MediclinicResearch Hub
RESEARCH ACADEMY · PROCEDURAL GUIDE

Research Ethics & Governance

A practical decision framework for participant protection, consent, data privacy and institutional approval without self-declaring exemption.

12 sections · Procedural guidance

First rule

The researcher should not use this website as authority to declare that ethics approval is unnecessary. The project should be sent through the authorised institutional/governance route for a documented determination when required.

Activities that commonly trigger formal review

  • Prospective recruitment of patients, staff or volunteers for research.
  • Randomisation or assignment of a research intervention.
  • Research procedures beyond routine care.
  • Collection of identifiable health information for a research question.
  • Secondary analysis of identifiable or linkable patient data.
  • Collection/use of biospecimens.
  • Genetic/genomic research.
  • Research involving vulnerable populations or sensitive topics.
  • Transfer/linkage of data between institutions or jurisdictions.

Activities that may use another route

  • Systematic/scoping/narrative reviews using only published aggregate data.
  • Some single case reports where local policy treats them as publication/clinical communication rather than research; publication consent still applies.
  • Clinical audit, QI or service evaluation when formally classified as such.
  • Analysis of genuinely anonymous public datasets under permitted terms.

Consent is separate from ethics approval

Ethics approval does not automatically mean consent is unnecessary, and consent does not replace ethics/governance approval. A waiver or alteration of consent must come from an authorised body under applicable rules.

Privacy checklist

  1. Collect only data needed for the protocol.
  2. Use coded study IDs; keep the re-identification key separate.
  3. Store data only in approved institutional systems.
  4. Restrict access to named team members.
  5. Encrypt transfer and avoid personal email/messaging/cloud drives.
  6. Define retention and destruction/archive dates.
  7. Avoid unnecessary exact dates, locations and rare combinations in publications.
  8. Use explicit permission for identifiable photographs/video/audio.

Research involving records

“Retrospective” does not mean “no approval.” Existing clinical information remains personal health data. The protocol should identify the dataset, fields, identifiers, extraction method, legal/governance basis, security controls and whether consent waiver is requested.

Participant-facing studies

Consent materials should explain purpose, procedures, risks/burdens, benefits (if any), alternatives, voluntariness, withdrawal, confidentiality, data use/sharing, compensation/costs when applicable, contact details and complaint routes. Avoid language implying that treatment depends on participation.

After approval

  • Use the approved protocol and consent version.
  • Submit amendments before implementation when required.
  • Report deviations, safety events and breaches through required routes.
  • Renew continuing approval if applicable.
  • Complete study closure and data archiving/destruction requirements.
Mediclinic / UAE checkpoint

Mediclinic Middle East publicly states that research projects carried out at MCME are to receive approval from its internal Research and Ethics Committee and applicable local regulatory authorities before initiation. The exact route varies by project, facility and emirate. Dubai projects may involve DSREC depending on applicability. This hub must therefore route users to the Research Office and current local forms rather than declaring a project “ethics exempt.” Institution-specific forms and contacts will be inserted after verification.

Who to contact · Forms & approvals

Final checklist

  • Project classification documented.
  • Required committees/authorities identified.
  • Data access route authorised.
  • Consent or authorised waiver documented.
  • Privacy/security plan approved.
  • Only approved protocol/material versions in use.
  • Amendment and incident reporting process known.
  • Closure/retention requirements known.

Risk assessment questions

  • What is the physical, psychological, social, legal, employment or privacy risk created by participation or data use?
  • Could the study reveal a diagnosis, behaviour, genetic result, immigration/employment issue or other sensitive information?
  • Could participation affect the clinician–patient relationship or make staff feel pressured by supervisors?
  • Will results be returned to participants, and what happens with unexpected/incidental findings?
  • Is compensation proportionate or potentially coercive?
  • Will data leave the UAE or be accessed by collaborators/vendors outside the approved environment?
  • Are AI/cloud tools proposed for patient data, recordings, transcription or analysis, and are they institutionally approved for that data class?

What to keep in the ethics/governance folder

  • Initial application and final approved protocol.
  • Approval letter/determination and all conditions.
  • Approved consent/PIS/recruitment versions.
  • Data-access/privacy approvals.
  • Amendments and approvals.
  • Deviations, breaches and safety reports where applicable.
  • Continuing review/renewal documents if required.
  • Closure report and final data-retention instructions.

Primary standards and sources