Prof. Dr. Larry AdamsAcademic, Author & Researcher

Chapter 7. Data Protection, Sensitive Topics and Legal Risk

Data protection laws. Most countries in the region have adopted or are developing personal data protection laws. Examples include the Philippines’ Data Privacy Act of 2012, Singapore’s Personal Data Protection Act 2012, Malaysia’s Personal Data Protection Act 2010 (amended 2024), Thailand’s Personal Data Protection Act B.E. 2562 (2019), Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) and Vietnam’s data protection decree of 2023, with further legislation since [17][19][21][22][24][25]. These laws typically cover consent, purpose limitation, security, data subject rights and restrictions on transfers abroad. If you or your institution are in Europe or other jurisdictions with their own rules (such as the EU’s GDPR), those may also apply to your handling of the data.

Practical steps

Collect only the personal data you need.

Tell participants how data will be stored, used, shared and for how long.

Use secure, encrypted storage and limit access.

Anonymize or pseudonymize data as early as possible.

Check rules on transferring personal data across borders before moving files.

Plan for secure deletion or archiving.

Sensitive topics. Sensitivity varies by country but often includes: royalty and monarchy; religion and blasphemy; ethnic and racial relations; separatism and territorial disputes; political opposition and elections; corruption; land and resource conflicts; historical violence; sexuality and gender identity; and national security. Some topics can expose participants and researchers to legal or physical risk [36].

Legal risk examples (illustrative, not exhaustive). Laws such as Thailand’s lèse-majesté provision, Malaysia’s sedition and official secrets laws, Singapore’s online falsehoods law, Indonesia’s electronic information law, the Philippines’ cybercrime law, Vietnam’s cybersecurity law and defamation and national-security laws across the region may affect what can be said, collected or published. Their application changes over time. Seek local legal and academic advice early and design projects to minimize risk to participants [59].

Protecting participants. The greatest risk is often not to the researcher but to local participants and partners, who remain after the researcher leaves. Consider whether interviewing or publishing could lead to retaliation, loss of employment, arrest or social stigma. Options include: avoiding collecting identifying information, using oral consent, delaying publication, disguising locations, or changing the research question [59][62].

Researcher safety and academic freedom. Academic freedom varies in the region. Researchers should know their institution’s emergency procedures, keep trusted contacts informed, secure devices and communications, and be prepared to change plans if conditions deteriorate [65][59].

Security of digital data. Use encryption, strong passwords, multi-factor authentication, secure messaging, and consider device inspection at borders. Avoid carrying sensitive data across borders unnecessarily.

Secondary data and public records. Even when data are public, publication can raise privacy and safety concerns. Assess risks before analysing or sharing them [69].

Ethics review for sensitive research. Be open with ethics committees about risks. Many committees can help design safeguards.

Reflection: What are the three highest risks to participants in your project, and how will you reduce each?

Part III: Doing Research in Practice