Research ethics is usually taught as a compliance exercise: fill in the form, get the approval, obtain the signature, file the certificate.
Taught that way it teaches the wrong thing , because the hardest ethical problems in social research are precisely the ones the form does not ask about — group harm, the impossibility of consent in most field settings, the tension between protecting participants and protecting institutions from scrutiny, and what you owe people after the study is finished.
And the rules exist because of specific events. This lesson starts with the one that shaped them, and then works outwards to the problems that the rules do not solve.
Forty years, six hundred men, and a treatment that existed.
In 1932 the United States Public Health Service began a study in Macon County, Alabama, one of the poorest counties in the country. It enrolled around 600 Black men — 399 with latent syphilis and 201 without — to observe the untreated course of the disease.
The men were not told they had syphilis. They were told they were being treated for "bad blood" , a vague local term covering several conditions. They were given free medical examinations, free meals on examination days, and burial insurance — which mattered enormously to men with no money and families who would otherwise have paid for a funeral.
They were given no treatment for syphilis. Diagnostic spinal taps were presented to them as "special free treatment". The study's purpose was observation until death, followed by autopsy.
By around 1947 penicillin was the standard, effective treatment for syphilis, and it was widely available. The study continued. Men in the study were actively kept from receiving it — steps were taken to prevent them being treated elsewhere, including through local physicians and, during the war, the draft board.
It ran for forty years. It was not secret from the profession: findings were published in medical journals throughout, and nobody stopped it.
It ended in 1972 because an employee of the Public Health Service, Peter Buxtun, having failed to get it stopped through internal channels, went to the press. The story broke in July 1972. The study was terminated in November.
The consequences for research governance were immediate : the National Research Act of 1974, the creation of institutional review boards in something like their modern form, and the Belmont Report of 1979, whose three principles still structure ethics review across much of the world.
And now the part that belongs specifically in a sociology course.
The harm did not stop with the men in the study. Economists Marcella Alsan and Marianne Wanamaker examined what happened to health-seeking behaviour among older Black men in the United States after the 1972 disclosure , and found a decline in medical interactions and outpatient visits, concentrated among Black men living closer to Macon County, alongside effects large enough that they estimated a measurable contribution to the Black–white life expectancy gap for that group.
The estimate has been debated, as such estimates are. The wider point is not in dispute and is the reason this is the story: a research betrayal became a durable social fact. Distrust of medical institutions among Black Americans has a documented history and a specific citation, and it has cost lives among people born long after the study ended.
Ethics violations are not only wrongs done to participants. They are events in the social world with consequences that outlast everyone involved — which is the sociological reading of the case, and the one most often left out.
Informed consent is the central principle of research ethics, and most social research cannot obtain it in the form the principle describes.
In a public square , you are observing hundreds of people who cannot all be asked.
In an organisation , the chief executive granted access. The cleaner did not , and cannot easily refuse to be observed at work.
In an ethnography , you consented with twelve people in January and by June the setting contains forty, most of whom drifted in (see 7.5.1).
In an audit study , telling employers would destroy the measurement — and the whole point is to observe what people do rather than what they say (see 7.4.2).
In administrative or platform data , there are two million people, none of whom can be contacted and all of whom agreed to terms of service they did not read (see 7.4.4).
None of these is a reason to abandon the principle. They are reasons to understand what the principle is protecting — autonomy, and the ability to decline — and to ask, in each case, what protects that when a signature cannot.
The framework, and what it covers
The three Belmont principles, and a fourth that sociology needs.
Respect for persons. People are autonomous agents who decide for themselves whether to participate, and those with diminished autonomy are entitled to protection. This is where consent lives.
Beneficence. Maximise possible benefits and minimise possible harms. Note the structure: it is a weighing, not a prohibition — research that carries some risk can be justified by what it produces, and research with no plausible benefit cannot justify any risk at all, including the participants' time.
Justice. The burdens and benefits of research should be distributed fairly. This is the principle Tuskegee violated most flagrantly — the burden fell on poor Black men in the rural South, and any benefit would have accrued elsewhere. It is also the principle behind the modern objection to research conducted on populations who will never have access to what it produces.
And a fourth, which the biomedical framework handles badly: respect for communities. Sociological findings are often about groups, and can harm a group without identifying any individual in it (below).
Informed consent has three components, and each fails differently. Information — enough to decide, in language that can be understood. Comprehension — which is a property of the participant's understanding, not of the document's completeness; a longer form is usually a worse one. Voluntariness — the absence of coercion or undue influence, which is precisely what is missing when the researcher is introduced by your manager, your doctor, your teacher or your caseworker.
And consent is a process, not a signature. It is renegotiated as the study changes, and it is revocable — which means participants must know how to withdraw and by when, and that "you may withdraw at any time" is meaningless if nobody tells them how.
Harm, and the kinds sociology produces.
Physical harm is rare in social research and is the model on which most of the machinery was built.
Psychological harm — distress from being asked about bereavement, abuse, illness, failure. Manageable and not a reason to avoid such research , since people frequently value being asked. The obligations are practical: warn in advance, allow skipping, do not press, know where to refer, and do not leave someone in distress at the end of an hour.
Social harm is the commonest in this discipline. Damage to relationships, standing, employment or safety from what becomes known — to a spouse, a manager, a community, an immigration authority.
Legal and economic harm — disclosure of criminalised or sanctionable behaviour; jeopardising benefits, employment or status.
And group harm, which is the distinctively sociological one. A study reporting rates of something stigmatised in a named community harms that community's members whether or not any individual is identified. The people harmed did not participate and cannot consent or withdraw , and no anonymisation touches it.
This is genuinely hard, and it must not collapse into "do not publish uncomfortable findings about groups." Research on discrimination, deprivation and violence within communities is necessary, and suppressing it protects nobody. The obligations are about how : report base rates and comparisons rather than raw counts that invite misreading; state the structural conditions rather than presenting a group as a type; anticipate how the finding will be used; and where possible involve the community in framing the question rather than only in supplying data.
Confidentiality and anonymity are different, and both can fail.
Confidentiality : the researcher knows who you are and will not disclose it. Anonymity : nobody knows, including the researcher — genuinely rare, and impossible in any interview study.
Deductive disclosure is the practical enemy. In an organisation of forty, "a female senior manager in the finance function" is a name. In a village, the pseudonym is transparent to everyone who lives there. Removing names does not anonymise a setting , and participants routinely underestimate this while researchers routinely over-promise.
The techniques : pseudonyms, altered non-essential details, aggregation of roles, delayed publication, and sometimes disguising the setting itself — each of which trades verifiability for protection (see 7.5.1), and each of which should be declared.
And confidentiality promises have limits that must be stated in advance, because they are real.
Legal compulsion. The clearest documented case is the Belfast Project — an oral history archive of interviews with former paramilitary participants in the Northern Ireland conflict, held at an American university, where interviewees were promised their recordings would not be released until their deaths. Following subpoenas issued under a mutual legal assistance treaty, material was ordered to be handed to police, and some was. The promise had been made in good faith by researchers who did not control the jurisdiction they were operating across.
Mandatory reporting. In many settings, disclosures about risk to a child or a vulnerable adult must be reported.
So the honest consent statement is not "everything you say is confidential." It is: here is what I will do to protect you, here are the circumstances in which I could be compelled or obliged to disclose, and here is what I cannot control. Anything stronger is a promise you may not be able to keep.
The studies that made the rules, graded honestly
Four cases, each teaching something different.
The Nazi medical experiments produced the Nuremberg Code of 1947, whose first principle is that voluntary consent is absolutely essential. It is the founding document, and it was written about crimes rather than about research.
Milgram's obedience experiments deceived participants into believing they were administering painful and possibly lethal shocks. Many showed extreme distress. The findings are among the most influential in social science, and the ethical objections were made at the time — most forcefully by Diana Baumrind, on the grounds of the distress caused and the durable damage to a person's view of themselves. Archival work has since complicated the standard account , indicating that debriefing was less prompt and less complete than reported, that many participants were not told the truth for some time, and that the procedure varied more across conditions than the published summary suggested.
The Stanford prison study requires stating plainly, because it is still taught as a demonstration of situational power. Archival analysis of the original materials has substantially undermined it : guards were given explicit guidance on being tough, at least one participant later said he had acted, and the study lacked the controls its conclusions require. It is best taught now as a case study in how a compelling narrative survives weak evidence — and its ethical problems, including the absence of an exit for participants, were real regardless.
And Humphreys' tearoom study (see 7.5.1): covert observation compounded by tracing participants to their homes under a false pretext, creating a document linking named individuals to criminalised behaviour. Substantively valuable, methodologically indefensible , and one of the direct provocations for social science ethics review.
What the four together establish is not that deception is always wrong or that covert work is never permissible. It is that researchers are not reliable judges of the risks their own research creates — every one of these was conducted by serious people who believed their work justified what they were doing.
Deception, covert work and the conditions under which they can be justified.
Deception is sometimes the only way to measure what people do rather than what they report (see 7.4.1, 7.4.2). The standard conditions under which it is approved:
No feasible alternative design would answer the question.
The risk to participants is no more than minimal , and specifically no more than they encounter in ordinary life.
Nothing is done that participants would be likely to object to on learning of it.
Debriefing is provided where possible — and it is not automatically a benefit. Telling someone they were deceived can itself distress them, and in field settings it may expose them to the very information the deception avoided. In audit studies, employers are generally not debriefed individually , and the justification is that the burden per employer is negligible while the knowledge is a public good.
Covert observation carries a heavier burden. It is most defensible in public settings where no individual is identified , and in studying powerful institutions that use access control to prevent scrutiny — where the alternative is that the powerful can only be studied with their permission, which is not a neutral outcome (see 7.1.2 on the hierarchy of credibility). It is least defensible where participants are vulnerable, identifiable or criminalised.
Vulnerability, payment and digital data: three places where the standard rules misfire.
Vulnerability is usually situational, not categorical. The standard lists — children, prisoners, people with cognitive impairment — capture some of it and miss most. A worker interviewed at work by someone their employer let in is in a situation of constrained voluntariness , whatever their capacity. So is an asylum seeker interviewed by someone who might be mistaken for an official, or a patient asked by someone in the clinic that treats them.
And over-protection has costs that are rarely counted. Categorically excluding a group from research protects them from research risk and from the benefits of an evidence base about them — the most-cited example being the historic exclusion of pregnant women from trials, leaving clinicians to make decisions with almost no evidence. "They are vulnerable, so we excluded them" is a decision with victims too.
Payment. Too little is extractive — asking people with the least to give time for nothing, so that research is subsidised by those it studies. Too much can be an undue inducement , particularly where the amount is large relative to a participant's income, because it can lead people to accept risks they would otherwise decline. The usual resolution is to pay for time and expenses at a rate that recognises the contribution without being decisive , and to pay in a form that does not jeopardise benefits.
Digital data, where the rules are least settled.
Publicly accessible is not the same as consented. A post is public in the sense that anyone can read it; the author did not agree to be a research subject, and quoting it verbatim in a paper makes it searchable and identifies them.
Terms of service are not ethics. A platform's permission to use data is not the users' permission.
Two cases mark the boundaries. The large-scale experiment in which a social media platform altered the emotional content of hundreds of thousands of users' feeds to study contagion — conducted without specific consent, published, and followed by an expression of concern from the journal and a substantial public argument about whether platform A/B testing becomes something different when it is published as science. And the case of a personality-testing dataset gathered for research that was subsequently used commercially and politically , which demonstrated that data collected under research conditions does not stay under them.
The working principles for digital work : consider whether the people would expect to be observed; paraphrase rather than quote where quotation is searchable; treat sensitive categories and identifiable individuals as requiring the same protections as offline; and remember that re-identification from combined datasets is far easier than intuition suggests (see 7.4.4).
Ethics review: what it does well, and the serious criticism.
What review boards do well. They catch identifiable harms to individuals, force researchers to think through consent and data security before starting, provide an independent check on people who are poor judges of their own projects, and give participants recourse.
And they are also institutional risk management , which is not the same thing as participant protection and occasionally conflicts with it.
The criticisms are substantial and come from people who take ethics seriously.
The model is biomedical. It was built for interventions on bodies, with discrete procedures, defined risks and a signature before anything happens. Applied to ethnography — where the design changes, the setting changes and consent is continuous — it fits badly , and the fit is worst for exactly the methods most likely to study power.
It can operate as prior restraint. A committee that requires all questions in advance cannot approve an emergent design. And research into institutions that can withhold consent — police forces, employers, government departments, corporations — is systematically harder to approve than research into the people those institutions act upon. The critical literature is blunt about the consequence: review can make the powerful harder to study than the powerless , which is an ethical outcome in its own right.
Both things are true at once. The abuses that produced the system were real, catastrophic, and committed by researchers who thought they were doing good. And a governance system built on that history can, in operation, protect institutions more reliably than it protects people. Holding both is the honest position, and it is 7.1.2's argument arriving in a committee room.
Because ethics is not a stage of a project. It is a property of every decision in it.
It is in the question — who benefits from this being known, and who bears the cost of it being known.
In the sampling — who is over-researched, and who is excluded for their own protection.
In the measurement — what a category does to the people placed in it (see 7.1.3 on looping effects).
In the fieldwork — what you promised, what you can deliver, what you do when you learn something you were not meant to.
In the analysis — what you do with the participant whose account undermines your argument.
In the writing — how people are represented to readers who will never meet them.
And after — what happens to the data, and whether anything returns to the people who supplied it.
