2.4 Confidentiality, Privacy & Protection of Participant Personal Information

Key Takeaways

  • ICH E6(R3) Principle 1.6 requires that the confidentiality of information that could identify participants be protected in accordance with applicable privacy and data protection requirements.
  • Privacy is the participant’s right to control disclosure; confidentiality is the obligation the trial team accepts once information has been disclosed to it.
  • The subject identification code list is the only record that links a participant’s code to their identity, and it stays under the investigator’s control at the site rather than being sent to the sponsor.
  • Informed consent — not the clinical trial agreement — is the instrument that authorises monitors, auditors, IRB/IEC and regulatory authorities to have direct access to a participant’s original medical records.
  • ICH E6(R3) Annex 1 section 4.3.3 requires security controls across the whole data life cycle, including user management, authentication, and measures to prevent, detect and mitigate breaches.
Last updated: August 2026

Confidentiality, Privacy & Protection of Participant Personal Information

Quick Reference: Privacy is the participant's right to decide what personal information is disclosed and to whom. Confidentiality is the duty the trial team assumes once that information has been disclosed to it. Data protection is the set of technical and organisational controls that make the duty real. ICH E6(R3) addresses all three: Principle 1.6 (confidentiality of identifying information), Principle 9.4 (record integrity, traceability and protection of personal information) and Annex 1 section 4 (Data Governance).

Why this is tested

The ACRP-CP Exam Content Outline lists "Confidentiality and privacy" as a knowledge statement in Domain 1 (Ethical and Participant Safety Considerations) and "Data quality systems and privacy principles" in Domain 5 (Research Design and Data Management). The exam does not test any single country's privacy statute — it tests whether you can apply the principle when it collides with something else the protocol also requires, which is almost always direct access for monitoring, audit or inspection.


The three concepts, precisely

ConceptWhose interestWhat it means operationally
PrivacyThe participant'sThe individual decides what is disclosed, to whom and for what purpose. Expressed through the informed consent process.
ConfidentialityThe trial team's dutyInformation already disclosed will not be released to unauthorised parties. Survives the participant's withdrawal and the end of the trial.
Data protectionThe system's controlsAccess control, authentication, encryption, secure transfer, retention limits, secure destruction. E6(R3) Annex 1 section 4.3.3.

Exam Watchout: A participant who withdraws consent ends future data collection, but does not erase data already collected. Data already generated remain part of the trial record precisely because integrity and the reliability of results (Principle 9) depend on them. Confidentiality obligations continue to apply to those retained data.


Coding, pseudonymisation and anonymisation

Almost all clinical trial data are coded (pseudonymised), not anonymised. Understanding the difference is a recurring item:

TermDefinitionRe-identification possible?
IdentifiableContains direct identifiers such as name, address, full date of birth, medical record numberDirectly
Coded / pseudonymisedDirect identifiers replaced by a participant code (e.g. 104-0032); a separate key links code to identityYes — by whoever holds the key
AnonymisedThe key has been destroyed and no reasonable means of re-identification remainsNo

The subject identification code list

This is the single most exam-relevant confidentiality record.

  • It is the only document that links the participant identification code to the participant's identity.
  • It is retained by the investigator/institution as part of the essential records and stays at the site.
  • It is not transmitted to the sponsor. The sponsor works with coded data.
  • A monitor may view it on site to verify that the participant exists and that eligibility and consent were properly documented, but does not copy or remove it.

Related site-held records with the same handling: the screening log, the enrolment log, and signed informed consent forms.


Reconciling confidentiality with direct access

Candidates often treat "direct access to source records" and "confidentiality" as contradictory. They are not, because the participant authorised the access.

Participant reads and signs the ICF
        │
        ├─► Authorises the investigator to grant DIRECT ACCESS to original medical
        │   records to: the monitor, the auditor, the IRB/IEC, and regulatory authorities
        │
        └─► Retains the promise that the participant will NOT be personally identified
            in any publication or report arising from the trial

Three rules follow:

  1. The ICF is the authorising instrument. If the consent form does not describe direct access, monitoring cannot proceed against that participant's records — the clinical trial agreement cannot substitute for the participant's own permission.
  2. Access is on site and is read-only in effect. Monitors review original records; they do not remove or retain identifiable copies.
  3. Any copy that must leave the site is redacted. If a source document (an ECG tracing, a radiology report, a discharge summary) has to be sent to the sponsor as supporting evidence, direct identifiers are obscured and the participant code is added before it leaves.

