2.4 Confidentiality, Privacy & Protection of Participant Personal Information
Key Takeaways
- ICH E6(R3) Principle 1.6 requires that the confidentiality of information that could identify participants be protected in accordance with applicable privacy and data protection requirements.
- Privacy is the participant’s right to control disclosure; confidentiality is the obligation the trial team accepts once information has been disclosed to it.
- The subject identification code list is the only record that links a participant’s code to their identity, and it stays under the investigator’s control at the site rather than being sent to the sponsor.
- Informed consent — not the clinical trial agreement — is the instrument that authorises monitors, auditors, IRB/IEC and regulatory authorities to have direct access to a participant’s original medical records.
- ICH E6(R3) Annex 1 section 4.3.3 requires security controls across the whole data life cycle, including user management, authentication, and measures to prevent, detect and mitigate breaches.
Confidentiality, Privacy & Protection of Participant Personal Information
Quick Reference: Privacy is the participant's right to decide what personal information is disclosed and to whom. Confidentiality is the duty the trial team assumes once that information has been disclosed to it. Data protection is the set of technical and organisational controls that make the duty real. ICH E6(R3) addresses all three: Principle 1.6 (confidentiality of identifying information), Principle 9.4 (record integrity, traceability and protection of personal information) and Annex 1 section 4 (Data Governance).
Why this is tested
The ACRP-CP Exam Content Outline lists "Confidentiality and privacy" as a knowledge statement in Domain 1 (Ethical and Participant Safety Considerations) and "Data quality systems and privacy principles" in Domain 5 (Research Design and Data Management). The exam does not test any single country's privacy statute — it tests whether you can apply the principle when it collides with something else the protocol also requires, which is almost always direct access for monitoring, audit or inspection.
The three concepts, precisely
| Concept | Whose interest | What it means operationally |
|---|---|---|
| Privacy | The participant's | The individual decides what is disclosed, to whom and for what purpose. Expressed through the informed consent process. |
| Confidentiality | The trial team's duty | Information already disclosed will not be released to unauthorised parties. Survives the participant's withdrawal and the end of the trial. |
| Data protection | The system's controls | Access control, authentication, encryption, secure transfer, retention limits, secure destruction. E6(R3) Annex 1 section 4.3.3. |
Exam Watchout: A participant who withdraws consent ends future data collection, but does not erase data already collected. Data already generated remain part of the trial record precisely because integrity and the reliability of results (Principle 9) depend on them. Confidentiality obligations continue to apply to those retained data.
Coding, pseudonymisation and anonymisation
Almost all clinical trial data are coded (pseudonymised), not anonymised. Understanding the difference is a recurring item:
| Term | Definition | Re-identification possible? |
|---|---|---|
| Identifiable | Contains direct identifiers such as name, address, full date of birth, medical record number | Directly |
| Coded / pseudonymised | Direct identifiers replaced by a participant code (e.g. 104-0032); a separate key links code to identity | Yes — by whoever holds the key |
| Anonymised | The key has been destroyed and no reasonable means of re-identification remains | No |
The subject identification code list
This is the single most exam-relevant confidentiality record.
- It is the only document that links the participant identification code to the participant's identity.
- It is retained by the investigator/institution as part of the essential records and stays at the site.
- It is not transmitted to the sponsor. The sponsor works with coded data.
- A monitor may view it on site to verify that the participant exists and that eligibility and consent were properly documented, but does not copy or remove it.
Related site-held records with the same handling: the screening log, the enrolment log, and signed informed consent forms.
Reconciling confidentiality with direct access
Candidates often treat "direct access to source records" and "confidentiality" as contradictory. They are not, because the participant authorised the access.
Participant reads and signs the ICF
│
├─► Authorises the investigator to grant DIRECT ACCESS to original medical
│ records to: the monitor, the auditor, the IRB/IEC, and regulatory authorities
│
└─► Retains the promise that the participant will NOT be personally identified
in any publication or report arising from the trial
Three rules follow:
- The ICF is the authorising instrument. If the consent form does not describe direct access, monitoring cannot proceed against that participant's records — the clinical trial agreement cannot substitute for the participant's own permission.
