation. Under the Common Rule, for example, informed consent generally includes a description of research procedures and a statement describing the extent to which confidentiality of records identifying the participant will be maintained. Other jurisdictions and institutions may impose different or additional requirements.
Researchers should therefore distinguish among collecting a recording for analysis, allowing research-team access, retaining it for a defined period, depositing it for future research, and publicly displaying or distributing it. These are not necessarily equivalent uses from a participant's perspective.
Secure the original files according to their disclosure risk
Identifiable media should not simply be treated like ordinary project files. Appropriate safeguards will depend on the study and institutional requirements, but the underlying questions are fairly consistent: where will the files be stored, who can access them, how will they be transferred, whether copies will be created, whether third-party services will process them, and what happens when access is no longer required?
Access should ordinarily be limited to people who need the identifiable material for an authorized research purpose. Where a participant code is used, keeping the linkage information separately and protecting it appropriately can reduce risk. That is pseudonymisation, however, not necessarily anonymisation.
If recordings are sent to a transcriber, collaborator, cloud platform, transcription service, or repository, that transfer is part of the data lifecycle and should be considered in advance. Researchers should follow applicable institutional requirements concerning approved storage, encryption, access controls, service providers, confidentiality arrangements, and cross-border transfers rather than choosing tools solely for convenience.
Transcription can reduce exposure, but it does not automatically resolve identifiability
For some studies, the original audio or video is needed mainly to produce and verify a transcript. A transcript can then be pseudonymised or anonymised to an appropriate degree by removing or modifying identifying information while preserving the information needed for analysis.
But two separate questions remain. First, can the transcript itself identify the participant through names, organizations, rare occupations, locations, events, or combinations of details? Second, what should happen to the original recording after transcription?
There is no universal rule that recordings must be deleted immediately after transcription, nor that they should always be retained. The appropriate decision may depend on the approved protocol, consent, analytic need, verification requirements, institutional retention rules, funder requirements, repository plans, and applicable law. The specific question of whether to retain identifiable recordings after transcription therefore needs to be decided deliberately rather than by habit.
Sharing and publication create a different level of exposure
A recording stored in a restricted research environment and a photograph reproduced in an open-access article may contain the same participant, but the disclosure context is very different. Once identifiable material is placed in a publication, conference presentation, public repository, website, or other broadly accessible venue, controlling subsequent copying and redistribution may become difficult or impossible.
NIH guidance on sharing human participant data recommends de-identifying data to the greatest extent compatible with scientific utility and considering controlled access and data-use agreements as additional privacy protections. The precise requirements vary, but the broader lesson is useful: a technically permissible disclosure is not automatically the most appropriate form of sharing.
For visual material, researchers should separately consider whether they have an appropriate basis and permission for the intended dissemination. The fact that a photograph was legitimately collected for analysis does not by itself answer whether the participant's photograph can be used in a publication or presentation.
Reassess identifiability before every new use or disclosure
Identifiability is contextual. Material that seems difficult to identify in isolation may become revealing when combined with other information. A blurred face may not solve the problem if a uniform, workplace, distinctive voice, event, or quoted details point to the same person.
This means de-identification should not be treated as a one-time clerical task. Before sharing, depositing, presenting, publishing, or repurposing research material, reconsider who could encounter it, what other information they may possess, and what consequences identification could have for the participant.
For data intended for reuse, the UK Data Service similarly recommends combining participant communication, technical measures such as anonymisation or pseudonymisation, and governance measures such as access controls and usage conditions. No single safeguard necessarily carries the entire burden.
04 · A Practical Example
Handling recorded interviews from collection to publication
Hypothetical Example
A study records video interviews with hospital staff
A research team is studying how healthcare workers experience the introduction of a new workplace system. Participants consent to video-recorded interviews for research analysis. The recordings show their faces and capture their voices. Some participants also mention their departments, job roles, colleagues, and unusual workplace events.
Collection
The researchers collect video because nonverbal interaction is relevant to the approved analysis. They explain the recording procedure and intended uses during consent rather than treating video as an incidental technical detail.
Storage
The original files are placed in the institutionally approved restricted storage environment. Access is limited to authorized members of the research team who need the recordings.
Transcription
Working transcripts replace participant names with study codes and remove unnecessary direct identifiers. The researchers also review contextual details that could reveal identity rather than assuming that replacing names is sufficient.
Analysis
Researchers use the original recordings when the visual information is analytically necessary and use the less identifying working materials when the original video is not needed.
Dissemination
The team wants to show a short video clip at a conference. Before doing so, they check whether the consent and approved protocol cover that form of identifiable dissemination. They do not infer permission merely from consent to video recording.
Retention
At the point specified in the research plan, the team reassesses which files still need to be retained and follows the applicable ethics approval, consent commitments, institutional policy, funder conditions, and legal requirements.
The important point is that "the data" are not a single object with one risk level. The original video, pseudonymised transcript, linkage file, presentation clip, and eventual archived dataset may each require different controls.
06 · What This Means for You
Make identifiability a lifecycle decision, not a file-cleaning task
The most useful question is not simply, "Have I removed the names?" Ask instead what identifiable information exists, why you need it, who needs access to it, what participants agreed to, and whether the protections remain appropriate at each later use.
A simple decision framework
If identifiable audio, video, or images are not necessary for the research purpose
Avoid collecting them or redesign collection to reduce unnecessary identifying information.
If identifiable material is necessary
Describe its collection and relevant uses appropriately in the research protocol and consent process, and apply safeguards proportionate to the disclosure risk.
If only some team members need the identifiable originals
Restrict access and use less identifying working versions where they are sufficient for the task.
If you plan a new use, audience, repository, publication, or presentation
Recheck consent, ethics approval, identifiability, access conditions, and applicable institutional or legal requirements before disclosure.
If identifiable originals are no longer needed
Follow the approved retention or disposal plan and applicable institutional, funder, repository, and legal requirements rather than retaining them indefinitely by default.
Risk also depends on context. Recognition by the general public is not the only concern. In a small professional community, school, workplace, village, patient group, or specialist field, a person may be readily identifiable to insiders from details that appear innocuous to everyone else. This becomes particularly important when several individually harmless details appear together.
Finally, document your decisions. A defensible data-management plan should make clear what identifiable materials exist, why they are required, where they are stored, who has access, how less identifying versions are produced, what uses are permitted, and when retention will be reviewed. Future-you will appreciate this more than a folder called "FINAL_REAL_FINAL_INTERVIEWS."
07 · A Quick Checklist
Before collecting or using identifiable research materials
Before collecting, sharing, or retaining identifiable media, check:
Confirm that the audio, video, photograph, or other identifiable material is genuinely necessary for the research purpose.
Identify what could reveal participants through names, voices, faces, locations, surroundings, metadata, distinctive characteristics, or combinations of details.
Ensure the collection and intended uses are consistent with the approved ethics protocol and the information provided during consent.
Use institutionally approved storage and transfer methods appropriate to the sensitivity and identifiability of the material.
Restrict access to people who need identifiable material for an authorized research purpose.
Keep linkage information separate and appropriately protected when pseudonymisation is used.
Review the confidentiality and data-processing implications before sending files to transcribers, collaborators, software services, or repositories.
Reassess identifiability and consent before using recordings or images in publications, presentations, teaching, repositories, or other new contexts.
Follow the applicable retention and secure-disposal requirements when identifiable originals are no longer required.