Why Ethics Belong in User Research
Ethical user research is both a moral obligation and a practical necessity. It keeps the people we design for at the center of our process. When companies skip ethical considerations during technology development, the result is often products that harm or alienate the very users they aim to serve — as seen in widely reported incidents involving privacy at Facebook and AI-powered photo tagging at Google.
Ethics are the moral standards that govern how an individual, team, or organization conducts its activities. In user research, that means protecting the dignity, rights, and welfare of the participants who share their time and personal data with us. Without a proactive approach, research teams risk bias, exclusion, demoralization, or outright legal violations.
Common forms of unethical research practice include:
- Recruiting an unrepresentative or non-inclusive sample.
- Failing to inform participants about study requirements or potential harm.
- Mishandling participant data or identifiable information.
- Reinforcing stereotypes through misgendering in reports, personas, or prototypes.
You might assume an internal review board, HR department, or corporate ethics team will handle these concerns. In user experience, that is rarely the case. Company ethics departments typically focus on product offerings, customer services, and internal processes — they rarely audit research practices specifically.
As UX researcher Victor Yocco notes in his work on ethical considerations in UX research:
“Researchers by training and trade have often been required to take courses and pass exams to reflect an awareness of potential ethical issues in research. We can best prepare our colleagues to avoid these situations through similar training and standards.”
Even when organizations lack the budget for formal training, practitioners can still build ethical standards into their daily work. The key is to start with a clear reference point: a Code of Ethics.
Starting With a Code of Ethics
Before changing tools, templates, or processes, define what your ethical standards actually are. A Code of Ethics serves as the yardstick for every future study, template, and tool your team adopts. It functions as a checklist to measure each new initiative against your agreed-upon moral principles.
Creating such a code benefits more than your research practice. It can also improve team culture and performance. UX practitioners already understand that empathy is fundamental to good design — and giving team members a deeper connection to the purpose of their work fosters a more inclusive, thoughtful environment.
The process of building an ethical user research practice does not require a dedicated ethics department or extensive training budget. It begins with personal accountability: setting standards for yourself, your team, and your organization, then holding everyone to them. A Code of Ethics is the first and most essential step — it gives you a stable foundation from which to build every other ethical practice.
Ethics as a Starting Point, Not a Finish Line
Building a code of ethics requires a handful of deliberate steps, and the result becomes the backbone for aligning your research work with shared standards. It’s an ongoing investment rather than a one-off document: evaluating processes, templates, tools, vendors, and workflows takes time. The effort pays off when you deliberately recruit diverse voices, protect their information rights, and represent them accurately within your organization.
Step 1: Make the Commitment
This sounds obvious but is often the hardest part. Following any set of standards means being more thoughtful and taking the time to get things right. Ethical practice is an investment in effort and time, spent reviewing and revising how you work so it aligns with your principles. It’s also a sound business decision: recruiting diverse participants, respecting their security, and representing them fairly inside your company is time well spent.
Step 2: Study What Already Exists
There’s no need to start from a blank page. Many organizations publicly share their own codes of ethics, offering useful models. Look at both academic and industry examples. Academia tends to lean on Institutional Review Boards (IRBs), which are rarely practical for industry research — that’s why it’s on us to uphold ethical standards ourselves.
Reviewing a broad range of examples with a researcher’s eye is key. Keep a log of each organization’s principles in a document or spreadsheet, collating 15–20 sources. Strong patterns and overlaps will emerge quickly, and those shared themes become the raw material for your own principles.
Useful starting points include:
- American Psychological Association
- New York University
- World Health Organization
- Nielsen Norman Group
- Interaction Design Foundation
- ESOMAR
Step 3: Learn the Laws That Apply to You
Regulations relevant to your state, union, or industry can compel a baseline level of ethical practice. The General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), for example, carry strict rules on how organizations collect, store, and secure consumer data — and those rules extend to how research is conducted. If you operate in the EU or California and aren’t familiar with them, start reading today.
These laws effectively codify ethics into legislation, with fines or legal action for non-compliance. But they are still a bare minimum; they don’t fully cover participant welfare or dignity during research.
Some industries go further. HIPAA protects sensitive patient health information, while Customer Network Proprietary Information (CPNI) safeguards details about the type, quantity, configuration, or location of telecommunications services a customer uses. Knowing your industry’s specific rules keeps you out of trouble and sharpens your own principles.
Step 4: Define Core Principles as a Team
This is where the work becomes collaborative. Whether your team is co-located or distributed, use what you gathered in the previous steps to brainstorm the principles you want to codify. A typical ideation workshop format adds rigor to the process.
Start with affinity mapping your academic and industry examples on sticky notes or a digital whiteboard. As a team, group principles that feel similar or overlapping. If two principles are closely related but distinct, keep both within the same cluster. When there’s debate over whether concepts like “Diversity” and “Inclusion” should be separate or combined, run a dot-voting exercise — each team member casts a vote to group or keep apart.
Next, fold in the laws and regulations you researched. Where they overlap with an existing principle, build that principle out. Where a regulation stands alone, give it its own principle.
