Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should You Do When Access to the Data Depends on Someone Else’s Permission?

Data may exist without being available to you. Learn how to identify who controls access, understand the approval process, reduce access risk, and avoid building a study around permission you may never receive.

446
When Research Data Access Requires Permission Guide 446 of 533
01 · The Question

The Data Exist, but Someone Else Decides Whether You Can Use Them

You have identified exactly the data your study needs. Perhaps they are student records held by a university, clinical records controlled by a hospital, administrative data maintained by a government agency, organizational records belonging to a company, or a restricted dataset managed by a repository.

The data exist. They may even be ideal for your research question.

But they are not yours to use simply because they exist.

Someone else controls access, and your study may depend on that person or organization deciding that you are eligible to receive or use the data. This creates a particular kind of feasibility risk: the evidence required by your research question exists, but your ability to obtain it is uncertain.

02 · The Short Answer

Treat Permission as a Research Dependency, Not an Administrative Detail

In Brief

When access to essential research data depends on someone else’s permission, identify the actual data custodian, determine the formal access requirements and restrictions, begin the appropriate process early, and treat the data as unconfirmed until the required authorization has genuinely been granted.

A promising conversation, supportive supervisor, available database, or submitted application does not necessarily mean you have access. If losing the data would make the study impossible, build that uncertainty into your feasibility assessment and consider a realistic alternative before committing the entire project to one external decision.

03 · What You Need to Know

How to Manage a Study When Someone Else Controls the Data

Data existence and data access are separate questions

The first distinction is simple but consequential. A dataset can exist without being accessible to you.

A university may have detailed student records. A hospital may retain the clinical information your study requires. A government agency may hold individual-level administrative data. A company may possess years of customer or employee records. None of this establishes that those data can be released for your proposed research.

Data availability The information required by the research has actually been collected or generated and exists in a potentially usable form.
Data access You have the authorization and practical means required to obtain or use the relevant data under the applicable conditions.

Before dealing with permission, you should already have established whether the data your research requires actually exist. Once existence is reasonably established, access becomes its own feasibility question.

Identify who actually controls access

The person who knows about the data may not be the person who can authorize their use.

A faculty member may know that a university database exists but have no authority to release student records. A physician may support your project but not control access to hospital data. An employee may be willing to share organizational information but lack permission to provide it for research.

Depending on the setting, authority may rest with a data custodian, records office, research office, repository, government agency, information-security unit, privacy or data-protection office, institutional review board or ethics committee, legal office, database owner, or another designated authority. Several may be involved.

Ask specifically: Who has the authority to approve the particular access I need?

That question is more useful than asking whether someone inside the organization is generally supportive of the research.

Determine exactly what kind of access you need

"I need the dataset" is usually too vague for serious access planning.

Specify the records, variables, population, dates, level of detail, identifiers, linkage requirements, and intended analysis. Determine whether you need identifiable data, coded or pseudonymized records, de-identified data, aggregate statistics, a public-use file, restricted microdata, or access through a secure environment.

The level of access can materially change the approval process.

For example, a provider may be able to release aggregate statistics relatively easily while individual-level records require additional review. A public-use dataset may suppress detailed geography or dates, while a restricted version contains them under tighter controls. A provider may permit analysis but require that the data remain on its servers.

Request the minimum level of access capable of answering the research question rather than automatically asking for the most detailed version available.

Find the official access process

Do not rely exclusively on informal advice when the provider has an established application procedure.

Repositories and government data providers often publish eligibility criteria, application forms, data-use conditions, security requirements, fees, approval procedures, and information about available datasets. Institutional data offices may have their own request systems. Some providers require researchers to submit a detailed list of variables or a research proposal before they will assess the request.

Read those requirements before finalizing your study. They may reveal that you are not eligible, that the data cannot be used for your intended purpose, or that the approval process is incompatible with your timeline.

If the process is unclear, preliminary contact with the appropriate custodian can help. This is one reason it may be useful to contact a potential data provider before finalizing the research question when the entire study depends on that source.

Expect access conditions, not simply a yes or no

Permission is often conditional.