Exam Watchout: A sponsor asking a coordinator to email an unredacted operative note to support an SAE narrative is asking for a confidentiality breach, no matter how urgent the safety question. Redact, apply the participant code, and send by the secure route named in the monitoring or safety plan.


What E6(R3) requires of the systems themselves

Annex 1 section 4.3 governs computerised systems used in trials, and the confidentiality-relevant obligations are concrete:

E6(R3) referenceRequirement
4.3.3 SecuritySecurity of trial data and records managed throughout the data life cycle; controls include user management and ongoing measures to prevent, detect and mitigate security breaches; consideration of authentication and password management, firewalls, antivirus, security patching, system monitoring and penetration testing; adequate backup must be maintained
4.3.8 User managementAccess rights granted, reviewed and revoked in line with the individual's actual role
4.2.5 Data transfer, exchange and migrationTransfers must preserve integrity — this is where insecure email and unencrypted media fail
4.2.7 / 4.2.8 Retention and access; destructionPersonal information is retained only as long as required and then destroyed securely

Site-level practice that satisfies these: individual named accounts with no shared logins, prompt deactivation when a staff member leaves the study, locked cabinets for paper source and consent forms, screen locks, and encryption of any portable media.


National frameworks — context, not exam content

You will meet the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in the European Economic Area, and your site's SOPs will reference whichever applies. ACRP states that the exam is referenced only to ICH guidelines and that no country-specific framework is tested. Learn them for your job; on exam day, reason from Principle 1.6, Principle 9.4 and Annex 1 section 4 instead.


Handling a breach

  1. Contain — recover or delete the misdirected information, revoke the exposed access.
  2. Assess — which participants, which data elements, identifiable or coded, who received it.
  3. Document — record the event contemporaneously in the site file, not in the participant's medical record.
  4. Notify — the sponsor and the IRB/IEC per their reporting requirements, plus any notification the applicable data protection framework requires.
  5. Investigate and correct — root cause analysis and corrective and preventive action (CAPA), because Principle 6.3 requires strategies that prevent recurrence, not just repair.

Realistic exam scenario

Scenario: A coordinator maintains the subject identification code list in a shared spreadsheet on the institution's network drive so that the on-call physician can identify trial participants after hours. The folder is accessible to the entire cardiology department, including staff with no role in the trial. During a routine monitoring visit the monitor discovers this and also finds that the departmental secretary, who is not on the delegation log, has been entering visit dates into the spreadsheet.

Evaluation:

  • Principle 1.6 is breached: identifying information is accessible to individuals with no trial role and no authorisation from the participants.
  • Annex 1 section 4.3.3 and 4.3.8 are breached: there is no meaningful user management, and access has not been limited to those who need it.
  • Principle 10 and the delegation record are also implicated — an individual not delegated a trial activity has been performing one.
  • Correct actions: restrict the folder to named delegated staff immediately; preserve the audit trail evidence of who accessed it; document the deviation; notify the sponsor and IRB/IEC per their reporting requirements; raise a CAPA that establishes a permission-controlled location and a periodic access review. The legitimate after-hours need is met by giving the on-call physician a defined, documented route to the investigator, not by widening access to the code list.
Loading diagram...
Who May See What: Identifiable versus Coded Participant Data
Test Your Knowledge

A sponsor’s data manager emails the site asking for the subject identification code list so that the sponsor can independently confirm that no participant was enrolled at two sites. What is the correct response?

A
B
C
D
Test Your Knowledge

Which instrument authorises a monitor to review a participant’s original hospital medical record during a monitoring visit?

A
B
C
D
Test Your Knowledge

A participant withdraws consent at week 12 of a 52-week trial and asks that "all my information be deleted." Under ICH E6(R3), what happens to the data already collected?

A
B
C
D