How-to: Privacy Assistant (GDPR)

English | Deutsch


GDPR in EFS


Beginning on 25th May, 2018, theĀ General Data Protection Regulation (GDPR)Ā redefines the legal requirements to conduct surveys. Users who seek to obtain insights from their respondents have to follow new rules when they process personal data relating to respondents. Some of the key changes are:

  • The GDPR rises the bar for relying on valid consent for conducting surveys. A valid consent requires a clear, informed, explicit and affirmative statement from your respondents. Users must inform respondents about the survey in clear and plain language. Pre-ticked consent boxes are prohibited and will not serve as a valid consent.

  • When they collect and assess feedback data, users must to be able to demonstrate how they comply with the new data protection regulation, e.g. users must define the purpose of data processing prior to each survey.

  • Personal data shall not be kept longer than is necessary for the purpose of the processing, i.e. feedback assessment. This implies that there is a time limit how long personal data can be used after the survey. Therefore, users should define a retention period for respondentā€™s personal data after which such data will be deleted.

  • The GDPR provides respondents with several rights, including a right to object any data processing, a right to withdraw consent and to transfer their data in a commonly-used machine readable format.

  • Supervisory authorities have powers to impose significant fines of up to Euro 20million or 4% of total worldwide annual turn-over for users that do not comply with the GDPR.

If activated,Ā Tivianā€™s Privacy Assistant

  • enables users to identify (ā€œflagā€) personal data prior to the survey to ensure complete and accurate deletion of personal data which is no longer needed after the survey.

  • supports users to create a ā€œconsent formā€ to obtain informed, explicit and valid consent from their respondents.

  • offers a library of purposes statements to provide adequate information to respondents about the purpose for data processing.

  • helps users to provide statutory information to their respondents as required by the GDPR, e.g. contact information, individual rights, retention period and many more.

  • allows users to create an information sheet for respondents on their personal data which can be exported (data portability).


Activating theĀ Privacy Assistant


You activate theĀ Privacy AssistantĀ to conduct the surveys in accordance with the General Data Protection Regulation (GDPR) for new and existing projects. TheĀ Privacy AssistantĀ is available for both new and existing projects and can be used for the following project types:Ā Anonymous survey,Ā Personalized survey,Ā Employee survey,Ā Panel survey, andĀ Master data survey.


New projects

You activate theĀ Privacy AssistantĀ for a new project by ticking the corresponding option under the tabĀ New project.Ā TheĀ AssistantĀ is already activated by default.Ā The survey status can only be set toĀ ActiveĀ once the duration of data retention period has been configured.Ā You deactivate theĀ Privacy AssistantĀ by unchecking the box.

You click on the info link to get a brief overview of the most importantĀ general data protection regulations for you as a user ofĀ Survey. There you will also find an overview of the scope ofĀ functionalities available in theĀ Privacy Assistant.


Existing projects

For existing projects, you activate theĀ Privacy AssistantĀ by checking the Option underĀ Project propertiesĀ and clickingĀ Save.Ā Ā The survey status is then automatically set toĀ No further participations.Ā This setting will remain in effect until you have configured the data retention period. This also applies to copies of projects that have been activated without theĀ Privacy Assistant.

  • Path:

[Existing project]Ā ā†’Ā Survey menuĀ ā†’Ā Project propertiesĀ ā†’Ā General options

The project status of a survey for which theĀ Privacy AssistantĀ was activated can be set toĀ ActiveĀ even if the consent form has not been configured, yet. Only the duration of data retention needs to be defined.

TheĀ Privacy Assistant, which can be activated subsequently for existing projects, applies to the surveys that are started after editing and saving the consent forum, i.e. for which consent must be given to participate.

If you set the status of a project toĀ Active, the Privacy Assistant can no longer be deactivated.


The portability of personal data


If a data subject addresses the request to you as the data controller to have access to the personal data collected about him or her, please contact support. You pass on this person's code and/or e-mail address. TIVIAN provides you with an overview of personal information about that person in a common and readable format.


The deletion of personal data


The personal data will be deleted at the end of the retention period defined for a specific project. In addition, the data subject has the option of contacting the data controller if he or she wishes to have the data deleted. You provide TIVIAN with the e-mail address and/or code of the participant who wishes to be deleted. In this way the participants can be identified in the system.


Deletion of personal data by the controller

One way of independently deleting personal data of all participants in a project can be found in theĀ Survey menuĀ underĀ Test and Validation, where you can click on the buttonĀ Delete personal dataĀ underĀ Reset survey.

  • The personal data of all participants with a disposition code higher than 12 will be deleted.

The deleted data will no longer appear inĀ MySightĀ after the automatic synchronization. The data will be removed from existing dashboards. The personal data that have been deleted can no longer be found in the detailed view of a project and the corresponding participant lists.


Deleting Participants

Participants who do not participate in a survey cannot give their consent to data processing. They have no access to the consent form. Nevertheless, the data of these participants will be stored in the participant administration. As of the Fall release, you will be able to delete this data.

You can tick the option "Automatic deletion of personal data" to activate this feature. After ticking this option, a period of time has to be defined. If a participant will not participate in the survey within this period of time the personal dataĀ (e-mail, first name, surname) will be deleted automatically.Ā The disposition code 43 is described asĀ Personal data deleted.

  • By default, the feature is disabled.


Automatic deletion of invited panelists

In theĀ Panel configurationĀ of theĀ PeopleĀ module you have the new menu itemĀ Automatic deletion of invited panelists. Now you can automate the deletion of both theĀ Tell-a-friend

  • panelists (module:Ā 

Panel Website) and the panelists with panel status (module:Ā Portals).

  • Tell a friend:Ā You check the option "Delete invited panellists without reaction after" and set the number of years, months or days after which the invited panellists who did not respond to the invitation should be deleted.

  • Panelist with panel status:Ā You check the option "Delete invited panelists without response after" and set the number of years, months or days after which the invited panelists who did not respond to the invitation should be deleted.

    • In addition, you select the panel statuses of the panelists to be deleted.


Disposition codes


Participants who have one of the disposition codes 20, 21, 22 and 23 will receive the disposition code 43 after deletion of their personal data. The purpose of this new disposition code is that participants who are in an 'intermediate state' such as 'participant is responding' (disposition code 21) can no longer participate in the survey after the deletion of their data.

  • Participants who do not give their consent will receive the disposition code 42.


ACL rights


You can control the work with theĀ Privacy AssistantĀ by assigning three ACL rights.Ā InĀ OptionsĀ under the menu itemĀ Team rightsĀ you assign write and/or read rights of the ACL rights to teams.

Right

Read

Write

Right

Read

Write

gdpr_activities

  • GDPR settings in theĀ Questionnaire editor

    • Personal data flagging

    • Data retention period

    • Consent form

  • User, c_ and p_ , Org_variables,

  • Flagging master data and questions as personal data

  • Panel configuration

    • Consent form configuration

  • GDPR settings in theĀ Questionnaire editor

    • Personal data

    • Data retention period

    • Consent form

  • User, c_ and p_ , Org_variables,

  • Flagging master data and questions as personal data

  • Panel configuration

    • Consent form configuration

gdpr_activities_log

  • GDPR activities log area for projects, master data and consent templates


gdpr_purpose_templates

Consent form templates can be:

  • exported

  • read

Consent form templates can be:

  • created

  • edited

  • copied

  • deleted

  • imported

  • exported


The GDPR settings in the Questionnaire editor


After activating theĀ Privacy Assistant, the next step will be to edit a Consent form.Ā By using the Consent form, you inform the participants about the purpose ofĀ the data processing and the most important privacy information such as the name of the company, the contact data, the representation or the type of personal data and their use. You also specify the retention period.

You will find the GDPR settings area in the questionnaire editor, where you can define the data retention period and edit the consent form, mark personal data and create the consent form in different languages.

  • The GDPR menu can be opened under the menu item by either marking one of the linksĀ Personal data flagging,Ā Duration of data retentionĀ orĀ Consent formĀ or clicking on theĀ EditĀ icons.


Configuration of the languages of the consent form

The colored background of the three sections indicates whether and to what extent the sections are configured. The data retention period will turn green as soon as you specify a duration, eitherĀ ExactĀ orĀ Unlimited.Ā The new ā€œStatusā€ column shows you which languages have already been configured.Ā These are marked either red (not configured) or green (configured).Ā The overall status of the consent form results from the configuration status of the individual languages. Three statuses can be displayed in color:

  • Red: Neither the default language nor any of the other languages have been edited.

  • Yellow: The default language has been configured, but at least one of the other languages has not been configured.

  • Green: All languages have been edited.

If the consent form has the "Yellow" status, the consent form is considered as configured.Ā By clicking on the menu itemĀ Personal data flagging,Ā Data retention periodĀ orĀ Consent formĀ you will reach the GDPR settings, where you will find an overview area under the menu item "Mark personal data", which lists, among other things, all participant variables used in the project and questions used in the questionnaire, which you can mark here as personal data.

Depending on which team (e.g. administrator) you belong to, you have write and/or read rights to configure the language. You configure the language of the consent form for which your team has write permission.Ā You can only read the content of the consent form in the languages for which your team has the read permission.Ā If your team has neither read nor write permissions, the created languages are only listed in the questionnaire editor without you being able to read or edit them.


The flagging of personal data


For each question and variable you create, you have the option to tick "Flag question as personal data" resp.Ā "Flag as personal data".Ā Under the menu itemĀ Personal data flaggingĀ in the Questionnaire editor, you get an overview of participant variables and questions that were selected as personal data.Ā In addition to this, you can mark other participant variables used in the project and questions that have not yet been marked as personal data.Ā 


The flagging of questions as personal data

For each question you create, you can select the checkbox next to ā€œResponses to this question contain personal data and should be deleted automatically as specified under Data retention period.ā€ to flag the question as personal data.

Path:

  • [Existing project]Ā ā†’Ā Survey menuĀ ā†’Ā Questionnaire editorĀ ā†’Ā PageĀ ā†’Ā Question


The flagging of c_ and p_ variables as personal data

On theĀ User-defined variablesĀ tab, you will create c_ and p_ variables that can be flagged as personal data by checking the corresponding option. These variables are not deleted, but the value is reset.


Flagging variables as personal data

For each variable that you create, you have the tickable option "Mark as personal data". In addition to the ability to flag variables as personal data, some variables listed in the table are flagged as personal data by default. This default setting cannot be deactivated.

Path:

  • [Existing project]Ā ā†’ Survey menuĀ ā†’Ā Participant administrationĀ ā†’Ā Participant variable

The following variables are marked as personal data by default.

Variables

Participant data

System user

Org user

Variables

Participant data

System user

Org user

u_account


u_account


u_email

u_email

u_email

u_email

u_firstname

u_firstname

u_firstname

u_firstname

u_name

u_name

u_name

u_name

u_mobile

u_mobile

u_mobile


u_mobile2


u_mobile2


u_gender

u_gender

u_gender

u_gender



u_country


u_street


u_street


u_phone


u_phone


u_adressĀ (all)




u_city


u_city


u_www


u_www


u_zip


u_zip



remote_addr




participant_latitude




participant_longitude




remote_host




Duration of data retention


Under the menu itemĀ Duration of data retention, you can specify the duration for which the data should be stored by ticking the "Exact" option, you can dispense with setting an expiration date by ticking the "Unlimited" option, or you select the option ā€œImmediately on completionā€. If you activate this option, personal data will be deleted immediately after the completion of the survey.

Ā 

  • You specify the duration of the storage in years, months or days. The start of the storage period depends on the individual start of the survey for each participant. The data will be deleted automatically after this period has expired.

The retention period of the personal data that is listed in the Installation Log cannot be changed. This data is kept permanently, i.e. until the project is deleted.

The default value for the retention period of personal data for Login Log or Admin Log is 90 days. You can increase this value. The maximum value is 360 days.


Consent form


You edit the privacy consent form in the questionnaire editor to use it for the current project.Ā Before the survey will start,Ā the consent form is going to be presented to the participants.


The sections of the consent form

Survey language and welcome message

Use the drop-down list to select a language. The default language is the default language of the survey. You create a welcome message, for which placeholders and known formats can be used.

  • In the section "Survey language" you generate a record, which allows you as the data protection officer or the data protection officer to print out and archive the consent form together with the entries in the configured languages.Ā In this print version, additional information such as comment, date and options can be ticked.

  • Use theĀ PreviewĀ button to call the questionnaire preceded by the consent form.

The selection of the consent form template

You use one of the templates created inĀ LibrariesĀ by selecting one of these consent form templates via the drop-down list.Ā The selection of the templates that are displayed to you depends on the language you have previously selected.Ā TheĀ Manage templatesĀ link takes you to theĀ LibrariesĀ where the consent forms created are managed.

