Research Ethics
Protecting Research Participants: A Practical Guide
What participant protection actually requires once the recorder starts running โ consent, confidentiality, de-identification, and the vendors you trust with your data.
Where the Obligation Comes From
In Australia, participant protection is governed by the NHMRC National Statement on Ethical Conduct in Human Research, which is why HREC review exists. Its values echo the principles that anchor human research protection internationally, and most institutions require researchers โ and increasingly their vendors โ to complete human research participant protection (PHRP or equivalent) training. Three principles do the work:
Respect for persons
Participants are volunteers, not data sources. They must understand what the study involves โ including who will hear their recordings and read their transcripts โ and agree to it freely. That is why consent language should name recording, transcription, and any third parties involved.
Beneficence
Maximise benefit, minimise harm. In qualitative research the most likely harm is a confidentiality breach โ a participant being identifiable from what they said. Encryption, access controls, and de-identification are beneficence in practice.
Justice
The burdens and benefits of research should be fairly distributed. Participant selection should not exploit convenient or vulnerable populations, and findings should serve the communities that contributed their voices.
Why Qualitative Data Carries Particular Risk
A survey response is a row of numbers. An interview recording is a person's voice describing their own life โ often naming their town, their employer, their diagnosis, their family. Even after names are removed, the combination of details in rich qualitative data can make a participant recognisable to anyone who knows them. That is why ethics committees treat recordings and transcripts as identifiable data by default, and why the handling chain โ every laptop, inbox, and vendor the files pass through โ is part of your protocol, not an implementation detail.
A Working Checklist for Your Data Handling Chain
Consent covers the full data path
Your consent form should state that sessions are recorded, that a professional transcription service may transcribe them, and how long recordings are kept. Ethics committees flag consent language that stops at "your responses will be kept confidential."
Agreements are in place before files move
Any vendor touching identifiable data should sign a confidentiality agreement or NDA โ and a data processing agreement as required; for US-collaborative research we can also sign a Business Associate Agreement (BAA).
Files travel and rest encrypted
Email attachments are not a transfer plan. Use an encrypted upload platform, and confirm data is encrypted at rest as well as in transit.
Access is restricted to trained people
Only staff who need a file to do their work should be able to open it โ and those staff should hold current human-subjects protection training (PHRP or equivalent).
Transcripts are de-identified before sharing
Names, places, dates, and other identifiers should be removed or replaced with consistent pseudonyms before transcripts are shared beyond the core team, archived, or deposited. De-identification logs give your ethics file an audit trail.
Documentation exists for your ethics committee
Security summaries, staff training certificates, and signed agreements โ collected once, reused in every application. If a vendor cannot produce them, that is your answer.
Where Landmark Fits In
Landmark has transcribed for university research teams since 1987, and the parts of participant protection that touch transcription are built into how we work: our staff complete human research participant protection (PHRP) and privacy training, files move through an encrypted platform with strict access controls, we sign NDAs and confidentiality deeds (we have agreements in place with many universities), and de-identification is included free with every transcription project. For your ethics file, we provide HREC-ready security documentation on request.