Summary

As a user researcher at DfE, you must handle all participant data gathered during user research securely, legally and ethically.

WarningYou are breaking the law if you do not meet this standard.

Categories

The categories applicable to this standard are:

User-Centred Design and Accessibility
  • User Research

Purpose

As a user researcher, you will collect lots of data from and about your research participants, much of which is 'personally identifying'.

This could be captured in video or audio recordings, or notes and transcripts.

As user researchers, it is our responsibility to handle this data in a way that:

  • meets UK GDPR law and the Department's data policies and processes
  • is ethical, treating our users safely and respectfully.

Why this is important

If we fail to correctly manage personal data gathered in user research, this presents risks to our research participants, to the Department, and to ourselves:

  • we could be breaking UK GDPR law, opening up the Department to legal challenges, fines, and negative publicity. Handling personal data incorrectly could be a serious disciplinary offence
  • if people don't understand what we are using their data for, we are not treating them ethically or with respect
  • if a person's personal data is accessed or used in a way that it shouldn't be, this could put the person at risk

How to meet this standard

To ensure you are meeting this standard you must complete the following checklist. If you select yes for all questions, you have met the DfE standard. If you select no to anything or you're unclear, seek the advice of a senior or lead UR.

Read this related guidance

Managing participants' personal data in user research in DfE - full guidance Gaining informed consent

You must:

If you are building a panel or other large list of people, you must:

  • have a record of permission to do this from your lead user researcher or the head of user research

If you are sharing any lists of people with other user researchers or teams, you must:

  • have a record of appropriate consent from every person in the list

Download this checklist as a spreadsheet (DfE Intranet)

Templates and tools to help you meet this standard

Using these templates and tools will help you meet this standard. (Links for DfE employees/contractors only)

Where to get advice

If you need advice on meeting this standard, you should contact:

Discuss this standard

This user research standard has been formally approved and adopted as a DfE Digital, Data, Technology standard. It will be iterated and improved over time, so please give us any feedback and suggestions.

You can do this in the #developing-user-research-standards channel in DfE Slack (opens in a new tab).

Declaring conformance with this standard

Conformance with the standard must be recorded every 12 months.

Owner and contacts

Standard owner
Tom Adams
Head of Profession - UR