Ethical guidelines for geoprivacy: a framework for researchers and ethics committees - PMC Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Int J Health Geogr . 2026 Mar 2;25:23. doi: 10.1186/s12942-026-00460-y Search in PMC Search in PubMed View in NLM Catalog Add to search Ethical guidelines for geoprivacy: a framework for researchers and ethics committees Milad Malekzadeh Milad Malekzadeh 1 Digital Geography Lab, Department of Geosciences and Geography, University of Helsinki, Helsinki, Finland Find articles by Milad Malekzadeh 1, ✉ , Yan Kestens Yan Kestens 2 École de santé publique de l’, Université de Montréal & Centre de recherche en santé publique, Montréal, Québec Canada Find articles by Yan Kestens 2 , Justine I Blanford Justine I Blanford 3 Faculty of Geo-Information Science and Earth Observation, University of Twente, Enschede, Netherlands Find articles by Justine I Blanford 3 , Camille Perchoux Camille Perchoux 4 Luxembourg Institute of Socio-Economic Research (LISER), 11 Porte des Sciences, L-4366 Esch-sur-Alzette, Luxembourg Find articles by Camille Perchoux 4 , Mir Abolfazl Mostafavi Mir Abolfazl Mostafavi 5 Centre de recherche en données et en Intelligence géospatiale, Université Laval, Quebec City, Québec Canada Find articles by Mir Abolfazl Mostafavi 5 , Grant McKenzie Grant McKenzie 6 Department of Geography, McGill University, Montreal, Canada Find articles by Grant McKenzie 6 , Eun-Kyeong Kim Eun-Kyeong Kim 4 Luxembourg Institute of Socio-Economic Research (LISER), 11 Porte des Sciences, L-4366 Esch-sur-Alzette, Luxembourg 7 LuxProvide S.A., 31 Rue du puits Romain, L-8070 Bertrange, Luxembourg Find articles by Eun-Kyeong Kim 4, 7, ✉ Author information Article notes Copyright and License information 1 Digital Geography Lab, Department of Geosciences and Geography, University of Helsinki, Helsinki, Finland 2 École de santé publique de l’, Université de Montréal & Centre de recherche en santé publique, Montréal, Québec Canada 3 Faculty of Geo-Information Science and Earth Observation, University of Twente, Enschede, Netherlands 4 Luxembourg Institute of Socio-Economic Research (LISER), 11 Porte des Sciences, L-4366 Esch-sur-Alzette, Luxembourg 5 Centre de recherche en données et en Intelligence géospatiale, Université Laval, Quebec City, Québec Canada 6 Department of Geography, McGill University, Montreal, Canada 7 LuxProvide S.A., 31 Rue du puits Romain, L-8070 Bertrange, Luxembourg ✉ Corresponding author. Received 2025 Aug 22; Accepted 2026 Feb 19; Collection date 2026. © The Author(s) 2026 Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/ . PMC Copyright notice PMCID: PMC13092162 PMID: 41772605 Abstract Background The increasing use of geographic data about individuals in health and social research raises ethical challenges that extend beyond existing legal frameworks. While regulations such as data protection laws define boundaries, they rarely provide researchers with sufficient practical guidance for addressing geoprivacy risks. Methods We developed a structured, reflexive ethical framework tailored for research involving human-centered geographic data. The framework was designed using a lifecycle approach and informed by both a review of existing literature and the expertise of the multidisciplinary author team. It organizes ethical considerations into five research phases: data collection, storage, sharing, analysis, and results dissemination. To enhance usability, we translated these considerations into 60 guiding questions, each assigned an importance level (high, moderate, or low). An ethical review applicability matrix was also introduced to help determine the level of ethical scrutiny required, based on study characteristics such as data type, granularity, linkage potential, and participant vulnerability. Results The framework offers a practical and scalable tool for embedding ethical reflection into research processes. It supports proportionate ethical review by aligning the sensitivity of specific research practices with the corresponding importance of guiding questions. To demonstrate its adaptability, we provide two case studies in the supplementary materials that apply the framework to different research scenarios with varying levels of geoprivacy sensitivity. Conclusions By encouraging early and context-aware engagement with ethical risks, this framework safeguards participant dignity, fosters transparency, and advances ethically responsible research involving geographic data. It equips both researchers and ethics committees with a systematic approach for addressing geoprivacy challenges across diverse health and social science contexts. Supplementary Information The online version contains supplementary material available at 10.1186/s12942-026-00460-y. Keywords: Geoprivacy, Geographic data ethics, Human-centered spatial research, Data protection and consent, Ethical data governance Introduction In recent years, the collection and use of geographic data related to individuals has become increasingly widespread in research. While traditionally central to fields such as geography, urban planning, and transportation, geographic data are now routinely used across diverse domains, from public health and environmental psychology to digital epidemiology and urban sustainability [ 1 – 9 ]. The integration of spatial context into research designs allows scholars to better understand where and under what conditions social, behavioral, or biological processes occur, and how place-based exposures influence outcomes [ 10 – 12 ]. Geographic data is no longer limited to studies of mobility or infrastructure. For example, health research might explore how access to green space affects mental wellbeing [ 13 ], or more broadly, how environmental characteristics of place relate to health behaviors or chronic disease [ 14 ]; and social science research may investigate inequality by studying locational access to education, services, or housing [ 15 ]. In many of these cases, the use of geographic information is essential to characterize place attributes, which help understand how context impacts the outcome of interest. This growing ubiquity of geographic data use is paralleled by a rapid expansion in our technical capacity to collect individual-level spatial data [ 16 , 17 ]. Advances in both hardware and software have made the capture of locational information effortless, often requiring only a few lines of code and using sensors embedded in even low-end smartphones. Mobile apps, wearable sensors, web-based mapping tools, and passive data from online platforms have made it easy to collect and store data about individuals’ locations, movements, and environments [ 18 , 19 ]. Map-based surveys, geotagged content, and location-tracking apps can now gather highly granular geospatial data with minimal effort from researchers or participants [ 8 , 20 – 22 ]. This ease of collection, however, comes with serious ethical challenges, especially when dealing with human geographic data [ 23 ]. These include implicit surveillance concerns as data is collected passively; contextual exposure where locations may reveal sensitive activities (e.g., visits to healthcare facilities or religious institutions); and challenges in consent processes where participants rarely comprehend the full inferential power of their location data. Moreover, neighborhood-level analyses can unintentionally reinforce social stigma [ 24 ], and location exposure can result in stalking, profiling, or discrimination [ 25 ] if such data are leaked or misused. Even anonymized trajectory data can often be re-identified by linking patterns of movement [ 26 ]. Geoprivacy, defined as “a special type of information privacy which concerns the claim of individuals to determine for themselves when, how, and to what extent location information about them is communicated to others” [ 27 ], captures the distinct nature of privacy concerns tied to geographic data [ 28 ]. As Keßler & McKenzie [ 29 ] argue in their Geoprivacy Manifesto, this concern is not simply a subset of general information privacy; it demands specific attention due to the unique risks and relational nature of geographic data. While legal instruments such as GDPR [ 30 ], HIPAA [ 31 ], and various national laws provide a regulatory baseline for data protection, they often fall short in addressing the practical ethical dilemmas faced by researchers. In reality, many projects struggle with delays, revisions, or outright rejections by ethics committees due to insufficient attention to the ethical implications of collecting, using and sharing geographic data. Another challenge arises from the unique nature of geographic data. Unlike other personal data, location information is inherently spatially and often temporally indexed, and is subject to spatial autocorrelation—what Tobler [ 32 ] framed as the First Law of Geography: “everything is related to everything else , but near things are more related than distant things.” This means that learning the whereabouts of an individual can also reveal information about their neighbors, communities, or shared environments. As a result, geoprivacy in research must extend beyond individuals to consider broader spatial contexts and social implications. Additionally, the rise of GeoAI and large-scale foundation models introduces new risks to geoprivacy. These models can infer detailed behavioral or contextual information about people based on geospatial similarity or sparse location traces, often uncovering patterns that were previously unthinkable [ 33 , 34 ]. These capabilities mean that even minimal location signals, such as a photo, a check-in, or a timestamped path, can lead to unintentional disclosure or privacy breaches when analyzed at scale by increasingly powerful models. All these developments underscore the urgent need for clearer ethical frameworks and practical guidance for researchers and ethics committees alike [ 35 , 36 , 44 ]. While the principles of data minimization and anonymization are well established, how these concepts should be applied to geospatial data remains inconsistent and poorly documented. Researchers often know why location data is needed (e.g., to assess environmental exposures at specific locations) may lack clear guidance on how to handle such data ethically and securely. At the same time, ethics committees are frequently unfamiliar with the unique risks and requirements of geographic data, making it difficult to evaluate what limitations or safeguards should be expected. In response to these challenges, this paper proposes a structured set of ethical questions and reflective prompts to support both research teams and ethical review boards in navigating geoprivacy issues for research. These questions are organized across the five major phases of a geospatial study—data collection, storage, sharing, analysis, and results dissemination—and are designed to be flexible, forward-looking, and context-aware. While this is not a technical or legal manual, it serves as a practical and evolving guideline to help safeguard people’s geoprivacy and support ethically responsible spatial research. Importantly, the goal is not to discourage the use of geographic data, but to empower researchers to use it responsibly by clarifying risks, promoting proportionate safeguards, and helping avoid overly restrictive decisions grounded in uncertainty. In shaping this framework, we draw on established scholarship and ongoing community debates, enriched by the collective expertise and applied experiences of the authors. This work was initiated following discussions at the Geoprivacy for Personalized Health