Ethics in practice
Consent as ongoing, the difference between anonymisation and pseudonymisation, retention windows, and when AI assistance becomes a participant-data question.
Consent as ongoing
The version of consent that most ethics applications describe — signed once, archived in a folder, referenced in the methods section — is the version of consent that’s least defensible. Qualitative research participants are consenting to a kind of relationship, not a transaction, and that relationship unfolds in ways that the participant cannot fully anticipate at signing.
The British Psychological Society’s Code of Human Research Ethics (2021) frames consent as a process, not an event. The practical reading: a participant who agreed in the recruitment interview to talk about “experiences in higher education” has not, by virtue of that initial agreement, consented to a specific anecdote about a colleague being included in a published paper. Re-consent at publication is the disciplined response; the alternative is the academic-press version of an HR investigation that the participant didn’t know they were enabling.
The disciplined practice has four moves:
- Consent at recruitment covers participation, recording, and retention. Make the retention window explicit (see below) and time-bounded.
- Renewable consent at any unanticipated use beyond the original protocol — a secondary analysis, a conference talk, a book chapter, a teaching example.
- Right to withdraw not just from future participation but from the existing dataset, with a clear cutoff (typically until anonymisation is complete and the dataset is locked).
- An accessible record of what each participant consented to, version-controlled. If you cannot produce, on request, the precise consent text the participant signed and the date of any subsequent re-consent, the consent record is not actually a record.
Anonymisation, properly
The terminological confusion is worth getting right: anonymisation is the irreversible removal of identifying information such that re-identification is not reasonably possible by any party. Pseudonymisation is the replacement of direct identifiers with a coded value while the re-identification key is held separately. The two are governed differently — pseudonymised data is still personal data under GDPR Article 4(5); fully anonymised data falls outside GDPR’s scope. Most qualitative datasets that describe themselves as “anonymised” are, technically, pseudonymised, and the methods section should say so.
What anonymisation actually requires for interview data:
- Direct identifiers removed — names, addresses, dates of birth, phone numbers, email addresses, NHS / SSN numbers.
- Indirect identifiers altered or generalised — job titles narrowed to sector, employer disguised, distinctive geographic detail generalised, distinctive biographical events (the specific clinical procedure, the unique role, the named research project) softened or omitted.
- Within-corpus deduplication. If two transcripts contain enough overlapping detail that cross-referencing them would re-identify either participant, that’s a re-identification risk that removing first names doesn’t fix.
- Test against motivated re-identification. Ask: could a person who already knew the participant identify them from a published quote? If yes, the quote needs further alteration or shouldn’t be quoted verbatim.
The ICO’s Anonymisation Code of Practice uses the “motivated intruder” test as the threshold: a reasonably competent person, motivated to re-identify, with access to publicly available resources, should not be able to do so. For qualitative interview data, the motivated intruder is often a colleague of the participant. Plan accordingly.
Retention windows
GDPR Article 5(1)(e) requires personal data to be retained no longer than necessary for the purposes for which it was processed. For qualitative research data, the “necessary” period is usually longer than the active analysis (because of journal verification requests, replication, secondary analysis) and bounded by the consent terms.
Common defensible patterns:
- Audio recordings: destroyed within 6–12 months of transcription, unless the audio itself is analytically necessary (e.g. paralinguistic features in conversation analysis).
- Pseudonymised transcripts: retained for the funder/institution’s minimum (often 10 years in UK research), then either fully anonymised and archived, or destroyed.
- Re-identification keys (the participant ID ↔ pseudonym mapping): destroyed at the earliest defensible point, typically once analysis is complete and no foreseeable need to contact participants remains. Keeping the key longer than the dataset is a common protocol violation.
- Consent forms: retained for the same minimum period as the data they consent to, stored separately from the data.
The AI-assistance question
AI-assisted coding raises an ethics question that the 2010s qualitative methods textbooks didn’t have to answer: when the analyst’s working tool is a third-party large language model, what obligations follow about the data sent to it?
Three pieces of the question matter:
1. Data transmission. Sending a transcript excerpt to a model provider is a transfer of (typically pseudonymised) personal data to a processor. Under GDPR, that requires a lawful basis, a Data Processing Agreement with the provider, and disclosure to participants either in the original consent form or via re-consent. Most ethics applications written before 2023 do not cover this. They need amending before AI assistance is used.
2. Training-data use. If the model provider may use submitted data to train future models, that is a disclosure that has to be in the consent form, and is in most cases a disclosure that participants would refuse. Use providers and tiers that contractually exclude submitted data from training. QualCanvas’s AI calls are routed through providers contracted on zero-data-retention terms; see trust/ai.
3. The interpretive responsibility. A code suggested by a model and accepted by an analyst is, ethically, the analyst’s code. The methods section should not describe AI-suggested codes as if they were a separate authorial voice. The audit trail should record which codes were AI-suggested; the analytical responsibility remains the researcher’s.
“Researchers retain the responsibility to ensure that their conduct meets relevant ethical standards regardless of the tools they employ.”
— BPS Code of Human Research Ethics, 2021
IRB / ethics-committee patterns
Three documentation habits make ethics-committee work straightforward at submission and at amendment:
Version the consent form. Every change gets a version number and a date. The methods section names the version each participant signed. This sounds bureaucratic; it is — and the day you need to demonstrate to a committee what a participant from 14 months ago actually agreed to, you will be glad of it.
Keep an analytical audit trail. Not the codebook (that is its own artefact); a separate log of methodological decisions: when a code was merged, why an interview was excluded, when the AI assistance was disabled for a section, why a quote was paraphrased rather than quoted directly. An audit trail is the qualitative equivalent of a lab notebook. It is the document a viva panel asks for.
Document the AI usage. Which provider, which model, which feature (auto-coding, code suggestion, summarisation), what was sent, what was retained. The default UK research ethics committee position in 2026 is that AI-assisted analysis is permissible with explicit disclosure to participants and a written DPA; without those, it is not.
In QualCanvas
QualCanvas records consent state per participant, retention windows per dataset, and a per-action audit log of AI usage (provider, model, feature, token count). The DPA template at trust/ai is available for download and review by institutional legal or research-governance teams.
What QualCanvas does not do is replace the ethics committee. None of this is legal advice; the jurisdiction-specific obligations under GDPR, HIPAA, NHS Research Ethics, or your institution’s IRB are obligations on you. The tooling is here to make compliance with those obligations easier to document.
Further reading
- British Psychological Society. (2021). Code of Human Research Ethics (3rd ed.). BPS.
- Information Commissioner’s Office. (2012; revised draft 2022). Anonymisation: managing data protection risk code of practice. ICO.
- European Parliament & Council. (2016). General Data Protection Regulation (Regulation (EU) 2016/679), Articles 4(5), 5(1)(e), 6, 9, 17.
- Iphofen, R. (Ed.). (2020). Handbook of Research Ethics and Scientific Integrity. Springer.
- Saldaña, J. (2021). The Coding Manual for Qualitative Researchers (4th ed.). SAGE. Chapter 2 on ethics in coding decisions.
- Mantelero, A. (2023). The Council of Europe and AI in research: Human Rights Impact Assessment of AI systems. CoE.
- World Medical Association. (2013, amended 2024). Declaration of Helsinki. WMA.
This chapter is in draft and is not legal advice. It has not yet been peer-reviewed by an external methodologist or by qualified legal counsel. Reviewer contact: [email protected].