Data protection is regulated by legislation and has to be adhered to by scientists, too. This overview shows where aspects of data protection have to be considered in rehabilitation research. Important legal sources are the code of social law X, the German Federal Data Protection Act and the data protection acts of the German states. Specific recommendations about patient information sheet and written informed consent are given for research based on interviews with study participants. Furthermore, operations such as collecting, processing, using, storing, publishing and archiving of personal data are explained, taking into account the requirements of data protection. A practical example (URL: www.thieme-connect.de/ejournals/toc/rehabilitation) shows how to separate personal data and research data using the services of an external data custodian.