{"id":27774,"date":"2021-06-30T10:27:12","date_gmt":"2021-06-30T08:27:12","guid":{"rendered":"https:\/\/www.testingtime.com\/?p=27774"},"modified":"2021-12-21T11:43:08","modified_gmt":"2021-12-21T09:43:08","slug":"gdpr-guide-for-ux","status":"publish","type":"post","link":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/","title":{"rendered":"Everything UX researchers need to know about GDPR\u2014An ultimate guide"},"content":{"rendered":"<h3>Table of contents<\/h3>\n<p><a href=\"#1\">1. What is GDPR?<\/a><br \/>\n<a href=\"#2\">2. <span style=\"font-weight: 400;\">How do UX researchers leverage data processing?<\/span><\/a><br \/>\n<a href=\"#3\">3. <span style=\"font-weight: 400;\">When do UX researchers need to obtain consent?<\/span><\/a><br \/>\n<a href=\"#4\">4. <span style=\"font-weight: 400;\">How to write a data policy notice the right way?<\/span><\/a><br \/>\n<a href=\"#5\">5. <span style=\"font-weight: 400;\">How can you prevent users from demanding to erase their data?<\/span><\/a><br \/>\n<a href=\"#6\">6. <span style=\"font-weight: 400;\">How should UX researchers organise the data collection process?<\/span><\/a><br \/>\n<a href=\"#7\">7. <span style=\"font-weight: 400;\">What other rights do test users have?<\/span><\/a><br \/>\n<a href=\"#8\">8. <span style=\"font-weight: 400;\">How can UX researchers ensure facial recognition privacy?<\/span><\/a><br \/>\n<a href=\"#9\">9. <span style=\"font-weight: 400;\">Who can help UX researchers to ensure GDPR compliance? <\/span><\/a><\/p>\n<h2><a id=\"1\"><\/a><span style=\"font-weight: 400;\">1. What is GDPR?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">GDPR stands for the <\/span><a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">General Data Protection Regulation<\/span><\/a><span style=\"font-weight: 400;\">. It\u2019s an EU regulation designed to <\/span><span style=\"font-weight: 400;\">harmonise data privacy laws<\/span><span style=\"font-weight: 400;\"> across Europe. Its main function is to help users gain control over the way companies use their personal data.\u00a0The European Data Protection Regulation is applicable as of May 25th, 2018.<\/span><b><\/b><\/p>\n<h3><a id=\"0\"><\/a><span style=\"font-weight: 400;\">1.1 What are the key principles of GDPR?<\/span><b><\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The GDPR sets out seven key principles:<\/span><\/p>\n<p><b>1. Lawfulness, fairness, and transparency<\/b><span style=\"font-weight: 400;\"><br \/>\nYou must inform users that you will collect their data and explain why you will do it.<\/span><\/p>\n<p><b>2. Purpose limitation<\/b><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">You can\u2019t collect data just for the sake of it. You should do it for a specific purpose (e.g., improving customer service, enhancing user experience, running a marketing campaign).<\/span><\/p>\n<p><b>3. Data minimisation<br \/>\n<\/b><span style=\"font-weight: 400;\">You shouldn\u2019t collect any data that doesn\u2019t serve the purpose of data collection. Let\u2019s say you want to use users\u2019 first names to personalise your marketing emails. You can ask users to provide their first names, but you are not allowed to ask them to provide their family names.\u00a0<\/span><\/p>\n<p><b>4. Accuracy<br \/>\n<\/b><span style=\"font-weight: 400;\">You should delete any inaccurate data from your database.<\/span><\/p>\n<p><b>5. Storage limitation<\/b><span style=\"font-weight: 400;\"><br \/>\nYou are not allowed to store user data longer than it\u2019s actually needed.\u00a0<\/span><\/p>\n<p><b>6. Integrity and confidentiality<br \/>\n<\/b><span style=\"font-weight: 400;\">You can\u2019t collect and process user data if you are not able to secure these processes.<\/span><\/p>\n<p><b>7. Accountability<br \/>\n<\/b><span style=\"font-weight: 400;\">You need to adopt and implement data protection policies and put written contracts in place with organisations that process personal data on your behalf.<\/span><\/p>\n<h3><a id=\"0\"><\/a><span style=\"font-weight: 400;\">1.2 What happens to the companies that do not comply with GDPR?<\/span><b><\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Failure to comply with these seven principles leads to fines of \u20ac 20 million, or 4% of the company\u2019s worldwide annual turnover, whichever is higher.\u00a0<\/span><span style=\"font-weight: 400;\">Do you doubt that these fines are a real thing? Check the list of the biggest GDPR fines and the reasons for these fines:<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Google<\/strong> \u2013 \u20ac 50 million. The tech giant didn\u2019t provide sufficient information to users in consent policies.<br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>H&amp;M<\/strong> \u2013 \u20ac 35 million. The company processed sensitive data about its employees\u2019 health and beliefs without having a specific purpose.<br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>TIM<\/strong> (Telecom Italia) \u2013 \u20ac 27.8 million. The company was penalised for bombarding millions of individuals with promotional calls and unsolicited communications.<br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>British Airways<\/strong> \u2013 \u20ac 22 million. Hackers attacked user databases and got their hands on login details, payment card information, and other sensitive data. The breach affected 400,000 customers.<br \/>\n<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Marriott<\/strong> \u2013 \u20ac 20.4 million. The hotel chain\u2019s guest reservation database wasn\u2019t secure enough. Eighty-three million guest records (30 million EU residents) were exposed after the database was compromised.<\/span><\/p>\n<h3><a id=\"0\"><\/a><span style=\"font-weight: 400;\">1.3 How does GDPR define the term \u2018personal data\u2018?<\/span><b><\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Probably one of the most confusing parts of GDPR is a vague description of the term \u2018personal data\u2018. GDPR defines personal data as \u2018any piece of information that relates to an identifiable person\u2018. No wonder that many UX researchers don\u2019t understand what kind of information they can and can\u2019t collect without a user\u2019s consent.