Keeping Research Participant Data Secure: A Practical Guide for Study Teams — Herarx Blog

Keeping Research Participant Data Secure: A Practical Guide for Study Teams

Ethics approval says participant data will be protected. Here is what "protected" has to mean in the tools the team actually uses, from consent to destruction.

August 25, 2026
Keeping Research Participant Data Secure: A Practical Guide for Study Teams
Back to blog

The ethics application promised that identifiable participant data would be stored securely, accessed only by named staff, and destroyed at the end of the study. Then the study started, and the data went into a spreadsheet on a shared drive because that is where things go. This guide is about closing the gap between the promise and the tools.

Separate identity from data, physically

The single most effective control. Participants' names, contact details and consent forms live in one place with restricted access; the study data lives elsewhere under a pseudonymous ID; the key linking them exists in exactly one restricted location. A researcher analysing the data never needs the names; a coordinator scheduling visits never needs the data. In Herarx the identifiable half is a participant sub-case under Advanced Security — encrypted with its own key, invisible to non-members, including workspace admins — and the study ID is a plain field on it. See cases as study records.

Name the people who can see identifiable data

Two or three, by name and role, and enforce it in the system — per-record access, not a folder permission everyone was added to "for now". When a student joins or leaves, access changes on the record, and the audit log shows it.

Collect consent so it can be found in 2035

A consent form on the participant's own record, with the version of the form they signed and the date. Electronic signature with email verification gives you the signer, the time and a tamper-evident document in one step, and re-consent after an amendment is a second request on the same record. Paper forms are scanned to the record and their physical location noted.

Log access

Who opened which participant record, when. A system-written, uneditable log — see what an audit trail is — is what turns "only named staff accessed it" from a promise into a demonstrable fact.

Devices and the field

Data collected on a tablet or phone should go into the record system at collection, not sit on the device. If the device must hold data temporarily, it is encrypted, passcoded, and wiped on a schedule. Lost-device procedure written down and tested: revoke its session, confirm nothing was stored locally.

Sharing with collaborators

Collaborators get access to what they need on the system — the pseudonymised data, or specific records — through their own verified accounts. Not an emailed export. The same rule as for any sensitive document: give access, don't send copies.

Destruction on schedule

Identifiable data has a shorter life than the study data; the ethics application says when. Put that date on the study record so it triggers a review, and destroy through a process that logs what was destroyed and when. Keep the pseudonymised data for the retention period the funder requires. See how long to keep a closed case.

The annual check

Once a year, with the ethics application open: who can see identifiable data today (does it match the list?), when was access last reviewed, is the destruction date still right, has the restore of the backup been tested. An hour, and the application stays true.