Three questions that do more work than any form.
Would I be comfortable if my participants read exactly what I have written, in full? Not the summary — the analysis.
Who bears the risk, and who gets the benefit? If those are different people, that requires justification.
And what would this look like in a newspaper? Not as a test of legality, but because the reaction of a reasonable outsider is a decent proxy for something researchers lose access to from inside a project.
Tuskegee was approved, funded, published and continued for forty years by people operating within their profession's norms. The lesson is not that they were monsters. It is that norms are not ethics , and that the mechanism which finally stopped it was one person deciding that the rules were not enough.
Tuskegee — 1932 to 1972, around 600 men, told they had "bad blood", denied penicillin after it became standard — produced the modern machinery: the National Research Act and the Belmont Report. And its harm outlived it as a social fact , with research linking the 1972 disclosure to reduced medical engagement and mortality effects among older Black men.
Consent is the central principle and most social research cannot obtain it as described — in public settings, in organisations where access is granted from above, in ethnographies whose populations change, in audit studies, in platform data. The principle protects autonomy and the ability to decline , and the question is always what protects those when a signature cannot.
Belmont's three principles — respect for persons, beneficence as a weighing, and justice in the distribution of burdens and benefits, which is what Tuskegee most flagrantly violated — plus a fourth sociology needs: respect for communities.
Consent requires information, comprehension and voluntariness , is a process rather than a signature, and is undermined whenever the researcher arrives through someone with power over the participant.
Group harm is the distinctively sociological harm : it falls on people who did not participate, cannot withdraw, and are not protected by anonymisation. The response is not suppression but care in framing, comparison and anticipation of use.
Confidentiality is not anonymity, and deductive disclosure defeats pseudonyms in small settings. Promises have limits — the Belfast Project showed that legal compulsion can override them across jurisdictions — so consent statements must say what cannot be controlled.
The founding cases teach one common lesson : Nuremberg, Milgram (with archival work complicating the debriefing account), the Stanford prison study (substantially undermined as evidence) and Humphreys were all conducted by serious people who believed the work justified the method. Researchers are not reliable judges of the risks they create.
Deception requires no feasible alternative, minimal risk, nothing participants would object to, and debriefing where it does not itself harm. Covert work is most defensible on the powerful and least on the vulnerable.
Vulnerability is situational; over-protection excludes people from an evidence base about them; payment must recognise without inducing; and public is not consented.
Ethics review catches individual harm and is also institutional risk management — built on a biomedical model, poorly fitted to emergent designs, and capable of making the powerful harder to study than the powerless.
Belmont principles — respect for persons, beneficence, justice.
Informed consent — information, comprehension, voluntariness; a process, not a signature.
Voluntariness — undermined by any power relation in the route to the participant.
Group harm — damage to a community from findings about it, unreachable by anonymisation.
Confidentiality / anonymity — the researcher knows and will not tell; nobody knows.
Deductive disclosure — identification from combinations of details despite removed names.
Debriefing — informing participants of deception afterwards; not automatically beneficial.
Minimal risk — no greater than that encountered in ordinary life.
Undue inducement — payment large enough to override a participant's judgement of risk.
Situational vulnerability — constrained voluntariness arising from position rather than category.
Prior restraint — the criticism that review can prevent research, disproportionately into powerful institutions.
Re-identification — recovering identities from combined or de-identified datasets.
One — write an honest confidentiality statement. For a study you might run, write what you would actually promise, including the circumstances under which you could be compelled to disclose. Compare it with the sentence most consent forms use.
Two — test for deductive disclosure. Take a setting you know — your workplace, a club, a course — and write a description of a member using only role, gender and tenure. Count how many people it could be.
Three — find the group harm. Take a research finding about a named community. Ask who is harmed by it who was not a participant, and what framing would have reduced that without suppressing the finding.
Four — apply the newspaper test. Take any study in this Part and imagine it reported by a hostile journalist. Note what would be hardest to defend, and whether that is a real problem or only an appearance.
Five — ask who bears the risk. For three studies you have read, write down who took the risk and who got the benefit. Where they differ, ask what justified it.
Ethics governs what research may do. The next lesson is about whether research does what it says it does at all.
Over the last fifteen years, systematic attempts to repeat well-known findings have failed at rates that shocked several disciplines — and the diagnosis implicates almost everything in this Part: publication bias, low power, analytic flexibility, and incentives that reward novelty over reliability.
7.8.2 — The Replication Crisis covers what was found, what causes it, which fields are affected and how badly, what has been done about it, and what a reader should conclude about a literature they cannot personally re-run.