Purpose statement

You use this text field to explain the purpose of the data processing. No content specifications will be made byĀ TIVIAN. Filling in this field is mandatory.Ā 

Privacy information

In this section, you have three radio buttons at your disposal that allow you to decide, depending on the project requirement, whether you want to create a consent form and privacy notice, create a consent form, or create a privacy notice.Ā The selection made regulates which of the fields appear and can be filled in.

GDPR Consent messages

You can maintain the labels of the consent form central. You enter the corresponding labels in the selected language, which will then be displayed in the questionnaire view.


Portal registration


It is possible to obtain consent to process personal data from new users registering on your portals.Ā When the setting is configured, the portal login dialog has a second checkbox under theĀ RegisterĀ tab.

You activate this underĀ General settingsĀ in the CMS ofĀ PortalsĀ by ticking the option ā€œActivate Privacy consent formā€.


Configuring the consent form in the People module

In the module People underĀ Panel configurationĀ you will find the menu item ā€œConsent formā€, where you can create the consent form for the purpose of registering a panelist. In order to be able to use this feature to capture the consent of future portal participants, you must configure the consent form in default language, otherwise the checkbox will not be displayed. One configuration applies to all portals. This feature is available both for the login dialog via the portal and for inviting other panelists via e-mail.Ā Otherwise the checkbox is not displayed.

  • In theĀ PeopleĀ module, you have a language overview under the menu itemĀ Consent form configurationĀ of theĀ Panel configuration, so that you can immediately recognize in which languages the consent form has already been created.


Export and import including DSGVO messages (Language editor)


From now on, you can also export the headings and values of the approval form and the approval message using the export in theĀ Language editor, provided the DSGVO option has been activated.


Libraries: Consent form templates


You do not have to configure the consent form for each project, but create consent forms underĀ Libraries, which you will use when creating an consent form as required.Ā Pre-filled forms depicting the most common use cases can also be found there, so that you have GDPR-compliant consent forms by means of minor but indispensable adjustments to your own project circumstances.

Ā Path:

  • Navigation barĀ ā†’Ā SystemĀ ā†’Ā LibrariesĀ ā†’Ā Consent form templates


Templates overview


Under the menu itemĀ Consent forms templatesĀ you will find a search, the three buttonsĀ Create template,Ā Import templatesĀ andĀ Export all templatesĀ and an overview table of the created templates.

  • You can edit, copy or delete existing form templates by clicking on theĀ pen,Ā copyĀ orĀ deleteĀ icon in the right column.Ā You change the permissions, i.e. who has access to the consent form template, by clicking on theĀ permissionĀ icon.

  • You have a language identifier that allows you to filter the consent form templates by language.


Create new template

To create a new form template, you click on the buttonĀ Create template.Ā Fields marked with an asterisk are mandatory and must be completed. The following fields are available:

Language identifier

You assign the consent form template to a language by ISO code so that you can select it in the questionnaire editor matching the language of the survey.

Name, description, content

You give the template a name and write a short description text. Enter the purpose of the data processing in the free text field "Content".

Privacy information

You can also enter the data protection information in advance in order to save it as a template. You specify:

  • Company name (controller)

  • Contact details

  • Controller's representative (if applicable)

  • What personal data will be collected and used

  • What special categories of personal data will be collected and used

  • Legal basis for processing

  • Recipient or categories of recipients of the personal data

  • Transfer of data to a non-EU/EEC country or international organisation, and safeguards

  • Statutory or contractual requirement

  • Automated decision making

  • Information on data subject rights

  • Information on right to withdraw consent

  • Information on supervisory authority

  • Name & contact details of data protection officer


Import templates

Use theĀ Import templatesĀ button to download and upload consent form templates.

You proceed as follows:

  • Click onĀ Download import templateĀ and select a target directory. The template is downloaded as an Excel file.

  • To import a Consent form template, select a file by clicking the appropriate button and saving it.


Select action

The overview table has theĀ ExportĀ template andĀ DeleteĀ template actions, which you can use for all templates on the page, for all templates created at all, or just for individual templates.


GDPR activities Log


A table is available underĀ GDPR activities Log, which informs you about the GDPR activities by means of the columns data, actions, user and log entry.

  • In theĀ PeopleĀ module under the menu itemĀ GDPR activites LogĀ of the main navigation you call up the same table.


Ā© 2024 Tivian XI GmbH