03 · What You Need to Know
How to Decide Whether Unconfirmed Data Access Is a Risk Worth Taking
Not having the data yet is not automatically a problem
Many legitimate research projects are developed before researchers physically possess the data they will eventually analyze. Restricted datasets may require an approved proposal. Institutional records may be released only after ethics and data-governance requirements are satisfied. Government microdata may require an application and secure-access arrangements.
In these situations, planning before access is not inherently poor research practice. In fact, the provider may require a well-developed research question and analysis plan before deciding whether access should be granted.
The relevant distinction is between data you do not have yet and data you have no credible reason to expect you will obtain.
Access pending through an established pathway
The required data are known to exist, you appear eligible to request them, the provider has a defined access process, and you understand the major requirements and timeline.
Access based mainly on assumption
You believe the data probably exist or expect someone will eventually provide them, but the custodian, eligibility, process, restrictions, or likelihood of approval has not been adequately established.
Both situations involve uncertainty, but they do not present the same level of feasibility risk.
First establish that the required data actually exist
Do not accept access uncertainty on top of existence uncertainty unless there is a compelling reason to do so.
Before making an unconfirmed dataset central to the project, establish as far as reasonably possible that the source contains the variables, population, timeframe, unit of analysis, and level of detail the research question requires.
If you are still assuming that an organization "must have" the relevant information, return to the more fundamental question of whether the data you need actually exist.
A study becomes especially fragile when two assumptions are stacked together: first, that the data contain what you need, and second, that you will eventually be allowed to use them.
Then establish that an access pathway actually exists
Knowing that data exist is not enough. Determine how researchers obtain them.
For a repository, this may involve published eligibility criteria and an application procedure. For institutional records, you may need to identify the relevant data custodian, research office, privacy office, ethics body, or other authority. Government and statistical data may be available through licensed files, restricted-access applications, secure research environments, or approved research projects.
For example, the UK Data Service uses different access conditions for different categories of data, with more sensitive data subject to additional requirements. The U.S. Census Bureau's Federal Statistical Research Data Centers similarly provide qualified researchers access to restricted federal statistical data through a formal proposal and secure-access process.
A defined pathway does not guarantee approval. It does transform the situation from "I hope somebody gives me the data" into a risk that can be investigated.
Ask whether you are actually eligible to obtain access
A formal access process is useful only if you can realistically satisfy it.
Some restricted datasets may require institutional affiliation, specific researcher status, training, security arrangements, ethics documentation, a data-use agreement, an approved research purpose, or access from a particular jurisdiction or environment. Other providers may restrict data to employees, collaborating institutions, approved projects, or researchers meeting particular qualifications.
Read the eligibility requirements rather than assuming that being a student or academic automatically entitles you to apply.
If access depends on your supervisor, institution, or collaborator meeting a requirement, verify that arrangement as well. Your project should not rely on institutional eligibility that nobody has actually confirmed.
Investigate what the provider can approve, not merely whether it accepts applications
An application pathway may exist while your intended use falls outside what the provider permits.
The provider might prohibit particular linkages, uses, geographical detail, commercial applications, attempts at re-identification, or analyses involving variables considered too sensitive for release. Some data may be available only in aggregated or de-identified form. Others may be accessed only within secure environments.
Before investing heavily in the project, compare your intended analysis with the provider's permitted uses and available access levels.
This is part of understanding what happens when access depends on someone else's permission. Permission is not merely a binary yes or no; the conditions attached to a yes may determine whether the question remains answerable.
Estimate the probability of access from evidence, not optimism
You usually cannot calculate a precise probability that your application will be approved. You can still make a more informed judgment than "I think it will be fine."
Useful evidence might include whether you meet published eligibility requirements, whether similar projects have received access, whether the proposed use fits stated policies, whether the data custodian has reviewed your preliminary enquiry, whether required approvals are obtainable, and whether the requested variables are routinely available under the relevant access mechanism.
Conversely, warning signs include unclear ownership, no established application process, reliance on one personal contact, uncertainty about whether the data can legally or institutionally be shared, or a request that falls outside the provider's normal access arrangements.
Do not convert an informal expression of support into an imaginary 90% approval probability. The point is not false precision. It is to distinguish evidence-based confidence from hope.
Estimate the time risk separately from the approval risk
You may be highly likely to receive access eventually and still have a serious feasibility problem.
Suppose a restricted-data application normally takes several months, followed by agreements, training, account setup, and data provisioning. Your thesis has six months remaining. Even if eventual approval seems likely, the project may not have enough time for meaningful analysis and writing after access arrives.
Think about two separate questions:
- How plausible is it that access will ultimately be granted?
- How plausible is it that usable access will be granted early enough for this project?
The second question is often more important for student research.
Approval and provisioning should therefore be included when estimating whether the study can be completed within the actual deadline.
Distinguish application status from access status
Researchers sometimes talk themselves into greater certainty by gradually changing the language they use.
"I found a dataset" becomes "I have a data source." "I emailed the provider" becomes "They are considering my request." "I submitted an application" becomes "I am getting access."
