skip to main content

Research Data Governance — ORE Part 1 MCQ

Instant feedback + full explanation. One question, done properly.

ModerateBehavioural Sciences & EthicsResearch Data GovernanceORE Part 1

A dentist is asked to provide a researcher with patient-level data for a service-evaluation study. The dataset has been de-identified, but the dentist is unsure whether individuals could still be identified when the data are combined with other available information. What is the most appropriate action before any disclosure?

Educational content. Not a substitute for clinical judgement or local policy.

Reveal the answer and explanation

Correct answer: AConfirm a justified, documented and lawful disclosure using only the minimum necessary information

Explanation lettering: E = shown as B · B = shown as C · C = shown as E

The best answer is A. Removing names or other direct identifiers does not guarantee true anonymisation where people may still be identifiable by linkage with other information. The dentist must therefore ensure that the proposed disclosure has a clear, documented and lawful purpose, is appropriately scrutinised through local information-governance arrangements, and contains only the minimum necessary information. This reflects Caldicott principles 1, 2, 3 and 6. B is unsafe because de-identification alone may leave re-identification risk. C is insufficient: verbal permission does not by itself establish an appropriate lawful and governed disclosure. D is also insufficient because a confidentiality agreement does not justify or legalise the transfer. E is wrong because research use may be appropriate when properly governed.

Reference: National Data Guardian, The Caldicott Principles, 2020. https://www.gov.uk/government/publications/the-caldicott-principles