workshop, which prompted the authors to develop a structured set of guiding questions addressing geoprivacy across the research lifecycle. The contribution lies not in surfacing entirely new ethical dilemmas, but in systematically assembling, structuring, and contextualizing recurring concerns into a coherent set of guiding questions that can be readily mobilized across diverse research settings. What do we mean by geographic data? When discussing geoprivacy, it is essential to define what qualifies as geographic data, particularly in the context of research involving human participants. This categorization is critical for ethical assessment as different types of geographic data present distinct privacy risks, require different consent procedures, and necessitate tailored protection mechanisms throughout the research lifecycle. For the purpose of this guideline, we categorize geographic data into three broad types, static, dynamic, and derivative, based on two key dimensions [ 37 – 39 ]: how explicitly location is recorded (direct vs. inferred) and how directly individuals are being tracked (static vs. dynamic) (Fig. 1 ). These categories are not absolute but serve as a practical heuristic to help researchers and ethics committees systematically evaluate privacy risks, determine appropriate safeguards, and implement proportionate mitigation strategies for different forms of geographic data. Importantly, derivative data often results in the identification of either fixed or tracked locations once processed. Thus, it may inherit the risks associated with those categories and should be assessed accordingly. Fig. 1. Open in a new tab Three types of human-related geographic data: Static (fixed locations such as homes or workplaces), Dynamic (movement or trajectory data over time), and Derivative (location inferred from media, text, or contextual clues) Fixed Geographic Data (Static) – This refers to non-tracked, static information associated with a specific location. Examples include home and work addresses, postal or ZIP codes, or single-response place-based survey data where participants provide one-time information about significant locations. While such data may seem less sensitive than tracking data, fixed geographic data can still reveal personal patterns, especially when combined with demographic or contextual variables. A single location point, when linked to external sources like census data or property records, can uncover sensitive attributes such as socioeconomic status, household composition, or health conditions. It is important to distinguish these one-time data points from repeated, time-stamped observations that might suggest patterns over time, while recognizing that both require careful ethical consideration. Tracked Geographic Data (Dynamic) – This includes data collected through continuous or intermittent monitoring of an individual’s movement, or data that reflect recurring patterns of activity over time [ 40 , 41 ]. Examples include GPS trajectories, geographic data from mobile apps or wearables, time-stamped travel diaries or mobility logs, and surveys designed to capture the temporal dimensions of activity locations. These datasets are inherently spatiotemporal, capturing both where and when an individual was present at a location. However, the degree of spatial and temporal granularity can vary widely. For instance, GPS data may be collected every few seconds, every few minutes, or even more sporadically, depending on the device or application. Similarly, map-based questionnaires may request information about activity locations with associated time frames, effectively capturing intermittent patterns of presence. These variations shape both the analytical potential of the data, and the privacy risks involved, revealing a continuum rather than a strict divide between static and dynamic forms of data collection. Derived Geographic Data (Derivative) – This refers to data that does not explicitly contain geographic coordinates but from which location information can be inferred [ 37 , 42 ]. Examples include textual references to places (e.g., “I had lunch near Central Park”), non-geotagged images or videos that visually reveal location clues (such as recognizable landmarks or signage), or metadata extracted from social media content. While these data do not include coordinates by default, advances in natural language processing and computer vision increasingly allow researchers and algorithms to extract geographic meaning from seemingly unstructured or contextless sources. For example, a photo without GPS metadata may still be locatable if it includes a well-known monument, and textual content can reference places that are easily resolvable via gazetteers. Even language patterns and term usage can provide probabilistic signals of location, reflecting broader concepts of geo-indicativeness. These indirect pathways to geographic information make derived data especially challenging to regulate and anonymize, often revealing unintended geoprivacy risks. These categories are intended to assist in evaluating the privacy implications of geographic data in research. However, it is crucial to acknowledge that spatial and temporal data collection exists on a continuum. A survey that collects a one-time address may pose different risks than one that asks for repeated updates or time-based presence at multiple locations. Likewise, the inference potential of derived data depends not only on what is collected but also on what external datasets and tools (e.g., large language models, gazetteers, foundation models) are available to those analyzing or linking the data. Understanding these categories and their nuances helps researchers and ethics reviewers better identify the types of data at play, the mechanisms of collection, and the implications for individual and community-level privacy. The lifecycle of geographic data in research Research involving geographic data generally follows a lifecycle comprising five interconnected phases [ 43 ] (Fig. 2 ). Each of these phases introduces specific ethical considerations related to privacy, consent, risk, and responsibility, which must be carefully assessed by both researchers and ethics committees. Understanding what each phase entails helps clarify where and how geoprivacy concerns arise. Fig. 2. Open in a new tab The lifecycle of research using geographic data about people involves five interconnected phases, data collection, storage, sharing, analysis, and results dissemination, each presenting distinct ethical considerations for protecting individuals’ geoprivacy Data Collection involves gathering geographic data from or about individuals. This can include collecting addresses or place names through surveys, recording movement patterns using GPS devices or smartphone apps, or deriving location information from images or text. This phase is where participants’ informed consent must be obtained, and decisions about what kind of geographic data to collect, at what resolution, and why, must be clearly justified. Data Storage refers to how the collected data are securely managed during and after the study. This includes decisions about where the data are stored (e.g., on institutional servers or cloud platforms), how long they are retained, how they are anonymized or de-identified, and who has access. It also involves implementing technical safeguards (e.g., encryption, access control) and ensuring compliance with institutional and legal standards. Data Sharing covers the transfer or release of geographic data to others, whether within research teams, with external collaborators, or through public data portals. Sharing increases privacy risks, particularly when data are highly granular or combined with other datasets. Ethical sharing involves ensuring data are adequately anonymized, aligned with participants’ consent, governed by formal agreements, and sensitive to potential misuse. Data Analysis involves processing and interpreting geographic data to produce research findings. While analysis often occurs in secure, internal environments, ethical risks persist, particularly regarding bias, fairness, and representation. Researchers must consider how data quality or algorithmic methods may produce skewed interpretations or amplify inequities. The goal is not only to avoid analytical errors but to ensure that analytical choices are aligned with the privacy risks and sensitivities inherent in geographic data. Results Dissemination concerns the communication of research results, including maps, spatial visualizations, tables, and written findings in academic publications, presentations, public reports, or media. Even when raw data is not shared, visual outputs may inadvertently expose sensitive or identifiable locations, for instance, by mapping home locations, vulnerable communities, or rare travel paths. Researchers must consider how spatial outputs are generalized, aggregated, or masked, and how audiences may interpret or misuse them. Ethical dissemination requires thoughtful design and explicit consideration of privacy, readability, and social impact. Each phase is interrelated, and decisions made in one phase can influence or constrain options in another. For example, choices during data collection, such as the spatial resolution of GPS tracking or whether to collect identifiers, directly impact storage security requirements and limit what can be ethically shared later. Similarly, if appropriate consent for data sharing is not obtained during collection, valuable collaborative opportunities may be precluded during the sharing phase. Analysis methods are constrained by earlier anonymization decisions, as techniques like differential privacy may introduce noise that precludes certain statistical approaches. Finally, visualization choices during dissemination are bounded by all previous decisions where maps showing individual points may be impossible if data was aggregated during storage or analysis phases. Ethical risks may accumulate across phases, especially if not considered early and holistically. Addressing geoprivacy concerns proactively at each step can help minimize downstream vulnerabilities and support responsible data practices throughout the research lifecycle. Ethical questions for geographic data privacy in research This guideline introduces a structured set of geoprivacy-related questions intended as a practical tool for both researchers and research ethics boards or committees. These questions are designed to promote reflection on key ethical concerns across the full lifecycle of geographic data involving individuals. They are meant to serve two primary purposes: (1) As a self-assessment checklist for research teams to review before submitting an application for ethical review; (2) As an evaluation framework for research ethics committees when reviewing studies involving the collection, storage, sharing, analysis, or dissemination of geographic data. The framework does not assign ethics committees responsibility for overseeing how research is conducted or communicated in practice; rather, it supports their role in evaluating the clarity, adequacy, and proportionality of the plans put forward by researchers at the review stage. Together, these questions aim to ensure that privacy risks, data security, informed consent, necessity, proportionality, and equity are considered at every stage of a project. To reflect the common flow of data handling in geographic research, we organize the questions into the five thematic phases (as previously shown in Fig. 2 ): Data Collection – Why is geographic data being collected? What type of data is needed, and