Privacy, Ethics & Regulatory Compliance

Privacy, ethics and regulatory compliance covers rules, practices and protections for collecting, storing and using multilingual survey data securely and responsibly.

Terms in this category explain consent language, lawful bases (for example GDPR), data residency and retention, anonymization, participant rights, accessibility and bias mitigation, plus processes for translation accuracy, audit trails and ethical review to ensure inclusive, compliant engagement.

Accessibility and Inclusive Design

Accessibility and inclusive design are practices that make surveys and digital forms usable by as many people as possible — including people with disabilities, different languages, literacy levels and varying access to technology. They focus on removing barriers so everyone can understand, complete and trust your survey.

Anonymization

Anonymization is the process of removing or transforming personal identifiers from survey data so individuals cannot be reasonably re-identified. It lets organisations use and share findings while protecting participants’ privacy.

Audit Trail

An audit trail is a timestamped record of actions and changes made to a survey, its translations and the responses. It shows who did what and when so organisations can verify decisions, resolve disputes and meet regulatory requirements.

Bias and Fairness in Survey Research

Bias and fairness in survey research refer to systematic errors that make some groups’ views less likely to be heard or accurately represented, and the practices used to ensure surveys treat different communities equitably. In multilingual and community surveys, this includes how sampling, question wording and translation affect who responds and what responses mean.

Binding Corporate Rules (BCRs)

Binding Corporate Rules (BCRs) are an organisation-wide privacy policy approved by EU data protection authorities that allow personal data to be transferred lawfully within a multinational group. They are legally binding on all group members and provide consistent safeguards for international data flows.

Children's Privacy (COPPA)

Children's privacy (COPPA) refers to the U.S. Children's Online Privacy Protection Act, which restricts how websites and online services collect, use and disclose personal information from children under 13. It requires parental notice, verifiable consent, and limits on data retention and sharing.

Consent Granularity

Consent granularity is the practice of offering people separate, specific choices about how their personal data will be used, shared and stored instead of a single all-or-nothing consent. It gives respondents control over each purpose or processing activity.

Consent Withdrawal

Consent withdrawal is a person's right to stop giving permission for their data to be processed. It lets participants rescind consent for a survey or study, requiring the data controller to stop using their identifiable data for the purposes covered by that consent.

Cross-border Data Transfer

Cross-border data transfer is the movement of personal data from one country to another — for example, when survey responses are stored, processed, or accessed outside the country where they were collected. Because data protection rules vary by jurisdiction, these transfers are regulated to protect people’s privacy and rights.

Data Breach Notification

A data breach notification is the formal message an organisation must send to regulators and/or people affected when personal data is exposed, lost or accessed without authorization. Its purpose is to explain what happened, what risk it creates, and what steps are being taken to reduce harm.

Data Controller vs. Data Processor

The data controller decides why and how personal data is collected and used; the data processor handles personal data on the controller’s instructions. Knowing which role your organisation plays determines legal responsibilities for compliance, security and responding to people’s data requests.

Data Minimization

Data minimization is the practice of collecting, storing and processing only the personal data that is necessary for a specific purpose. In surveys and forms it means asking for the least amount of information needed to achieve your goals and keeping it only for as long as required.

Data Portability

Data portability is the right and technical ability to obtain and move a person's personal data from one system to another in a usable, machine-readable format. It helps participants and organisations access, reuse and transfer survey responses without vendor lock-in.

Data Processing Agreement (DPA)

A Data Processing Agreement (DPA) is a legal contract that sets out how a service provider (the processor) may handle personal data on behalf of an organisation (the controller). It defines responsibilities, security measures, subcontractor rules and what happens if something goes wrong.

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is a structured process for identifying and reducing privacy risks when a project or system will process personal data in ways that could harm people. It helps organisations decide whether a project is safe, legally compliant and what controls are needed before launch.

Data Retention Policy

A Data Retention Policy sets how long an organisation keeps the personal data collected through surveys and when/how it is deleted or anonymised. It balances legal obligations, operational needs and participants' privacy.

Data Subject Access Request (DSAR)

A Data Subject Access Request (DSAR) is a request from an individual asking an organisation for a copy of the personal data it holds about them and information about how it’s being used. DSARs are a legal right in many jurisdictions (for example under the EU’s GDPR).

Differential Privacy

Differential privacy is a mathematical framework for sharing information about a dataset while limiting how much any single individual's data can be learned from published results. It adds controlled noise to outputs so aggregated statistics remain useful but individual responses are protected.

HIPAA (Health Data Privacy)

HIPAA (Health Insurance Portability and Accountability Act) is a U.S. law that sets rules for protecting people’s personal health information. Organisations that create, store or transmit protected health information (PHI) must follow privacy, security and breach-notification requirements under HIPAA.

Human Subjects Research Regulations

Human subjects research regulations are laws, ethical guidelines and institutional rules that govern studies involving people, intended to protect participants’ rights, safety and privacy. They determine when a project needs ethical review, informed consent, and specific data-handling safeguards.

Informed Consent

Informed consent is the clear, voluntary agreement a person gives after being told what a survey will ask, how their answers will be used, who will see them, and how long they will be kept. For multilingual surveys this means presenting that information in a language the participant understands and recording their affirmative choice.

Institutional Review Board (IRB)

An Institutional Review Board (IRB) is an independent committee that reviews research involving people to ensure it is ethical and that participants are protected. It assesses risks, consent processes and data handling before a study can proceed.

K-anonymity

K-anonymity is a privacy technique that reduces the risk of re-identifying people in a dataset by ensuring each record is indistinguishable from at least k‑1 others on key identifying fields. It's commonly used before sharing or publishing survey results to protect participants' identities.

L-diversity

L-diversity is a data anonymisation principle that reduces the risk of revealing sensitive attributes by ensuring each group of records that look the same on non-sensitive fields contains at least l well‑represented values of the sensitive field. It is used to make shared or published datasets safer without destroying their usefulness.

Lawful Basis for Processing

A lawful basis for processing is the legal reason you rely on to collect, store or use someone’s personal data (for example under GDPR). For surveys and forms you must pick and document an appropriate basis — common ones are consent, legitimate interests, public task and legal obligation.

Legitimate Interest Assessment

A Legitimate Interest Assessment (LIA) is a short, documented test organisations use under data protection law (for example GDPR) to decide whether they can lawfully process personal data without consent because their legitimate purpose does not override individuals’ rights.

Privacy Notice

A privacy notice is a short explanation given to survey participants about who is collecting their data, why it's being collected, how it will be used and how long it will be kept. It tells people their rights and how to contact the organisation with questions or concerns.

Privacy by Design

Privacy by Design is a proactive approach that builds privacy protections into systems and processes from the start, not added later. For survey makers it means collecting only what you need, protecting participant data, and making privacy the default setting.

Pseudonymization

Pseudonymization is a data-protection technique that replaces identifying information (like names or emails) with pseudonyms or tokens so individuals aren’t directly identifiable while still allowing controlled re‑identification when necessary. It reduces privacy risk without permanently removing the ability to link records.

Purpose Limitation

Purpose limitation is a privacy principle that requires organisations to collect personal data only for specific, explicit purposes and not to use it for unrelated reasons without further legal basis or consent. In practice it means states why you’re collecting survey responses and sticks to that purpose unless participants agree otherwise.

Re-identification Risk

Re-identification risk is the chance that someone who provided ‘anonymised’ survey data can be identified by combining that data with other information. Even when direct names are removed, small details or combinations of answers can reveal who responded.

Re-identification Risk Assessment

A re-identification risk assessment evaluates how likely it is that anonymised or pseudonymised data can be linked back to real people. It helps organisations identify, reduce and document privacy risks before collecting, storing or sharing survey data.

Right to Erasure (Right to be Forgotten)

The right to erasure (often called the right to be forgotten) lets an individual ask an organisation to delete their personal data when there is no lawful reason to keep it. It’s a privacy right in laws such as the EU GDPR and some other national/state laws.

Security by Design

Security by Design is the practice of building security and privacy into a product from the start rather than adding it later. For Hearo, it means surveys, translations and response workflows are designed with encryption, minimal data collection and secure defaults to protect participants and administrators.

Special Category Data

Special category data (sometimes called sensitive personal data) is personal information that is especially private and needs stronger legal and practical protections. Collecting or processing it usually requires a clear legal basis and extra safeguards.

Standard Contractual Clauses (SCCs)

Standard Contractual Clauses (SCCs) are pre-approved contractual terms that organisations use to lawfully transfer personal data from the EU/UK to countries without an EU adequacy decision. They set binding obligations on exporters and importers to protect personal data during cross-border transfers.

T-closeness

T-closeness is a privacy criterion for anonymised datasets that limits how different the distribution of a sensitive attribute inside any group of similar records can be from its distribution in the whole dataset. It helps reduce the risk that an attacker can infer a person’s sensitive value from a released dataset.

Third-Party Data Sharing

Third‑party data sharing is when an organisation gives collected survey data to another organisation or service (for example a translation vendor, analytics provider, or researcher). It covers any transfer of personal or survey responses outside the team that collected them.

Vendor Due Diligence

Vendor due diligence is the process organisations use to evaluate a supplier’s security, privacy, legal and ethical practices before they buy or share data. It checks whether a vendor can safely handle the organisation’s information and meet regulatory and community obligations.

Vulnerable Populations Protections

Vulnerable Populations Protections are safeguards, processes and design choices that reduce risk and ensure dignity, safety and meaningful consent when collecting information from people who may be at higher risk of harm or misunderstanding. They adapt consent, privacy, communication and data handling to the needs of those groups.