A provider may approve access only for specified researchers, variables, purposes, periods, or locations. Data may have to remain in an approved computing environment. Researchers may be prohibited from attempting re-identification, linking the data with external sources, redistributing files, publishing small cell counts, or using the data for purposes outside the approved project.

Some restricted-data systems also review analytical outputs before researchers can remove them from a secure environment.

For example, the U.S. Census Bureau's Federal Statistical Research Data Centers provide qualified researchers access to restricted federal statistical data for approved projects within secure facilities. Access involves a formal proposal process, and approved researchers must satisfy relevant requirements. Similarly, ICPSR distinguishes among public-use, restricted-use, and other controlled access arrangements, with additional requirements applying to sensitive data.

The important planning question is therefore not only Can I get access? It is also Under what conditions would I be allowed to conduct the analysis?

A data use agreement can shape the study

Access to restricted data may involve a data use agreement or similar contractual instrument.

Such agreements can specify who may access the data, the permitted purpose, storage and security requirements, restrictions on disclosure or redistribution, requirements following completion of the project, and consequences of noncompliance. The exact terms vary by provider and jurisdiction.

Read the agreement rather than treating it as paperwork to be signed after the methodological decisions have already been made.

If the agreement prohibits linkage with another dataset, for example, and your research question depends on that linkage, you have a methodological problem rather than merely an administrative inconvenience. Likewise, if collaborators must individually receive authorization, your staffing plan may need to reflect that requirement.

Ethics approval and data-provider permission are not necessarily the same thing

Researchers sometimes assume that approval from one authority automatically satisfies another.

It may not.

Your institution may require ethics or institutional review for the proposed research. Separately, the data provider may require its own authorization before releasing or allowing access to records. A provider may also impose privacy, security, contractual, or legal requirements independent of the research-ethics process.

Conversely, receiving permission from a data custodian does not automatically establish that all research-ethics requirements have been satisfied.

Research ethics or institutional approval Determines whether the proposed research satisfies the applicable ethical and institutional requirements within the relevant review framework.
Data-provider authorization Determines whether the organization controlling the data permits the requested access and use under its policies, agreements, legal obligations, and other requirements.

The exact sequence varies. Some data providers require ethics documentation before reviewing access. Others may provide preliminary confirmation needed for an ethics application. Verify the requirements rather than assuming a universal order.

Privacy and identifiability can determine what you receive

Many access restrictions exist because research data can reveal information about individuals or organizations.

Removing obvious identifiers such as names does not necessarily eliminate disclosure risk. Detailed combinations of age, location, occupation, dates, diagnoses, institutional characteristics, or other variables can sometimes make records identifiable.

Providers may therefore suppress variables, aggregate categories, alter dates, remove geographical detail, or restrict access to secure environments. These protections can affect whether the released dataset retains enough detail for your analysis.

Do not assume that because the provider possesses a variable, you will receive that variable in its original form.

Data minimization can improve both feasibility and protection

Requesting every potentially interesting variable can make an access application harder to justify and create unnecessary data-management obligations.

Instead, map each requested variable to the research question and planned analysis. If a field does not contribute to the study, consider whether you need it at all.

This approach can reduce exposure to sensitive information and make the request easier to explain. It also forces useful methodological discipline: every variable should have a reason for being there.

In settings governed by privacy frameworks, data minimization may also reflect formal principles or requirements. Researchers should follow the rules applicable to their institution, provider, jurisdiction, and dataset.

Find out whether the data can leave the provider

Access does not always mean receiving a file that you can download to your computer.

Highly sensitive data may be available only through a secure data enclave, remote desktop, controlled laboratory, virtual environment, or physical research data center. The provider may restrict internet access, software installation, external storage, copying, printing, or removal of analytical outputs.

This can materially affect feasibility. If your planned analysis requires software unavailable in the secure environment, you may need another analytical approach or permission to install it. If access requires physical travel, costs and scheduling become relevant. If all outputs undergo disclosure review, publication timelines may need additional allowance.

Ask how access is technically delivered before assuming that approval means you will simply receive a spreadsheet.