Step back and review the whole set. Aim for no more than 10 principles and no fewer than four: too many become hard to track; too few make specific examples difficult. Each principle should be specific enough that every team member can think of two or three ways to apply it in daily work. If you have too many, look for overlap and combine related concepts into a larger principle.
After working through these exercises, a typical set might look like:
- Sensitivity And No Harm,
- Honesty And Transparency,
- Confidentiality And Data,
- Accuracy And Impartiality,
- Diversity, Equity And Inclusion.
Step 5: Draft and Gather Feedback
Once your high-level principles feel solid, it’s time to make the Code actionable. Expand each principle with three components:
- A brief description — define the principle in detail and explain why it matters. Note who it applies to: not just participants, but internal processes and stakeholder teams as well.
- Bulleted agreements — these are the most important part. They make the principle concrete by spelling out how the team applies it in everyday work. In effect, they become a checklist used when planning, recruiting, conducting, and reporting research.
- A few examples — frame each example as an ethical problem followed by the appropriate solution tied to an agreement. Real past experiences make the best material.
Drafting these components together is a strong occasion for a roundtable discussion about each principle’s definition and any unique ethical situations researchers have faced. Open conversation around the best wording builds collective buy-in and deepens everyone’s grasp of each principle.
Here’s how one principle might look in practice:
- Honesty And Transparency
Maintains the integrity of our individual researchers and our research work. This principle applies not only to participants but also internally when discussing study design or findings.- Inform participants of study requirements upfront;
- Inform participants where their data is going and how it will generally be used;
- Explain any purposeful manipulation at a session’s end;
- Explain the pros and cons of methodologies, and study limitations to internal stakeholders.
Example:
When designing a study with biometrics, devices with sensors need to be worn by participants. It should be communicated to participants that they will be wearing devices on or close to the skin which may cause minor irritation. The researcher should clearly explain why and where they’ll be needed in the study.
Step 6: Validate and Finalize
Once the first draft has buy-in from your team, get outside perspective. Schedule meetings with your legal and ethics department contacts to share your work and check against anything you might have missed. These groups uphold ethics across the business and will have in-depth knowledge of CCPA, GDPR, and related regulations that could affect your final Code.
If you haven’t worked closely with these teams before, you may need to introduce them to what your team does first. That could mean two separate sessions: one to explain your purpose, and a follow-up to review the Code. If they weren’t aware user research was happening, they may already be concerned about privacy law — in which case remind them this Code exists precisely to get everyone on the same page.
From Principles To Process
A Code of Ethics only has value if it changes how research is actually done. The following areas are where those principles translate most directly into concrete practices, templates, and documentation. The upfront investment in building these foundations is significant, but the ongoing maintenance is comparatively light. Start with the areas below, then look for other parts of your workflow that could benefit from the same scrutiny.
Recruitment And Screening
If your Code of Ethics includes commitments to Diversity, Equity, and Inclusion, your screener questionnaire template and recruitment practices are the first place those commitments need to show up. The wording and administration of demographic questions — particularly around race, ethnicity, and gender — require special care because people identify in varied and nuanced ways.
Several practical considerations can make demographic questions more ethical:
- Briefly explain why you are asking for personal information such as gender or race before requesting it. Context reassures participants who worry their data may be misused.
- Use
select all that applycheckbox options so participants can reflect mixed-race or multi-dimensional gender identities. - Always provide a
prefer not to answeroption. - Be exhaustive with race response options to avoid forcing participants into inaccurate classifications.
- Include
non-binaryandprefer to self identifyoptions for gender.
Beyond screener wording, the recruitment process itself should make a deliberate effort to source a diverse participant pool, even for qualitative studies with small sample sizes. When working with recruitment firms or panel tools, this is generally achievable. But sometimes it means cancelling sessions and re-recruiting when initial efforts yield a homogeneous group — for example, nine out of ten participants being middle-aged white men. Diversity commitments require that willingness to restart recruitment.
Data Retention And Management
Participants share sensitive personally identifiable information with the expectation that it will remain private and secure — and regulations like GDPR and CCPA may require it by law. A comprehensive Data Retention Policy should cover all information collected from participants. While templates and resources exist to help draft such policies, the essential questions are consistent:
- What data is being collected?
- Is it being stored, and for what purpose?
- How long will it be retained before deletion?
- How is the data secured?
- Who has access to it?
Once drafted, the policy should be reviewed by your Legal team to ensure it meets local and federal requirements, particularly around specialized data categories such as CPNI or HIPAA. Then train your team on the policy and explain why safeguarding participant information matters. A practical enforcement mechanism is to include a Data Retention Plan section in every Test Plan document, outlining what data is collected during the research session, how it will be used, whether it will be stored, and how it will be protected. For example, a contextual inquiry that discusses COVID-19 vaccination status should document exactly that information:
| Data | Instrument | Retention Plan | Notes |
|---|---|---|---|
| Name And Likeness | Video/Audio Recording And Recruitment firm | Codify as ID # | Identification is not important. Participant will be anonymized. |
| Mailing Address | Recruitment Firm | Delete after data collection | Only needed for moderator’s arrival during the study. |
| Vaccination Status | Video/Audio Recording | Maintain for 6 months | Needed to create personas. Data not needed after study completion. |
Informed Consent And NDAs
Keeping participants informed and comfortable throughout the research process is a core ethical obligation. This begins with providing clear documentation and a forum for questions before the study starts. When research involves confidential or internally safeguarded work, Non-disclosure Agreements help keep participant involvement undisclosed — but these documents should never be dense legal texts that are difficult to follow.
