Ethiclear
← All posts
A how-to guide

How to Assess Risk in Online Survey Research

5th August 2026 · 3 min read

There's a persistent shorthand in research ethics that an online survey is automatically low risk — no physical intervention, no direct contact, easy to complete and easy to leave. That shorthand describes the method, not the risk, and the two aren't the same thing. A survey asking about a deeply sensitive personal experience carries real risk regardless of how it's delivered.

The problem

Teams wave surveys through review because the method looks harmless, and the delivery mechanism gets mistaken for the actual risk. A survey asking about routine consumer preferences from a general adult population carries little risk; a survey asking about trauma, illegal activity, or mental health from a population that includes minors or people in vulnerable circumstances carries real risk, however simple the survey mechanics are. Treating "just a survey" as automatically low risk skips the assessment that actually matters.

The challenge

Real risk hides in the topic, the population, and how open-text answers get handled — three places a method-based shortcut never looks. It's common for a survey to describe itself as anonymous without the underlying data flow genuinely supporting that claim: an IP address logged by default, a platform that ties responses to an account, a small sample where combinations of demographic answers could plausibly identify someone. Free-text fields carry their own risk too — participants often disclose more identifying or sensitive information in an open box than a structured question would have prompted, sometimes including details about other people who never consented to anything. And a participant can be distressed by a survey's content even though nothing about the delivery method itself was distressing, which is why a visible way to skip a question or exit, and signposted support where the topic warrants it, matters independent of how routine the format seems.

The solution

Matching review depth to the actual risk comes down to three checks:

  1. Method isn't risk. "Just a survey" isn't automatically low risk — assess it the same honest way any other study would be assessed.
  2. Look at the topic and population, not just the format. A genuinely low-risk survey still moves through review quickly under this approach; one that only looked low-risk because of its format gets the scrutiny it actually needs.
  3. Check anonymity against the real data pipeline, not just what the participant information sheet claims — including the survey platform's own data-handling practices, since it's a third-party processor like any other.

A short pilot with a handful of people outside the research team — specifically looking for questions that feel more sensitive or identifying than intended — catches problems a desk-based assessment alone can miss. And risk doesn't end when the last response is submitted: how long raw responses are retained, who continues to have access, and when they're eventually deleted or anonymised are still live questions once collection ends.

← Back to all posts
Ethiclear
hello@ethiclear.com
About Us
Applications
Docs and Info
©2026 Seastorm Limited (Company number 11867862).
Registered in England and Wales. All rights reserved.