Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Can Researchers Use Administrative, Clinical, Educational, or Government Records Without Individual Consent?

Researchers can sometimes use existing administrative, clinical, educational, or government records without obtaining individual consent, but there is no general research exemption simply because records already exist. The applicable pathway depends on identifiability, purpose, legal authority, ethics requirements, privacy protections, and the rules governing the records.

374
Using Existing Records Without Individual Consent Guide 374 of 398
01 · The Question

Can Records Created for Services or Administration Later Be Used for Research?

Hospitals accumulate clinical records. Schools maintain enrollment and academic information. Government agencies hold administrative databases. Employers, public programs, and other organizations generate records while carrying out their ordinary functions.

These records can be extraordinarily valuable for research because they describe real populations over long periods without requiring researchers to collect the same information again. But the people represented in them may never have been asked whether their records could be used for research. Does that make research use impossible?

02 · The Short Answer

Some Records Research Can Proceed Without Individual Consent

In Brief

Yes. Researchers can sometimes use existing administrative, clinical, educational, or government records without obtaining individual consent, but only when an applicable ethical and legal pathway permits the secondary use.

The fact that an organization lawfully holds a record for its original purpose does not automatically authorize research access. Researchers must establish whether consent is required, can be waived, or is unnecessary under the governing framework and must separately satisfy privacy, confidentiality, access, and sector-specific requirements.

03 · What You Need to Know

Existing Records Were Usually Created for a Different Relationship

Records research is secondary research

When researchers analyze records that were originally created for clinical care, education, public administration, service delivery, or another nonresearch activity, they are conducting a form of secondary research. The researcher is using existing information for a purpose different from the activity that generated it.

The U.S. Common Rule expressly recognizes secondary research using identifiable private information that was collected for nonresearch purposes or for research studies other than the proposed secondary study. It provides several regulatory pathways under which such research may proceed, depending on the circumstances.

Lawful possession of a record does not automatically authorize research use

A hospital may legitimately possess a patient's medical record because it provided clinical care. A university may legitimately maintain a student's academic record because it administers education. A government agency may lawfully collect information to operate a public program.

Those original purposes do not necessarily give every researcher within or outside the organization unrestricted access to the records.

The organization may hold the records The records were legitimately collected or maintained for clinical, educational, administrative, governmental, or another authorized purpose.
A researcher may use the records A separate research, privacy, legal, institutional, or data-governance basis permits the proposed secondary use and access.

Identifiability can substantially change the analysis

Whether researchers receive identifiable information is often important. Under the U.S. Common Rule, research involving identifiable private information can constitute human-subjects research. Secondary research involving information from which investigators cannot readily ascertain participants' identities may be treated differently.

The Common Rule exemption at 45 CFR 46.104(d)(4), for example, covers certain secondary research uses of identifiable private information or identifiable biospecimens when specified conditions are satisfied. One pathway applies when investigators record information so that subjects' identities cannot readily be ascertained directly or through linked identifiers, do not contact subjects, and will not re-identify them.

This does not mean that researchers should personally decide that their records study is exempt. OHRP recommends institutional policies designating an appropriate person or entity to determine whether secondary research involving coded private information constitutes exempt or nonexempt human-subjects research.

Consent can sometimes be waived for identifiable records research

When a records study is nonexempt human-subjects research, individual informed consent may still not always be required. Under the U.S. Common Rule, an IRB may waive or alter consent when the criteria in 45 CFR 46.116(f) are satisfied.

Among other requirements, the research must involve no more than minimal risk, the research could not practicably be carried out without the waiver or alteration, and the waiver must not adversely affect participants' rights and welfare. Where identifiable private information or identifiable biospecimens are involved, the regulations also address whether the research could practicably be carried out without using the information or biospecimens in an identifiable format.

A waiver is therefore a reviewed determination, not a conclusion researchers reach merely because contacting everyone in a database would be difficult.

Clinical records can be governed by overlapping rules

Clinical records illustrate why there is rarely a single consent question. Research involving medical records may be subject to human-subjects regulations, health-information privacy rules, professional confidentiality duties, institutional policies, and other national or local laws.

Under the U.S. Common Rule, one provision of the secondary-research exemption specifically addresses investigators' use of identifiable health information when that use is regulated under the HIPAA Privacy Rule for qualifying purposes. This pathway exists because a separate regulatory privacy framework applies to the information.

Accordingly, “the IRB waived consent” should not be interpreted as “every privacy requirement has disappeared.” Different frameworks may require different authorizations or waivers.

Educational records can have their own confidentiality regime

Educational records may contain grades, attendance, disability information, disciplinary records, demographic characteristics, financial information, and other sensitive material. Access for ordinary educational administration does not necessarily authorize research use.

Researchers should identify the laws and institutional policies governing the particular records and institution. Requirements can differ by jurisdiction, educational level, funding arrangement, record type, and whether information has been appropriately de-identified.

The same principle applies to other sector-specific records. “Administrative data” is a description of how information originated, not a universal legal category with one research rule.

Government records are not automatically public records

Government agencies hold both public information and highly confidential records. The fact that information is maintained by a government body does not mean that anyone may obtain person-level records for research.

Access may depend on legislation, agency authority, confidentiality provisions, data-sharing agreements, ethics review, security requirements, or formal application procedures. Researchers should distinguish genuinely public records from restricted administrative microdata.

Philippine privacy law does not reduce research to a simple consent-or-no-consent rule

The Philippine Data Privacy Act requires personal information to be processed fairly and lawfully and for declared, specified, and legitimate purposes. It also provides several possible criteria for lawful processing rather than treating consent as the only possible basis.

The Act further recognizes historical, statistical, and scientific purposes in its general data-privacy principles while requiring appropriate safeguards. Sensitive personal information receives additional protection under the Act.

Researchers working with Philippine records therefore need to identify the applicable lawful basis, purpose, proportionality, security, confidentiality, and institutional requirements rather than assuming either that research always requires consent or that the word “research” creates a blanket exception.

Research should use only the information it actually needs

Administrative databases can contain hundreds of variables because they were built to operate services rather than answer one research question. Researchers should resist requesting the entire database simply because it is easier for the custodian to export it.

Where feasible, define the necessary population, time period, variables, level of detail, and identifiers before records are released. Data minimization can reduce privacy exposure without sacrificing the research question.

Linkage requires additional consideration

A records study may begin with one administrative database and later propose combining it with another. That step can materially change the privacy and consent analysis because linkage can create information that neither source revealed alone.

Whether researchers can link different datasets without recontacting participants should therefore be evaluated explicitly rather than assumed from permission to use the original records.

Not contacting people does not mean the study cannot affect them

Records research can expose sensitive patterns, generate classifications, stigmatize groups, or support decisions affecting populations even when researchers never communicate with an individual participant.

The absence of direct interaction often reduces burden, but it does not make records research ethically trivial. Privacy, confidentiality, scientific validity, fairness, and responsible reporting remain relevant.

Watch Out

Do not assume that records are available for research merely because you work for the organization that holds them. Operational access to a clinical, educational, administrative, or government system is not automatically research authorization.

04 · A Practical Example

Using Hospital Records Without Contacting Every Patient

Hypothetical Example

A retrospective study of treatment patterns

A hospital research team wants to examine several years of existing clinical records to study patterns in treatment and patient outcomes. Tens of thousands of patients are represented, and the researchers do not plan to contact them.

Define the research need The investigators identify which clinical variables, dates, population, and follow-up information are actually necessary.
Determine regulatory status The institution evaluates whether the proposed records research involves human subjects, qualifies for an applicable exemption, or requires IRB review under the governing framework.
Address consent If consent would otherwise be required, the investigators may request a waiver where permitted and must justify how the applicable waiver criteria are satisfied.
Address privacy separately The team establishes the lawful basis and privacy conditions for access, including whether researchers need identifiable information or whether a custodian can provide a more limited research file.
Protect the records Access is restricted to authorized personnel, unnecessary variables are excluded, and disclosure controls are applied to research outputs.

The study may ultimately proceed without individually contacting every patient, but not because existing medical records are automatically free for research. It proceeds because an authorized pathway permits the secondary use under defined safeguards.

05 · What Researchers Often Get Wrong

Common Misunderstandings About Research Using Existing Records

Misconception

“The organization owns the database, so its researchers can use it.”

Possession or control of records does not automatically establish research authorization. Consent, privacy law, confidentiality, institutional policy, sector-specific rules, and ethics requirements may restrict secondary access.

Misconception

“Retrospective research never requires consent.”

There is no universal rule of that kind. Retrospective records studies may qualify for exemptions or waivers in some circumstances, while others may require consent or another authorization.

Misconception

“Government records are public data.”

Some government information is public, while other records are protected by confidentiality, privacy, statistical secrecy, sector-specific legislation, or access restrictions. Government custody alone does not determine public accessibility.

Misconception

“If an IRB approves the study, privacy law no longer matters.”

