Data protection and research confidentiality
How we handle research participant data and client data. This is the page institutional clients read before they contract with us, and it deserves the detail it gets.
Participant data
Personal identifiers are separated from analysis datasets at the point of data entry and stored separately, with access limited to named team members on that study. Analysis datasets are pseudonymised. Re-identification keys are held separately again.
Storage, encryption and access
Every study’s protocol and contract specify where its data will be stored, on whose infrastructure and in which jurisdiction, before collection begins. We do not start fieldwork on a study whose data-handling arrangement has not been written down and agreed.
Our standing requirements are that identifiers are stored separately from analysis data; that devices used for collection and entry, and transfers between the field and the office, are encrypted; that access is granted person by person by the study’s principal investigator and recorded in the study file; and that a person’s access ends when their role on the study ends. The specific arrangement for your study is set out in its protocol and is available to you on request.
Retention and destruction
Retention periods are set in each study's protocol and contract, and follow whichever is longer: the funder's requirement or the condition of ethical approval. At the end of that period, data is securely destroyed and the destruction is recorded.
Client confidentiality
Client data and findings are confidential. We do not disclose a client's identity, data or results without written permission. We work under NDA where a client requires it, and we can sign before scoping.
Data ownership
By default the commissioning organization owns the data and the report. We ask permission — never assume it — to reference the work in our portfolio or to use anonymised data in subsequent research. Any secondary use requires a written agreement.
Sub-processors and field partners
Data collection runs through vetted field partners. Each is bound by a written agreement covering confidentiality, data handling and destruction, and each is named to the client before fieldwork begins. The current list of partners engaged on a study is available to that study’s client on request.
Breach notification
If participant or client data is lost, exposed, or accessed without authorisation, the study’s principal investigator and the Managing Director are informed immediately, and the affected client is informed within 72 hours of us becoming aware — with what we know at that point, rather than waiting for a finished account. Where the study holds ethical approval, the reviewing committee is notified on the same timescale. A written report follows once the cause is established, setting out what happened and what we have changed. We would rather tell you early and revise than tell you late and complete.
Cross-border transfer
Research data stays in Bangladesh unless a study requires otherwise. Where a study does involve transferring data out of the country — to a collaborating institution, for example — what is transferred, to whom, and under what safeguards is specified in the protocol and approved by the reviewing ethics committee before any data moves. Identifiable data is not transferred across borders without that approval and without participant consent that covers it.
For institutional clients
If your procurement process requires a data-processing agreement, a named sub-processor list, evidence of ethical approval, or a signed NDA before scoping, ask and we will provide them. We would rather answer these questions before a contract than during one.
Contact
Questions about this policy:
info@theideology.org
The Ideology, Flat 1B, House 50, Road 28, Gulshan 1, Dhaka 1212, Bangladesh
Last updated
22 September 2026. We date every version of this page and note here what changed.
