OUR PRIVACY PRINCIPLES
Respondent´s privacy is our top priority. We rely primarily on demographic and aggregated data from which we cannot directly identify people. Our internal policies and procedures conform to applicable laws and industry standards around the globe. They also incorporate the commitment to include appropriate privacy protections in the design and implementation of our products and services.
The practices described in this Privacy Statement are undertaken by D&D Insights and our associated companies operating together around the world.
We deploy respondent-friendly privacy controls that are easy to find and easy to use. We believe in responsible stewardship of data, and we are continually striving to improve our own practices and maintain a high standard for our industries.
While developing our products and services, we assess their potential impact on personal data and embed appropriate privacy protections into our data processing activities, taking into account the other privacy principles described below.
We are committed to responsible stewardship of the data under our control and to compliance with all applicable data protection laws that regulate the collection, use and disclosure of data about individual people. Our internal privacy team oversees compliance with applicable privacy laws and our internal privacy policies. We use tools and methods designed to prevent individuals from being identifiable in our data, reports and insights, and we take steps to prevent the data we collect from being reused in ways that have not been communicated to individuals and/or could negatively affect them.
THE DATA D&D Insights COLLECTS
We collect personal data from:
- Our panelists—individuals and households who agree contractually to participate in one or more of our panels. We also process personal data in order to recruit for panels that accurately represent the “total audience.”
- People we contact in regard to our surveys conducted online, in person, by telephone, email, or postal mail.
- Website browsers, mobile and other devices that are measured by our digital and mobile products, or segmented into audiences for online or mobile advertisements.
- Visitors to our websites and people who contact us via our websites, via email, or other means.
- Public sources—about the public activities of certain public figures, such as professional athletes.
- Publicly available social media posts, for products that measure online reaction to video content, products, and brands.
- Our employees, contractors, and business contacts at other companies in the course of conducting our business.
MEANINGFUL NOTICE AND CHOICE
We provide clear notice about what data we collect and how we use it. We offer choices about our data collection at a time and in a context that reflect the sensitivity of the data being collected. Panelists and survey respondents agree to the collection and processing of their data and may withdraw their participation at any time. Individuals also have the ability to opt out of our online and mobile data collection at any time.
We are continually working to maintain the personal data we collect so that it is complete, accurate, relevant and up to date.
BASIS FOR PROCESSING
Many privacy laws require companies to establish a lawful basis for their uses of personal data. We have established different lawful bases for different types of processing, in almost all cases our basis for processing personal data will be one of the following:
- Performance of a contract—we operate our research panels and conduct surveys on the basis of a contract—a panel membership or market research agreement between us and our research subjects. For many panels, these agreements cover all members of a household, because market research practices often require analysis of data at a household level.
- Consent—Where we base the processing of personal data on consent, we may seek consent directly from individuals or, where we act as a data processor (a service provider to another company), we may rely on consent obtained by the data controller (a third party who typically has a direct relationship with the individual and obtains consent).
- Legitimate Interests—In some cases, we may base the processing of personal data on our legitimate interest in performing market research or other services, because of its benefits in improving the efficiency of our clients and the markets in which they operate. Where we rely on this as our basis for processing, we make sure our activity is appropriately balanced by strong privacy protections designed to minimize the risks to data subjects.
DATA MINIMIZATION AND COLLECTION LIMITATION
Following the concept of data minimization, we limit the collection of personal data to the extent possible while still enabling us to derive meaningful and accurate measurements and insights.
- When we use direct identifiers, we limit access to such information both internally and externally and implement appropriate data security measures, which are designed to protect individuals’ privacy.
- Before we obtain third-party data, we review the third party’s data collection practices and the privacy notices that are made available to individuals to make sure that our use of the data is consistent with the commitments those companies have made to individuals.
- When we have removed identifying elements from the data that we collect, we take steps to prevent the data from being re-associated with identifiable data.
LIMITED USE AND RETENTION
We restrict access to and use of personal data to our associates and service providers with a legitimate business purpose. We have established records retention policies to limit how long we keep personal data.
We only retain your data in a way that can identify you for as long as is necessary to support the research project and findings.
In practice, this means that once we have satisfactorily reported the anonymous research findings, we will securely remove your personal, identifying data from our systems immediately after project closure.
ACCESS, CORRECTION, ERASURE AND PORTABILITY
We provide individuals with reasonable opportunities to access the personal data we hold about them and correct it if it’s inaccurate.
Depending on your country or state (US) of residence, under applicable law individuals may have various additional rights with respect to personal data processed.
Rights may include one or more of the following:
- To request confirmation as to whether or not personal data is processed, and, where that is the case, access a copy of the data we hold and to request it is updated or corrected where it is inaccurate.
- To object to processing of personal data.
- To propose other restrictions on the processing of personal data.
- To request that personal data is deleted (where applicable).
Individuals that are interested in exercising one or more of the rights described above can contact us at firstname.lastname@example.org.
Only the individual data subject or an “Authorized Agent” permitted to act on their behalf may submit a request. An “Authorized Agent” means a natural person or a business entity that has been properly authorized to act on the individual’s behalf. Please note, we may deny a request from an Authorized Agent if they do not submit proof that they have been authorized by the individual data subject to act on their behalf.
A request must:
- Provide sufficient information that allows us to reasonably verify that the requestor is the person about whom we collected personal data or their Authorized Agent.
- Include sufficient detail to allow us to properly understand, evaluate, and respond to it.
We cannot respond to a request or provide personal data if we cannot verify the identity of the requestor or their authority to make the request. To verify a requestor’s identity, we will match data provided when the request is submitted to any personal data we already maintain.
We comply with applicable laws regarding the collection of data about children. When we collect personal data from children, we do so with parental consent, which can be withdrawn at any time.
We respect applicable local laws regarding cross-border transfers of and access to personal data.
DISCLOSURES OF DATA TO THIRD PARTIES
We do not sell data that directly identifies individuals, and we contractually prohibit our clients re-identifying individuals from the de-identified data that we provide them.
Furthermore, we contractually prohibit recipients of our data from using it to make decisions regarding credit, insurance, housing, employment or other legal effects on individuals. We contractually require service providers that have access to our data to keep it secure and use it to perform only the services they have been engaged to provide.
We implement multi-layered organizational, technical and administrative measures that are designed to protect the personal data under our control. These include, among other things: limiting access to data, using technology measures like firewalls, encryption, malware protection and intrusion detection, maintaining policies that are aligned to a wide variety of legal requirements and holding our associates accountable for maintaining safe data-handling practices and adhering to our internal policies. We have a global organization of qualified data security professionals and engage in regular system testing and updating of our controls to keep pace with changing technology and security threats.
GLOBAL REACH, LOCAL TOUCH
We are committed to respecting the diverse cultures and local laws of the countries in which we operate.