Home · Data protection

Data protection and research confidentiality

How we handle research participant data and client data. This is the page institutional clients read before they contract with us, and it deserves the detail it gets.

Participant data

Personal identifiers are separated from analysis datasets at the point of data entry and stored separately, with access limited to named team members on that study. Analysis datasets are pseudonymised. Re-identification keys are held separately again.

Storage, encryption and access

Every study’s protocol and contract specify where its data will be stored, on whose infrastructure and in which jurisdiction, before collection begins. We do not start fieldwork on a study whose data-handling arrangement has not been written down and agreed.

Our standing requirements are that identifiers are stored separately from analysis data; that devices used for collection and entry, and transfers between the field and the office, are encrypted; that access is granted person by person by the study’s principal investigator and recorded in the study file; and that a person’s access ends when their role on the study ends. The specific arrangement for your study is set out in its protocol and is available to you on request.

Retention and destruction

Retention periods are set in each study's protocol and contract, and follow whichever is longer: the funder's requirement or the condition of ethical approval. At the end of that period, data is securely destroyed and the destruction is recorded.

Client confidentiality

Client data and findings are confidential. We do not disclose a client's identity, data or results without written permission. We work under NDA where a client requires it, and we can sign before scoping.

Data ownership

By default the commissioning organization owns the data and the report. We ask permission — never assume it — to reference the work in our portfolio or to use anonymised data in subsequent research. Any secondary use requires a written agreement.

Sub-processors and field partners

Data collection runs through vetted field partners. Each is bound by a written agreement covering confidentiality, data handling and destruction, and each is named to the client before fieldwork begins. The current list of partners engaged on a study is available to that study’s client on request.

Breach notification

If participant or client data is lost, exposed, or accessed without authorisation, the study’s principal investigator and the Managing Director are informed immediately, and the affected client is informed within 72 hours of us becoming aware — with what we know at that point, rather than waiting for a finished account. Where the study holds ethical approval, the reviewing committee is notified on the same timescale. A written report follows once the cause is established, setting out what happened and what we have changed. We would rather tell you early and revise than tell you late and complete.

Cross-border transfer

Research data stays in Bangladesh unless a study requires otherwise. Where a study does involve transferring data out of the country — to a collaborating institution, for example — what is transferred, to whom, and under what safeguards is specified in the protocol and approved by the reviewing ethics committee before any data moves. Identifiable data is not transferred across borders without that approval and without participant consent that covers it.

For institutional clients

If your procurement process requires a data-processing agreement, a named sub-processor list, evidence of ethical approval, or a signed NDA before scoping, ask and we will provide them. We would rather answer these questions before a contract than during one.

Request our data-protection documents →

Contact

Questions about this policy:
info@theideology.org

The Ideology, Flat 1B, House 50, Road 28, Gulshan 1, Dhaka 1212, Bangladesh

Last updated

22 September 2026. We date every version of this page and note here what changed.

Scroll to Top