Skip to content
StudyDex
Research Ethics (CITI)

To Minimize Potential Risks of Harm, a Researcher Conducting an Online Survey Can:

Quick answer

Design the survey so that no direct or indirect identifiers are collected, keeping responses anonymous. This protects participants' privacy and confidentiality and greatly reduces the harm that could result from a data breach or subpoena of the records.

The answer

The best way for a researcher to minimize potential risks of harm in an online survey is to not collect any personally identifying information in the first place. When a survey captures no direct identifiers (name, email, Social Security number, IP address) and no indirect identifiers (a combination of ZIP code, birth date, job title, or other quasi-identifiers that could re-identify someone), the data are effectively anonymous. If there is no link between a response and a real person, then even a hacked database, a lost laptop, or a legal subpoena cannot expose who said what. Anonymity removes the risk at its source rather than trying to guard against it after the fact.

This is the option CITI and IRB training reward because it reflects the ethical principle of minimizing risk: the strongest control is one that makes a harmful disclosure impossible, not merely unlikely.

Privacy vs. confidentiality

CITI modules stress that privacy and confidentiality are not the same thing. Privacy is about the participant's control over access to themselves and their information during data collection. Confidentiality is about how the researcher handles and protects the data after they are collected. An online survey can protect privacy by letting people respond alone, at their own pace, without an interviewer present; it protects confidentiality through encryption, restricted access, coded data, and secure storage. Anonymity is the strongest form of confidentiality protection because there is no identifiable data to safeguard.

Why the weaker choices fall short

Other commonly listed options only reduce risk partially. Collecting identifiers but promising to keep them secure still leaves an identifiable dataset that can be breached, subpoenaed, or accidentally disclosed. Storing data on a password-protected personal computer is a confidentiality measure, but a stolen device or malware can defeat it, and it does nothing if the file itself contains names. Sharing preliminary results with colleagues or using a free, unvetted survey platform can actually increase exposure. These approaches manage risk downstream; designing out the identifiers eliminates it upstream.

A practical risk-minimization checklist

Even when some identifiers are unavoidable, researchers layer protections: disable IP-address and metadata logging in the survey tool, use SSL/HTTPS encryption for transmission, separate any contact list (for incentives) from the response data, use a coded ID instead of a name, store data on institutionally approved secure servers, and delete identifiers as soon as they are no longer needed. For a study to move from identifiable to anonymous in the eyes of an IRB, there must be no reasonable way to link a response back to a participant. That is why the anonymity-by-design answer is the strongest of all.

Walk the decision
  1. 1

    Does the survey collect a name, email, or IP address?

    These are direct identifiers. Disable IP/metadata logging and drop name/email fields to move toward anonymity.

  2. 2

    Could combined answers (ZIP + birthdate + job) re-identify someone?

  3. 3

    Are responses transmitted and stored securely?

  4. 4

    Is any contact list kept separate from responses?

Frequently asked

What is the difference between anonymity and confidentiality in research?

Anonymity means the researcher collects no information that could identify a participant, so responses cannot be linked to any individual. Confidentiality means identifiers may be collected but the researcher takes steps to protect them from disclosure. Anonymity is the stronger protection because there is no identifiable data to leak.

How can researchers minimize risk in online surveys?

The strongest step is to design the survey so no direct or indirect identifiers are gathered. Additional safeguards include disabling IP logging, using HTTPS encryption, storing data on approved secure servers, separating any contact list from responses, and deleting identifiers as soon as they are no longer needed.

What are direct and indirect identifiers?

Direct identifiers name a person outright, such as full name, email, phone number, Social Security number, or IP address. Indirect (or quasi-) identifiers are pieces like ZIP code, birth date, gender, or job title that seem harmless alone but can re-identify someone when combined.

Does an online survey need IRB approval?

Usually yes, if it involves human subjects and is conducted or funded by an institution. Truly anonymous, minimal-risk surveys may qualify for exempt or expedited review, but the IRB, not the researcher, makes that determination before data collection begins.

Start freeLog in