Protecting Your Participants, Team, and Organization with ReOps
Checking session availability…
Hang tight while we load the latest updates.
Data privacy. You've heard the term and probably watched the training on it every year if you are in a corporate environment, but have you incorporated it into your UX practices? Kasey Canlas knows the struggle of initially figuring out how to start. Previously she too was puzzled by the terms PII, Data Processor, Data Controller. Lucky for you, she knows how to start you on your journey and give actionable steps to build a secure data-privacy-compliant research practice. The audience will learn how to evaluate existing processes, identify potential data privacy issues, and establish safeguards and best practices to add to your strategy.
Protecting Your Participants, Team, and Organization with ReOps
Kasey Canlas at UXDX Community: Protecting Your Participants, Team, and Organization with ReOps. Video: https://youtu.be/QJtVrdU2hsg
Readable transcript: edited from the recording's captions for readability (fillers and false starts removed, punctuation and section headings added). Wording is the speaker's own. Timestamps are positions in the video. Names marked [?] could not be verified against the audio.
Why this matters to me
[00:00:00] Yeah, I have 25 minutes. We'll kick this off and try to get through as much as possible. I'm here today to talk to you about how to protect your team. And it doesn't have to be just research operations, I like to think of it as a team effort. If you didn't know who I am, I've been in research operations for the last four and a half years. I'm going to talk about some data privacy, and documenting your data can sound a little scary. Personally identifiable information, also known as PII: you've probably heard it, you may not know what it means, but I'm going to talk to you more about it.
[00:00:32] So you're probably thinking, why does this sound so interesting to you? Because for some people, I know that you end up falling asleep during the compliance training. And that's okay. Essentially, I grew up in the Midwest. It was a very small town. I wasn't known as me, as Kasey Canlas. I'm always Jim's granddaughter, Kim's oldest, one of those Robinson girls. And I'm not going to tell you my whole life story, we don't have that kind of time. But it's essentially a small town, a small county. Everybody knows who each other are. It's not that unusual to do something wrong and then hear about it later on. And my sister followed in my mother and my grandmother's footsteps. And this will come back shortly. I promise we're going somewhere with this.
[00:01:19] So I was working at an educational publisher and COVID hit. Everyone was hit hard by COVID. Originally we thought it would just be remote working and this would be awesome. We're like, see you in three weeks, and then we were not sure if we were coming back to the office, and it was two months, and now I'm never working in the office, I'm fully remote.
[00:01:38] Back in my county there were 19% of the people that were below the poverty line. There were 16% of households that didn't have a computer, and there were 26% that did not have access to broadband internet. The reason I talk about this is because we actually moved home to my parents' house for three months, because I had a newborn and we were trying to raise him between three different people. I had my mom and my sister who were working from home as well, as teachers, and so we thought that that could help.
[00:02:13] However, I could hear my sisters struggling when they were talking about teaching, and my mom struggling. We'd sit there at the dinner table and they would say how they didn't see their first graders, or they didn't see their fourth graders, and they would wonder how they were, because their students had a lack of access to resources, to technology.
[00:02:33] So as we were going back and forth to try to figure out who we were going to recruit, this was a highly sensitive topic, because COVID was very triggering for a lot of people. And essentially, I had asked my sister, along with my mom and other rural teachers I knew, I said, "Can you sign up for our panel?" This was back before COVID. Can you let us know if you would be interested in talking to us for a while, because we're doing some research around this.
[00:03:04] Not a lot of people knew what the effects of COVID-19 were going to be on teachers, on education. We didn't know if it was safe for students to be in school physically. But students being at home had its own problems. So there were some children that were at home while their parents went to work because they didn't have daycare set up. There were some who go to school for nourishment, for food: that's their primary place that they go to get food, and if they're not going to school then how are they getting that? Domestic violence rose.
[00:03:33] And as I was reviewing this panel, we didn't have that many rural teachers, and so I sent who we had to my researchers, and my sister was invited for one of them. And she was so nervous, and she was like, "I don't know what I'm going to say, I don't want to say the wrong thing." And I told her, I said, don't worry, just tell the truth. That's all we want to know, just tell the truth. And so she was chosen.