Check whether all members of the research team can obtain access

Restricted access may be granted to named individuals rather than to an entire research group.

Your supervisor, statistician, research assistant, programmer, or collaborator may need separate authorization, training, confidentiality agreements, or institutional affiliation. Some data cannot be shown to anyone who has not been approved, even if that person is advising the project.

This can create an unexpected problem for student researchers. You may obtain access but later discover that the specialist helping with the analysis cannot see the data.

If methodological support is likely to be necessary, investigate access requirements for collaborators before assuming they can work directly with the dataset.

Approval timelines belong in your research timeline

Permission can take longer than expected, particularly when several organizations or review processes are involved.

The sequence might include preparing a proposal, obtaining institutional endorsement, ethics review, provider review, revisions, legal or contractual review, security assessment, signing agreements, completing training, account creation, and eventual data provisioning.

Not every request involves all of these stages, but even a subset can consume a meaningful portion of a thesis or grant period.

Ask the provider what steps normally occur and what timelines can reasonably be expected. Then include those stages when estimating whether the study can be completed within your deadline.

Approval can still be denied

A well-prepared request does not guarantee access.

The provider may determine that the proposed use falls outside participant consent, applicable law, institutional policy, contractual restrictions, or the dataset's permitted purposes. Disclosure risk may be too high. The requested variables may be unavailable for release. The organization may lack the resources to prepare the data. Another agreement may prevent sharing.

This possibility should influence how heavily you allow the project to depend on unapproved data.

Permission can be narrower than expected

Sometimes the answer is not "no" but "not quite."

You may request ten years of records and receive five. You may ask for exact dates and receive month and year. You may request individual-level geography and receive region. You may want to link two files but receive permission to analyze them separately.

A conditional or reduced-access approval can therefore require changes to the question, analysis, or claims.

When access is granted, compare what was actually approved with the data requirements of your research question. Do not proceed merely because the word "approved" appears in the correspondence.

Do not describe access as secured before it is secured

Researchers should use precise language when describing the status of data access.

Status What it means How to treat it in planning
Potential source identified You know an organization or repository appears to possess relevant data. Access is unverified.
Preliminary enquiry completed The provider has indicated that an access route may exist. Useful feasibility evidence, but not permission.
Application submitted A formal request is under review. Access remains uncertain.
Conditional approval Access may proceed after specified requirements are satisfied. Verify that the conditions are achievable and compatible with the study.
Authorized access The required approvals and agreements are in place for the specified use. Proceed only within the approved scope and conditions.

These distinctions are especially important in proposals. Saying "the data are available" when you mean "I have identified an organization that may consider an application" can make a study appear substantially more feasible than it actually is.

Consider the consequences of a single point of failure

Some studies have several possible data sources. Others depend completely on one organization.

If one restricted dataset is the only source containing the exposure, outcome, population, and timeframe required by your question, denial of access may end the project as currently designed.

That does not necessarily mean you should avoid the study. It does mean you should recognize the dependency explicitly.

Ask what happens if access is denied, delayed, narrowed, or revoked. Could another dataset answer the question? Could you collect primary data? Could the question be modified without becoming trivial or fundamentally different?

This prepares you for the next decision: whether you should base a research project on data you have not yet been guaranteed access to.

Watch Out

Do not begin using restricted, confidential, identifiable, or otherwise controlled data simply because someone informally sent you a copy. Verify that the person had authority to provide the data and that your proposed possession and use comply with the applicable approvals, agreements, institutional requirements, and data-protection obligations.

Keep a realistic alternative when the dependency is critical

A fallback is particularly valuable when approval may take months or when denial would otherwise make the project impossible.

An alternative might be another dataset, a public-use version with a narrower question, primary data collection, another provider, a different timeframe, or a modified analysis. The fallback should still represent worthwhile research rather than a hastily invented emergency project.

There is also a point at which maintaining two elaborate studies "just in case" becomes inefficient. The objective is risk management, not conducting two theses simultaneously. Identify the smallest credible alternative that protects the project from a foreseeable access failure.