at what level of granularity? How is participant awareness and consent ensured? Data Storage – Where is the data stored, who controls it, and what safeguards are in place to manage access, retention, and security? Data Sharing – Who can access raw or identifiable data? What agreements are in place when data is shared with third parties? Data Analysis – How is the data processed, and are ethical implications such as bias, representation, and risk of re-identification being considered? Results Dissemination – How are findings reported or visualized, and could they unintentionally reveal private or sensitive geographic information? Each of these phases raises specific ethical concerns, and the boundaries between them are not always clear-cut. For instance, data sharing within a research team may differ significantly from sharing with collaborators at other institutions. Similarly, disseminating results through scientific publications may reintroduce privacy risks, even when raw data is not shared, through maps or spatial visualizations that pinpoint identifiable locations. By structuring these questions in alignment with the research data lifecycle, we emphasize that ethical issues do not arise in isolation. Decisions made during data collection affect storage and sharing; analysis methods influence what is safe or responsible to report; and visualization choices can shape public understanding and potential harm. To support prioritization, each question is assigned an importance level to indicate the relative weight and urgency of its ethical implications. These levels are not fixed across all studies but serve as a general guide: High – Essential for safeguarding participant privacy or ensuring ethical integrity. Failure to address may result in significant ethical or legal consequences. Moderate – Contextually important and expected to be addressed in most studies. Ethical relevance may vary depending on study design or population. Low – Supports best practices and ethical reflection but is less likely to result in harm if not rigorously addressed. More applicable in specific or high-risk scenarios. Based on our evaluation, 23 questions were assigned a high level of importance, 24 were categorized as moderate, and 15 as low. To help researchers and ethics committees apply the importance levels in a practical and proportionate way, we offer the following Ethical Review Applicability Matrix ( Table 1 ) . This matrix is not a rigid decision tool, but a flexible guide to determine the appropriate depth of ethical reflection based on the sensitivity of the study. By assessing where a study falls across key criteria, researchers can identify whether only the high importance questions should be addressed, whether both high and moderate questions are relevant, or whether a full review including low importance questions is warranted. This approach avoids unnecessary burden for low-risk studies while ensuring that higher-risk projects receive appropriate ethical scrutiny. Table 1. Ethical Review Applicability Matrix for Geoprivacy Questions Criterion Low ethical sensitivity (High Importance Qs only) Moderate ethical sensitivity (High + Moderate Importance Qs) High ethical sensitivity (All Qs) Type of data acquisition Fully secondary data with documented prior ethics approval and consent Secondary data with unclear or partial ethics info Primary data collection (e.g., GPS, interviews, apps) Level of geographic granularity Aggregated to coarse units (e.g., census tracts) Moderate granularity (e.g., street level, named landmarks, low population regions) High precision (e.g., exact coordinates, home/work) Temporal resolution One-time non-routine location or short snapshot (e.g., survey) Periodic collection (e.g., activity logs, diary) Continuous and/or long-term tracking (e.g., GPS, wearables) Linkage to other datasets No known linkage to other datasets and low likelihood of future linkage Linked to non-sensitive datasets (e.g., weather, POIs) Linked to sensitive data (e.g., health, income, behavior) Type of geographic data Static only (e.g., home ZIP code) Mix of static and derived data Dynamic and/or derived with inference risks Presence of sensitive locations No sensitive places collected Some indirectly inferable locations Explicit collection of home, work, identifiable, or care-related places Consent structure Public data or open with informed consent Reused or opt-out consent structure Active consent needed or complex dynamic consent Study population vulnerability General adult population Populations with limited vulnerabilities (e.g., youth, elderly) Marginalized or high-risk groups (e.g., migrants, Indigenous, conflict zones) Geographic context Neutral or public locations Contexts with some socio-political sensitivity Politically contested, culturally sensitive, or high-surveillance areas Dissemination intent Aggregated results for academic use only Some public release with masking Public-facing maps, media communication, open data publishing Analysis complexity Descriptive statistics, no modeling Aggregation or basic machine learning Predictive modeling, behavioral profiling Institutional safeguards Full institutional support with IT/security oversight Partial or informal infrastructure No clear safeguards, third-party platforms, or external hosting Open in a new tab For each criterion in the table, select the column that best reflects your study context (low, moderate, or high sensitivity). Based on the overall distribution of responses, you can determine the recommended level of ethical reflection: If most criteria fall under Low Sensitivity, we suggest focusing efforts on addressing the high importance questions. If 2 to 5 criteria fall under moderate or high sensitivity, we recommend addressing both high and moderate importance questions. If more than 5 criteria fall under high sensitivity, we encourage engaging with the full set of questions, including those marked as low importance. While we encourage all research teams to consider the full spectrum of questions where feasible, we recognize that ethical review processes must also be proportionate to the risks involved. This matrix is therefore offered as a practical guide to help researchers and ethics committees prioritize their efforts without compromising ethical integrity. To demonstrate how this framework can be applied in practice, we provide two case studies in Supplementary Materials I and II: Case Study A analyzes GPS-based tracking and ecological momentary assessments to study stress in urban environments, and Case Study B examines text-based social media data during a natural disaster to understand population needs and response patterns. These examples walk through the full set of questions and illustrate how different types of geographic research may respond differently depending on the data type, participant group, and research setting. This framework encourages a proactive and interconnected approach to safeguarding people’s geoprivacy, supporting both compliance with legal standards and alignment with evolving ethical best practices. It is important to emphasize that the assigned importance levels represent the authors’ expert judgment and are intended as heuristic guidance rather than prescriptive standards. Their purpose is to support, not substitute, the ethical reasoning of individual researchers and review boards. We explicitly recognize that the ethical sensitivity of geographic data elements is highly context-dependent and may vary substantially depending on study design, population size, geographic setting, and data linkage. For example, commonly used aggregated units such as ZIP codes or administrative areas may present low risk in some contexts, but may become highly sensitive in others, such as when linked to small populations or specific environmental or health exposures. We therefore strongly encourage users to critically assess and, where necessary, reinterpret or reassign the importance of each question based on the nature of their study and the specific risks involved. This framework is designed to be adaptable, supporting proportionate ethical reflection across diverse geographic research contexts. Data collection Ethical data collection begins with a clear understanding of why geographic data is needed and how it will be gathered. This phase requires attention to data minimization, informed consent, the sensitivity of the data, legal and cultural obligations, and bias in sampling and access. Each of these aspects influences both the privacy risks and the inclusivity of the research. The following questions help assess whether data collection practices are proportionate, transparent, and respectful of participants’ rights. Data minimization Q1. Are researchers collecting only the geographic data necessary to achieve their research objectives? Importance level: High The principle of data minimization requires that data collection be limited to what is strictly needed. This includes considerations of spatial precision (e.g., coordinates vs. neighborhood), temporal frequency (e.g., continuous vs. periodic tracking), and data type. Unnecessary detail increases privacy risks without contributing to research value. Q2. Have researchers clearly justified the need for geographic data and the specific level of spatiotemporal granularity required for their research questions? Importance level: High Geographic data should only be collected when it is essential to answering the research question. This includes both spatial and temporal dimensions. For instance, neighborhood-level analysis may not require exact home coordinates, and studying monthly activity patterns may not justify collecting GPS data at minute-by-minute intervals. If coarser spatial or temporal resolution is sufficient, high-resolution data collection may be ethically unjustified. Q3. Is the scope of geographic data collection appropriate for the study’s stated objectives , avoiding the inclusion of data that could enable unintended or unrelated future uses? Importance level: Moderate While Q2 focuses on spatial and temporal resolution, this question addresses the scope of geographic data elements being collected. Ethics committees should assess whether researchers are gathering only the geographic variables needed for the stated research aims. Ethics committees should assess whether the geographic data being collected is proportionate to the study goals and whether there is a risk of function creep, where data collected for one purpose is later used for unrelated analyses. Informed Consent and Participant Awareness This section focuses primarily on studies where consent is the legal basis for processing geographic data; where alternative legal grounds apply, these questions should be adapted to emphasize transparency, information duties, and proportional safeguards rather than consent alone. Q4. Are researchers clearly informing participants about what geographic data will be collected , how it will be used , and what risks are involved? Importance level: High. Informed consent is not just about listing data types; it must include an explanation of what can be inferred from the data. For example, even if researchers do not directly ask for home or workplace locations, these can often be derived from repeated GPS traces. Participants should be made aware of such risks and implications in plain language. Researchers must also explain how long the data will be used, whether it might be linked with other datasets, and who will have access to it. Q5. Is the consent process designed to be understandable , concise , and appropriate for the target population? Importance level: High Lengthy or overly technical consent forms can discourage meaningful engagement. The consent process should be designed with the participant’s perspective in mind, avoiding jargon, keeping the text concise, and using plain language. When technical terms are unavoidable, researchers should include short explanations, examples, or visual aids to ensure comprehension. This is particularly important for studies involving diverse populations or participants with varying levels of digital literacy. Q6. Do participants have the ability to tailor their level of participation in geographic data collection , including the option to opt out at any time without negative consequences? Importance level: Low Ethical research should avoid a binary “all-or-nothing” model of consent. Instead of forcing participants to either fully opt in or opt out, researchers should offer a more nuanced and flexible approach to participation. Participants should be able to: Temporarily pause data collection. Limit data collection to specific periods (e.g., only during work hours, weekdays, or daytime). Choose what types of geographic data they are comfortable sharing (e.g., general location vs. precise GPS coordinates). This model respects individual preferences and privacy thresholds, allowing participants to retain control over how much and what kind of data they contribute. These options must be clearly communicated during the consent process, and participants should be supported in adjusting their preferences at any point during the study. Q7. Have researchers implemented mechanisms to ensure participants remain aware when data collection is occurring? Importance level: Moderate Consent should also include ongoing awareness. Participants may forget that data collection is happening, especially in long-term or passive sensing studies. To address this, researchers should integrate mechanisms such as: In-app reminders or regular emails confirming ongoing participation. Notification indicators (e.g., a visible icon, a blinking light on a sensor, or periodic prompts). Clear instructions for how to pause or stop participation at any time. These features support an “ethical-by-design” approach, helping ensure transparency, autonomy, and trust throughout the study. Type and sensitivity of data Q8. Are researchers collecting geographic data that could directly or indirectly identify individuals , and how are those risks being mitigated? Importance level: High Even when participants are not asked to provide specific identifiers like home or work addresses, these locations can often be inferred from mobility traces or spatial behavior patterns. To reduce re-identification risks, researchers should: Allow participants to define and exclude private or sensitive locations or areas from analysis. Provide examples of places participants may consider private (e.g., home, workplace, partner’s residence, or other frequently visited third places). Use spatial obfuscation techniques, such as lowering spatial precision or aggregating data over broader geographic units. Q9. Are researchers collecting real-time geographic data , and have they evaluated how its risks differ from retrospective data collection? Importance level: Moderate Real-time geographic data carries heightened privacy and security risks compared to retrospectively collected data. If breached, real-time information could be exploited for surveillance, stalking, or other harms. Researchers must clearly justify the necessity of real-time collection and assess whether the benefits outweigh the risks. Where possible, real-time collection should be replaced or supplemented with delayed or buffered data uploads. Q10. Have researchers designed an appropriate data transmission and storage strategy that minimizes exposure during collection? Importance level: Low If real-time data transmission is not essential, researchers should consider storing data locally on participants’ devices and allowing delayed uploads under their control. This approach reduces vulnerability to interception or misuse during transmission. If local storage is not feasible due to device limitations or technical constraints, researchers must adopt secure, encrypted transfer methods and clearly communicate these protocols to participants. Regardless of method, participant control over when and how data is shared should be prioritized. Q11. Have researchers assessed the data collection platform or device for its impact on geoprivacy and data control? Importance level: Low The tools used for geographic data collection, whether custom apps, commercial platforms, or wearable sensors, may introduce additional privacy risks. Researchers should evaluate: Data ownership and access policies: Participants must be informed if the platform or device provider retains access to their data. Third-party servers: If data is first stored on external servers before being transferred to research institutions, privacy risks increase. Using institution-secured environments for direct data collection is preferable. Third-party dependencies: Platforms using third-party plugins (e.g. basemap providers) often transmit locational metadata to external servers (e.g., to render a map). Even if the core dataset remains secure, these interactions may introduce vulnerabilities. Alternative tools: When possible, researchers should use privacy-preserving services and collect data directly into secure institutional environments. If third-party services are unavoidable, the risks must be acknowledged and justified. Security verification: Data collection tools or platforms should undergo independent security assessments to ensure they implement appropriate encryption and protection measures for intermediary storing and transmitting geographic data. Legal and ethical frameworks Q12. Are researchers complying with relevant data protection regulations for geographic data collection and processing (e.g. , GDPR , HIPAA , or local equivalents)? Importance level: High Legal compliance is the baseline for ethical research involving geographic data. Researchers must demonstrate how their data practices align with applicable laws such as the General Data Protection Regulation (GDPR), the Health Insurance Portability and Accountability Act (HIPAA), or national and institutional guidelines. This includes attention to consent, data retention, cross-border data transfers, and rights to data access or deletion. Q13. Are researchers considering cultural , political , or contextual sensitivities related to specific locations or populations? Importance level: Low Geographic data may involve places that carry cultural, legal, or historical significance, such as Indigenous lands, sacred sites, politically contested areas, or conflict zones. Ethical research requires awareness of these contexts and, where appropriate, engagement with local communities or stakeholders. Researchers should consider not just what is legally permitted, but what is respectful, equitable, and culturally appropriate. Bias in sampling Q14. Are researchers evaluating how the data collection method may introduce sampling bias , particularly among groups with limited access to technology? Importance level: Moderate Geographic data collection often relies on smartphones, mobile apps, or web-based platforms. These tools can exclude individuals who: Do not own compatible devices. Lack consistent internet or mobile connectivity. Have limited digital literacy or comfort with technology. Such exclusion can lead to sampling bias that disproportionately underrepresents older adults, low-income groups, rural populations, and others systematically disadvantaged in digital access. Researchers must identify these risks early and design studies to minimize exclusion wherever possible. Q15. Have researchers implemented strategies to make participation more inclusive and reduce technological barriers? Importance level: Moderate To avoid biased sampling, researchers should: Design data collection platforms that are intuitive and easy to use. Provide clear, step-by-step instructions for participants unfamiliar with the technology. Offer alternative data collection modes (e.g., paper surveys, map-based interviews, or phone-based reporting) for participants unable to use apps or digital tools. When possible, provide loaner devices or equipment to participants who lack access. Q16. Have researchers considered how post-processing and data cleaning steps might introduce additional bias? Importance level: Moderate Data exclusion often occurs during post-processing due to poor data quality, such as GPS gaps or inconsistent entries. However, missingness is not always random. Certain groups (e.g., those with older phones or those living in areas with poor signal coverage) may produce systematically incomplete data. Automatically removing these records can amplify inequality in representation. Researchers should: Document and assess patterns in missing or low-quality data. Develop strategies to validate or supplement incomplete records rather than discarding them. Consider the use of sensitivity analyses to understand how exclusion may impact study results. Data storage Data security & protection measures Q17. Are researchers implementing appropriate security measures (e.g. , encryption , access controls) to protect stored geographic data from unauthorized access or breaches? Importance level: High Geographic data, particularly when linked to individuals, requires robust protection. This includes both technical safeguards (e.g., encryption, password protection, access logs) and organizational controls (e.g., staff training, user authentication protocols). Ethics committees should evaluate whether the level of security matches the sensitivity and identifiability of the data collected. Q18. Are there clear mechanisms in place for securely deleting geographic data once it is no longer needed? Importance level: Moderate Retention beyond the justified use period increases privacy risks and may violate legal or institutional policies. Researchers must describe: Retention timelines for each type of data (e.g., raw vs. processed). How data will be securely deleted or anonymized after use. How deletion will be verified and documented, especially when data are stored across multiple systems or institutions. Q19. Have researchers provided an ethical justification for how long each type of geographic data will be retained? Importance level: Moderate Different data types may require different retention timelines based on their sensitivity and analytic value. Ethics committees should examine whether the retention plan is: Proportionate to the research goals. Transparent to participants. Consistent with legal and institutional guidelines. For example, dynamic trajectory data may be deleted shortly after aggregation, while anonymized survey-linked data might be retained longer for reproducibility. Q20. Have researchers justified their chosen level of security based on the sensitivity and type of geographic data being stored? Importance level: Low Not all geographic data carries the same privacy risk. Ethics committees should assess whether researchers differentiate between static, dynamic, and derivative data. Security protocols should reflect these distinctions. For instance, fine-grained GPS logs may require more restricted access and longer encryption keys than anonymized survey responses. Q21. Does the data management plan demonstrate awareness of institutional and regulatory requirements for securing geographic data? Importance level: Moderate Researchers should align their practices with institutional IT policies, national and international data protection laws (e.g., GDPR, HIPAA), and specific guidelines on geographical or sensitive personal data. The ethics application should demonstrate familiarity with these requirements and describe how compliance is being maintained. Q22. Have researchers identified who is responsible for data security and what oversight mechanisms are in place? Importance level: High A clear accountability structure is essential. The data management plan should specify: Who is responsible for maintaining security (e.g., PI, data manager). What oversight mechanisms (e.g., audits, role-based access control) ensure ongoing compliance. Q23. Have researchers considered the security and ethical implications of participant withdrawal after data has been collected? Importance level: Moderate Participants should be able to withdraw from the study at any time, but researchers must also specify what happens to their data afterward. Questions to consider include: Can the data be fully deleted, especially if already de-identified? Have researchers communicated the limits of withdrawal to participants? Are there protocols for identifying and removing data in linked datasets? Anonymization and de-identification Q24. Have researchers anonymized or de-identified geographic data where appropriate , and clearly documented the methods used and the inherent limitations of geographic anonymization? Importance level: High Anonymization should be implemented when identifiable data is no longer needed, especially after data linkage is complete. However, researchers must explicitly acknowledge that geographic data presents unique challenges for anonymization due to spatial autocorrelation and the inherent structure of geographic information. Anonymization of geographic data is limited by several key factors: spatial uniqueness, where distinctive movement patterns such as daily commutes can identify individuals even after direct identifiers are removed; spatial autocorrelation, which makes masking a single location ineffective if nearby, behaviorally linked points remain visible; geographic context, as physical features like roads or barriers constrain movement into predictable paths; and temporal persistence, where repeated visits to the same places over time create a consistent signature that simple anonymization techniques cannot eliminate. The ethics application should specify: When and how identifiers are removed. What level of anonymization is used and its known limitations for geographic data. How these limitations have been communicated to participants. At what point participants’ data can no longer be individually deleted, and why. Q25. Have researchers assessed whether de-identified geographic data could still be re-identified when combined with other datasets? Importance level: High Even after direct identifiers are removed, geographic data can remain highly identifiable due to patterns in movement, residence, or behavior [ 26 ]. Re-identification risks increase when datasets are linked or publicly available auxiliary data exists. Ethics committees should assess whether researchers have: Considered dataset linkage scenarios (even if not planned). Stored high-risk data in separate, access-controlled environments. Conducted a risk assessment or data protection impact assessment to evaluate likelihood and impact of re-identification. Q26. Have researchers considered how anonymization choices might introduce bias or affect data quality and representation? Importance level: Low Techniques like generalization, masking, or aggregation can reduce identifiability but also risk distorting spatial patterns or excluding vulnerable groups. For example, overly coarse anonymization may limit the analytical visibility of small populations or infrequent behaviors, particularly when aggregation thresholds are applied. Ethics reviewers should consider whether anonymization: Introduces systematic bias. Disproportionately affects certain areas or demographics. Was tailored to balance privacy protection with scientific utility. Q27. Have researchers justified their choice of privacy-preserving techniques , and clearly explained the trade-offs involved? Importance level: Low There is no universally applicable privacy-preserving method for geographic data. Techniques such as differential privacy, spatial cloaking, k-anonymity, or geomasking offer varying levels of protection, but differ in their assumptions, computational requirements, and impact on data fidelity. Researchers must provide a rationale for their selected approach, demonstrating how it aligns with the sensitivity of the data, the intended analytical methods, and the specific privacy risks in context. Importantly, researchers should articulate the trade-offs between privacy protection and data utility, explaining, for instance, how reduced spatial or temporal resolution may limit certain analyses but is necessary to mitigate re-identification risks. Ethics committees should evaluate the quality of this justification, rather than whether a specific method has been used. Rigid expectations can hinder legitimate research or lead to over-engineering, especially when simpler techniques may suffice. A proportionate, transparent, and context-sensitive explanation is essential to ensuring that privacy-preserving choices are both ethically and scientifically defensible. Access and internal use Q28. Have researchers clearly defined who has access to geographic data , and implemented controls to minimize unnecessary exposure? Importance level: High Controlling internal access to geographic data is essential for maintaining confidentiality and data protection. Ethics committees should verify that researchers have identified who will have access to the data and for what purposes. The data management plan should specify named individuals and their roles (e.g., PI, data manager, analyst), while also outlining how new staff will be added, trained, and monitored over time. To limit exposure, researchers should implement role-based access controls (RBAC), ensuring that each individual only accesses the data they require to fulfill their responsibilities. As access needs may change throughout the project, oversight mechanisms should be in place to audit permissions and revoke access when appropriate. In addition, everyone with access to sensitive data should be trained in handling location-based information securely, with particular emphasis on preventing indirect disclosure through careless use or sharing. Q29. If using cloud-based storage , have researchers ensured that service providers meet institutional and legal data protection standards? Importance level: High When using external cloud services, researchers must assess whether the provider complies with relevant legal and institutional standards (e.g., GDPR, HIPAA, university IT policies). This includes evaluating the provider’s protocols for: Data encryption (both at rest and in transit). Physical and jurisdictional location of servers. Access logging and breach notification procedures. Contractual safeguards regarding data ownership and control. Ethics committees should ensure that data stored in the cloud is afforded equivalent protection to that held within institutional systems. When feasible, using institution-managed storage environments is preferable due to greater oversight and long-term accountability. When using cloud based services, particular attention should be paid to whether cloud services might automatically process geographic data for their own purposes, such as improving location services or training AI models. Data sharing The sharing of geographic data introduces distinct ethical considerations, many of which depend on the type of data being shared. While the guiding questions in this section apply broadly, it is important that researchers and ethics committees differentiate between static, dynamic, and derivative data, as each poses unique privacy challenges. Static geographic data (e.g., home addresses, workplaces) may directly reveal personally significant or identifiable locations. Dynamic geographic data (e.g., GPS trajectories, movement traces) can expose behavioral patterns and routines that increase the risk of re-identification when shared. Derivative geographic data (e.g., textual references, images, or videos) may contain implicit or inferred locational content, often not immediately obvious, which can still be extracted through additional processing. The following questions support the ethical review of data sharing practices and are organized into general considerations followed by data type–specific concerns. Ethics committees should pay particular attention to whether researchers have meaningfully assessed the risks and safeguards relevant to the specific type(s) of geographic data being shared. Purpose and justification Q30. Have researchers clearly justified why geographic data is being shared , and is the sharing ethically proportionate to the study’s objectives? Importance level: High Data sharing must be grounded in a clear and explicit rationale. Whether the sharing occurs within a collaborative research project across institutions or involves wider external access, researchers should articulate how sharing supports the scientific aims of the study. This includes detailing how the data will be used by collaborators and whether the scale and scope of the shared dataset are proportionate to the intended benefit. Ethics committees should assess whether data sharing is necessary for the study to proceed or whether similar outcomes could be achieved through alternative, less privacy-intrusive strategies. Q31. Does the proposed data sharing align with the scope of consent originally provided by participants? Importance level: High Consent must explicitly cover any data sharing arrangements, including sharing between organizations working on the same project. Participants should understand not only that their data may be shared, but who will have access, under what conditions, and for what purposes. For collaborative projects, this may involve data flow across institutional or national boundaries, each with its own regulatory and ethical implications. If researchers intend to share data beyond the original study team or for new purposes not covered in the consent form, they must provide a strong ethical justification and, where necessary, seek re-consent. Q32. Have researchers demonstrated that the benefits of sharing outweigh the privacy risks , including in collaborative or multi-institutional settings? Importance level: Moderate Sharing geographic data across institutions, whether for data analysis, infrastructure support, or project management, can increase scientific rigor, enable replication, and reduce redundancy. These benefits are particularly relevant in longitudinal or consortium-based studies. However, even within trusted partnerships, risks such as inconsistent data handling practices, insufficient oversight, or differences in institutional safeguards can introduce vulnerabilities. Ethics committees should assess whether appropriate data governance structures, agreements, and technical safeguards are in place to ensure that collaboration does not compromise participants’ privacy. Data anonymization and aggregation for sharing Q33. Have researchers applied an appropriate level of anonymization for shared geographic data , distinct from the standards used for internal storage? Importance level: High Data that remains within a secure institutional environment may tolerate a different level of detail than data being shared externally. When geographic data is transferred to other