Watching my sister's interview
[00:04:00] And it was like two weeks later, I was doing the notes for this research effort and I was going through all of the videos, and I got to watch hers. And it really changed things for me when I was watching her. Because what my sister said when she came up on the screen was, "I worry about my kids, not seeing them every day, not knowing how they are. We don't have a lot. It's hard, but you do the best you can with what we have."
[00:04:26] And at that moment, I saw her cry. Previously she had been on the Zoom screen, she was biting her nails, she was looking away. You could tell that it was important to her to talk about sending paper packets home to some students, or some students not being able to log on and having technological difficulties.
[00:04:45] But when I saw someone that I know break down like that, it hit me. If it wasn't for me working for this company, if it wasn't for me inviting her to participate in this interview, she wouldn't have been vulnerable and she wouldn't have said all of the things that she was saying. And while it was important, I didn't want this video to be used for anything other than what she had agreed to, which was the research.
[00:05:08] And so that's how I came to care more about data privacy and to care more about participants. Because they're not just participants. They're somebody's mom, somebody's grandma, somebody's sister, somebody's husband, you name it, they're somebody's somebody. And so, how can we protect them? I've got a couple of steps. So, first we have data privacy. Second, we have scavenger hunt. Third, we have write it down. Four, ask permission. And fifth, form the fellowship.
What is PII, and why it matters
[00:05:42] So let's talk data privacy. What do we need to know? The first thing we need to know is, I am not a data privacy professional. I'm also not a legal professional. So I want you to know that everything I say is speaking 100% from a research ops perspective and what I've learned as I went through this. I'll probably say this again.
[00:06:01] So what is PII? I'm sure you're already trying to read this, and I'm sure your eyes have already glazed over. So don't read it. Well, I mean, you can if you want to later, but I'm not going to have you. If I search the internet, can this person be identified by the information? That's the easiest way to think about it. So, if I search the internet, can this person be identified by the information? That's PII, as simple as it is.
[00:06:27] There are European data laws, European Union data privacy laws. So there's the 2016 GDPR, that's the gold standard. It protects EU citizens and people that reside in the EU. And then there's also a court decision that came out just three years ago where it invalidated Privacy Shield. So it said, I don't think that there's currently enough guidelines around the protection of our PII, of our privacy. And so there's now potentially going to be a new data privacy law called the transatlantic data privacy. So I've linked that in there if you want to read more about it.
[00:07:05] But you might be wondering why this is important to you and your company. Essentially, there are risks to your company if this gets violated. There are fines. You can risk lawsuits. This could harm your company's reputation, and it could damage the trust of your participants. And you're probably like, well, why would companies get fined? And essentially the way that companies can get fined is if employees are instructed to collect data illegally. So if you're like, should we really be collecting this, and they're like, sure, yeah — maybe you should dig in more and make sure there's a reason behind it. Because essentially you should have a reason for anything that you're collecting. Or maybe that you don't have the necessary security measures. So it's very easy to get someone's information.
[00:07:55] All right, so you're like, great, that's cool, I love that you're telling me about my company, but why is it important to you? So you can actually be held responsible if you're knowingly collecting, keeping, sharing personal data illegally, and it's not related to your job, and you don't have permission from your data controller, which is often your employer. And if you sell the personal data, that could be terribly bad. I mean, you would get a fine. You're not going to get jail time, but it is a criminal offense. So I think that it's important to at least talk about and see how we can put stuff into play to make it better.
Start your scavenger hunt, and write it down
[00:08:32] So let's talk about starting your scavenger hunt, but instead of gold, we are going to talk about PII. The five questions you need to know are who, what, where, when, and why. We've all learned this in grade school. We're going to bring it back again. And then once you know, write it down, because seriously, remembering is really hard. I've tried it. It doesn't work well. I've also got a basic template that I have shared with Rory and he'll share with you, and it kind of can run you through the different steps and make it a little easier for you to document it out.
[00:09:07] And then what you're going to be asking for, for the "what", is: what research task may involve PII? So this can be database, screener, scheduling, consent forms. I could read them all. Anything that you might be doing with research, anytime you're talking to participants, you could be collecting PII. There are two that I have starred and also made purple, called final reports and presentations, and research repository. They shouldn't contain PII. It's a joke. Don't do it. I just put it on there as a gotcha. So I'm putting it there to just keep saying, don't do it, don't do it, keep it out of there. Anywhere that everybody can see stuff, try to limit it as much as possible.