04 · A Practical Example

When the Perfect Dataset Is Controlled by Someone Else

Hypothetical Example

A thesis using institutional student records

A graduate student wants to examine whether patterns of first-year learning-management-system activity are associated with subsequent academic persistence. The university possesses student-level activity logs, enrollment records, and academic information that could potentially support the study.

The student has discussed the idea with a faculty member who says the data "should be available." The student initially plans to finalize the thesis around those records.

Identify the actual custodian The student learns that the faculty member does not control the records. Research access requires approval through designated university offices.
Specify the request Instead of asking for "student data," the student identifies the cohorts, LMS variables, enrollment outcomes, covariates, period, and linkage required for the planned analysis.
Investigate the conditions The university explains that the proposed project requires institutional review, an approved data request, and specified data-security procedures. Some identifying information will not be released to the researcher.
Check methodological compatibility The student verifies that the de-identified records can still be linked internally before release in a way that preserves the variables required for the analysis.
Recognize the remaining uncertainty The student treats the dataset as a proposed source rather than guaranteed data until the formal process is completed.
Prepare an alternative Because access is central to the thesis, the student identifies a narrower study using a public or independently collectable source that could be pursued if institutional access is not obtained by a predetermined decision point.

The faculty member's encouragement was useful, but it was never the decisive permission. By identifying the actual access pathway before finalizing the project, the student can distinguish a promising research idea from a study whose evidence is genuinely obtainable.

05 · What Researchers Often Get Wrong

Common Mistakes When Research Data Require Permission

Misconception

If my supervisor or collaborator can see the data, I can use them too

Access rights do not necessarily transfer between people. Your supervisor or collaborator may have access because of a particular role, agreement, employment relationship, or approved project. Determine whether your proposed research use and your own access require separate authorization.

Misconception

If the organization supports my study, the data request is basically approved

General institutional support and formal data authorization are different. Privacy, security, legal, ethics, contractual, or data-governance review may still be required, and the eventual access may be narrower than originally requested.

Misconception

De-identified data can always be shared freely

Removing direct identifiers does not automatically remove every disclosure risk or legal, contractual, ethical, and institutional restriction. Detailed records may remain sensitive, and providers may impose conditions on de-identified data as well. Follow the requirements applicable to the specific data and setting.

Misconception

Ethics approval automatically gives me access to the data

Ethics approval may be necessary without being sufficient. The organization controlling the data may require a separate application, agreement, security review, or authorization. Conversely, provider permission does not automatically satisfy every institutional ethics requirement.

Misconception

If I have submitted the application, I can describe the data as available

An application under review is not approved access. Describe the status accurately and account for the possibility of delay, conditions, or denial when evaluating feasibility.

Misconception

Once access is approved, I can use the data for related questions too

Restricted access is often granted for a specified project, purpose, population, variables, period, or research team. A related analysis may still fall outside the authorized use and require an amendment or new approval. Check the applicable agreement rather than assuming that possession creates unrestricted research rights.

06 · What This Means for You

Turn an Uncertain Permission Into a Manageable Research Risk

If someone else controls essential data, make the access pathway part of your study planning. Identify the custodian, specify exactly what you need, determine the formal process, understand the conditions, estimate the timeline, and decide how much uncertainty your project can tolerate.

The more completely your research question depends on one restricted source, the less reasonable it is to treat access as paperwork that can be handled later.

A simple decision framework

If the data are public and your intended use is permitted under the applicable conditions
Document the source, version, terms, and any institutional requirements, then proceed with the broader dataset suitability assessment.
If access is restricted but you clearly meet the eligibility requirements and the timeline is manageable
Begin the formal process early and treat access as pending until authorization is complete.
If approval requires conditions that affect the analysis
Determine whether the approved variables, environment, linkage, collaborators, and output restrictions still allow the research question to be answered.
If the provider cannot guarantee access before your project deadline
Establish a decision point and an alternative rather than allowing the entire project timeline to remain indefinitely dependent on the request.
If access is denied or the approved data cannot answer the question
Use another source, collect new data if feasible, or revise the research question instead of using controlled data without authorization or stretching inadequate data beyond what they support.