institutions, collaborators, or made available to the public, the likelihood of misuse, unintended re-identification, or linkage with external datasets increases. Ethics committees should ensure that researchers have assessed whether stronger anonymization, including coarser spatial or temporal resolution, suppression of rare cases, or further aggregation, is warranted in the sharing context. Q34. Is the geographic data being shared at a resolution appropriate to its intended use , and not at the maximum level of detail available? Importance level: Moderate Sharing high-resolution spatial or temporal data when only coarse information is needed introduces unnecessary privacy risk. Researchers should justify the chosen resolution based on the analytical needs of the recipients. In many cases, it may be appropriate to release aggregated or downsampled versions of the data for general access while retaining finer-grained versions under restricted conditions. Q35. Have researchers considered producing multiple versions of the dataset with varying levels of anonymization or access control? Importance level: Low Different audiences may require different levels of access. A single dataset may be too detailed for public sharing but suitable for restricted internal use within a secure research environment. When possible, researchers should consider releasing tiered datasets, such as: A fully anonymized public version with coarse spatial resolution (e.g., census track or neighborhood level) and limited attributes that carries minimal re-identification risk. A semi-restricted version with intermediate spatial precision (e.g., street-level without exact coordinates) and more detailed attributes, available to approved researchers through an application process. A higher-resolution restricted-access version for close collaborators, accessible only within secure data environments and under strict data use agreements. The raw data maintained securely by the original research team, used only for validation or specific approved analyses. Ethics committees should evaluate whether the sharing strategy reflects this type of proportionate access control and whether researchers have documented the specific anonymization techniques applied to each tier. Governance and agreements Q36. Are formal data-sharing agreements in place that clearly define responsibilities , limitations , and conditions for data use? Importance level: High Before geographic data is shared beyond the originating institution, a formal agreement should be established. These agreements must outline: Who holds primary control over the data. What types of data use are permitted (and what uses are explicitly prohibited). Whether further redistribution is allowed and under what approval process. Commitments to respect participant consent and maintain confidentiality. The process for handling secondary or unanticipated uses of the data. In some research contexts, particularly where secondary use of sensitive geographic data is anticipated, these governance functions may be supported by a data access committee or a similar managed access mechanism that reviews access requests and specifies conditions for use. Ethics committees should assess whether the chosen governance approach and the agreement ensure ongoing accountability and reflects the sensitivity of the data being shared. Q37. Do recipient institutions have adequate data protection protocols , and are their researchers trained in privacy and geographic data handling? Importance level: High Transferring geographic data to collaborators or third parties increases the potential for inconsistent practices and unintentional disclosure. Ethics committees should verify that recipients have: Sufficient technical infrastructure (e.g., secure servers, encryption). Training and awareness for staff handling sensitive geographic data. Procedures aligned with the original ethical approvals and data governance policies. Q38. Do governance documents address cross-institutional and cross-jurisdictional legal compliance , particularly in international collaborations? Importance level: High When data crosses borders, researchers must account for differences in national regulations. The data-sharing agreement should specify: How jurisdictional differences will be addressed. Whether the recipient country or institution offers an adequate level of data protection, as defined by applicable frameworks (e.g., GDPR adequacy decisions). Which party bears legal responsibility in case of a breach or misuse. Q39. Do agreements include clear provisions for end-of-project responsibilities , breach management , and participant notification? Importance level: High Data governance must extend to the full research lifecycle. Ethics committees should ensure that agreements include: A plan for data disposal, retention, or archiving after project completion. A clearly defined dispute resolution process in case of disagreements over data use. Protocols for managing and reporting data breaches, including whether and how participants, institutional leads, and regulators will be notified. Q40. Have researchers considered involving participant or community perspectives in governance structures , particularly in longitudinal or sensitive studies? Importance level: Low In studies involving marginalized communities or long-term data collection, participants may have an ongoing interest in how their data is used. Researchers should consider participant-informed governance mechanisms, such as advisory boards or participatory oversight, to ensure that long-term data stewardship remains aligned with community values and expectations. Open data considerations The open data movement promotes transparency, reproducibility, and knowledge sharing by making research data freely available. However, these principles can sometimes conflict with geoprivacy protection, creating tension between openness and privacy that requires careful navigation [ 28 ]. The following questions address how researchers can balance open science aspirations with ethical obligations to protect participants’ geoprivacy. Q41. Have researchers conducted a thorough risk assessment prior to publicly sharing geographic data? Importance level: High Open access to geographic data can advance transparency, reproducibility, and broader societal impact. However, it also introduces unique ethical risks. Once data is made public, control over its use is lost, and it may be combined with other datasets in ways not originally anticipated. Researchers must conduct a pre-release assessment to evaluate whether public sharing could lead to re-identification, location-based harm, or misuse, particularly for sensitive areas or vulnerable populations. This assessment should explicitly consider how open data objectives may conflict with privacy protection. For instance, full reproducibility might require precise coordinates that could compromise anonymity, while perfect privacy protection might render data too aggregated for meaningful reuse. Researchers should document how they balanced these competing values and, when necessary, implement controlled access mechanisms as an alternative to fully open data. Ethics committees should review whether the potential societal benefits of sharing clearly outweigh these risks, and whether appropriate compromises have been made to serve both open science and privacy goals. Q42. Have researchers provided clear documentation outlining the appropriate and inappropriate uses of the shared dataset? Importance level: Low Publicly shared data should be accompanied by responsible reuse guidelines that help downstream users understand the limitations of the dataset, including: Data uncertainty or processing methods. Restrictions on types of analyses (e.g., no individual profiling or location prediction). Ethical obligations in secondary use, such as attribution and citation. These guidelines serve not only as a deterrent for unethical reuse but also help signal the values and boundaries of the original research team. Q43. Is the dataset shared under an appropriate license that clearly defines permissible uses and restrictions? Importance level: High All open data should be accompanied by a well-defined license, such as a Creative Commons or institutional license. The license should: Specify whether use is limited to non-commercial, educational, or research contexts. Prohibit any attempts at re-identification or misuse for surveillance, discrimination, or commercial exploitation. Clarify whether derivatives can be created and under what conditions. A license is not a replacement for ethical review but a foundational element of open data governance. Data type-specific sharing considerations While many ethical principles of data sharing apply broadly, the privacy risks introduced by sharing geographic data vary significantly depending on the type of data involved. Ethics committees should assess whether researchers have tailored their data sharing strategy and safeguards accordingly. Static geographic data Q44. If sensitive fixed locations are included , have researchers implemented additional safeguards to prevent unintended disclosure? Importance level: High Particular attention is needed when data points correspond to places that carry heightened privacy concerns (e.g., shelters, religious centers, or private residences). Q45. Have researchers justified the spatio-temporal resolution of the shared data , and considered whether coarser aggregation could reduce privacy risks? Importance level: Moderate The release of highly precise spatial or temporal data may not be necessary to achieve scientific goals. Researchers should consider whether neighborhood-level spatial resolution or broader temporal intervals would suffice, and explain why finer detail is required if used. Coarser aggregation can often reduce privacy risks without compromising analytical value. Q46. Have researchers assessed whether combining geographic data with demographic or contextual attributes increases re-identification risk , and taken reasonable steps to mitigate that risk? Importance level: Moderate Even static geographic data can become identifying when combined with small population groups, rare characteristics, or sensitive contextual variables. Researchers should assess the cumulative disclosure risk introduced by such combinations and take reasonable steps to mitigate it, such as through aggregation, suppression, or limiting the release of high-risk variables. Ethics committees should evaluate whether these mitigation measures are proportionate to the sensitivity of the data and the likelihood of re-identification. Dynamic geographic data Q47. Have researchers addressed the risk that recurring patterns in the data (e.g. , home-work commutes) could be used to identify individuals? Importance level: Moderate Dynamic datasets often reveal regular spatial-temporal routines. Researchers should demonstrate how such patterns are detected and, if necessary, blurred, abstracted, or removed from shared versions of the dataset. Q48. Do sharing agreements or protocols limit the extent of temporal analysis allowed on the dataset? Importance level: Moderate Even if anonymized, dynamic data may allow inferences about sensitive behaviors. Researchers should restrict or explicitly define acceptable uses of the time component to mitigate risk. Q49. Has the team assessed whether certain timeframes (e.g. , nights , weekends) require additional protections due to their personal or sensitive nature? Importance level: Low Some temporal slices may be more privacy-invasive than others. Ethics reviewers should evaluate whether the dataset has been appropriately filtered or flagged for these higher-risk periods. Derivative geographic data Q50. Have researchers reviewed the dataset for implicit location references , such as place names in text or identifiable landmarks in images? Importance level: Low Seemingly non-spatial data (e.g., social media posts, photos, videos) can still reveal geographic information. Ethics committees should verify whether researchers have systematically audited the dataset for such content. Q51. Does the sharing plan recognize that aggregate analysis or external tools (e.g. , gazetteers , image recognition) can reintroduce geographic specificity? Importance level: Moderate Even vague or partial location indicators may become identifiable when processed with AI tools or linked with external databases. Researchers should demonstrate awareness of such indirect disclosure pathways. Q52. Have researchers evaluated the risks of location inference using emerging technologies such as natural language processing or computer vision? Importance level: Low Advanced techniques can extract geographic information from unstructured data sources. Ethics committees should ensure that sharing plans address this potential and explain whether further de-identification steps are necessary. Data analysis Trade-offs between geoprivacy and utility in analysis Q53. Have researchers addressed how statistical and spatial accuracy are affected by privacy-preserving techniques applied to the data? Importance level: Moderate Working with privacy-protected geographic data introduces distinct statistical challenges, including spatial uncertainty, modified distributions, and reduced statistical power. Researchers should demonstrate their awareness of these issues and explain how they: Account for spatial uncertainty in their analytical models. Handle ecological fallacies when working with aggregated data. Employ appropriate statistical methods designed for privacy-protected data. Ethics committees should verify that researchers have not simply applied standard statistical approaches without considering these special challenges. Ethical implications of analytical methods Q54. Have researchers evaluated whether their analytical methods might reinforce or amplify biases present in the geographic data? Importance level: Moderate Even when data is collected ethically, biased patterns can emerge during analysis, particularly if geographic data is incomplete, unequally distributed, or skewed toward particular groups. Researchers must examine how their chosen models, spatial aggregations, or analytical decisions could perpetuate or exaggerate existing disparities. Ethics committees should ensure that analytical plans include strategies to detect and mitigate such biases, for example, through subgroup validation, fairness auditing, or transparency in reporting data limitations. Q55. Have researchers assessed whether their findings could negatively impact marginalized or vulnerable populations? Importance level: Moderate Geographic analysis can unintentionally stigmatize communities or expose individuals to risk. For example, hotspot mapping, risk prediction, or profiling of behaviors by neighborhood can lead to labeling or increased surveillance [ 24 ]. Researchers should explicitly reflect on the potential social and policy implications of their results, especially when working with historically underrepresented or over-policed populations. Ethics committees should review whether researchers have taken adequate steps to minimize harm, such as using aggregated results, avoiding sensational framing, or engaging with affected communities during interpretation. Q56 . Have researchers critically evaluated whether their datasets and analytical methods appropriately represent and serve diverse populations or regions , especially marginalized or vulnerable groups or regions ? Importance level: Moderate. Geographic and demographic representation in datasets fundamentally shapes who benefits from research. While this concern is particularly important in AI/ML applications, it extends beyond them to all forms of geographic analysis. Researchers must critically examine: Whether training, reference, or benchmark datasets adequately represent all relevant populations across geographic areas and demographic dimensions. If certain communities are systematically underrepresented, creating “data shadows” where findings have limited validity. How analytical choices might amplify existing inequalities by producing insights primarily beneficial to already advantaged groups. Whether models, algorithms, or statistical methods perform consistently across different subpopulations and geographic contexts. For AI/ML applications specifically, additional concerns include algorithmic bias embedded in training data, uneven model performance across geographic areas, and whether validation procedures account for demographic and spatial variations, especially in the case of foundation models or pre-trained models, where biases may be inherited from large, opaque datasets not tailored to the study context. Ethics committees should ensure researchers have documented these representational issues and, where possible, implemented strategies to mitigate biases that could lead to discriminatory or inequitable outcomes based on location or group membership. Reproducibility and transparency Q57. Are researchers documenting their data analysis methods in a way that supports transparency and ethical accountability , even if full reproducibility is not feasible? Importance level: Moderate In geographic research involving sensitive or identifiable data, reproducibility may be limited by legal or ethical constraints. However, this does not preclude transparency. Researchers should clearly document analytical decisions, preprocessing steps, and modeling workflows to ensure that their results are auditable and interpretable, even if others cannot fully reproduce the analysis with the same dataset. This level of transparency helps ethics committees and peers assess the integrity of the findings while respecting geoprivacy obligations. Q58. Have researchers evaluated whether their analytical outputs could be repurposed for harmful or unethical uses (i.e. , dual-use risks)? Importance level: Moderate Geospatial analyses, particularly those involving prediction, classification, or surveillance, can be co-opted for purposes beyond the original research intent. Examples include: Targeting individuals or communities for surveillance or profiling. Use in law enforcement or military contexts without human rights safeguards. Commercial exploitation of behavioral patterns or movement data. Researchers should explicitly assess these dual-use scenarios and, where relevant, build ethical safeguards into dissemination plans, including restrictions on downstream access or application of the outputs. Results dissemination Q59. Are researchers presenting geographic results in a way that avoids revealing sensitive or identifiable locations? Importance level: High Maps, spatial visualizations, and geospatial summaries are powerful tools for communicating research, but they carry unique privacy risks. Even when raw data is anonymized, spatial outputs can inadvertently expose individuals or communities. Researchers should consider: Aggregating results to coarser geographic levels (e.g., neighborhood, district). Applying spatial generalization or obfuscation techniques to sensitive locations. Avoiding small-area mapping when findings relate to vulnerable or stigmatized populations. Ethics committees should assess whether visualization choices have been carefully reviewed to minimize disclosure risk. Q60. Have researchers assessed whether public-facing dissemination of geographic findings could lead to misinterpretation , media amplification , or unintended harms? Importance level: Moderate Maps and spatial narratives may be misused once released, especially if presented without context. Researchers should anticipate how their findings might be received by media, policymakers, or the public, especially in cases involving inequality, risk mapping, or spatial disparities. Mitigation strategies include: Providing clear explanations of spatial uncertainty or methodological limits. Avoiding sensational or deterministic interpretations of spatial patterns. Including caveats about generalizability and ethical considerations in all public reports. Ethics committees should verify that researchers have thought critically about how geospatial results are communicated and whether dissemination plans reflect an awareness of geoprivacy implications. Conclusion The ethical use of geographic data about individuals is becoming increasingly central to a wide range of research disciplines, from health and mobility studies to social science and urban planning. As the capacity to collect, link, and analyze geographic data grows, so too do the ethical responsibilities of researchers and the oversight roles of ethics committees. This guideline offers a structured framework to address these responsibilities through a comprehensive set of questions tailored to each stage of the geographic data lifecycle: from collection and storage to sharing, analysis, and dissemination. Rather than prescribing fixed rules or technical solutions, the approach taken here is grounded in reflexive practice. The questions are intended to be used as a self-assessment tool for researchers and a review aid for ethics committees, encouraging both to think critically about the risks, trade-offs, and contextual factors involved in working with geographic data. By embedding ethical reflection early and iteratively into the research design, researchers are more likely to build trust with participants, safeguard data dignity, and enhance the overall integrity of their work. This framework can also serve as a valuable training resource for students and early-career researchers, helping them develop ethical awareness from the outset. This framework also emphasizes that ethical challenges are not uniform across all geographic data types or study contexts. The potential harms associated with static, dynamic, or derivative geographic data vary, as do the privacy expectations of individuals and communities. The guideline is therefore deliberately adaptable, with questions that prompt justification and documentation rather than compliance with a fixed standard. In practice, this means different projects may arrive at different conclusions; what matters is that those decisions are ethically reasoned, transparent, and proportionate. Finally, while this guideline focuses on practical questions for immediate research planning and ethics review, it also points to the need for ongoing engagement with broader institutional and regulatory developments. As new technologies and new data sources continue to emerge, ethical practices must evolve in parallel. We hope this framework not only supports individual studies but also contributes to a shared, evolving conversation about how to conduct responsible and people-centered geographic research in a world of accelerating data capabilities. Supplementary Information Supplementary Materials (61.9KB, docx) Acknowledgements We gratefully acknowledge all participants of the 2nd Specialist Workshop on Geoprivacy for Personalized Health whose discussions and insights helped shape the ideas presented in this paper but who do not meet the criteria for authorship. Author contributions All authors contributed to the conception and design of the paper. MM drafted the initial manuscript. All authors contributed to critical revisions, read, and approved the final version of the manuscript. EKK and GM organized the workshop and led the discussions. Funding Open Access funding provided by University of Helsinki (including Helsinki University Central Hospital). This paper draws on discussions held during the 2nd Specialist Workshop on Geoprivacy for Personalized Health (GP4H 2025) at Luxembourg Institute of Socio-Economic Research (LISER) in Esch-sur-Alzette, Luxembourg in February 27-28, 2025, which was organized by Eun-Kyeong Kim and Grant McKenzie. The workshop was jointly funded by the Luxembourg National Research Fund (Fonds National de la Recherche - FNR) under Award No. 18789786 as well as the Gouvernement du Québec and the Ministère des Relations internationales et de la Francophonie under Award No. MRIF/08.801 and supported by LISER. Data availability No datasets were generated or analysed during the current study. Declarations Ethics approval and consent to participate Not applicable. This study did not involve human participants, human data, or human tissue. Consent for publication Not applicable. This manuscript does not contain data from any individual person. Competing interests The authors declare no competing interests. Footnotes Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. Contributor Information Milad Malekzadeh, Email: [email protected]. Eun-Kyeong Kim, Email: [email protected], Email: [email protected]. References 1. Kestens Y, Thierry B, Chaix B. Re-creating daily mobility histories for health research from raw GPS tracks: validation of a kernel-based algorithm using real-life data. Health Place. 2016;40:29–33. [ DOI ] [ PubMed ] [ Google Scholar ] 2. Perchoux C, Brondeel R, Klein S, Klein O, Thierry B, Kestens Y, et al. Does the built environment influence location-and trip-based sedentary behaviors? Evidence from a GPS-based activity space approach of neighborhood effects on older adults. Environ Int. 2023;180:108184. [ DOI ] [ PubMed ] [ Google Scholar ] 3. Chaix B, Benmarhnia T, Kestens Y, Brondeel R, Perchoux C, Gerber P, et al. Combining sensor tracking with a GPS-based mobility survey to better measure physical activity in trips: public transport generates walking. Int J Behav Nutr Phys Activity. 2019;16:1–13. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 4. Blanford JI, Huang Z, Savelyev A, MacEachren AM. Geo-located tweets. Enhancing mobility maps and capturing cross-border movement. PLoS ONE. 2015;10(6):e0129202. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 5. Malekzadeh M, Long JA. Mobility deviation index: incorporating geographical context into analysis of human mobility. J Geogr Syst. 2024;26:427–448. 10.1007/s10109-024-00444-1 6. Malekzadeh M, Reuschke D, Long JA. Quantifying local mobility patterns in urban human mobility data. Int J Geogr Inf Sci. 2024; 39(5):945–950. 10.1080/13658816.2024.2389410 7. Fillekes MP, Giannouli E, Kim E-K, Zijlstra W, Weibel R. Towards a comprehensive set of GPS-based indicators reflecting the multidimensional nature of daily mobility for applications in health and aging research. Int J Health Geogr. 2019;18:1–20. 10.1186/s12942-019-0181-0 [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 8. Kim E-K, Conrow L, Röcke C, Chaix B, Weibel R, Perchoux C. Advances and challenges in sensor-based research in mobility, health, and place. Health Place. 2023;79:102972. 10.1016/j.healthplace.2023.102972 [ DOI ] [ PubMed ] [ Google Scholar ] 9. Röcke C, Luo M, Bereuter P, Katana M, Fillekes M, Gehriger V, et al. Charting everyday activities in later life: study protocol of the mobility, activity, and social interactions study (MOASIS). Front Psychol. 2023;13:1011177. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 10. Siła-Nowicka K, Vandrol J, Oshan T, Long JA, Demšar U, Fotheringham AS. Analysis of human mobility patterns from GPS trajectories and contextual information. Int J Geogr Inf Sci. 2016;30(5):881–906. 10.1080/13658816.2015.1100731. [ Google Scholar ] 11. Mennis J, Mason M, Ambrus A. Urban greenspace is associated with reduced psychological stress among adolescents: a Geographic Ecological Momentary Assessment (GEMA) analysis of activity space. Landsc Urban Plan. 2018;174:1–9. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 12. Liao Y, Intille SS, Dunton GF. Using ecological momentary assessment to understand where and with whom adults’ physical and sedentary activity occur. Int J Behav Med. 2015;22:51–61. [ DOI ] [ PubMed ] [ Google Scholar ] 13. Poom A, Willberg E, Toivonen T. Environmental exposure during travel: a research review and suggestions forward. Health Place. 2021;70:102584. [ DOI ] [ PubMed ] [ Google Scholar ] 14. Poulsen AH, Sørensen M, Hvidtfeldt UA, Christensen JH, Brandt J, Frohn LM, et al. Concomitant exposure to air pollution, green space, and noise and risk of stroke: a cohort study from Denmark. Lancet Reg Health Eur. 2023. 10.1016/j.lanepe.2023.100655. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 15. Järv O, Masso A, Silm S, Ahas R. The link between ethnic segregation and socio-economic status: an activity space approach. Tijdschrift voor economische en sociale geografie. 2021;112(3):319–35. [ Google Scholar ] 16. Nelson T, Amy EF, Peter K, Somayeh D, Bo Z, Michael G et al. A research agenda for GIScience in a time of disruptions. International Journal of Geographical Information Science [Internet]. 2025;39(1):1–24. Available from: 10.1080/13658816.2024.2405191 [ DOI ] [ PMC free article ] [ PubMed ] 17. Liu X, Chen M, Claramunt C, Batty M, Kwan MP, Senousi AM, et al. Geographic information science in the era of geospatial big data: a cyberspace perspective. Innovation. 2022. 10.1016/j.xinn.2022.100279. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 18. Ranjan Y, Rashid Z, Stewart C, Conde P, Begale M, Verbeeck D, et al. RADAR-base: open source mobile health platform for collecting, monitoring, and analyzing data using sensors, wearables, and mobile devices. JMIR Mhealth Uhealth. 2019;7(8):e11734. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 19. Malekzadeh M, Ha HJ, Sila-Nowicka K, Brum-Bastos V, Lee J, Demšar U, et al. How can we make GPS tracking studies more open, reproducible, and collaborative? A vision for the OpenGPS platform. Data Brief. 2025. 10.1016/j.dib.2025.111603. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 20. Goodchild MF. Citizens as sensors: the world of volunteered geography. GeoJournal. 2007;69(4):211–21. 10.1007/s10708-007-9111-y. [ Google Scholar ] 21. Kestens Y, Thierry B, Shareck M, Steinmetz-Wood M, Chaix B. Integrating activity spaces in health research: Comparing the VERITAS activity space questionnaire with 7-day GPS tracking and prompted recall. Spat Spatiotemporal Epidemiol [Internet]. 2018;25:1–9. Available from: https://www.sciencedirect.com/science/article/pii/S1877584516300223 [ DOI ] [ PubMed ] 22. Chaix B, Kestens Y, Perchoux C, Karusisi N, Merlo J, Labadi K. An interactive mapping tool to assess individual mobility patterns in neighborhood studies. Am J Prev Med. 2012;43(4):440–50. [ DOI ] [ PubMed ] [ Google Scholar ] 23. MacEachren AM, Jaiswal A, Robinson AC, Pezanowski S, Savelyev A, Mitra P et al. Senseplace2: Geotwitter analytics support for situational awareness. In: 2011 IEEE conference on visual analytics science and technology (VAST). IEEE; 2011. pp. 181–90. 24. Goodchild M, Appelbaum R, Crampton J, Herbert W, Janowicz K, Kwan MP et al. A white paper on locational Inform public interest. American Association of Geographers. 2022. 10.14433/2017.0113 25. Leszczynski A. Geoprivacy. In: Understanding Spatial Media. SAGE Publications Ltd; 2017. p. 235–244. 10.4135/9781526425850.n22 26. Cassa CA, Wieland SC, Mandl KD. Re-identification of home addresses from spatial locations anonymized by Gaussian skew. Int J Health Geogr. 2008;7(1):45. 10.1186/1476-072X-7-45. [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 27. Duckham M, Kulik L. Dynamic & mobile GIS: Investigating change in space and time. Location privacy and location-aware computing. Taylor & Francis; 2006. pp. 34–51. 28. Solymosi R, Buil-Gil D, Ceccato V, Kim E, Jansson U. Privacy challenges in geodata and open data. Area. 2023;55(4):456–64. [ Google Scholar ] 29. Keßler C, McKenzie G. A geoprivacy manifesto. Trans GIS. 2018;22(1):3–19. [ Google Scholar ] 30. European Parliament and Council of the European Union. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) [Internet]. 2016 [cited 2025 May 16]. Available from: https://eur-lex.europa.eu/eli/reg/2016/679/oj 31. U.S. Department of Health and Human Services. HHS.gov. 1996 [cited 2025 May 16]. Summary of the HIPAA Privacy Rule. Available from: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html 32. Tobler WR. A computer movie simulating urban growth in the Detroit region. Econ Geogr. 1970;46(sup1):234–40. [ Google Scholar ] 33. Wang S, Huang X, Liu P, Zhang M, Biljecki F, Hu T et al. Mapping the landscape and roadmap of geospatial artificial intelligence (GeoAI) in quantitative human geography: An extensive systematic review. Int J Appl Earth Obs Geoinformation [Internet]. 2024;128:103734. Available from: https://consensus.app/papers/mapping-the-landscape-and-roadmap-of-geospatial-wang-huang/acc7119cf9045b3fb5c559248189ccbe /. 34. Janowicz K, Sieber R, Crampton J. GeoAI, counter-AI, and human geography: a conversation. Dialogues Hum Geogr. 2022;12(3):446–458. 10.1177/20438206221132510 [ Google Scholar ] 35. McKenzie G, Kim E-K. Report from the 1st Workshop on Geoprivacy for Personalized Health, September 13, 2024, Montréal, Québec, Canada. OSF (Open Science Framework); 2024. 10.17605/OSF.IO/SDVEM 36. Kim E-K. Proceedings of the 2nd Specialist Workshop on Geoprivacy for Personalized Health, February 27–28, 2025, Esch-sur-Alzette, Luxembourg.Luxembourg Institute of Socio-Economic Research (LISER); 2025. 10.17605/OSF.IO/S5FD7 37. Floridi L. Information: A very short introduction, vol. 225. Oxford University Press; 2010. [ Google Scholar ] 38. Sinton D. The inherent structure of information as a constraint to analysis: Mapped thematic data as a case study. Harvard papers on geographic information systems. 1978. 39. Goodchild MF, Yuan M, Cova TJ. Towards a general theory of geographic representation in GIS. Int J Geogr Inf Sci. 2007;21(3):239–260. 10.1080/13658810600965271 [ Google Scholar ] 40. Laube P. Computational movement analysis. 5th ed. Berlin: Berlin: Springer International Publishing; 2014. [ Google Scholar ] 41. Peuquet DJ. It’s about time: a conceptual framework for the representation of temporal dynamics in geographic information systems. Ann Assoc Am Geogr. 1994;84(3):441–461. 10.1111/j.1467-8306.1994.tb01869.x [ Google Scholar ] 42. Goodchild MF. Geographical data modeling. Comput Geosci. 1992;18(4):401–8. [ Google Scholar ] 43. Bishop W, Grubesic TH. Data Lifecycle. In: Bishop W, Grubesic TH, editors. Geographic Information: Organization, Access, and Use [Internet]. Cham: Springer International Publishing; 2016. pp. 169–86. Available from: 10.1007/978-3-319-22789-4_9 44. Kim E-K, McKenzie G. Report from the 2nd Specialist Workshop on Geoprivacy for Personalized Health, February 27–28, 2025, Esch-sur-Alzette, Luxembourg, Luxembourg Institute of Socio-Economic Research (LISER); 2025. 10.17605/OSF.IO/XRFK4 Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Supplementary Materials Supplementary Materials (61.9KB, docx) Data Availability Statement No datasets were generated or analysed during the current study. Articles from International Journal of Health Geographics are provided here courtesy of BMC ACTIONS View on publisher site PDF (1.8 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top