Ethics verdicts: answer key

Introduction to Social Research Methodology

Author
Affiliation

Ben Stanley

Department of Social Sciences, SWPS University

Published

November 3, 2026

All verdicts below follow the session-4 lecture (the notes’ sections on the core principles, the cautionary tales, the manager as researcher, consent that cannot be freely refused, employee monitoring, confidentiality in small teams, customer data and the GDPR), and they agree with the answers ticked in the session-4 class poll. Two of the five verdicts, on cases C and D, are judgement calls: the model verdict is the one the poll ticks, and the alternative a group may defensibly reach is given with each.

Task 1: first impressions

There is no model answer: the point of the one-word verdicts is the comparison in Task 3. The class poll records them without ticking any option.

Do not correct first impressions when they are given. It is more useful to notice which of them lean on the proposers’ own arguments: “the contract already says the premises are monitored” (A), “the platform belongs to the company” (B), “participation is voluntary” (C), “the data already exist” (D) and “responses are completely anonymous” (E). Each of these is an argument the lecture took apart, and Task 3 asks groups to notice when analysis changed their minds.

Task 2: deliberating the cases

Case Model verdict Decisive principles Judgement call?
A. The stockroom camera Not permissible Covert observation linked to named staff; fails the covert test; lawful monitoring is not research use No
B. The chat-log study Permissible with safeguards Informed consent, purpose limitation, privacy No
C. The manager’s own survey Permissible with safeguards Power asymmetry and voluntary participation; confidentiality Yes: “not permissible in this form” is defensible
D. The recycled exit interviews Permissible with safeguards Purpose limitation; a broken confidentiality promise; data minimisation Yes: “not permissible” is defensible
E. The six-person team survey Permissible with safeguards Anonymity versus confidentiality; deductive disclosure; power asymmetry No

“Permissible as it stands” is the wrong verdict for all five cases. None of the proposals can run unchanged.

Case A: the stockroom camera

Model answer for case A: The stockroom camera Model answer for case A, the stockroom camera: not permissible. At stake: covert observation, informed consent, privacy, no harm, purpose limitation and power asymmetry. Covert watching plus records linked to whoever was on shift is exactly the Humphreys combination; the contract’s line that the premises are monitored is lawful monitoring, not a licence to study, because purpose matters. Instead: treat suspected theft as a security matter, not as research; if the board wants to understand shrinkage, study stock handling openly, with nothing linked to named staff. The covert test fails: the question is arguably important, since shrinkage has doubled, but an open design would work, the harm is not minimal because footage is tied to named staff, and no disclosure is planned. What could go wrong: an assistant who happened to be on shift during a coded irregularity is treated as a suspect, on footage she never knew existed. A The stockroom camera NOT PERMISSIBLE AT STAKE covert observation informed consent privacy no harm purpose limitation power asymmetry Covert watching plus records linked to whoever was on shift: exactly the Humphreys combination. “The contract says the premises are monitored” is lawful monitoring, not a licence to study — purpose matters. WHAT COULD GO WRONG An assistant who happened to be on shift during a coded “irregularity” is treated as a suspect — on footage she never knew existed. INSTEAD Treat suspected theft as a security matter, not as research. If the board wants to understand shrinkage, study stock handling openly, with nothing linked to named staff. THE COVERT TEST: IT FAILS Important question? Arguably — shrinkage has doubled. No open design would work? No. Harm minimal? No: footage is tied to named staff. Disclosure follows? No: none is planned.
Figure 1: Model answer for case A: not permissible.

Figure 1 summarises the verdict, the principles at stake, what to do instead and the covert test.

Verdict: not permissible.

Principles at stake. This is covert observation of employees, and covert observation inherits the full burden of justification the lecture set for deception. It fails that test (see Task 4). Worse, the footage is to be coded against “which employee is on shift”, so covert watching is joined to identifiable records: exactly the combination the lecture drew from Tearoom Trade, where a passing intrusion becomes a permanent, attributable file. The staff have given no informed consent, their privacy is breached, and the risk of harm is economic and serious, since a named employee can be suspected of theft on ambiguous footage. The manager’s two arguments both fail. “If we announce it, behaviour will change” is the methodological bind that the lecture accepts only when every other condition is also met, and here they are not. “The employment contract already says the premises are monitored” confuses lawful monitoring with research use: “the employer may monitor” does not mean “the researcher may study”, which is purpose limitation. The regional manager also holds power over the people being watched (power asymmetry).

Safeguards. None rescue this proposal as research, because what it is designed to do is identify individuals covertly. Suspected theft is a security matter for Meridian’s lawful monitoring, not a research question for the research team. If the board wants to understand why shrinkage has doubled, that is a different study: one that examines stock handling openly, with nothing linked to named staff.

What could go wrong. An assistant who happened to be on shift during a coded “irregularity” is treated as a suspect, on footage she never knew existed.

Marking note. Groups that answer “permissible with safeguards: announce the cameras and stop linking footage to individuals” have in fact designed a different, open study. Credit the redesign, but the verdict on the proposal as written stays “not permissible”.

Case B: the chat-log study

Model answer for case B: The chat-log study Model answer for case B, the chat-log study: permissible with safeguards. At stake: informed consent, purpose limitation, privacy, covert observation, data minimisation and, arguably, no harm. It is the lecture’s own test case: messages written to do a job were never offered for research, and reporting patterns, not individuals, protects only the report, because the analyst still reads every message in full. Safeguards: announce the study and ask for consent; export only what the question needs; anonymise and aggregate before analysis, with codes, not names; report team-level patterns only. The cure for covert research is to make it overt: announced, consented to and anonymised before anyone reads it, the study is no longer covert at all. What could go wrong: a cashier’s private complaint about her store manager, read in full by the analyst, finds its way back to the manager. B The chat-log study PERMISSIBLE WITH SAFEGUARDS AT STAKE informed consent purpose limitation privacy covert observation data minimisation no harm (arguably) The lecture’s own test case. Messages written to do a job were never offered for research, and “patterns, not individuals” protects only the report: the analyst still reads every message in full. WHAT COULD GO WRONG A cashier’s private complaint about her store manager, read in full by the analyst, finds its way back to the manager. SAFEGUARDS Announce the study and ask for consent; export only what the question needs; anonymise and aggregate before analysis — codes, not names; report team-level patterns only. THE CURE FOR COVERT RESEARCH Make it overt. Announced, consented to and anonymised before anyone reads it, the study is no longer covert at all.
Figure 2: Model answer for case B: permissible with safeguards.

Figure 2 gives the verdict, the principles at stake, the safeguards and the lecture’s cure for covert research.

Verdict: permissible with safeguards.

Principles at stake. This is the lecture’s own test case (“studying ‘team communication’ by silently reading the team’s chat history”), and the lecture’s answer applies directly: it breaches informed consent, purpose limitation and privacy, and arguably no harm. Employees know the platform belongs to the company, but messages written to do a job were never offered for research, and silently reading them is covert observation. The analyst’s promise that the report will “only discuss patterns, not individuals” protects the report, not the people, because the analyst still reads six months of messages in full. Reading everything when the question concerns tone, response times and who talks to whom also breaches data minimisation.

Safeguards. Announce the study to the eight teams and obtain consent. Export only what the question needs. Anonymise and aggregate before analysis, replacing names with codes before anyone reads a message, and report team-level patterns only. At that point, as the lecture put it, the study is no longer covert at all: the cure for covert research is usually to make it overt.

What could go wrong. A cashier’s private complaint about her store manager, read in full by the analyst, finds its way back to the manager.

Case C: the manager’s own survey

Model answer for case C: The manager’s own survey Model answer for case C, the manager’s own survey: permissible with safeguards, a judgement call. At stake: voluntary participation, power asymmetry, confidentiality, no harm and a conflict of interest. Her 14 subordinates cannot freely refuse the person who writes their reviews, and named answers make candour risky, so the data will be biased as well as coerced; and she wants a particular answer. Safeguards: a neutral party, HR or an external researcher, invites and runs it; no named accounts; refusal invisible and without consequence; she sees only the overall store result. Also defensible: not permissible in this form, if the group argues that no safeguard makes refusal safe while she is both requester and subject. Without the words hope and expect, consent would still not be free: the constraint is the situation, not the wording, because she is still their manager and she reads named answers. What could go wrong: an assistant who rates her fairness low is followed up individually, and her shifts get worse. C The manager’s own survey PERMISSIBLE WITH SAFEGUARDS JUDGEMENT CALL AT STAKE voluntary participation power asymmetry confidentiality no harm conflict of interest Her 14 subordinates cannot freely refuse the person who writes their reviews, and named answers make candour risky: the data will be biased as well as coerced. And she wants a particular answer. WHAT COULD GO WRONG An assistant who rates her fairness low is “followed up individually” — and her shifts get worse. SAFEGUARDS A neutral party (HR or an external researcher) invites and runs it; no named accounts; refusal invisible and without consequence; she sees only the overall store result. ALSO DEFENSIBLE Not permissible in this form, if the group argues that no safeguard makes refusal safe while she is both requester and subject. WITHOUT “HOPE AND EXPECT”? Still not free. The constraint is the situation, not the wording: she is still their manager, and she reads named answers.
Figure 3: Model answer for case C: permissible with safeguards, a judgement call.

Figure 3 gives the verdict and its defensible alternative, the principles at stake, the safeguards and the answer to the plenary question about the invitation’s wording.

Verdict: permissible with safeguards (a judgement call).

Principles at stake. The requester writes the participants’ performance reviews, so this is the lecture’s plainest case of power asymmetry, and it contaminates every principle at once. Voluntary participation: all three warning signs are present, since she controls rewards and sanctions, participation is visible on named accounts, and “I hope and expect everyone will contribute” makes refusal look like disloyalty. Confidentiality: answers are named and she reads them all herself, “so I can follow up individually”. No harm: anyone who criticises her is identifiable to the person with power over their shifts and promotion. Named accounts also collect more than the question needs, which arguably breaches data minimisation. And because candour carries risk, the data will be biased as well as coerced. She also wants the data “to prove” her style works: a manager evaluating her own project has a conflict of interest.

Safeguards. These are the lecture’s three safeguards for consent that cannot be freely refused, plus one for confidentiality. A neutral party (HR or an external researcher) invites staff and runs the survey. There are no named accounts. Non-participation is invisible, with no chasing of named non-responders, and an explicit, believable statement says that refusal has no consequences. She sees only the overall result for the store. With 14 staff that result is above the common minimum cell size of ten, but any breakdown, by role or by shift, would fall below it. The “hope and expect” sentence goes.

Also defensible: not permissible in this form. The lecture’s limiting case is a tiny team, an insistent manager and a charged topic, where “refusal may never be safe”. A group that argues that no safeguard makes refusal and candour safe while she remains both the requester and the subject of the survey has reached a defensible verdict, provided it says so explicitly.

What could go wrong. An assistant who rates her fairness low is “followed up individually”, and her shifts get worse.

Case D: the recycled exit interviews

Model answer for case D: The recycled exit interviews Model answer for case D, the recycled exit interviews: permissible with safeguards, a judgement call. At stake: purpose limitation, informed consent, confidentiality, data minimisation and no harm. Leavers were told the interviews were confidential and for HR purposes only, so a board report with quotes is a new purpose and a broken promise; names and health disclosures are far more than the question needs. Safeguards: analyse anonymised transcripts, with names and health details removed, and report aggregated reasons for leaving only, with no verbatim quotes. Also defensible: not permissible, if the group holds that the original promise rules out any re-use without fresh consent. The surprise test: would the leavers be surprised to find their words in a board report? If so, a consent boundary is being crossed. What could go wrong: a leaver’s health disclosure, quoted anonymously, is recognised by the manager she criticised. D The recycled exit interviews PERMISSIBLE WITH SAFEGUARDS JUDGEMENT CALL AT STAKE purpose limitation informed consent confidentiality data minimisation no harm Leavers were told “confidential and for HR purposes only”: a board report with quotes is a new purpose and a broken promise. Names and health disclosures are far more than the question needs. WHAT COULD GO WRONG A leaver’s health disclosure, quoted “anonymously”, is recognised by the manager she criticised. SAFEGUARDS Analyse anonymised transcripts, with names and health details removed; report aggregated reasons for leaving only — no verbatim quotes. ALSO DEFENSIBLE Not permissible, if the group holds that the original promise rules out any re-use without fresh consent. THE SURPRISE TEST Would the leavers be surprised to find their words in a board report? If so, a consent boundary is being crossed.
Figure 4: Model answer for case D: permissible with safeguards, a judgement call.

Figure 4 gives the verdict and its defensible alternative, the principles at stake, the safeguards and the surprise test.

Verdict: permissible with safeguards (a judgement call).

Principles at stake. The leavers were told the interviews were “confidential and for HR purposes only”. A new study whose findings, with quotations, go to the board is a new purpose (purpose limitation), and no one has consented to it (informed consent). Quoting excerpts to the board breaks the promise of confidentiality. Calling the excerpts “anonymised” does not help: they are not anonymous to board members and managers who knew the leavers, which is deductive disclosure again. The transcripts contain names of criticised managers and health disclosures, far more than a study of why staff quit requires (data minimisation), and both the leavers and the managers they named could be harmed (no harm). The surprise test from the customer-data slide applies: would the leavers be surprised to find their words in a board report? They would, which is a sign that a consent boundary is being crossed.

Safeguards. The analysis runs on anonymised transcripts, with the names of employees and managers and all health details removed before analysis. The report gives aggregated reasons for leaving only, with no verbatim quotes. With 74 interviews the overall pattern can be reported safely, but breakdowns by store would quickly fall below a minimum cell size.

Also defensible: not permissible. A group may hold that “confidential and for HR purposes only” rules out any re-use without fresh consent, and that a promise to departing staff should not be reinterpreted once they have gone. That is a defensible verdict. Any verdict that keeps the verbatim quotes is not. Groups who argue that a turnover study is itself an “HR purpose” narrow the purpose problem but do not remove it, because the board report and the quotations still break the confidentiality promise.

What could go wrong. A leaver’s health disclosure, quoted “anonymously”, is recognised by the manager she criticised.

Case E: the six-person team survey

Model answer for case E: The six-person team survey Model answer for case E, the six-person team survey: permissible with safeguards. At stake: anonymity versus confidentiality, power asymmetry, no harm and data minimisation. In a team of six, role and tenure identify people, so the agency can honestly promise only confidentiality; and the results, with verbatim comments, go to the very supervisor being rated. Safeguards: drop the role question and the tenure breakdown; report the team only merged into a larger unit, the minimum cell size; no verbatim comments. The cover message it needed: your answers are confidential, not anonymous; the agency sees them, no one at Meridian does; results are reported only with a larger group, and comments are never quoted. More damaging: a promise made and broken, which harms those exposed and every future study, because the organisation remembers. What could go wrong: the newest member is alone in her tenure band, and her critical comment lands, verbatim, on her supervisor’s desk. E The six-person team survey PERMISSIBLE WITH SAFEGUARDS AT STAKE anonymity vs confidentiality power asymmetry no harm data minimisation In a team of six, role and tenure identify people: the agency can honestly promise only confidentiality. And the results, with verbatim comments, go to the very supervisor being rated. WHAT COULD GO WRONG The newest member is alone in her tenure band; her critical comment lands, verbatim, on her supervisor’s desk. SAFEGUARDS Drop the role question and the tenure breakdown; report the team only merged into a larger unit (minimum cell size); no verbatim comments. THE COVER MESSAGE IT NEEDED “Your answers are confidential, not anonymous: the agency sees them, no one at Meridian does. Results are reported only with a larger group; comments are never quoted.” MORE DAMAGING? A promise made and broken. It harms those exposed and every future study, because the organisation remembers.
Figure 5: Model answer for case E: permissible with safeguards.

Figure 5 gives the verdict, the principles at stake, the safeguards, the cover message the survey needed and the answer to the plenary question on broken promises.