Permission uncertainty does not automatically make a study infeasible. It becomes dangerous when the uncertainty is hidden. Once the dependency is explicit, you can decide rationally whether to wait, apply, redesign, or pursue another source.

07 · A Quick Checklist

Before Depending on Data Someone Else Controls

Before making restricted data central to your study, check:
Confirm that the specific variables, population, period, level of detail, and linkage required by your research question actually exist.
Identify the person, office, repository, or organization with formal authority to grant the access you need.
Specify the minimum data and level of detail necessary for the proposed analysis rather than requesting everything potentially available.
Read the official eligibility criteria, application procedure, data-use conditions, fees, security requirements, and expected access process.
Determine which ethics, institutional, privacy, contractual, or other approvals apply in addition to the provider's authorization.
Verify whether the data can leave the provider's environment and whether your required software, computing procedures, and collaborators are permitted.
Estimate the complete approval and provisioning timeline rather than assuming access begins when the application is submitted.
Describe access accurately as preliminary, pending, conditional, or authorized rather than treating these statuses as interchangeable.
Compare the data actually approved with the requirements of your research question before beginning the planned analysis.
Prepare a realistic alternative when denial or substantial delay would otherwise make the project impossible.
08 · Frequently Asked Questions

Frequently Asked Questions About Research Data Permission

Who should I ask for permission to use research data?

Ask the authority responsible for the specific data and proposed use. Depending on the setting, this might be a data custodian, repository, institutional research office, records office, government agency, data-protection or privacy office, research committee, or another designated authority. An employee who can view the data does not necessarily have authority to release them.

Is permission from my supervisor enough to use institutional data?

Only if your supervisor is formally authorized to grant that particular access under the institution's procedures, which should not be assumed. Institutional records commonly have governance, privacy, security, ethics, or administrative requirements beyond an individual supervisor's approval.

Is ethics approval the same as permission to access data?

Not necessarily. Ethics or institutional review and data-provider authorization can be separate processes serving different purposes. Your project may require both. Verify the requirements and sequence applicable to your institution, provider, jurisdiction, and dataset.

What is a data use agreement?

A data use agreement is an agreement governing how specified data may be accessed and used. Depending on the provider, it may define authorized researchers and purposes, security requirements, restrictions on disclosure, linkage or redistribution, publication conditions, project duration, and responsibilities when the project ends.

Can I use data that a colleague sends me?

Do not assume that possession equals authorization. Determine whether your colleague was permitted to share the data, whether you are authorized to receive and use them, and what ethics, institutional, contractual, privacy, or other conditions apply. This is particularly important for identifiable, confidential, proprietary, or restricted records.

What if I receive only part of the data I requested?

Compare the approved data with the minimum requirements of the research question. If suppressed variables, shorter coverage, aggregation, or prohibited linkage prevents the intended analysis, revise the question or seek another source rather than assuming partial access is automatically sufficient.

How early should I apply for restricted data?

Early enough to accommodate the provider's full review and provisioning process within your research schedule. Determine the actual steps first, because timelines vary substantially across datasets and organizations. When access is a critical dependency, include a point at which you will switch to an alternative if approval has not arrived.

What if access is likely but not guaranteed?

Assess how dependent the study is on that source, how credible the access pathway is, how long approval may take, and whether a viable alternative exists. If losing the data would collapse the entire project, examine carefully whether you should base the project on data you have not yet been guaranteed access to.

09 · The Bottom Line

Until Permission Is Granted, Access Remains a Study Assumption

The Bottom Line

When someone else controls essential research data, identify the actual authority, understand the formal access process and conditions, apply early enough for your project timeline, and do not treat the data as secured until the required authorization is genuinely in place.

Permission may determine which variables you receive, where analysis occurs, who can work with the data, what outputs can be released, and whether the study can proceed at all. Treat those conditions as part of research design and feasibility, not as paperwork to solve after the question and methodology have already been fixed.

10 · Sources and Further Reading

Sources and Further Reading

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes