Methodology · Chapter 6.0

Ethics in practice

Consent as ongoing, the difference between anonymisation and pseudonymisation, retention windows, and when AI assistance becomes a participant-data question.

9 min read · Updated May 2026

In this chapter
  1. Consent as ongoing
  2. Anonymisation, properly
  3. Retention windows
  4. The AI-assistance question
  5. IRB / ethics-committee patterns
  6. In QualCanvas
  7. Further reading

Anonymisation, properly

The terminological confusion is worth getting right: anonymisation is the irreversible removal of identifying information such that re-identification is not reasonably possible by any party. Pseudonymisation is the replacement of direct identifiers with a coded value while the re-identification key is held separately. The two are governed differently — pseudonymised data is still personal data under GDPR Article 4(5); fully anonymised data falls outside GDPR’s scope. Most qualitative datasets that describe themselves as “anonymised” are, technically, pseudonymised, and the methods section should say so.

What anonymisation actually requires for interview data:

The ICO’s Anonymisation Code of Practice uses the “motivated intruder” test as the threshold: a reasonably competent person, motivated to re-identify, with access to publicly available resources, should not be able to do so. For qualitative interview data, the motivated intruder is often a colleague of the participant. Plan accordingly.

Retention windows

GDPR Article 5(1)(e) requires personal data to be retained no longer than necessary for the purposes for which it was processed. For qualitative research data, the “necessary” period is usually longer than the active analysis (because of journal verification requests, replication, secondary analysis) and bounded by the consent terms.

Common defensible patterns:

The AI-assistance question

AI-assisted coding raises an ethics question that the 2010s qualitative methods textbooks didn’t have to answer: when the analyst’s working tool is a third-party large language model, what obligations follow about the data sent to it?

Three pieces of the question matter:

1. Data transmission. Sending a transcript excerpt to a model provider is a transfer of (typically pseudonymised) personal data to a processor. Under GDPR, that requires a lawful basis, a Data Processing Agreement with the provider, and disclosure to participants either in the original consent form or via re-consent. Most ethics applications written before 2023 do not cover this. They need amending before AI assistance is used.

2. Training-data use. If the model provider may use submitted data to train future models, that is a disclosure that has to be in the consent form, and is in most cases a disclosure that participants would refuse. Use providers and tiers that contractually exclude submitted data from training. QualCanvas’s AI calls are routed through providers contracted on zero-data-retention terms; see trust/ai.

3. The interpretive responsibility. A code suggested by a model and accepted by an analyst is, ethically, the analyst’s code. The methods section should not describe AI-suggested codes as if they were a separate authorial voice. The audit trail should record which codes were AI-suggested; the analytical responsibility remains the researcher’s.

“Researchers retain the responsibility to ensure that their conduct meets relevant ethical standards regardless of the tools they employ.”

— BPS Code of Human Research Ethics, 2021

IRB / ethics-committee patterns

Three documentation habits make ethics-committee work straightforward at submission and at amendment:

Version the consent form. Every change gets a version number and a date. The methods section names the version each participant signed. This sounds bureaucratic; it is — and the day you need to demonstrate to a committee what a participant from 14 months ago actually agreed to, you will be glad of it.

Keep an analytical audit trail. Not the codebook (that is its own artefact); a separate log of methodological decisions: when a code was merged, why an interview was excluded, when the AI assistance was disabled for a section, why a quote was paraphrased rather than quoted directly. An audit trail is the qualitative equivalent of a lab notebook. It is the document a viva panel asks for.

Document the AI usage. Which provider, which model, which feature (auto-coding, code suggestion, summarisation), what was sent, what was retained. The default UK research ethics committee position in 2026 is that AI-assisted analysis is permissible with explicit disclosure to participants and a written DPA; without those, it is not.

In QualCanvas

QualCanvas records consent state per participant, retention windows per dataset, and a per-action audit log of AI usage (provider, model, feature, token count). The DPA template at trust/ai is available for download and review by institutional legal or research-governance teams.

What QualCanvas does not do is replace the ethics committee. None of this is legal advice; the jurisdiction-specific obligations under GDPR, HIPAA, NHS Research Ethics, or your institution’s IRB are obligations on you. The tooling is here to make compliance with those obligations easier to document.

Further reading

This chapter is in draft and is not legal advice. It has not yet been peer-reviewed by an external methodologist or by qualified legal counsel. Reviewer contact: [email protected].

Try QualCanvas free