Verdict: permissible with safeguards.

Principles at stake. The survey promises that “responses are completely anonymous”, and a six-person team cannot support that promise. In a team that small, role and tenure identify people (deductive disclosure), so the agency can honestly promise only confidentiality: it could identify respondents, but undertakes not to reveal them. Calling a confidential survey anonymous is, in the lecture’s words, itself a small deception, and consent given on a false promise is arguably not fully informed. The tenure-band breakdown and the verbatim comments make identification certain, since prose style identifies people as surely as names do. The results go to the head of digital, who is the very supervisor being rated (power asymmetry), so candid respondents risk real harm. Questions about role and tenure serve no purpose in a team of six except identification (data minimisation). Running the survey through an external agency helps with who collects the data, but not with who receives the results.

Safeguards. Drop the role question and the tenure breakdown. Report the team only merged into a larger unit, because six is below the minimum cell size. Report no verbatim comments. Promise confidentiality, not anonymity, and say exactly who will see what.

What the cover message should have said. Something like: “Your answers are confidential, not anonymous: the agency will see them, but no one at Meridian will see individual answers. Because the team is small, results will be reported only together with a larger group, and comments will never be quoted.”

What could go wrong. The newest member of the team is alone in her tenure band, and her critical comment lands, verbatim, on her supervisor’s desk.

Marking guidance for Task 2

  • Name the principle and how it is breached. “It feels wrong” earns nothing, as the worksheet warns. “Purpose limitation: the footage is collected for security and repurposed for research” earns full credit.
  • Safeguards must be concrete enough to act on tomorrow. “Be careful with the data” is not a safeguard. “Names replaced by codes before anyone reads a message” is.
  • Insist on the vocabulary. Any group that proposes to “make it anonymous” must say how anonymity is achieved, or concede that only confidentiality is possible (B, D, E).
  • “What could go wrong” should name a specific person and a specific harm, such as an assistant, a cashier or a leaver, rather than “employees could be upset”.
  • Judgement calls. On C and D, credit either “permissible with safeguards” or “not permissible” if the reasoning is sound. “Permissible as it stands” earns no credit on any case.
  • Common errors to correct: treating lawful access as ethical licence (A, B, D); treating a reporting promise (“only patterns”, “only aggregates”) as if it protected the people whose data are read in full (B, D); and believing that an external agency makes a survey anonymous (E).

Task 3: the pattern check

Model answer to Task 3: which principles are at stake in which case A matrix of the eight principles from the worksheet against the five cases, one defensible reading; the class poll leaves this question open. Case A, the stockroom camera: informed consent, no harm, privacy, deception and covert observation, purpose limitation, and arguably power asymmetry; not permissible. Case B, the chat-log study: informed consent, privacy, covert observation, purpose limitation, data minimisation, and arguably no harm; permissible with safeguards. Case C, the manager’s own survey: voluntary participation, no harm, privacy and confidentiality, power asymmetry, and arguably data minimisation; permissible with safeguards, a judgement call. Case D, the exit interviews: informed consent, no harm, privacy and confidentiality, purpose limitation, data minimisation; permissible with safeguards, a judgement call. Case E, the six-person team: no harm, privacy and confidentiality, power asymmetry, data minimisation, and arguably informed consent and deception; permissible with safeguards. Totals: privacy, anonymity and confidentiality is at stake in all five cases, and is outlined; no harm in four plus one arguably; informed consent and data minimisation in three plus one; purpose limitation in three; deception and covert observation, and power asymmetry, in two plus one; voluntary participation in one. Voluntary participation Informed consent No harm Privacy, anonymity, confidentiality Deception and covert observation Power asymmetry Purpose limitation Data minimisation cases at stake A Stockroom camera not permissible B Chat-log study with safeguards C Manager’s own survey with safeguards D Exit interviews with safeguards E Six-person team with safeguards 1 3 + 1 4 + 1 5 2 + 1 2 + 1 3 3 + 1 verdict at stake arguably judgement call one defensible reading — the poll leaves this question open
Figure 6: Model answer to Task 3: one defensible reading of which principles are at stake in which case.

1. Which single principle was breached most often? There is no single correct answer, and the poll leaves this question unticked. Figure 6 gives one defensible reading. On that reading, privacy, anonymity and confidentiality is at stake in all five cases, with no harm close behind. The pairing is the lecture’s own point: social and economic harms usually arise not from the questions but from a failure of protection afterwards. Informed consent and purpose limitation (A, B, D) and data minimisation (B, D, E) are also good answers if argued. What matters is that the group can point to the specific breach in each case it counts.

2. Which case was closest to the line? C and D are the designated judgement calls, and most groups will name one of them. Groups persuaded by the manager’s “behaviour will change” argument may name A. Use the disagreement in the plenary: the aim is to make the reasoning visible, not to settle the verdict by vote.

3. Where did deliberation change your mind? No model answer. The shifts worth drawing out are those in which a proposer’s argument persuaded a group at first sight and analysis undid it: the contract (A), the company’s platform (B), the “voluntary” label (C), the data that “already exist” (D), the promise of anonymity (E). Compare the poll’s first-impression round with the final verdicts to show the class where this happened.

Task 4: plenary discussion

Model answers to two Task 4 plenary prompts Two cards. “It’s already in the contract”: the answer is purpose limitation. Lawful access is not ethical research use: data gathered, or monitoring allowed, for one purpose cannot be freely re-used for another, and no one was ever asked to be a research subject. Cases A, B and D all lean on lawful access: the employment contract in A, the company’s own platform in B, records HR already holds in D; none of them amounts to research use. If Meridian had an ethics committee, which proposals would reach it? A discussion point: each looks like routine business, A like security, B like analytics, C like a manager’s feedback, D like HR housekeeping and E like a staff survey, so probably few, if any. Review is most needed exactly where nobody calls it research; where no committee exists, the researcher must be the committee. “It’s already in the contract” PURPOSE LIMITATION lawful access … A the employment contract B the company’s own platform D records HR already holds ≠ research use Data gathered — or monitoring allowed — for one purpose cannot be freely re-used for another, and no one was ever asked to be a research subject. If Meridian had an ethics committee… DISCUSSION which would reach it? each looks like routine business: A security B analytics C a manager’s feedback D HR housekeeping E a staff survey Probably few, if any. Review is most needed exactly where nobody calls it research: where no committee exists, the researcher must be the committee.
Figure 7: Model answers to the two plenary prompts not answered on the case slides.

Lawful access versus ethical research use. The concept is purpose limitation: data collected, or monitoring permitted, for one purpose cannot be freely re-used for another. Cases A (the contract), B (the company’s own platform) and D (records HR already holds) all lean on lawful access, and in none of them was anyone asked to become a research subject (Figure 7).

Case A and the covert test. Covert observation of employees is justifiable only if the question is important, no open design would work, harm is minimal and disclosure follows. Case A does not pass. The question is arguably important, since shrinkage has doubled. But stock handling can be studied openly, the harm is not minimal because footage is tied to named staff, and no disclosure is planned (Figure 1). “Announcing it would destroy its value” is never sufficient on its own: it addresses only one of the four conditions.

Case C without “hope and expect”. Consent would still not be free. The constraint is the situation, not the wording: she is still the participants’ manager, and she reads named answers. Deleting the sentence removes the loudest pressure, not the power. The safeguards change who asks and who sees (Figure 3).

Case E and the broken promise. What can the agency honestly promise? Confidentiality, not anonymity. Which is more damaging? A promise made and broken. It harms the people exposed and every future study, because the organisation remembers, while an honest promise of limited confidentiality does neither. The cover message it needed is given under case E (Figure 5).

If Meridian had an ethics committee. This is a discussion point with no single answer. A likely line is that few, if any, of the five proposals would ever reach a committee, because each looks like routine business rather than research: A like security, B like analytics, C like a manager’s feedback, D like HR housekeeping, E like a staff survey (Figure 7). That is the lecture’s point about review. It is most needed exactly where nobody calls the activity research, and where no committee exists, the researcher must be the committee.