Methodology and research standards

Research Privacy and Data Protection

Participant data protection begins with deciding whether information should be collected at all—not merely with storage after collection.

Scope

This policy applies to participant, respondent, researcher, contact, field, audio, image, note, administrative, and digital data used in research. It is read with study-specific privacy notices, commissioner contracts, and applicable requirements.

Protection principles

Specified purpose

Collect data for a clear and legitimate research purpose.

Minimization

Collect the least information necessary.

Accuracy

Correct errors where they affect the person or research.

Restriction

Limit access and use to authorized purposes.

Limited retention

Do not retain information without a legitimate need.

Security and accountability

Use technical and organizational measures and document decisions and incidents.

Data categories

  • Nonidentifying or aggregate data.
  • Pseudonymized data linkable through a separate key.
  • Direct identifiers such as name, telephone, or identification number.
  • Sensitive data such as health, politics, violence, or children’s information.
  • Operational and technical data such as time, location, and device.
  • Confidential materials owned by a commissioner or partner.

Minimization and identity separation

  • Do not collect names or telephone numbers merely for convenience.
  • Use participant codes rather than identifiers in instruments.
  • Store linkage keys separately and securely.
  • Delete contact information when no longer needed.
  • Avoid open-text fields that elicit unnecessary identifying detail.
  • Remove file metadata before publication or sharing.

Notice and consent

Study notices explain who collects information, purpose, data categories, use, sharing, retention, rights, and inquiry channels. Separate permission is obtained for recording, recontact, or image use where required.

Access and permissions

  • Least privilege necessary for the role.
  • Individual accounts and appropriate authentication.
  • Periodic review and removal after assignment end.
  • Access logging for highly sensitive data where practical.
  • No permanent storage on personal devices or unapproved services.

Transfer and storage

  • Encrypted connections and suitable services.
  • No open email attachments for sensitive files.
  • Protected devices and backups.
  • Separation of contact details from responses.
  • Known storage locations and providers.
  • Assessment of international transfers according to sensitivity and safeguards.

Retention and deletion

Each project defines retention for raw, pseudonymized, anonymized, contact, recording, and consent information. Periods may vary by purpose, contract, audit, complaint, and law. When no longer needed, data are deleted, anonymized, or moved to restricted archives.

Sharing and research access

  • Commissioners do not automatically receive identifying data.
  • Outputs, ownership, and access rights are defined by agreement.
  • Restricted data require data-use arrangements.
  • Variables are removed or aggregated where reidentification risk is high.
  • Participant contact and reidentification are prohibited.
  • Data requests are reviewed for purpose, risk, and capacity.

Publication

Findings are published in aggregate or anonymized form. Small cells, qualitative quotations, maps, images, and stories are reviewed so combined detail does not identify a person, household, or sensitive location.

Participant rights

  • Ask how information is used.
  • Correct inaccurate identifying information.
  • Request no further contact.
  • Withdraw optional consent where applicable.
  • Request deletion or restriction in appropriate cases.
  • Complain about privacy or security.

Data incidents

Suspected loss, exposure, or unauthorized access is contained; necessary evidence is preserved; data, people, and potential harm are assessed; action and notification needs are determined; and causes are reviewed to prevent recurrence.

Digital data and AI

Restricted or identifying data are not uploaded to public AI or analysis tools. Provider contracts, processing location, retention, and training use are reviewed, and human responsibility for decisions and verification is retained.