- Access is on site and is read-only in effect. Monitors review original records; they do not remove or retain identifiable copies.
- Any copy that must leave the site is redacted. If a source document (an ECG tracing, a radiology report, a discharge summary) has to be sent to the sponsor as supporting evidence, direct identifiers are obscured and the participant code is added before it leaves.
Exam Watchout: A sponsor asking a coordinator to email an unredacted operative note to support an SAE narrative is asking for a confidentiality breach, no matter how urgent the safety question. Redact, apply the participant code, and send by the secure route named in the monitoring or safety plan.
What E6(R3) requires of the systems themselves
Annex 1 section 4.3 governs computerised systems used in trials, and the confidentiality-relevant obligations are concrete:
| E6(R3) reference | Requirement |
|---|---|
| 4.3.3 Security | Security of trial data and records managed throughout the data life cycle; controls include user management and ongoing measures to prevent, detect and mitigate security breaches; consideration of authentication and password management, firewalls, antivirus, security patching, system monitoring and penetration testing; adequate backup must be maintained |
| 4.3.8 User management | Access rights granted, reviewed and revoked in line with the individual's actual role |
| 4.2.5 Data transfer, exchange and migration | Transfers must preserve integrity — this is where insecure email and unencrypted media fail |
| 4.2.7 / 4.2.8 Retention and access; destruction | Personal information is retained only as long as required and then destroyed securely |
Site-level practice that satisfies these: individual named accounts with no shared logins, prompt deactivation when a staff member leaves the study, locked cabinets for paper source and consent forms, screen locks, and encryption of any portable media.
National frameworks — context, not exam content
You will meet the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in the European Economic Area, and your site's SOPs will reference whichever applies. ACRP states that the exam is referenced only to ICH guidelines and that no country-specific framework is tested. Learn them for your job; on exam day, reason from Principle 1.6, Principle 9.4 and Annex 1 section 4 instead.
Handling a breach
- Contain — recover or delete the misdirected information, revoke the exposed access.
- Assess — which participants, which data elements, identifiable or coded, who received it.
- Document — record the event contemporaneously in the site file, not in the participant's medical record.
- Notify — the sponsor and the IRB/IEC per their reporting requirements, plus any notification the applicable data protection framework requires.
- Investigate and correct — root cause analysis and corrective and preventive action (CAPA), because Principle 6.3 requires strategies that prevent recurrence, not just repair.
Realistic exam scenario
Scenario: A coordinator maintains the subject identification code list in a shared spreadsheet on the institution's network drive so that the on-call physician can identify trial participants after hours. The folder is accessible to the entire cardiology department, including staff with no role in the trial. During a routine monitoring visit the monitor discovers this and also finds that the departmental secretary, who is not on the delegation log, has been entering visit dates into the spreadsheet.
Evaluation:
- Principle 1.6 is breached: identifying information is accessible to individuals with no trial role and no authorisation from the participants.
- Annex 1 section 4.3.3 and 4.3.8 are breached: there is no meaningful user management, and access has not been limited to those who need it.
- Principle 10 and the delegation record are also implicated — an individual not delegated a trial activity has been performing one.
- Correct actions: restrict the folder to named delegated staff immediately; preserve the audit trail evidence of who accessed it; document the deviation; notify the sponsor and IRB/IEC per their reporting requirements; raise a CAPA that establishes a permission-controlled location and a periodic access review. The legitimate after-hours need is met by giving the on-call physician a defined, documented route to the investigator, not by widening access to the code list.
A sponsor’s data manager emails the site asking for the subject identification code list so that the sponsor can independently confirm that no participant was enrolled at two sites. What is the correct response?
Which instrument authorises a monitor to review a participant’s original hospital medical record during a monitoring visit?
A participant withdraws consent at week 12 of a 52-week trial and asks that "all my information be deleted." Under ICH E6(R3), what happens to the data already collected?