Methodology and research standards

Research Privacy and Data Protection

Participant data protection begins with deciding whether information should be collected at all—not merely with storage after collection.

Scope

This policy applies to participant, respondent, researcher, contact, field, audio, image, note, administrative, and digital data used in research. It is read with study-specific privacy notices, commissioner contracts, and applicable requirements.

Protection principles

Specified purpose

Collect data for a clear and legitimate research purpose.

Minimization

Collect the least information necessary.

Accuracy

Correct errors where they affect the person or research.

Restriction

Limit access and use to authorized purposes.

Limited retention

Do not retain information without a legitimate need.

Security and accountability

Use technical and organizational measures and document decisions and incidents.

Data categories

  • Nonidentifying or aggregate data.
  • Pseudonymized data linkable through a separate key.
  • Direct identifiers such as name, telephone, or identification number.
  • Sensitive data such as health, politics, violence, or children’s information.
  • Operational and technical data such as time, location, and device.
  • Confidential materials owned by a commissioner or partner.

Minimization and identity separation

  • Do not collect names or telephone numbers merely for convenience.
  • Use participant codes rather than identifiers in instruments.
  • Store linkage keys separately and securely.
  • Delete contact information when no longer needed.
  • Avoid open-text fields that elicit unnecessary identifying detail.
  • Remove file metadata before publication or sharing.

Notice and consent

Study notices explain who collects information, purpose, data categories, use, sharing, retention, rights, and inquiry channels. Separate permission is obtained for recording, recontact, or image use where required.

Access and permissions

  • Least privilege necessary for the role.
  • Individual accounts and appropriate authentication.
  • Periodic review and removal after assignment end.
  • Access logging for highly sensitive data where practical.
  • No permanent storage on personal devices or unapproved services.

Transfer and storage

  • Encrypted connections and suitable services.
  • No open email attachments for sensitive files.
  • Protected devices and backups.
  • Separation of contact details from responses.
  • Known storage locations and providers.
  • Assessment of international transfers according to sensitivity and safeguards.

Retention and deletion

Each project defines retention for raw, pseudonymized, anonymized, contact, recording, and consent information. Periods may vary by purpose, contract, audit, complaint, and law. When no longer needed, data are deleted, anonymized, or moved to restricted archives.

Sharing and research access

  • Commissioners do not automatically receive identifying data.
  • Outputs, ownership, and access rights are defined by agreement.
  • Restricted data require data-use arrangements.
  • Variables are removed or aggregated where reidentification risk is high.
  • Participant contact and reidentification are prohibited.
  • Data requests are reviewed for purpose, risk, and capacity.

Publication

Findings are published in aggregate or anonymized form. Small cells, qualitative quotations, maps, images, and stories are reviewed so combined detail does not identify a person, household, or sensitive location.

Participant rights

  • Ask how information is used.
  • Correct inaccurate identifying information.
  • Request no further contact.
  • Withdraw optional consent where applicable.
  • Request deletion or restriction in appropriate cases.
  • Complain about privacy or security.

Data incidents

Suspected loss, exposure, or unauthorized access is contained; necessary evidence is preserved; data, people, and potential harm are assessed; action and notification needs are determined; and causes are reviewed to prevent recurrence.

Digital data and AI

Restricted or identifying data are not uploaded to public AI or analysis tools. Provider contracts, processing location, retention, and training use are reviewed, and human responsibility for decisions and verification is retained.

Data inventory

Each project maintains a record of data categories, source, purpose, sensitivity, storage location, access, retention, and disposition. The inventory helps prevent collection of unused variables or retention of unknown copies.

Roles and responsibilities

Controller or decision-maker
Determines the purpose and essential means of processing under applicable law and agreement.
Processor or contractor
Processes data under documented instructions and does not use them for an unauthorized independent purpose.
Study lead
Defines research necessity and ensures minimization and protection.
Data manager
Manages structure, permissions, versions, transfer, and deletion.
Authorized user
Accesses only the minimum information required for the assigned task.

Deidentification and pseudonymization

Direct identifiers are removed when no longer needed and may be replaced with a code while the linkage key is stored separately. Removing a name does not make data anonymous where location, age, occupation, or a rare combination can identify a person.

Sensitive data and small groups

  • Collect only the minimum necessary.
  • Reduce geographic or temporal precision in publication.
  • Combine or suppress small cells where reidentification risk is high.
  • Restrict variables or provide secure-environment access.
  • Review linkage risks with other sources.
  • Document the decision to release or restrict.

Devices and accounts

  • Use institutional accounts with appropriate authentication.
  • Encrypt sensitive devices or files where feasible.
  • Do not share through personal accounts or unapproved applications.
  • Maintain systems and address device loss or staff departure.
  • Close sessions and withdraw access when a role ends.

Secure transfer

Transfer method is selected according to sensitivity, size, and destination. It may use an expiring link, encryption, or an approved exchange environment. Passwords are not sent in the same channel, and restricted data are not uploaded to public services merely for convenience.

Sharing with a commissioner

A commissioner does not automatically receive names, contact details, or every variable. The agreement defines need, whether a deidentified file or tables are delivered, and responsibility for participant requests and incidents.

Individual rights requests

Where access, correction, deletion, or restriction rights apply, requests are handled with identity verification, protection of others, and record identification. Anonymity, research requirements, or legal duties may prevent full fulfilment, and the reason is explained.

Retention and deletion

MaterialRetention approach
Recruitment contact informationDelete or separate after contact and verification are no longer required.
Linkage keyRetain for the shortest necessary period under highly restricted access.
Analytical datasetRetain according to agreement, purpose, rights, and archiving plan.
RecordingsDelete after transcription and review where no other legitimate need exists.
Consent and quality recordsMay be retained proportionately to demonstrate compliance and accountability.
BackupsExpire through a documented replacement cycle and are not used for ordinary operation.

Incidents

  1. Contain the affected access, link, device, or account.
  2. Identify data, people, duration, and recipients.
  3. Assess likelihood and severity of harm and existing protection.
  4. Document the decision and any legal or contractual notification.
  5. Communicate with affected persons where necessary and useful.
  6. Correct the cause and review procedures.

Data-protection impact assessment

Enhanced assessment is used where a project involves large-scale monitoring, highly sensitive data, children, source linkage, new technology, or consequential automated decisions. It describes necessity, proportionality, risk, controls, alternatives, and the decision.