Keeping Research Participant Data Secure: A Practical Guide for Study Teams
Ethics approval says participant data will be protected. Here is what "protected" has to mean in the tools the team actually uses, from consent to destruction.
The ethics application promised that identifiable participant data would be stored securely, accessed only by named staff, and destroyed at the end of the study. Then the study started, and the data went into a spreadsheet on a shared drive because that is where things go. This guide is about closing the gap between the promise and the tools.
Separate identity from data, physically
The single most effective control. Participants' names, contact details and consent forms live in one place with restricted access; the study data lives elsewhere under a pseudonymous ID; the key linking them exists in exactly one restricted location. A researcher analysing the data never needs the names; a coordinator scheduling visits never needs the data. In Herarx the identifiable half is a participant sub-case under Advanced Security — encrypted with its own key, invisible to non-members, including workspace admins — and the study ID is a plain field on it. See cases as study records.
Name the people who can see identifiable data
Two or three, by name and role, and enforce it in the system — per-record access, not a folder permission everyone was added to "for now". When a student joins or leaves, access changes on the record, and the audit log shows it.
Collect consent so it can be found in 2035
A consent form on the participant's own record, with the version of the form they signed and the date. Electronic signature with email verification gives you the signer, the time and a tamper-evident document in one step, and re-consent after an amendment is a second request on the same record. Paper forms are scanned to the record and their physical location noted.
Log access
Who opened which participant record, when. A system-written, uneditable log — see what an audit trail is — is what turns "only named staff accessed it" from a promise into a demonstrable fact.
Devices and the field
Data collected on a tablet or phone should go into the record system at collection, not sit on the device. If the device must hold data temporarily, it is encrypted, passcoded, and wiped on a schedule. Lost-device procedure written down and tested: revoke its session, confirm nothing was stored locally.
Sharing with collaborators
Collaborators get access to what they need on the system — the pseudonymised data, or specific records — through their own verified accounts. Not an emailed export. The same rule as for any sensitive document: give access, don't send copies.
Destruction on schedule
Identifiable data has a shorter life than the study data; the ethics application says when. Put that date on the study record so it triggers a review, and destroy through a process that logs what was destroyed and when. Keep the pseudonymised data for the retention period the funder requires. See how long to keep a closed case.
The annual check
Once a year, with the ethics application open: who can see identifiable data today (does it match the list?), when was access last reviewed, is the destruction date still right, has the restore of the backup been tested. An hour, and the application stays true.