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So what types of data does GDPR apply to?<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Name<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phone number<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An identification number<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Location data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet protocol (IP) addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cookie identifiers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Frequency Identification (RFID) tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser type and version<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Operating system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Referral source<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Length of visit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Page views\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Website navigation paths<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Type of software<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Users\u2019 digital fingerprint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Face images and videos<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Medical history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Criminal records<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bank statements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Payment data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credit card data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employment evaluation<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This list can go further. Basically, any textual, video, audio, numerical, graphical, and photographic data\u00a0that somehow relates to the users should be considered as personal data.<\/span><\/p>\n<h2><a id=\"2\"><\/a><span style=\"font-weight: 400;\">2. How do UX researchers leverage data processing?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Some UX researchers are not fully aware of how often they \u2018process\u2018 user data. Data processing occurs every time you save the user\u2019s data to a spreadsheet, send a thank-you email to a test user, or share the test result report with your client. The more often you process sensitive data, the higher the chances of a data breach or another data-related issue.<\/span><b><\/b><\/p>\n<h2><a id=\"3\"><\/a><span style=\"font-weight: 400;\">3. When do UX researchers need to obtain consent?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">UX researchers can\u2019t start collecting any personal data before they get the declaration of consent. There are no exceptions to this rule.\u00a0<\/span><span style=\"font-weight: 400;\">If you have already collected some data and now need to collect some missing personal data, they need to obtain an additional declaration of consent from the test user.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Let\u2019s say you\u2019ve run a test with 100 participants. You know the names and ages of these users. Now you want to extend your study and get to know the gender of your participants. You should create an additional consent form and ask test users to sign it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you are going to <\/span><a href=\"https:\/\/www.testingtime.com\/en\/blog\/legal-issues-in-remote-testing\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">record or observe test users<\/span><\/a><span style=\"font-weight: 400;\">, you should specify that in informed consent. You should explain who will watch the record and for what purpose. Also, you should mention whether test users will be observed in real time.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You should be aware that if you ignore this rule, the consequences will be dramatic. If you fail to comply with GDPR, you will likely be fined.<\/span><b><\/b><\/p>\n<h3><a id=\"0\"><\/a><span style=\"font-weight: 400;\">3.1 TestingTime\u2019s feature: document to be signed<\/span><b><\/b><\/h3>\n<p><span style=\"font-weight: 400;\">With TestingTime you can have documents signed by your test users before the study. Let\u2019s say, a non-disclosure agreement, or a consent to record the test. You can do this very easily and completely digitally through their <\/span><a href=\"https:\/\/app.testingtime.com\/web\/customer\/order\/additional\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">online order form<\/span><\/a><span style=\"font-weight: 400;\">. Simply activate the option \u201cDocument to be signed\u201d in the \u201cAdd-ons\u201d section. This will allow you to upload a document of your choice.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">TestingTime will subsequently integrate the document to be signed directly into their recruitment process. Every document will be legally signed, including the date, the full name of the test user and their electronic signature. You will have access to all signed documents in your order overview before commencing the test.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b><\/b><\/p>\n<div id=\"attachment_27932\" style=\"width: 1524px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-27932\" class=\"size-full wp-image-27932\" src=\"https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN.png\" alt=\"TestingTime NDA \" width=\"1514\" height=\"976\" srcset=\"https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN.png 1514w, https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN-328x211.png 328w, https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN-202x130.png 202w, https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN-768x495.png 768w, https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN-1024x660.png 1024w, https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/TestingTime-NDA-neutral-EN-480x309.png 480w\" sizes=\"auto, (max-width: 1514px) 100vw, 1514px\" \/><p id=\"caption-attachment-27932\" class=\"wp-caption-text\">Source: <a href=\"https:\/\/app.testingtime.com\/web\/customer\/order\/additional\" target=\"_blank\" rel=\"noopener\">TestingTime<\/a><\/p><\/div>\n<p>A GDPR-compliant template for an NDA can be found\u00a0<a href=\"https:\/\/www.grekodom.com\/article\/nda-gdpr-en\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>. It is advisable to clarify with your internal or an external legal team what to do in case of doubt.