Use precise language instead.
| Status |
What you actually know |
Remaining uncertainty |
| Potential source identified |
A provider appears to possess relevant data. |
Contents and access may still be unverified. |
| Feasibility investigated |
The data and access pathway appear compatible with the proposed study. |
Formal approval remains outstanding. |
| Application submitted |
The provider is formally considering the request. |
Approval, conditions, and timing remain uncertain. |
| Conditional approval |
Access is expected if specified requirements are satisfied. |
Conditions may still delay or alter usable access. |
| Access authorized |
The relevant approval has been granted for the specified use. |
Practical provisioning and compliance requirements may remain. |
| Usable access established |
You can actually work with the approved data under the required conditions. |
The remaining risks concern the dataset and analysis rather than whether access will arrive. |
This may sound pedantic until a thesis deadline is approaching and "approval expected soon" has occupied the methodology section for three months.
Ask what happens if access is narrower than requested
Researchers often frame the risk as approval versus rejection. A third outcome is common: approval with restrictions.
You may receive fewer years, fewer variables, less detailed geography, aggregated rather than individual-level information, or data that cannot be linked with another source. Your statistician may not be authorized to access the secure environment. The provider may prohibit an analysis you intended to conduct.
Ask whether the research question survives those plausible restrictions.
If the study works only when every requested variable is provided at maximum detail, the project may be more fragile than it first appears.
Measure dependency by asking what happens if the answer is no
The importance of uncertain access depends on the consequences of failure.
Suppose your preferred dataset is one of four suitable sources. Denial would be inconvenient but manageable. Now suppose one organization alone holds the historical records needed to answer your question. Denial would eliminate the study as designed.
These projects should not be evaluated as though they carry the same risk.
Replaceable dependency
Another appropriate source, site, dataset, or design can answer substantially the same research question if the preferred source becomes unavailable.
Single point of failure
The project cannot answer its central research question if one particular source does not become available.
The more your project resembles the second situation, the stronger the case for resolving access before making an irreversible commitment.
A backup dataset is useful only if it can answer a worthwhile question
"I have a backup" can sound reassuring until you inspect what the backup actually contains.
An alternative should be evaluated using the same standards as the preferred source. Does it contain the necessary population, variables, timeframe, and level of detail? Can you access it? Does its design support the intended analysis?
If using the alternative would require a substantially different research question, acknowledge that. Your contingency plan may really be an alternative study rather than an alternative dataset.
That can still be sensible, particularly for a time-limited thesis. It should simply be planned rather than improvised.
Set a decision point instead of waiting indefinitely
One practical way to manage uncertain access is to establish a point after which continuing to wait would make the project infeasible.
Work backward from the final deadline. Estimate how much time you need after receiving the data for familiarization, cleaning, analysis, interpretation, writing, review, and revision. Add reasonable allowance for complications. The latest date at which access can arrive while still leaving enough time becomes an important decision point.
If access has not been secured by then, activate the alternative plan.
This is more useful than saying, "If the data do not arrive, I will change topics," without deciding when that change must occur.
Do not underestimate the work that begins after access is granted
Receiving the dataset is not the finish line of the access process. It is the starting line of the analysis process.
You may need to learn the documentation, understand unfamiliar coding, merge files, apply weights, construct variables, investigate missingness, reproduce derived measures, adapt to a secure environment, or resolve unexpected quality problems.
If your schedule assumes that statistical analysis begins the afternoon the data arrive, your access deadline is probably too late.
Before depending on the dataset, make sure you have also considered what should be checked before building a study around an existing dataset.
Access uncertainty may be more acceptable at some stages than others
The amount of uncertainty you can reasonably tolerate may depend on where you are in the research process.
During early topic exploration, it may be perfectly reasonable to investigate a question contingent on restricted data. Before registering a protocol, submitting a final thesis proposal, committing grant resources, or reaching a point where changing the project would cause substantial delay, stronger evidence of access may be warranted.
The threshold also depends on the consequences of failure. A funded research team with several possible data sources can tolerate uncertainty differently from a master's student with a fixed graduation deadline and one possible dataset.
Feasibility is contextual.
Do not bypass the access process because the deadline is approaching
Pressure can create a dangerous temptation: if someone inside the organization can send the file informally, perhaps the formal process can be sorted out later.
Do not assume that possession makes the data legitimate to use.
Restricted, confidential, proprietary, identifiable, or institutionally controlled data may be subject to ethics requirements, privacy obligations, contracts, security rules, and formal authorization. A colleague who can technically export a file may not have authority to provide it for your research.
Watch Out
If the approved access pathway is taking longer than expected, do not solve the feasibility problem by obtaining controlled data through an unofficial route. A delayed project can be redesigned; unauthorized data use can create research-integrity, privacy, institutional, and potentially legal problems.
Sometimes the correct decision is to choose another study
A dataset can be ideal scientifically and still be a poor foundation for your present project.
If access is highly uncertain, approval is likely to extend beyond your deadline, no adequate alternative exists, and the question cannot be answered without that particular source, choosing another project may be the more defensible decision.
This does not mean the research idea was bad. It means the current combination of question, evidence, and circumstances is too fragile.
A project that can actually be completed with credible evidence is usually a better thesis than an elegant protocol that spends its final semester waiting for permission.