Research ethics
Introduction to Social Research Methodology
Foundations of research ethics
Why research ethics matters
Social research studies people — their behaviour, opinions, relationships, and data — and so every study, however modest, is an intervention in someone’s life. Research ethics is the discipline of making sure that intervention is defensible. It protects three things simultaneously. First, it protects participants: their rights, dignity, and well-being. Second, it protects the research itself, because data obtained through fear, pressure, or deception is usually bad data — people who do not feel safe do not tell the truth. Third, it protects the reputation of research: every ethical scandal makes participants warier and the next study harder to conduct, for everyone.
In organisational settings the stakes are concrete rather than abstract. An employee survey run badly can damage trust, morale, and individual careers, not merely a dataset. Ethics is therefore not a bureaucratic hurdle to be cleared before the “real” research begins; it is part of what makes the research real (Babbie, 2017).
Figure 1 summarises the argument: every study is an intervention in someone’s life, and ethics protects participants, the research itself and the reputation of research at once. The three stand or fall together; at Meridian, a badly run employee survey damages trust, morale and careers, not just a dataset.
Key principles of research ethics
Modern research ethics rests on a small set of principles, first codified in medical research (most influentially in the Belmont Report of 1979) and now standard across the social sciences.
| Principle | What it demands |
|---|---|
| Respect for persons | Treat participants as autonomous agents, never as mere material for the study |
| Autonomy | People decide for themselves whether to take part |
| Beneficence | The research should do good |
| Nonmaleficence | At a minimum, the research must avoid doing harm |
| Justice | Risks and benefits must be fairly distributed; the risks must not be loaded onto the powerless |
These abstractions become practical through five working rules — voluntary participation, informed consent, no harm, privacy protection, and a near-prohibition on deception — which the next section takes in turn.
Figure 2 shows how the principles relate. Respect for persons is the master principle, and autonomy flows from it; beneficence and nonmaleficence are two different demands, since a study can help no one while harming no one, or produce valuable knowledge while harming its participants. The panel on the right lists the five working rules through which the abstractions become practice.
Core ethical principles
Voluntary participation
No one may be required to take part in research: participation must be a free choice, made without pressure or penalty. Voluntariness has two corollaries that are often forgotten. Participants retain the right to decline any individual question, and the right to withdraw at any point, without giving a reason and without consequence.
The test of voluntariness is not whether the researcher said participation was voluntary, but whether a reasonable participant would feel free to refuse. This is why researchers must watch for soft coercion: course credit, gift vouchers, or a boss’s “encouragement” can make refusal feel costly even when no explicit threat is made. In the workplace, voluntariness is the principle that comes under the greatest strain — a point developed at length in the organisational section below.
Figure 3 reads from left to right and top to bottom: the free choice runs through every stage of a study, from agreeing to take part to withdrawing at any point; the test is whether a reasonable participant would feel free to refuse; and soft coercion puts a price on refusal without any threat being made.
Informed consent
Informed consent is voluntary agreement to participate, given after the participant understands what the research involves. To be genuinely informed, a participant needs to know: the purpose of the study and who is conducting it; what participation involves and how long it will take; the risks and benefits, honestly stated; what will happen to their data and who will see it; and their right to withdraw at any time.
Consent is best understood as a process rather than a signature. A consent form that nobody read protects the researcher, not the participant. Some groups — children, some patients, prisoners — have limited capacity to give informed consent, and research involving them requires special safeguards such as the participant’s assent combined with a guardian’s consent.
Figure 4 sets out informed consent as voluntary agreement plus understanding, lists the five things a participant must know (effectively the template for any consent form), and adds the two qualifications: consent is a process rather than a signature, and people with limited capacity to consent need extra safeguards.
No harm to participants
Research must not leave participants worse off, and in social research harm is rarely physical. The harms to anticipate are psychological (distress, embarrassment, reawakened trauma), social (damaged reputation or relationships if answers become known), and economic (consequences for a job, promotion, or benefits).
The researcher’s duty is to anticipate harm through risk assessment before the study begins, not to apologise for it afterwards. The standard mitigation tools are careful question design, debriefing participants after the study, signposting sources of support, and — above all — protecting what participants disclose. An organisational example makes the point: asking employees to rate their manager is harmless only if the manager can never trace an answer back to its author.
Figure 5 shows the three kinds of harm, notes that social and economic harm usually follow from a failure of protection afterwards, and sets anticipation (a risk assessment before the study, leading to the mitigation tools) against apologising afterwards.