[00:09:43] And then who. So who's involved is normally your data processor, your data controller, who has access, and who is involved. I'm sure you're like, I don't know these words, I don't know what a data processor is, a data controller. It's a very easy way to think about it. Essentially, who your data processor is is just doing what you tell them to do. Who the data controller is is who is in charge of how your data is being used. So oftentimes we would be the data controller, because we will tell a tool — so let's say I have my database in Salesforce, I am telling Salesforce, here's what to do with that data.
[00:10:26] And often if you look at vendors, they'll say that they're compliant with GDPR, but then if you read in the fine print, it also says that they leave it up to customers to decide what to do with that data. So it's always good to look through the fine print, or look and see what they have there, to make sure that if you're held liable, you are making sure that what you tell them to do is compliant. And I always tell you to talk to your data privacy person and talk to your legal, because they know what is specific for your company, for your size, for your location. It varies all across the board.
[00:11:03] So going back to what: first name, last name, email address, employer, phone number, occupation, age range, any audio, screen or video recordings, these could all be examples of PII. Sometimes it depends on whether or not they're contained together. So remember before how I said, can you identify this person with this information? If you just have Joe at Pepsi, who is a customer service rep, let's say, that might not be PII, because you probably can't find that exact Joe that is a service rep at Pepsi. Let's say that you have Joe, the CEO at Pepsi. Well, now there's probably only one CEO, so you've limited it down to where you can figure out who it is very easily.
Where, when and why you collect it
[00:11:50] And then the next is where. So we have tools. Where are you storing PII? What tools might it be in? Have you been emailing back and forth about different people and possibly included PII in there? Have you stored it somewhere on a OneDrive or a SharePoint or anything like that? If so, you need to make sure that you keep track of what you're putting where, and when you're keeping it and when you're deleting it.
[00:12:16] So, know when you are collecting PII and why you're collecting PII. So, at what step of the process are you collecting it, and when are you taking it away? When are you deleting it or anonymizing it? And to anonymize it means that you take away everything that identifies that person. So instead of Joe Schmo, it might be participant one. Instead of "they work at Pepsi", it might be "they work at a refreshment company", or something like that, making it a little more generic.
[00:12:49] So we have an example here of how I kind of documented it out. So here's the PII in the first column. You can see the reason to collect it. So why would you need their first name? Because you're going to talk to the participant and you're going to probably communicate with them, and you don't want to just be calling them "hey, you". So that's why you would need that. Or maybe you're doing incentives, so then you would need an email address to contact the participant, and you might need an email address to send the incentive. And what is the occupation? So you might be looking at something specific to their occupation and that's why you need it, because it's necessary criteria for your studies.
[00:13:26] And then documenting out where it's stored. This is anywhere and everywhere it might be. And then explaining what you're going to do with it once you have it. So, are you going to anonymize it, which is taking out all the identifying pieces? Are you going to delete it, so it's gone? Or are you going to retain it for a certain amount of time? And you have to know that if you're retaining it, you can't retain it for ever. It can't be just, yeah, I'll get rid of that at some point in time. Normally you should reach out to your data privacy officer. They have a specific time that they've listed. If you're a smaller company and don't have a data privacy officer, I'm sure there's somebody that serves that purpose in your company.
[00:14:04] Also, with video recordings, it should be important to say that a video recording is always PII. There's not really a way you can anonymize it, because it's their face, it's their voice, that's something very specific to you. There are ways that you can blur things, change voices, but just know that if you're taking a video, it's normally PII.
Ask permission: consent and NDAs
[00:14:29] Also, ask permission. You can't just assume it's okay. You need to have something around consent and making sure that you tell them what you're doing with it. So for example, what is consent? There's all of this in GDPR, and it talks about being freely given and specific and informed and unambiguous. And I could go into this a lot more, but I only have 25 minutes, so I wanted to give you an easier way to think about it for right now.
[00:14:54] An informed consent document is in plain language. It's easy for the participants to understand, and it tells you, I'm collecting this information, and is it possible for us to do this? Can we record your video? Can we record your screen if you choose to share it?
[00:15:12] And then an NDA is a non-disclosure agreement, and this sometimes gets confused with an informed consent. You may have your participants sign something, but really when they sign an NDA they're saying, okay, don't share any of our secrets, this is something that's top secret, like the secret sauce information. Whereas informed consent is something that a participant can read, can understand — oh, we're doing a study on blah blah blah, and the information collected is blah blah blah — and can say, yes, I consent to that. So that is the difference between those two.
Form the fellowship
[00:15:43] And then let's talk forming the fellowship. Essentially, if you have ever watched Lord of the Rings, this is where the fellowship comes in. You might be familiar with the fellowship, you may not. You might be familiar with Lord of the Rings, or you could be like my parents, where I was telling them I have this great analogy and I'm talking them through all of the fellowship and how it relates to everything with data privacy, and they're like, "Yes, this is great, this is amazing," and I'm so excited about it. And then when I say, "So what did you think?" they were like, "It sounded good, you were enthusiastic, but I don't know what you were talking about," because they hadn't seen Lord of the Rings. So hopefully you stick with me. We'll see.
[00:16:24] So in Lord of the Rings, it discusses an all-powerful ring, with this one ring. Oh no, hold on a second, I might have to pause, because my dogs are going to be jerks. Sorry about that. There is a never-ending feud with the mailman, and he just comes to our house every time, and he's running late today. So, back to the PII, or back to the one ring.
[00:17:04] So with the one ring, if it's in the wrong hands, you could destroy everything. So the ring is PII, because you have to keep PII safe, and you have to keep it safe until it can be destroyed, because it can corrupt even the most pure-hearted. And so I always like to think of us as the hobbits.
[00:17:30] All right? So the people who do research are the hobbits. You are the pure-hearted ones, and the fellowship is essentially created to protect the one ring. So you are in charge of working with all of these people that are legal, that are data privacy, that are your project team, and anybody who's doing research or interacting with participants. You have to keep it safe on its journey through all of the research, through all of whatever you're doing, usability studies, you say it, you know it, until you can destroy it in Mount Doom, or delete it off of your SharePoint or wherever it might go. So this is essentially your fellowship, and that's how it relates to Lord of the Rings. PII, ring. Data privacy, maybe. Legal is — I don't know.
[00:18:19] And so essentially, just remember that you always need to keep it safe, and you're not alone in this. You don't have to be the people that know everything about everything. You actually have a lot of wonderful people that are the experts in their fields. That's why I say I'm just a research ops professional. I work with people who are in data privacy, I work with people who are in legal, because they know more about their specific field than I do and they can help inform me. And I promise that if you go and talk to them, they're going to be more than excited to talk with you about what they do and how you can make things compliant.
To sum it up
[00:18:56] So to sum it up, we've got data privacy and security. So this is your team, where they can conduct a privacy review, give you feedback, give you advice on any issues like how long should you keep this, when should it be anonymized. They can also set up different safeguards, so it might be stuff around controlling who has access to your information, or setting up auto-deletion.
[00:19:22] And then we have legal. So that's where it's ensuring that you have the proper documentation in place. This is normally where it comes to, like, if you're having them draft NDAs, or if they're drafting participation terms, if you have a program or something where you use it as a panel to get participants in. They can also review your informed consent documents to make sure it doesn't conflict with your NDAs or any other legal documents that they might sign, because it is essentially considered a legal document. So you want to make sure that they are saying the same thing.
[00:19:52] So to bring it back: we can ask permission, we can limit access, we can store it in a secure place, we can delete it when it's no longer needed or when a participant revokes permission. So remember how I said you can't keep it forever? Also, participants can say, you know what, I don't feel really great about that video that I did, or I don't want you to have that any more. And it's up to you to delete that when they ask, because they are in charge of their own information. And talk to your team about processes. Use that sheet that I gave you. Say, hey, what documents do we need, what templates do we need, what best practices should we have in here? And have that get implemented.
[00:20:29] And last of all, I'm going to re-emphasize that there is no one-size-fits-all approach. It's based on how much risk your company is willing to take. Each company is different. Each company has different regions, different laws, different places, different industries. It could be all over the board. And so I will always ask you to reach out to your professionals in your company, because they know what is right for you, they know what is right for your company. And then there's also some more — this is it for this presentation, but I do have some stuff in the appendix as well to help you around just who's European countries, what's adequate, what's not, just to give you more information. So that is it for my presentation.
Q&A
[00:21:13] Rory: Excellent, thank you very much. I thought that was a really good analogy with the Lord of the Rings for how you can kind of abuse it, and the temptation is there to abuse it.
