03 · What You Need to Know
Why Legal Permission and Ethical Justification Are Different
Law and Ethics Ask Different Questions
Legal analysis asks what applicable law requires, permits, restricts, or prohibits. Research ethics asks whether research decisions can be justified according to relevant ethical principles and responsibilities.
Legal compliance
Concerns whether conduct satisfies applicable statutes, regulations, legally binding requirements, and other enforceable legal obligations.
Ethical justification
Concerns whether the purpose, methods, risks, burdens, protections, treatment of participants, and other research decisions are ethically defensible.
The two domains overlap extensively. Human-research regulations often embody ethical commitments such as informed consent, risk minimization, independent review, and additional protections for certain populations. But overlap does not make the concepts identical.
Research Regulations Often Translate Ethical Principles Into Enforceable Requirements
The relationship between the Belmont Report and U.S. human-subject regulations provides a useful example.
Belmont identifies respect for persons, beneficence, and justice as basic ethical principles. HHS explains that its human-subject protection regulations were developed in large part from Belmont and related work of the National Commission. The U.S. Common Rule establishes regulatory requirements concerning institutional review boards, informed consent, and other protections for research within its scope.
This illustrates how ethical reasoning can influence law and regulation. Once incorporated into regulation, particular protections become legal or regulatory requirements for covered research.
But the ethical principle remains broader than the particular rule created from it.
Not Every Ethical Responsibility Can Be Reduced to a Regulation
Research produces situations that detailed rules cannot anticipate completely.
A regulation may specify when consent is required, but researchers may still need to decide how to explain an unfamiliar procedure understandably. A privacy rule may establish requirements for particular categories of data while leaving researchers with choices about whether collecting every legally accessible variable is ethically necessary. A law may permit a recruitment arrangement that nevertheless creates avoidable pressure or unfairness.
Rules establish boundaries and procedures. Ethical judgment remains necessary within the spaces where several legally permissible options exist.
Legally Accessible Data Are Not Automatically Ethically Unproblematic Data
Digital and data-intensive research makes the distinction particularly visible.
A researcher may be legally permitted to access certain information, or information may be publicly accessible. That does not automatically answer every ethical question about collecting, linking, analyzing, quoting, or publishing it.
Researchers may still need to consider reasonable expectations of privacy, sensitivity, identifiability, vulnerability, potential group harms, contextual norms, and applicable disciplinary or institutional guidance.
Conversely, ethical concern does not mean researchers may disregard applicable law. Both analyses are necessary.
Legal Minimums and Ethical Best Judgment Are Not Necessarily the Same
Some legal and regulatory standards function as minimum protections. Researchers or institutions may decide that stronger safeguards are appropriate in a particular study.
For example, an institution may adopt policies that are more protective than the regulatory baseline. HHS guidance on the U.S. Common Rule explicitly notes that institutions can implement their own policies and procedures and that these may be more protective than regulatory requirements.
A researcher therefore should not assume that satisfying the minimum legally enforceable standard necessarily exhausts every institutional or ethical responsibility.
Different Laws Can Apply to the Same Research
“The law” is rarely one rule.
Research can be governed by overlapping legal regimes concerning human-subject protection, data protection, health information, clinical products, children, employment, education, intellectual property, or other matters. Which rules apply depends on jurisdiction, funding, institution, research population, data source, and study type.
Even within the United States, HHS guidance emphasizes that satisfying one regulatory exemption does not eliminate separate requirements that may arise under FDA rules or state law. The Common Rule itself does not replace federal, state, or local laws that provide additional participant protections.
This is why researchers should avoid generic statements such as “the study complies with all privacy laws” unless the applicable legal framework has actually been identified and verified.
Research Across Countries Can Involve Multiple Ethical and Legal Frameworks
International research adds another layer. A project may originate in one country, be funded from another, collect data in several jurisdictions, and involve collaborating institutions with different requirements.
The 2024 Declaration of Helsinki instructs researchers involved in medical research to consider the ethical, legal, and regulatory norms and standards of the countries where the research originates and where it is conducted, together with applicable international standards. It also states that national or international requirements should not reduce the participant protections contained in the Declaration.
The broader issue of how ethical standards vary across countries and research settings therefore cannot be solved simply by identifying whichever jurisdiction appears least restrictive.
Legal Permission Does Not Automatically Resolve Risk-Benefit Questions
A procedure can be legally permitted yet still require ethical scrutiny.
Suppose researchers can lawfully collect a large set of identifiable variables. The ethical question remains whether all of those variables are necessary for the research, whether the resulting privacy risks are proportionate, whether less identifiable information would suffice, and how access should be controlled.
Legality tells researchers that a legal barrier may not prohibit the action. It does not necessarily tell them that the action is the most ethically defensible option among those available.
Legal Compliance Does Not Replace Respect for Persons
A consent document can satisfy formal requirements while still communicating badly.
If prospective participants cannot understand what the research involves because the information is unnecessarily technical, simply meeting formal disclosure requirements may not fulfill the ethical purpose of informed consent.
Belmont frames informed consent through information, comprehension, and voluntariness. The ethical objective is meaningful decision-making, not paperwork for its own sake.
Ethical Approval and Legal Compliance Are Also Different
Researchers sometimes treat ethics approval as evidence that all relevant legal questions have been resolved. That assumption can be unsafe.
An ethics committee or institutional review board evaluates matters within its remit. It may consider regulatory criteria extensively, but approval should not automatically be interpreted as specialist legal advice about every data-protection, contractual, employment, intellectual-property, international-transfer, or other legal issue a project might involve.
Likewise, obtaining legal advice does not substitute for ethical review where such review is required.
The question of whether ethics approval itself is enough to make research ethical raises a parallel distinction: formal authorization matters, but responsibility continues beyond the authorization.
Ethically Defensible Does Not Mean Researchers May Ignore the Law
The distinction between ethics and law works in both directions.
A researcher may sincerely believe that an action is ethically preferable while an applicable law or regulation prohibits it. Personal ethical conviction does not ordinarily give a researcher authority to disregard binding legal requirements.
If researchers believe a legal or institutional requirement creates an ethical problem, the appropriate response is generally to seek clarification, modification, lawful alternatives, formal exceptions where available, or changes through legitimate institutional or legal processes rather than quietly ignoring the rule.
The more difficult question of whether something can be legally permitted but ethically questionable should therefore be kept distinct from whether researchers may violate a legal requirement because they disagree with it.
Some Requirements Are Institutional Rather Than Legal
Researchers also need to distinguish law from institutional policy.
A university may require ethics review for categories of research that are not independently required to undergo a particular form of review by national law. An institution may impose stricter data-security requirements, additional training, particular consent procedures, or internal restrictions on research activity.
Those rules matter to researchers working under the institution's authority, but calling every institutional requirement “the law” obscures where the requirement actually comes from.
This distinction becomes particularly important when asking whether ethically defensible research can still be prohibited by institutional rules.
Professional and Disciplinary Standards Add Another Layer
Researchers may also be accountable to professional codes, disciplinary norms, journal requirements, funder conditions, contractual obligations, and international ethical guidance.
Some of these requirements may have legal consequences in particular circumstances; others operate primarily through professional or institutional accountability. Their status should be identified rather than assumed.
The practical lesson is that “Is this legal?” is one important question among several, not a universal substitute for them.