Principal investigators, research coordinators, and research ethics and privacy offices

Can a research team put participant data into ChatGPT under an REB-approved protocol?

Sources verified Sanitized Ai Team

The short answer

Only if your REB-approved protocol and the participants' consent allow it. TCPS 2 requires researchers to describe their data safeguards to the REB and to obtain approval before substantive changes, including changes to privacy and confidentiality measures, so running identifiable participant data through an unapproved AI tool may fall outside what was approved. Ask your REB before using the tool, not after.

The situation

A research coordinator at a hospital research institute is three weeks behind on a qualitative study of patients living with chronic pain. There are forty interview transcripts to code. She pastes the first ten into a personal ChatGPT account and asks for recurring themes. The output is useful, and the backlog starts to shrink.

The transcripts include first names, the clinics participants attend, a spouse's job, a child's diagnosis. The protocol the research ethics board (REB) approved said data would be stored on an encrypted institutional server and accessed only by the study team. The consent form told participants the same thing. Nobody on the team thinks of the chatbot as a disclosure; it feels like software on her desk. The principal investigator's question, when she finds out, is whether the study is still within its approval.

What the rules actually say

The Tri-Council Policy Statement, TCPS 2 (2022), sets the ethics framework for research involving humans in Canada. Compliance is a condition of funding from CIHR, NSERC and SSHRC for researchers and their institutions, and other organizations may adopt it. It does not mention generative AI. Its privacy and review rules apply to any tool that handles participant information.

What researchers promise the REB

Chapter 5 sets out the duties that matter here:

  • Article 5.1: researchers must safeguard information entrusted to them and not misuse or wrongfully disclose it; institutions must support them.
  • Article 5.2: researchers must describe their confidentiality measures in their REB application and in the consent process.
  • Article 5.3: researchers must give the REB details of how information will be safeguarded across its full life cycle (collection, use, dissemination, retention and disposal) and assess privacy risks at every stage. The REB weighs limits on use and disclosure and the risk of re-identification.
  • Article 5.4: institutions where data are held must provide appropriate security safeguards.

What participants were told

Under Article 3.2, the information given to prospective participants generally includes what will be collected, for what purpose, and who will have access to information about their identity. If the consent form named the study team and an institutional server, an outside AI provider was not part of that picture.

Changing how data are handled

Article 6.16 requires researchers to submit substantive changes to approved research to the REB in a timely way. Its guidance names changes to measures that protect privacy and confidentiality as examples, and says substantive changes should not be implemented without documented REB approval, except to eliminate an immediate risk to participants. Article 6.15 asks researchers to report unanticipated issues that may increase risk to participants.

Is there AI-specific guidance?

Not at the national level yet. As of its July 2026 update, the Panel on Research Ethics' list of guidance documents did not include one on generative AI. Some institutions have filled the gap. A 2024 research ethics guide from Island Health, a BC health authority, says generative AI tools should not be used on personally identifiable research data without consent, treats participants' own words as potentially identifying, and recommends naming the specific tool and where its data are held in the consent form. That is one institution's policy, not a national rule, but it shows the direction REBs are taking. Provincial health privacy laws add their own research rules; see our guide on Quebec's health information act.

Why policies and bans fall short

Most research teams already have a data management plan and signed confidentiality agreements. Neither was written with a chatbot in mind, and "the protocol does not mention AI" is easy to misread as permission. Coordinators and graduate students under deadline pressure are exactly the people who reach for the fastest tool.

A blanket ban tends to push that work to personal laptops and phones, which is worse for participants and invisible to the institution. LayerX reported in 2025 that organizations have no visibility into about 89% of AI usage. The REB cannot review what it never hears about, and a team cannot report an issue it did not notice. Our article on keeping health information out of AI prompts covers why that content cannot be pulled back once submitted.

What a practical control looks like

These steps keep AI use inside the approval rather than around it. Your REB and institutional privacy office have the final word.

  1. Map where AI would help. Transcription, coding, translation, literature review, analysis code. Note which uses touch participant data and which do not.
  2. Amend before you use. For any use involving participant data, submit a change under Article 6.16 describing the tool, the data, where it is processed and held, and retention. Ask the REB whether consent materials need updating for new participants or existing ones.
  3. Prefer institution-approved tools and de-identified data. Ask your privacy or IT office which AI tools have been assessed, and agree with the REB on what de-identification means for your data type.
  4. Train the whole team, including students and trainees, with examples of indirect identifiers in transcripts and notes. Our guide for technology transfer offices covers the parallel problem for invention data.
  5. Set the incident path. If identifiable data reach an unapproved tool, report to the REB and the privacy office promptly and document what happened.
  6. Keep records of amendments, approvals and training so the team can show the safeguards it described are the ones it uses.

Sanitized Ai is a browser extension for Chrome, Edge and Firefox that supports steps 3 to 6. It detects personal information, health information and identifiers in prompts and file uploads to the major AI assistants, and redacts or blocks them before submission. The researcher sees a plain-language explanation of what was flagged and why, which reinforces the protocol at the moment someone is tempted to step outside it.

Once participant data are submitted to a public AI tool they cannot be recalled and become subject to the provider's terms. Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never the prompt content, giving the institution audit-ready records without reading anyone's prompts. Those records can help show an REB that the described safeguards operate in practice, though no tool guarantees an ethics or regulatory outcome. See our healthtech page.

Frequently asked questions

Our approved protocol does not mention AI. Does that mean we can use it?

Silence is not approval. The REB approved the specific safeguards and access arrangements described in your application and consent materials. Sending identifiable data to a new third-party AI tool is likely a change to privacy and confidentiality measures, which TCPS 2 says should not be implemented without documented REB approval. Ask your REB how it wants the change submitted.

Is it acceptable to use AI tools on de-identified data?

The risk is lower, and many REBs will consider it, but de-identification is harder than it looks for free text. Interview transcripts can identify people through their own words, workplaces or family details, a point some institutional research ethics guidance makes explicitly. Confirm with your REB what counts as adequately de-identified for your study.

Does TCPS 2 apply to our organization?

TCPS 2 is a condition of funding for researchers and institutions that receive funds from CIHR, NSERC or SSHRC, and other organizations may adopt it voluntarily. Provincial and federal privacy laws apply separately, so a study can be bound by both the policy and a statute such as a provincial health information law.

A team member already pasted identifiable participant data into ChatGPT. What should we do?

Tell your REB promptly. TCPS 2 asks researchers to report unanticipated issues that may increase risk to participants, and the institution's privacy office will need to assess any legal notification duties. Record what was shared, when and in which tool, and do not try to handle it quietly within the team.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading