Secondary consent: what biobanking research gets right and wrong
A biological sample collected during a study rarely gets used exactly once. It's common practice to retain samples in a biorepository for future research, sometimes years later, on questions nobody could have described at the time the original consent form was signed. Work examining secondary consent practices in a prostate cancer biorepository looks directly at how well the consent process actually handles this, and finds the gap between good intentions and consistent practice is wider than it should be.
The basic tension
Broad, one-time consent at collection is operationally simple: a participant agrees once, and the sample can be used for whatever future research the biorepository's governance permits. It's also the model participants understand the least well, because it asks them to consent to research that doesn't exist yet, described only in general terms.
Secondary consent, going back to participants (or documenting a clear, previously agreed process for not doing so) before a new specific use, respects participant autonomy more directly, but it's operationally much harder. Participants move, lose contact, or in some cases have died by the time a new research use is proposed, sometimes a decade or more after the original sample was collected.
What the research on this actually shows
The biorepository work highlights a few recurring, practical problems that don't show up when secondary consent is discussed only in the abstract:
- Contact information degrades quickly. A meaningful share of participants become unreachable well before most of a biorepository's useful research lifespan has passed, meaning a strict secondary-consent requirement effectively excludes their samples from future use regardless of how they'd have felt about it.
- Consent forms vary widely in how clearly they describe future use. Some are specific about categories of future research; others use language broad enough that it's unclear what a participant actually understood they were agreeing to.
- Governance committees, not just consent language, do a lot of the real protective work. Independent review of proposed secondary uses, even under a broad initial consent, functions as an important safeguard when going back to every individual participant isn't practically possible.
Broad and secondary consent, weighed against each other
Neither model is simply better. Each trades a different risk for a different practical constraint, which is easiest to see set out directly.
| Broad, one-time consent | Secondary, re-contact consent | |
|---|---|---|
| What the participant actually understands at signing | General categories of future use, often vaguely described | Nothing beyond the original study, by design |
| Operational burden over time | Low, no re-contact required | High, and grows as contact information ages |
| Coverage as time passes | Full, every sample remains usable under the original terms | Shrinks steadily as participants become unreachable |
| Where the real protection has to come from | Independent governance review of each proposed new use | The participant's own renewed decision each time |
| Best suited to | Large, long-running biorepositories with active governance | Smaller collections, or uses clearly outside anything the original consent could have anticipated |
The table makes the practical case clearer than the ethical one: broad consent scales, secondary consent respects autonomy more directly but degrades with time. Good biorepository governance doesn't pick one and ignore the other's failure mode, it uses broad consent's scalability while building in enough of secondary consent's spirit, through genuine independent review, that the two failure modes don't compound.
A timeline that makes the tension concrete
Consider a sample collected under a broad consent form at enrolment into a prostate cancer study. Five years later, a genuinely valuable secondary use is proposed, a genomic analysis nobody anticipated when the original consent was written. By this point, a meaningful share of the original cohort has moved, changed contact details, or is no longer reachable through the information collected at enrolment.
A strict secondary-consent requirement, applied retroactively, would exclude every unreachable participant's sample from research many of them might well have supported, not because they objected, but because nobody could ask. A governance-review model instead asks whether the proposed genomic analysis falls within what a reasonable participant would have expected from the original broad consent's stated categories, and whether the study's ethics oversight considers it appropriate to proceed without individual re-consent. Neither approach is perfect. The point of comparing them side by side is that the choice has real, differently distributed consequences, not that one option avoids the problem entirely.
What this means for designing a consent process
None of this argues for abandoning secondary consent where it's genuinely achievable, or for treating broad consent as an acceptable substitute everywhere. It argues for being explicit and realistic about which model a given biorepository or study is actually using, and building the right safeguards around that choice:
- Be specific in the original consent about what "future research" actually means, categories of use, types of studies, rather than a vague blanket statement that technically covers everything and meaningfully informs very little.
- Build a genuine, independent review process for new proposed uses, so that broad consent isn't functioning as a blank cheque with no ongoing oversight.
- Maintain contact information proactively, not reactively. A biorepository that only tries to re-contact participants once a new use is proposed will lose a predictable share of its population to outdated contact details, regardless of how well-intentioned the process is.
- Be honest with participants at the point of original consent about what will and won't trigger a new conversation with them. A participant who understands upfront that broad consent means they won't be re-contacted for every future use is in a genuinely different position, ethically and practically, than one who assumes they will be.
The broader point about consent design
Secondary consent for biobanked samples is a specific case of a more general problem: consent given at one point in time struggles to anticipate everything that will happen to data or samples years later. The honest response to that isn't to pretend the problem is solved by a well-worded initial form. It's to build ongoing governance, review, and transparency into the process, so that whatever model of consent a given biorepository uses, broad, secondary, or some hybrid, is actually matched by real, ongoing protection rather than a form participants signed once and never thought about again.