<\/p>\n<h3><a id=\"0\"><\/a><span style=\"font-weight: 400;\">3.2 When is consent valid?<\/span><b><\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The trickiest part of GDPR compliance is that UX researchers should not only <\/span><i><span style=\"font-weight: 400;\">obtain consent <\/span><\/i><span style=\"font-weight: 400;\">and also make sure that it\u2019s <\/span><i><span style=\"font-weight: 400;\">valid<\/span><\/i><span style=\"font-weight: 400;\">. Here is a list of conditions that proves the validity of the test user consent:<\/span><\/p>\n<p>The consent<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">is freely given. You are not allowed to force users to consent.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">is specific and designed for a particular purpose.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">provides test users with sufficient information for decision-making.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">is free from any ambiguous statements.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">is an <\/span><i><span style=\"font-weight: 400;\">act<\/span><\/i><span style=\"font-weight: 400;\">. Users need not just read the information, but check the box and click the \u2018submit\u2018 or \u2018agree\u2018 button.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">is distinguishable from other matters.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">request is written in clear and plain language.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">isn\u2019t presented as a precondition of a service<\/span><b><b><br \/>\n<\/b><\/b><\/li>\n<\/ul>\n<h2><a id=\"4\"><\/a><span style=\"font-weight: 400;\">4. How to write a data policy notice the right way?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Writing a data policy notice is the first step to GDPR compliance. Here is a list of rules you should follow to create a winning data policy notice.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Include the name of your organisation and the names of third parties that will have access to personal data.<\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Be clear about intention. Test users should have a clear understanding of what specific data will be collected and for what purpose. If you are going to <a href=\"https:\/\/www.testingtime.com\/en\/blog\/legal-issues-in-remote-testing\/\" target=\"_blank\" rel=\"noopener\">record video or audio<\/a> of the testing process, you should inform users upfront. If you don\u2019t do it, you will put your UX research at risk.<\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remember that the vast majority of European users are not native English speakers. You should write everything in plain language and avoid using words that your target audience may not understand. Do you need help with writing texts for a global audience? If so, you can <\/span><a href=\"https:\/\/www.essaysupply.com\/website-content-writing\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">order website content writing<\/span><\/a><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> and ask experts to write a data policy notice on your behalf.<\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Draw users\u2019 attention to the fact that they have the right to object to processing their data and demand to erase it from the database without undue delay.<\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Don\u2019t try to manipulate users\u2019 decisions. Instead, provide them with all necessary data and let them decide whether they should share their personal data.<\/span><\/li>\n<\/ul>\n<h2><a id=\"2\"><\/a><span style=\"font-weight: 400;\">5. How can you prevent users from demanding to erase their data?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">According to GDPR, you should write in your privacy policy that people can withdraw their consent at any time. And that\u2019s another point where UX researchers can face a challenge.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If test users use their right to withdraw the consent, researchers will lose part of the collected data. Naturally, it may negatively affect the results of the testing.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What can UX researchers do to protect the results of their work while maintaining GDPR compliance? They can add such a clause to their privacy policy:<\/span><\/p>\n<blockquote><p><i><span style=\"font-weight: 400;\">If our <\/span><\/i><b><i>X organisation<\/i><\/b><i><span style=\"font-weight: 400;\"> bases the processing of your personal data on a balancing of interests, you can object to the processing. This is the case in particular if the processing is not necessary for the purpose of fulfilling a contract with you, which is set out by <\/span><\/i><b><i>X\u00a0<\/i><\/b><i><span style=\"font-weight: 400;\"><b>organisation<\/b>\u00a0in each case in the description of functions below. <\/span><\/i><i><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/i><i><span style=\"font-weight: 400;\">When withdrawing your consent in this way, personal data in the way it does. If the objection is justified, <\/span><\/i><b><i>X organisation<\/i><\/b><i><span style=\"font-weight: 400;\"> will examine the matter and either cease or adapt the data processing or present you with compelling and legitimate reasons for why <\/span><\/i><b><i>X organisation<\/i><\/b><i><span style=\"font-weight: 400;\"> will continue to process it.<\/span><\/i><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">This information will make test users understand that they can\u2019t withdraw their consent for no reason. So people (those who actually read the privacy policy and have concerns regarding their personal data security) will think twice before declaring consent. If you write your policy this way, it will significantly decrease the number of test users who will withdraw their data.