
Consent isn't paperwork: what the law asks for, and what the method asks for
View contents
I was putting together an interview guide template to publish here, going through the content I already had written, and I could not find a single sample consent form anywhere in my own files — but before writing one I stopped to think about how it gets used, whether it gets used at all, and what it is actually for.
This post is what I learned along the way, and the template is at the end.
A note for readers outside Chile: the specific statute below is Chilean, and I am not going to pretend it applies to you. The structure does travel — what to tell someone, what to ask separately, what to write down — and at the end of each section it should be clear what you would need to check in your own jurisdiction.
Why this is method, not paperwork
The obvious reason to ask for consent is that it is the right thing to do: you are recording a person, storing what they say, and showing it to other people. That alone is enough.
But there is a second reason, and it is the one I find more interesting for those of us doing research: someone who did not understand what they agreed to will not tell you what they actually think.
Think about it from the other side. You sit down with someone you do not know, a camera is on, you are not sure who will see this, and you have no idea whether what you say could come back to you somehow. In that situation people are careful. Not dishonest — careful. They give the reasonable answer, the presentable one, the one that commits to nothing. And that is exactly the data that is useless.
The first minutes of a session decide whether the person is going to open up. Done well, consent is the tool you have for that: it tells them what will happen, who will see it, how far it goes, and that they can stop whenever they want. Done fast and in passing, it communicates the opposite — that there is a formality to get out of the way before the real thing starts.
That is why I think it is worth treating as part of the session design rather than as the errand before it. Those first minutes are where we stake the rapport, along with every formality we have to get through.
What the law asks for in Chile
There is a date that matters here. A project I am running with a company has had me reading the law, and it turns out that Law 19.628 on the protection of private life is in force until 30 November 2026. On 1 December, Law 21.719 takes over, replacing much of that framework and creating a data protection agency.
So if you are reading this when I published it, the framework I describe below has under three months left.
Three articles bear directly on what we do.
Article 3 names us. It explicitly covers "surveys, market studies or public opinion polls or other similar instruments". And it requires informing people of two concrete things: "whether answering is mandatory or optional, and the purpose for which the information is being requested".
The first one almost never gets said out loud. Telling someone "you can skip any question" is a requirement.
The same article adds something that goes further than what we usually do: the communication of results "must omit the marks that could allow the identification of the persons consulted". Marks, not names. A report that says "Participant 3, head of operations at a mining company in the north" has no name in it and identifies her perfectly. That happens a lot in B2B studies with small samples.
Article 4 says it has to be in writing. Verbatim: processing requires that "the data subject expressly consents", whoever authorizes "must be duly informed as to the purpose", and "the authorization must be recorded in writing".
That has an awkward practical consequence for remote sessions, which gets its own section below.
The article adds that authorization "may be revoked, though without retroactive effect, which must also be done in writing". That "without retroactive effect" settles a question I had and felt awkward putting in the template: if someone asks to delete their data after the session, do you have to redo the analysis? You delete their recording and their contact details, you stop using their material from that point on, and what is already folded into the general analysis stays. It is worth telling people that beforehand.
Article 7 is about us, the people who work with personal data. We are bound to secrecy, and that duty "does not cease upon having ended their activities in that field". You leave the project, you leave the company, the duty stays. (Here I fall back on my role as a psychologist seeing patients, where professional secrecy works the same way and nobody argues about it. In research it gets named a good deal less.)
I am leaving you the link to the law because it is long and I do not read lawyer. What I quoted is articles 1 through 7, the ones I got to read properly; about the later ones I am saying nothing. I also did not read Law 21.719 article by article, so I am not claiming what exactly changes for a research consent form. When it comes into force, this part will need redoing.
None of this is legal advice, obviously.
The most common mistake: one checkbox
If I had to keep a single change, it is this one.
Almost every consent form I have seen has one checkbox, or one signature, covering everything: taking part, being recorded, being quoted, having your face in a presentation. The person ticks one thing and has thereby authorized four.
They are different decisions, and someone can perfectly well want one and not the others. There are people who do not mind talking but are uncomfortable on video. There are people who do not mind being recorded but do not want a clip of themselves circulating in an internal presentation where someone might recognize them. When you bundle it all together, what you get is a signature.
In the template I split them into four:
- taking part in the session
- being recorded (and what is recorded: audio, video, screen)
- being quoted verbatim, without a name, in the report
- having a video clip used in presentations
It costs three lines and it changes the conversation.
Now, something that keeps nagging at me: nobody has ever said no to me. Sometimes I have not even finished explaining and they are already saying yes, no problem.
But the fact that people almost never say no is not a reason to skip it. I do it so the person gets to size up the limits of the setting before walking in. Who will be there, how long it lasts, what it is about, what happens to the recording afterwards. That does not depend on them questioning it, it depends on me telling them.
That is where separate checkboxes help. They force four stops instead of one, and each stop names a concrete thing the person now knows, even if they say yes to all four.
The remote problem
Here is where the law and the practice do not get along.
Article 4 asks for written authorization. But most sessions today happen over video call, and on a video call nobody signs anything. What people do, when they do anything, is read something at the start and ask "is that okay with you?" with the recording already running.
That does not satisfy Article 4 on its own. And conversely, emailing a PDF and getting it back signed does not solve the real problem either, because signing without reading is the most common thing there is. You satisfy the law and you get none of the things consent is actually for.
What ended up seeming reasonable to me is doing both, because they solve different problems:
- Send the document beforehand, by email or a form, and get it back completed. That is what satisfies the written requirement.
- Read a short script at the start anyway, with the recording already running. That is what makes the person actually understand what they said yes to.
The full script is in the template. Two things I learned about reading it: you have to wait for an audible "yes", because silence or a nod is worth nothing when you review the recording later; and you have to make a real pause at "any questions before we start?". If you read straight through it, the person understands that this is not the moment to ask, and does not ask.
The template
I wrote it and it is available for free, with no email required: Informed consent template for UX Research (in Spanish).
It has three parts: the document to fill in and sign, the verbal script for remote sessions, and a checklist before using it. Everything in brackets gets replaced.
It is written in the second person and without legal language, on purpose. No "the participant hereby declares". If someone needs to read it twice, the template failed: a consent form that is not understood is just a form.
It carries a CC BY 4.0 license, so you can adapt it and use it in paid work as long as you credit the authorship. The license covers the template, not the consent form you complete with it: that document and your participants' data are yours.
What this does not cover
Quite a lot, actually.
It does not cover sensitive data. The law defines these in article 2(g) and includes personal habits, racial origin, political ideologies and opinions, religious beliefs, physical or mental health, and sexual life. If your study touches any of those, this template falls short and that is where someone with legal training should look at it.
It does not cover minors, who need authorization from whoever has legal care of them, plus the child's own assent.
It does not cover GDPR. If you have participants in the European Union it applies and asks for more: an explicit legal basis, an identified processor, the right to portability.
And it does not cover what arrives with Law 21.719 in December, which is exactly what I have left to study.
There is also something I did not resolve while writing this: what happens with automatic transcription tools and AI meeting notes. When you tell someone "only we will hear this", is that true if the audio went through a third-party service to be transcribed? That is a whole separate topic and it goes further than anything I can say today.
If you use the template and find a hole in it, or if you have clarity on any of these parts that I do not, I would like to hear it.


