Data protection and information security
Documented handling from collection on device through encrypted transfer, role-based access, retention and destruction. Direct identifiers stripped before a dataset leaves the assignment team.
We document the full path of a record: collection on device, encrypted transfer, storage with role-based access, retention period, and destruction. Direct identifiers are stripped before any dataset moves beyond the assignment team. Where a financier applies its own data-protection regime, we work to that regime and evidence it.
In practice
- Documented collection → transfer → storage → retention → destruction
- Encrypted transfer; role-based access control
- Anonymisation before dataset release
- Device-level control on CAPI hardware
- Alignment to the financier's data regime where specified