Informed Consent documents vary in structure, though the key components remain consistent:
- Thank the participant for considering participation.
- Explain the study topic at a high level, giving enough detail to build understanding without overwhelming.
- Provide a clear, bulleted list of expectations and activities involved in the session.
- Disclose any potential risks, danger, or manipulation inherent in the study.
- Remind participants of the time commitment, any follow-up activities, and the incentive structure.
- End with a request for written consent, including signature and date.
Participants must be able to deny or withdraw consent at any time, without warning, reason, or penalty. Informed consent is meaningless if participants feel coerced into maintaining it. This applies equally during sessions — when research touches triggering or emotional topics, or when an emergency interrupts a session, participants should feel empowered to step away without fear of losing their incentive or facing retaliation.
Ethical Internal Artifacts
Ethical obligations extend beyond the study itself into the reports, prototypes, and personas that outlive the research and shape design decisions for months. Three areas deserve particular attention.
Findings Reports
Reporting should be as representative and impartial as the study design and administration. The audience should come away with an accurate understanding of what was learned and how, including the study's limitations:
- Include a
study setupsection describing methodology, with both strengths and weaknesses stated transparently. - Provide a
participantssection that bullet-lists attributes. Note diversity limitations — for instance, if you recruited 30 women out of 40 total participants despite best efforts, say so. - Avoid using participant faces in photos unless explicit consent was given, especially for sensitive topics.
- Draw direct quotes, audio, and photos from a range of participants to reflect the diversity of your recruit.
- Don't paraphrase quotes or over-infer without solid context. This protects impartiality and mitigates unconscious bias.
- Keep demographic information out of individual qualitative findings. Statements like "two male Caucasians said X" risk reinforcing institutionalized biases. Demographics should only be segmented in quantitative samples where statistical analysis can reveal meaningful differences.
Personas
Personas help communicate generative research findings, but they can also reinforce gender, age, and racial stereotypes if created carelessly. The goal is to craft personas that remain humanizing without enforcing bias. The following guidance helps walk that fine line:
- Avoid human names altogether where possible. Names frequently promote biased assumptions about gender roles or occupational status. Pithy shorthand titles like
Cautious ComparerorImpulsive Spendercan exemplify a persona more effectively without the baggage. - If names are necessary for humanization, use gender-neutral and culturally diverse names. Western European-only names can erase the identity of users from other backgrounds. Options like Adrian, Armani, Kai, Krishna, Maren, Noor, Sam, Jaylin, Jordan, and Yoshi span cultural and gender boundaries.
- Prefer artistic visualizations over photos. A persona for a car manufacturer communicates more truthfully with an illustration of a scale weighing cost against safety than with a stock photo of a worried-looking person. Artistic illustrations that are ambiguous in gender, race, and body type remain inclusive without stigmatizing.
- Do not include disability status unless it was a direct focus of your research or you are intentionally building a set of personas around varying abilities or intersectionality. Well-intentioned inclusion of marginalized communities can end up misrepresenting them.
- Skip demographics like gender, race, or sexual orientation unless you're doing segmentation work. Personas should reflect shared attitudes and behaviors that typically transcend demographic categories.
Design Prototypes
The same care extends to prototypes. When placing fictitious characters at the heart of mock-ups, lean on gender-neutral and culturally diverse names for elements like the account name of an authenticated user. For profile images, use artistic illustrations or a diverse range of stock photography. When a design represents multiple individuals, step back and check that the holistic group shows diversity rather than focus on one gender, race, culture, or body type.
Why Ethics Belongs In The Business Case
Embedding ethical principles into user research is not just a moral obligation; it is also a strategic advantage. Clear ethical guidelines keep decision-making consistent, reduce risk, and demonstrate accountability to both users and the wider society.
When ethics are woven into your team’s templates, workflows, and standard processes, it signals a genuine commitment to user dignity and welfare. Establishing this kind of practice does not require a massive overhaul — it takes deliberate and sustained effort, but the investment pays off in trust and long-term viability.
Ultimately, nobody else will enforce these standards for you. There is no external authority watching over the field of human-computer interaction; the responsibility rests with each practitioner to center the humans they design for in everyday business decisions.
Further Reading
- Conducting Accessibility Research In An Inaccessible Ecosystem
- Building A User Segmentation Matrix To Foster Cross-Org Alignment
- Everything I Know About UX Research I First Learned From Lt. Columbo
- Three Approaches To Amplify Your Design Projects