[00:21:30] Kasey: It really is. You see stuff like that and, not that you want to do that, because you always have a really clear idea of what you want, but you're always like, there is so much that you could do that's terrible with it. So I always think the one ring is a really nice analogy.
[00:21:44] Rory: Great. So as we said at the start, if you have any questions, please do add them in on the side there if you're watching on uxdx.com or on whichever platform you're watching on, and I'll put those questions through to Kasey. But I've got a couple of different questions that I want to touch on. The first one I'll start with is, with that kind of security group, do you advocate — and there's two kind of ways that I've seen this work, there's the kind of the gate, that you have to go through them to get things done, or there's the audit approach where they tell you it and they might audit you at some point to make sure it's working. Do you have a preference for which way companies structure it, or is there a pro and con that you see of that?
[00:22:32] Kasey: A gate or an audit? Is there a pro or a con? They both sound like cons to me. No, I'm just kidding. It's great if it's already set up in there, but oftentimes whatever your circumstances are, whatever research you're setting up, they might not have thought about it in that specific way. So what I normally say is, when you're initially starting to think about these things and you fill out that sheet and you get all of your information there, that helps start the conversation. So then you just set up like a half hour, or however long it may be, and just say, "Hey, I'd like to run you through the different things that we're collecting and I'd like to start an informed consent document." So then you talk to legal and you say, "Hey, here's what we're doing and here's what I'd like to ask them if it's okay if we do." Because oftentimes you'll maybe not have an informed consent document, so you've just been collecting this. And it's really great to start bringing them into the conversation, because they can really change how you're looking at things and help guide you in a proper way.
[00:23:32] Rory: And I guess that some of the people out there might be watching from, I guess, smaller companies that don't have the security department or don't have the legal department. So what's the best steps you can do if you're kind of almost on your own doing this?
[00:23:50] Kasey: Well, there's somebody somewhere. Even if you have a team of two that is on your company, one of you is designated as the chief data privacy officer. There's somebody that has to always be assigned that, so somebody is at least assigning that. However, I will say there's a lot of great information out there. I'm actually creating an article right now about how to do an informed consent document. Once again, I'll say, if you have a legal person, it's great to have them review it. If you don't have a legal person, I would not take my advice as a legal professional. I would just use whatever I give you as a template and still have somebody look it over that is legally educated. Not me. Definitely not.
[00:24:33] Rory: I don't think you caveated that enough there.
[00:24:35] Kasey: I know. I really like to throw that in at the beginning, at the end, anytime there's a flow[?].
[00:24:42] Rory: One thing that I guess some companies have said is, there is a value in holding on to data, because maybe right now you don't know how to monetize that data, but that could become very valuable in the future. So how do you balance that kind of the potential of the data versus, I guess, the risk of the data?
[00:25:08] Kasey: That is a good question. That's one that comes up often, because you might work with somebody — like in my previous work experience I have met with PMs that say, "What should we be talking to them about? What should we be collecting?" And they're like, "Just ask them everything. Just ask them everything just in case we need that." And then you're saying, "Well, why would we ask them that? What is the thing that is driving this?" And they might not be able to tell you. They're like, "Just because we might need it someday."
[00:25:32] And really, it's not best practice, because if you have all of this information but you don't have a reason why — if, say, you were ever to get audited or have somebody look into your different processes, the first question they're going to ask you is why. Why do you have this? And if you say, well, that PM that was here like a year ago, he said just collect everything, they're not going to think that that's a great response.
[00:25:59] So I'll say that I know that that's a constant thing, but talk to your data privacy person, talk to legal, or whoever decides in your company, and see what their retention policy is. See how long they want to keep things. Sometimes it's a year, sometimes it's two years, sometimes it's six months. And then really think about too: if I collect this data, am I really going to be going back to it in a year, in two years, and will it still be relevant? Do I need to know that identifying information, or is it okay if I just know it's P1, or somebody from a soda company?
[00:26:32] Rory: Brilliant. Yeah. So hopefully people can get some, I guess, motivation to push back on those requests now.
[00:26:41] Kasey: Yeah.
[00:26:42] Rory: Excellent. So that brings us to time. But thank you very much, Kasey. I really enjoyed that, and I hope everybody out there did as well. So thank you for that.