Privacy, anonymity, confidentiality
Three related terms are frequently confused, and the distinctions matter (Babbie, 2017):
| Term | What it means |
|---|---|
| Privacy | The participant’s right to control what they reveal about themselves, and when |
| Anonymity | Not even the researcher can link a given response to a given person |
| Confidentiality | The researcher could identify respondents, but promises not to reveal identities |
Most surveys described as “anonymous” are in fact merely confidential: if the researcher could work out who answered — from an email invitation, an IP address, or a combination of background questions — the study should not be described as anonymous. The practical protections are pseudonyms, aggregated reporting, encryption, secure storage, and separating identifying information from responses as early as possible.
Figure 6 draws the three terms. Privacy concerns the boundary itself: what the participant chooses to reveal. Anonymity is a property of the data: there is no link between person and response, not even for the researcher. Confidentiality is a property of the researcher’s conduct: the link exists, but it is kept locked. The warning underneath names the commonest mislabelling.
Deception
Deception means misleading participants about the purpose or nature of the research, whether by active lying or by concealment. It is sometimes argued to be necessary: telling people you are studying honesty changes how honestly they behave. But deception directly violates informed consent, so it carries a heavy burden of justification. It may be considered only when the research question has real value and cannot be answered any other way, when the risk of harm is minimal, and when participants are fully debriefed afterwards.
Deception is indefensible when it hides real risks from participants, when an honest design would have answered the question, or when the deceived can never be told. Covert observation — watching people who do not know they are being studied — is deception’s close cousin and is judged by exactly the same test.
Figure 7 pairs each condition under which deception may be considered with its mirror image, the case in which deception is indefensible: an honest design would have worked, real risks are hidden, or the deceived can never be told.
Cautionary tales and the rise of ethical review
The classic cases
The modern ethics-review system was not designed in the abstract; it was built in response to specific studies that went wrong. Five are worth knowing as historical anchors.
Figure 8 places them, and the more recent Facebook study discussed below, on one timeline, together with the institutional response they provoked.
| Study | What happened | The breach | The lesson |
|---|---|---|---|
| Milgram obedience experiment (1961) | Participants believed they were delivering painful electric shocks to another person; many were severely distressed yet urged to continue | Deception about the study’s nature; intense psychological stress without warning | Protect participants from severe distress even in simulated settings |
| Stanford Prison Experiment (1971, Zimbardo) | Students role-playing guards and prisoners descended into abuse and extreme distress; halted after six days of a planned fourteen | Consent did not cover risks of this kind; harm was allowed to continue once visible | The duty of care runs throughout the study; stop when harm emerges |
| Tuskegee syphilis study (1932–1972) | The U.S. Public Health Service observed untreated syphilis in African-American men who were never told their diagnosis and were denied penicillin once it became the standard cure | Exploitation of a vulnerable population; no consent; deliberate denial of treatment | The precise violation of justice: the powerless bearing all the risk for none of the benefit |
| Guatemala syphilis study (1946–1948) | Researchers deliberately infected prisoners, soldiers, and psychiatric patients without consent; unearthed in 2010, prompting formal U.S. government apologies | Deliberate infliction of harm on people unable to refuse | Never compromise on informed consent, above all with vulnerable populations |
| Tearoom Trade (1970, Humphreys) | Humphreys covertly observed men’s sexual encounters in public restrooms, recorded number plates, traced home addresses, and interviewed the men under a false pretext | Deception combined with a profound violation of privacy | Covert observation plus identifiable records compounds one violation with another |
A sixth, recent case shows that digital settings do not suspend the rules. In the Facebook emotional contagion study (2014), Facebook and researchers from Cornell and UCSF manipulated the news feeds of roughly 700,000 users to test whether emotional states spread through networks — without informed consent, on the strength of a terms-of-service clause. The public outrage that followed established that a terms-of-service checkbox is not informed consent, and posed a question directly relevant to management: A/B tests on customers and analytics on employees raise the same issue of when routine business practice becomes research on unwitting subjects.
Public reaction to Tuskegee in particular led directly to the Belmont Report (1979) and the modern apparatus of ethical review.
The lecture presents each case as a case file, in a common layout, reproduced below.
Milgram’s obedience experiment (1961)
Figure 9 reads like the other four case files: on the left the year, researcher and aim, with the principles breached marked in red (here deception and no harm); on the right what was done, the breach, the consequence and the lesson.
The Stanford Prison Experiment (1971)
Figure 10 marks informed consent and no harm: consent to a role-play did not cover risks of this kind, and the harm was allowed to continue once visible, until an outside observer ended the study.
Tuskegee and Guatemala
Figure 11 marks four principles, the most of any case: justice, informed consent, no harm and deception. It is the purest violation of justice, with the powerless bearing all the risk for none of the benefit.
Tearoom Trade (1970)
Figure 12 marks deception and privacy, and adds what was at stake for the men observed and the workplace parallel: covert watching plus identifying records.
Facebook emotional contagion (2014)
Figure 13 marks a single principle, informed consent, breached at scale, and draws the parallel with A/B tests on customers and analytics on employees.
Research integrity
Ethics governs not only how researchers treat participants but how they treat the truth. The three cardinal sins of research conduct are fabrication (inventing data), falsification (distorting data, or cherry-picking what to report), and plagiarism (presenting others’ work as one’s own). The corresponding positive duties are to preserve raw data, report honestly — including unwelcome findings — correct errors promptly and transparently, and disclose conflicts of interest. In organisational research this last duty bites hard: a consultant paid by a sponsor who wants a particular answer has a conflict of interest that must be declared.
Figure 14 sets the three cardinal sins against the four positive duties, and gives three workplace examples of conflicts of interest, whose minimum ethical response is to declare them.
Ethics committees and review
The institutional response to the scandals above was independent ethical review before data collection begins. An ethics committee (in the United States, an Institutional Review Board) scrutinises the proposed study: its risks, consent procedures, data-protection arrangements, and any involvement of vulnerable groups. Review is proportionate — a low-risk anonymous CAWI survey receives lighter scrutiny than covert observation or research with children.
The deeper value of review is the discipline of justification: writing the application forces the researcher to confront the risks of their own design. Organisations rarely have formal ethics committees, which is exactly why a manager-researcher must internalise the reviewer’s questions and apply them to their own proposals. A useful rule of thumb: if you would be uncomfortable defending your design to an independent reviewer — or seeing it described in the press — redesign it.
Figure 15 shows where review sits (between design and data collection), the four questions a committee asks, the scale of proportionate scrutiny, and the two lessons for organisations: the deeper value of review is the discipline of justification, and where there is no committee the researcher must ask its questions.
Ethics in organisational research
The manager as researcher
Everything in the preceding sections quietly assumed a researcher with no power over participants. In organisational research that assumption fails. A manager researching subordinates holds power over their pay, promotion, workload, and continued employment, and this power asymmetry contaminates every principle at once: voluntariness (can they really refuse?), the honesty of the data (will they tell a powerful person the truth?), and the avoidance of harm (a careless finding can follow someone through their career).
Employees are, in this specific sense, a vulnerable population in workplace research — not because they lack the capacity to consent, but because both refusal and candour carry risk for them. For Meridian, the running case, this means that when the board asks the research team to survey staff about why colleagues quit, the team’s first design question is ethical rather than statistical.
Figure 16 draws the power asymmetry, from the manager’s control over pay, promotion, workload and continued employment to the team who are also the participants, and the three principles it contaminates at once.
Consent that cannot be freely refused
“Participation is voluntary” rings hollow when the invitation comes from the person who writes your performance review. The warning signs that consent is not genuinely free are: the requester controls the participant’s rewards or sanctions; participation is visible, so everyone can see who opted out; and the organisational culture treats refusal as disloyalty.
Safeguards can restore genuine choice: have the invitation come from a neutral party (HR or an external researcher) rather than the line manager; make non-participation invisible (no attendance lists, no chasing of named non-responders); and give an explicit, believable assurance that refusal carries no consequences. If no safeguard can make refusal safe, the honest conclusion is that valid consent is impossible in that form — and the study should not run in that form.
Figure 17 pairs each warning sign with the safeguard that answers it, and ends with the limiting case in which no safeguard makes refusal safe.
Employee monitoring and covert observation at work
Employers can often lawfully monitor email, chat, and CCTV — but “the employer may monitor” does not mean “the researcher may study”. Purpose matters: data collected for security or operational reasons, silently repurposed for research, bypasses consent entirely. Covert observation of employees inherits the full burden of deception and is justifiable only if the question is important, no open design would work, harm is minimal, and disclosure follows. Most workplace research questions fail that test: communication, morale, and teamwork can almost always be studied openly. The Humphreys lesson applies directly — covert watching combined with identifiable records is the worst possible combination.
Figure 18 shows lawful monitoring silently repurposed as research, the four conditions of the covert test (most workplace questions fail the second), and the Humphreys lesson. Its test case, reading a team’s chat history, is answered in the lecture: it breaches consent, purpose limitation and privacy, and arguably no harm, and the fix is to announce the study, obtain consent, and anonymise and aggregate before analysis, at which point it is no longer covert.
Insider research
Insider research means studying the organisation you belong to: the manager, HR analyst, or student researching their own workplace. Its advantages are real — access, context, trust, and an insider’s understanding of what things mean. Its ethical hazards are equally real. There is role confusion: is this conversation a chat between colleagues or data collection? There is prior knowledge: the insider knows things participants never consented to have used as data. And there is the exit problem: the research ends, but the researcher still works there, holding what they learned.
The safeguards are to make the researcher role explicit and visible, keep clear consent boundaries around what counts as data, and agree what will happen to findings before collecting them. Colleagues’ friendliness is not consent: an insider must ask more formally, not less, precisely because the relationship blurs the line.
Figure 19 reads down each column: an advantage of insider research, the ethical shadow it casts, and the safeguard that answers it.
Confidentiality in small teams
The standard survey promise — “responses are anonymous and reported only in aggregate” — quietly breaks in small groups. In a six-person team, “the two people dissatisfied with management” are identifiable to any manager who knows the team, without any names being collected. Deductive disclosure is the general form of the problem: individuals can be identified by combining attributes (role by tenure by department can single a person out) even when no identifier appears in the data.
Figure 20 shows the problem: a manager who knows a six-person team can identify “the two dissatisfied” without any names, and deductive disclosure narrows all staff, crossed with department, tenure and role, down to one person.
| Safeguard | How it works |
|---|---|
| Minimum cell size | Report results only for groups above a threshold (commonly n ≥ 10); suppress smaller groups |
| Coarsening | Merge departments, band tenure, drop fine-grained background questions |
| Care with open text | Never report verbatim comments with group labels attached — writing style itself identifies |
The cardinal rule is to never promise more protection than you can deliver: a broken promise of anonymity does more damage than an honest promise of limited confidentiality. In the Meridian case, the e-commerce unit has seven staff — reporting its engagement score separately identifies no one by name, and everyone in fact.
Figure 21 illustrates the three safeguards and the cardinal rule: groups below the minimum cell size are suppressed or merged, fine categories are coarsened into bands, and quoted comments never carry group labels.
The ethics of using customer data
Organisations hold rich customer data — transactions, loyalty-card histories, complaints, browsing behaviour — and it is tempting research material. But customers consented to a purchase, not to being research subjects: re-use of their data for research is a new purpose that needs its own justification. Three questions should be asked before touching customer data. Can the analysis run on anonymised or aggregated data (usually it can)? Would customers be surprised to learn their data was used this way? Does the study create new risks for them — profiling, discrimination, exposure? The Facebook study marks the boundary: routine product analytics shades into human-subjects research the moment the organisation manipulates customers’ experience or studies identifiable individuals rather than aggregates.
Figure 22 shows why re-using customer data for research is a new purpose, the three questions to ask before touching it, and the spectrum from aggregate business intelligence to human-subjects research, on which the Facebook study sits at the far end.
GDPR and organisational research
In the EU, personal data used in research falls under the GDPR. At a practical level, four ideas cover most of what an organisational researcher needs.
| GDPR concept | Practical meaning for research |
|---|---|
| Lawful basis | Every use of personal data needs a legal justification (consent, legitimate interest, among others). For employee data, consent is legally doubtful precisely because of the power imbalance — the law mirrors the ethics |
| Purpose limitation | Data collected for one purpose cannot be freely re-used for another |
| Data minimisation | Collect only what the question requires; if you do not need names, do not collect names |
| Storage limitation | Keep data only as long as needed, then delete it; know where it lives and who can access it |
Truly anonymised data — with no way back to individuals — falls outside the GDPR altogether, which is one more reason to anonymise early. Good practice for any study is to be able to state, in one sentence each: the lawful basis, the purpose, what is collected, where it is stored, and when it will be deleted.
Figure 23 attaches the four ideas to the life of personal data: lawful basis covers every use; data minimisation applies when data are collected, purpose limitation when they are used, and storage limitation while they are kept and when they are deleted. Anonymising early takes data outside the GDPR altogether.
An ethics checklist for organisational research
Before fieldwork begins, the researcher should be able to answer five questions, settled in the design rather than improvised after the data arrive:
- Who is the researcher, and what power do they hold over participants?
- Is participation genuinely refusable — and invisible when refused?
- What exactly is promised about anonymity or confidentiality, and can that promise survive small-team reporting?
- Is any existing data (HR records, chat logs, customer files) being repurposed, and on what basis?
- Who sees the results, and at what level of aggregation?
Figure 24 gives the same five questions as they apply to Meridian, each with a pointer to the tool from this session that answers it.
Conclusion
Ethics protects participants, the quality of the data, and the credibility of research itself, and the three stand or fall together. The core principles — voluntary participation, informed consent, no harm, privacy protection, and a near-prohibition on deception — were written in the aftermath of real scandals, from Milgram and Tuskegee to the Facebook emotional contagion study. Independent ethical review institutionalised those lessons; where no committee exists, the researcher must be the committee. Organisational research adds a distinctive complication: power. When the researcher signs the participants’ performance reviews, voluntariness, candour, and confidentiality are all at risk simultaneously, and the safeguards must be designed in from the start. The habit to build is to ask, of every proposed study: who could this harm, and what would make it defensible? — and to be willing, if no safeguard works, not to run the study at all.