What is Third-Party Data Sharing?
Third‑party data sharing is when an organisation gives collected survey data to another organisation or service (for example a translation vendor, analytics provider, or researcher). It covers any transfer of personal or survey responses outside the team that collected them.
Third‑party data sharing means sending or allowing access to participant data — names, contact details, survey answers, or derived records — to organisations or services that are not the original data controller. In the context of surveys, third parties commonly include cloud hosting providers, AI translation services, external analysts, research partners, vendors who process payments or run SMS/email delivery, and any subcontractors they use.
Sharing can be direct (you export and send files to someone) or indirect (a software provider passes responses to an AI translation engine). Legal and ethical obligations depend on what data is shared, why it's shared, whether the data can identify people, and where the third party is located. Good practice requires documenting the purpose, securing appropriate contracts, minimising what is shared, and telling participants how their data may be used.
Usage example
A council runs a multilingual consultation using Hearo. Responses are automatically translated by an external AI provider. Because that provider processes raw responses (including free‑text answers), the council treats the provider as a third party and signs a data processing agreement, limits which fields are sent for translation, and notes third‑party processing in the consultation privacy notice.
Practical application
Why this matters: sharing survey data with third parties affects participant privacy, legal compliance, and community trust. Mismanaged sharing can expose sensitive information, violate data protection laws (like GDPR/CCPA), and damage relationships with respondents—especially in multilingual or vulnerable communities. Practical steps organisations should take:
- Define purpose and lawful basis: only share when there is a clear need and legal justification (consent, contractual necessity, legitimate interest, or other lawful basis).
- Minimise data: share only the fields required for the task and remove direct identifiers where possible (pseudonymise or anonymise).
- Use contracts and safeguards: sign data processing agreements that require security, limit use, ban resale, and control sub‑processors.
- Check international transfers: ensure adequate protections if a third party is outside your jurisdiction (standard contractual clauses, approved frameworks, or local legal advice).
- Be transparent with participants: disclose who will see their data, for what purpose, and how they can object.
- Review and monitor vendors: confirm security certifications, retention policies, and incident procedures; perform a DPIA for high‑risk processing.
For Hearo users this is especially relevant when using built‑in AI translation or exporting open‑text responses: treat translation engines and external analysts as third parties and follow the steps above to protect participants and meet compliance requirements.
FAQ
Do I always need participant consent to share survey responses with third parties?
Not always. The requirement for consent depends on the legal framework and the type of data. Under laws like GDPR, you need a lawful basis for processing (consent is one option, but others include legitimate interest or performance of a task in the public interest). For sensitive personal data (health, ethnicity, political opinions) consent is typically required. Regardless of legal basis, transparency is essential: tell participants who you may share data with and why, and allow objections where appropriate.
Are AI translation services considered third parties and how should I manage them?
Yes. If your responses are sent to an AI translation provider, that provider is a third party or processor. Treat them as such: limit what you send (avoid unnecessary identifiers or sensitive text), sign a processing agreement, verify their security and retention policies, consider on‑device or private deployment options if available, and keep an audit trail of which responses were translated and by whom.
What counts as 'minimising' data before sharing it with a third party?
Minimisation means only sharing the exact data fields needed for the third party's purpose. For example, send the text of survey answers required for translation but remove names, contact details and any unrelated identifiers. Where possible use pseudonymised identifiers instead of real names, and aggregate data when detailed records aren’t necessary.
What should we include in our privacy notice about third‑party sharing?
Be clear and specific: name categories of third parties (e.g., 'AI translation providers', 'analytics partners', 'research partners'), explain the purpose of sharing, state the legal basis and retention period, describe participant rights (access, rectification, objection), and provide contact details for questions or complaints. If you rely on consent for some sharing, explain how participants can give or withdraw consent.