tezvyn:

Anonymity vs. Confidentiality in UX Research

AI-drafted, machine-checkedintermediate

Anonymity severs the link between data and identity; confidentiality hides that link under lock and key. Use anonymity for sensitive surveys and confidentiality for follow-up studies. The footgun is claiming anonymity while keeping names or emails on file.

WHY IT EXISTS: Researchers need honest feedback, especially about sensitive behaviors, failed tasks, or health information. If participants fear personal or professional consequences from their answers, they censor themselves. Anonymity and confidentiality are two distinct ways to reduce that fear and protect participants from harm, but they operate on different mechanics and offer different levels of protection.

THE MENTAL MODEL: Think of anonymity as shredding a document so no one can trace it back to the author. Think of confidentiality as placing the signed document in a locked safe that only the researcher can open. In the first case, the link is gone forever. In the second, the link exists but is guarded by a promise and access controls.

HOW IT WORKS: Anonymity requires that no personally identifiable information is collected, and no combination of data points can re-identify the individual. This means no names, no email addresses, no video, no device IDs, and sometimes no timestamps if they are granular enough to pinpoint a user. Confidentiality allows the researcher to know who said what, but binds them contractually and procedurally from disclosing that link to anyone else. Data may be stored with participant codes, access logs may be restricted, and reports must aggregate or blur details so third parties cannot infer identities.

WHEN TO USE IT: Choose anonymity when the topic is sensitive, when no follow-up is needed, and when the risk of re-identification outweighs the value of knowing who spoke. Unmoderated card sorts, broad satisfaction surveys, and whistleblower-style feedback channels fit here. Choose confidentiality when you need to schedule a second session, link pre-test and post-test scores, or comply with institutional review boards that require audit trails.

WHEN NOT TO USE IT: Do not promise anonymity if you are running a moderated Zoom session, collecting emails for incentive payouts, or capturing screen recordings with embedded account names. Do not rely on confidentiality alone if a subpoena could force disclosure, if your storage lacks encryption, or if your team is so small that stakeholders can guess who said what from quotes alone.

ONE CANONICAL EXAMPLE: A hospital UX team tests a new patient portal. They promise anonymity but record session videos and keep sign-in sheets. A clinician later recognizes a colleague's voice in a highlight reel. The team actually practiced confidentiality, not anonymity, because the video created a recoverable link between the data and the person. The correct design would have been to strip audio and faces for anonymity, or to lock raw footage in an encrypted, role-restricted drive and show only blurred transcripts to the wider product team for true confidentiality.

Get five bites like this every day.

Tezvyn delivers a daily feed of 60-second tech bites with quizzes to lock in what you learn.