Our work often touches political opinion, security, and personal circumstance in places where a data leak or a badly handled interview is not a minor incident. Every engagement follows an ethics review modeled on Institutional Review Board (IRB) standards, and our data handling is built around the principles of the EU General Data Protection Regulation (GDPR), regardless of where a project sits.
Before any fieldwork, survey, or interview begins, each project goes through an ethics review modeled on Institutional Review Board practice: informed consent, voluntary participation, risk-to-participant assessment, and special protocols for vulnerable populations and sensitive topics. This applies whether or not a client's own institution requires it.
We apply GDPR's core principles — data minimization, purpose limitation, defined retention periods, and respect for data-subject rights — to every project, not only those involving EU residents or clients. It is our baseline standard rather than a jurisdiction-triggered exception.
We identify what data is needed, what is sensitive, and what protections and consent procedures the project requires before any collection begins.
Field teams and survey instruments are built around informed consent and data minimization, collecting only what the research question requires.
Data is encrypted at rest and in transit, held on access-controlled systems, and never stored on personal or unmanaged devices.
Analysts work from de-identified or pseudonymized data wherever possible, with identifying information kept separate and access-limited.
Findings are aggregated and reported in ways designed to prevent re-identification of individual participants.
Data is retained only for the period agreed with the client and securely deleted afterward, consistent with GDPR storage-limitation principles.
Questions about how a specific engagement would handle your data, or requests related to personal data we hold, can be directed to our team.
Contact Us