GDPR Data Processing

This document provides an overview of The Field Data's approach to GDPR and how the platform supports privacy-conscious research operations.

Commitment to Privacy

Our company is committed to providing its clients with a secure, reliable platform that prioritizes security and safety above all else. Each year, we invest significant resources in enhancing our security capabilities and regularly conduct penetration tests and code scans to meet the requirements of demanding organizations.

We build products that reconcile the need for data privacy with the need for organizations to continuously learn from their customers. This document is intended to give our customers an overview of regulations in force in the European Union and how our company helps customers meet these requirements.

GDPR Overview

In 2016, the European Union introduced the General Data Protection Regulation, or GDPR. GDPR makes significant changes to the ways companies and organizations collect and manage personal data, especially personally identifiable information, or PII.

GDPR places substantial requirements on organizations to protect personal data, while also helping the research and customer insights industry ensure personal data is managed responsibly. Our company's view is that GDPR is a positive development for organizations collecting and managing PII.

What Is PII?

The European Union has defined personally identifiable information in broad terms. PII includes, but is not limited to:

  • IP address
  • Email address
  • Name
  • Residential address
  • Username
  • Any data point or combination of data points that could be used together to identify an individual

Researchers should take special care in processing and managing PII to avoid potentially significant fines and regulatory issues under GDPR. Collecting or viewing PII is permissible when it is done correctly and lawfully.

Data Controllers and Processors

A data controller is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

A data processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Organizations that license our company, or similar tools, for the purpose of collecting customer information are data controllers, whereas our company acts as a data processor regardless of whether your organization uses our professional services. Our company's goal as a data processor is to help customers operate in a GDPR-compliant way while gathering valuable customer insights.

GDPR has specific requirements that our company helps clients address through robust software solutions. These requirements include:

  • Informing citizens of the European Union how their data is collected and how it will be used
  • The right to export personal data
  • The right to be forgotten
  • Accessing PII on the principle of least-privilege access
  • Making Terms of Use and Privacy Policies easy to understand

Explicit User Consent

European Union citizens need to be informed how their data is collected and stored, including where common website analytics tools capture IP addresses. To support this, we can trigger privacy-related notices when a community member first accesses a community from the European Union. We infer location based on the IP address of the user accessing the community.

When an EU-based user is detected, The Field Data can display information regarding the data collection tools used and how the data is used. The Field Data provides default templates, and the information and text displayed can be customized.

In addition, users must generally explicitly consent to Terms of Use or Rules of Participation. In other words, users must purposefully check a box to accept the Terms. The Field Data provides the ability to configure this setting in community settings.

The Right to Be Forgotten

Another core principle of GDPR is that users should be able to erase their data, effectively eliminating an organization's ability to access their personal data. GDPR requires that user consent is as easy to revoke as it is to give.

While The Field Data recognizes the desire to maintain high member numbers, we also believe in complying with the spirit of the regulation and do not make account erasure an unnecessarily difficult process, although the platform may ask the member to confirm at least twice that they want to erase their account and account data. Account erasure is irrevocable. If a member wants to participate in the community again, they must rejoin as a new member.

On rare occasions, clients may choose to ban or delete a community member for antisocial behavior. Banning a community member does not revoke their right to access data they have provided or to delete their account. These individuals may access the Privacy page and can download or erase their data there after authenticating their account.

Least-Privilege Access to PII

GDPR's principle of least privilege access means personally identifiable information should be accessible to the fewest people possible, and only where there is a compelling business need.

Our company provides controls to manage access to PII. We automatically designate templated profile fields like email address, IP address, names, username, and street address as PII. Our customers can also designate other profile fields as PII and decide which researchers may access that information.

Exchange Integrations

Our company does not send PII through our API to our Exchange partners. When profiling data is shared via our API, it is linked based on the our company UserID. This pseudonymizes member data and helps enable integrations with reduced privacy risk.

An exception may apply where our company is connected by API to a system such as a customer relationship management platform and a field like an email address is used as the key value to connect different systems.

Easy-to-Understand Terms and Privacy Policies

GDPR also requires that Terms of Use, or Rules of Participation, and Privacy Policies are easy for the general public to understand. Our company provides sample templates for Terms of Use and Privacy Policies to support this requirement.

GDPR Readiness Checklist for Research Communities

  • Consult with your organization's legal or privacy team
  • Review privacy messaging in your community, including privacy acceptance modals, privacy overviews, and privacy policies
  • Ensure you are requiring user consent in accordance with your company's policies
  • Review which moderators and researchers have access to PII
  • Review Terms of Use and Privacy Policies for ease of understanding

Contact

If you have general questions about our company's approach to GDPR and privacy, please contact our sales team at request@thefielddata.com.

Back