Ethics review and data-protection compliance perform different functions. Researchers may need both ethics authorization and a lawful basis for obtaining and processing the records.

Misconception

“If obtaining consent is expensive, it can be waived.”

Cost and difficulty may be relevant to practicability, but a waiver requires the criteria of the governing framework to be satisfied and the authorized reviewing body to make the determination.

Misconception

“No participant contact means no participant risk.”

Records can contain highly sensitive information, and breaches, inappropriate linkage, re-identification, stigmatizing analysis, or disclosure can affect individuals and groups without any direct researcher-participant interaction.

06 · What This Means for You

Identify the Authority for Research Use Before Requesting the Records

If your study relies on records created outside your project, begin by identifying why those records exist, who controls them, which rules protect them, and what legal or ethical mechanism would permit your research access.

A simple decision framework

If participants already authorized the proposed secondary research use
Confirm that your study falls within that authorization and satisfy the remaining ethics, privacy, access, and security requirements.
If individual consent was not obtained for research use
Determine whether an applicable exemption, waiver, statutory authority, lawful processing basis, or other authorized pathway permits the study.
If identifiers are unnecessary for the analysis
Ask whether the custodian can prepare an appropriately limited or non-identifiable research dataset rather than releasing identifying records.
If the records are governed by a sector-specific confidentiality regime
Satisfy those requirements in addition to general research-ethics and data-protection obligations.

If your study relies on records originally collected for another purpose, the ethical question is therefore broader than whether secondary research requires new consent. You also need authority to obtain, process, protect, and report the particular records involved.

07 · A Quick Checklist

Before Using Existing Records Without Individual Consent

Before requesting or analyzing the records, check:
Identify why the records were originally collected and which organization controls them.
Determine whether the proposed activity constitutes human-subjects research under the applicable framework.
Check whether existing consent or another authorization covers the proposed research use.
If consent is absent, establish whether an exemption, waiver, statutory authority, or other lawful pathway applies.
Identify sector-specific rules governing clinical, educational, government, employment, or other records involved in the study.
Request only the records, variables, dates, and identifiers necessary for the approved research purpose.
Determine whether the research team can work with coded or non-identifiable information instead of direct identifiers.
Establish secure access, transfer, storage, retention, and output-disclosure controls before receiving the data.
Obtain the required ethics, privacy, institutional, and data-custodian determinations before beginning analysis.
08 · Frequently Asked Questions

Frequently Asked Questions About Research Using Existing Records

Can researchers use medical records without patient consent?

Sometimes. The applicable pathway depends on jurisdiction, identifiability, the research design, health-information privacy requirements, and whether an exemption, consent waiver, authorization waiver, or other lawful basis applies.

Can researchers use student records without asking students?

Potentially, but educational records may be governed by privacy and confidentiality requirements separate from general research-ethics rules. Researchers should establish the applicable legal and institutional pathway before accessing individual-level records.

Can government administrative data be used for research without consent?

In some circumstances, yes. Government agencies may have statutory or other lawful mechanisms for approved research use, but these vary by jurisdiction and dataset. Government-held information should not automatically be treated as public information.

Does removing identifiers mean consent is unnecessary?

It may change the human-subjects and privacy analysis, but the result depends on the applicable definitions and access arrangements. De-identification does not automatically resolve every ethical issue associated with secondary use.

Who decides whether a records study qualifies for an exemption?

Follow your institution's authorized determination process. OHRP recommends that institutions designate an appropriate person or entity knowledgeable about human-subject protection regulations rather than leaving investigators to make unsupported determinations themselves.

Can researchers contact people identified through records?

Do not assume that permission to analyze records includes permission to contact the people represented in them. Participant contact may require additional ethics approval, consent procedures, custodian authorization, or privacy safeguards.

Does research value override confidentiality restrictions?

No. Scientific value is relevant to ethical review, but researchers still need an authorized pathway for access and use. Valuable research does not by itself nullify confidentiality, privacy, consent, or statutory restrictions.

09 · The Bottom Line

Existing Records Can Support Research Without Consent in Some Circumstances, but Not Without Authority

The Bottom Line

Administrative, clinical, educational, and government records can sometimes be used for research without obtaining individual consent, but researchers need a valid ethical and legal pathway for the particular records and proposed use.

Do not equate organizational possession with research permission. Establish the study's regulatory status, lawful access basis, sector-specific restrictions, need for identifiers, and required safeguards before the records move from their original administrative purpose into research.

10 · Sources and Further Reading

Authoritative Guidance on Secondary Research Using Existing Records

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes