Q1.13.4Cross-border research governanceresearchdesign

Cross-border research must map every applicable jurisdiction and transfer

Aliases: cross-border data transfer · multijurisdictional research · data localization

What it is

Cross-border research governance addresses compliance and ethics when participants, researchers, sponsors, cloud services, and storage occupy different jurisdictions. “Origin and participant location” is a minimum reminder, not a complete legal formula. Applicability may depend on researcher establishment, controller role, service targeting, nationality, sensitive-data type, and sector rules.

Why it happens

An interview conducted in one place may upload to a cloud region in another and be annotated by a team in a third. Each step can change controller–processor duties, lawful basis, transfer mechanism, notice, and individual rights. A consent phrase saying data “may cross borders” does not replace required safeguards, contracts, approvals, or localization. Vendor subprocessors create less visible transfer chains.

Studying it

Map collection location, fields, identity keys, devices, server regions, access, subprocessors, retention, and deletion. Privacy, legal, and ethics owners with relevant jurisdictional expertise should build a requirements matrix covering notice, lawful basis, transfer mechanism, and incident response. Use test accounts to verify routing and deletion rather than trusting configuration labels alone.

Where it stops holding

There is no universal rule that simply adds two countries' requirements; laws can conflict, apply extraterritorially, or provide exemptions. Participant consent is often neither sufficient nor the best lawful basis for every transfer. Truly irreversible anonymous data may fall outside some regimes, but pseudonymization, encryption, or name removal usually does not make personal data anonymous.

Applying it

Complete jurisdiction and vendor review before recruitment, minimize sensitive fields, and separate identity keys. Lock storage regions, access roles, transfer mechanisms, retention, and breach responsibilities. Disable transcription or collaboration services that cannot demonstrate compliance. Reassess when scope, vendors, or uses change instead of reusing old consent.

Related

  • Same group: Q1.13.1 Granular recording consent · Q1.13.2 Permission and assent for minors · Q1.13.3 Deception and debriefing
  • Adjacent: Q1.06 Privacy, anonymity, and withdrawal · Q1.15 Technical preparation for remote research
  • Search terms: cross-border data transfer · data localization · controller processor

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Q1.13.4