Skip to main content

Prolific IDs, data collection and security

Prolific IDs, data collection and security

Collecting participant data comes with a few important responsibilities. While the exact data you collect and how you collect it will depend on your study, there are some key principles to keep in mind when working with Prolific participants.


Record your participants' Prolific IDs

You must record the Prolific ID of every participant who takes part in your study.

Prolific doesn't connect directly to your data-collection software, so you need to record Prolific IDs yourself. This allows you to identify which participant contributed which data.

There are two common ways to do this:

Whichever method you use, make sure the Prolific ID is captured correctly and stored alongside the participant's study data.


Why are Prolific IDs important?

If you don't record Prolific IDs, you won't be able to reliably identify which data belongs to which participant. This can make it impossible to take action if a participant submits poor-quality or invalid data, because you won't know which Prolific account the data came from.


Check your completion URL

Your completion URL is another important part of the data-collection process.

Make sure that:

  • Your completion URL is working correctly.

  • It submits the correct completion code back to Prolific.

  • The completion code matches the one configured for your study.

A correctly configured completion URL helps Prolific identify participants who have successfully completed your study and reduces confusion about who has and hasn't completed it.


Keep Prolific IDs secure

Prolific IDs are participant identifiers, so you should handle them carefully and only share them when necessary.

If you're planning to make your study data publicly available, for example, through OSF or a university data repository,you should remove Prolific IDs before publishing the dataset.

Consider whether participants could be identified from any combination of the information you're sharing, rather than looking at Prolific IDs in isolation.


Only collect the data you need

Only collect data that's necessary for your stated research purpose.

For example, don't collect or store information such as:

  • IP addresses

  • Cookies

  • Device information

Unless you genuinely need it for your study.

Before collecting additional information, ask yourself:

Do I need this data to achieve the purpose of my study?

You should also be transparent with participants about the information you're collecting and why you're collecting it.


Keep your study data secure

The security measures you use should be appropriate to the level of risk associated with your study.

For a low-risk study, such as a short questionnaire about personality, basic security measures may be sufficient.

For higher-risk studies, for example, research involving mental health, drug use or other sensitive information, you should consider stronger safeguards, such as:

  • Encryption

  • Pseudonymisation

  • Two-factor authentication (2FA)

  • Strong, unique passwords

  • User access controls

  • Access logging

The appropriate measures will depend on factors such as the type and sensitivity of the data you're collecting, how much data you're processing, the purpose of your research, and the potential impact of a security breach.


Document your security processes

Whatever the risk level of your study, you should document the security measures you've put in place.

You should also have processes for monitoring whether those measures are working effectively and for responding to potential security issues.

If you're unsure what security measures are appropriate for your study, your institution's Data Protection Officer (DPO) or equivalent data protection contact should be able to provide further guidance.


Key things to remember

Before launching your study, make sure you:

  • Record every participant's Prolific ID.

  • Check that your completion URL and completion code work correctly.

  • Remove Prolific IDs before publicly sharing your research data.

  • Only collect data that's necessary for your research purpose.

  • Tell participants what data you're collecting and why.

  • Use security measures that are appropriate to the sensitivity and risk of your data.

  • Document your security processes and monitor their effectiveness.

  • Contact your institution's Data Protection Officer if you need further advice.

Did this answer your question?