<\/span><\/p>\n<h2><a id=\"6\"><\/a><span style=\"font-weight: 400;\">6. How should UX researchers organise the data collection process?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">One of the biggest mistakes UX researchers make is that they try to collect as much data as possible. They think that even though they don\u2019t need this data right now, they will probably use it later. They ask test users to provide the information they don\u2019t need, and that goes against the GDPR principles.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The rule of thumb for GDPR compliance is to collect only that data that you actually need to make a specific decision or improve UX design. You should understand that if you need more information later, you will be able to obtain it.<\/span><\/p>\n<h2><a id=\"7\"><\/a><span style=\"font-weight: 400;\">7. What other rights do test users have?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Test users have a right to ask you to provide the data you have about them. So you should store the data adequately and be ready to give users access to their data upon their request. Also, you should be prepared to answer users\u2019 questions about how their personal information is being used.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Besides, you should correct information about test users if they ask you to. You should do it to comply with the user\u2019s rights and to improve your database accuracy.\u00a0<\/span><b><\/b><\/p>\n<h2><a id=\"8\"><\/a><span style=\"font-weight: 400;\">8. How can UX researchers ensure facial recognition privacy?\u00a0<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Face images and videos are considered personal data. It means that if UX researchers want to video-record the user tests and share these videos with customers, they should comply with GDPR.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The thing is that face images are particularly prone to misuse. Anyone who gets access to the images can gather sensitive personal data and hack into accounts. If you decide to <\/span><a href=\"https:\/\/www.deidentification.co\/wp-content\/uploads\/2018\/09\/White-Paper-GDPR-and-D-ID.pdf\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">store face images<\/span><\/a><span style=\"font-weight: 400;\">, you should find a way to eliminate the risks of misuse, unauthorised tracking, and identity theft.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What anonymisation methods do companies use?<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Face blurring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pixelation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Face swapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterioration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Quality reduction<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">All these anonymisation techniques have one significant drawback \u2013 they dramatically affect the visual similarity of the face image. If UX researchers don\u2019t want to sacrifice image quality, they should use software similar to D-ID\u2122, which protects face images while preserving visual similarity.<\/span><\/p>\n<h2><a id=\"9\"><\/a><span style=\"font-weight: 400;\">9. Who can help UX researchers to ensure GDPR compliance?\u00a0<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Basically, UX researchers are not the only people in the organisations responsible for data collection and processing. The company needs to comply with GDPR in Europe at the highest management level and throughout the organisation. Managers of the company should use appropriate technical and organisational measures:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adopt and implement data protection policies on a corporate level<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Put written contracts in place with third-party organisations that process personal data on the company\u2019s behalf<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maintain documentation of all data processing activities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implement advanced security measures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Record and report personal data breaches<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review and update accountability measures on a regular basis.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">GDPR is a big topic, and it may take you some time to research it. I hope this article will help you learn the basics, so you can start working on your UX research projects.\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Table of contents 1. What is GDPR? 2. How do UX researchers leverage data processing? 3. When do UX researchers need to obtain consent? 4. How to write a data policy notice the right way? 5. How can you prevent users from demanding to erase their data? 6. How should UX researchers organise the data [&hellip;]<\/p>\n","protected":false},"author":82,"featured_media":27915,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"footnotes":""},"categories":[8990,8989],"tags":[],"class_list":["post-27774","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-research-methods","category-research-strategy"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.5 (Yoast SEO v20.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Everything UX researchers need to know about GDPR\u2014An ultimate guide - TestingTime<\/title>\n<meta name=\"description\" content=\"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Everything UX researchers need to know about GDPR\u2014An ultimate guide\" \/>\n<meta property=\"og:description\" content=\"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\" \/>\n<meta property=\"og:site_name\" content=\"TestingTime\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/testingtime\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-30T08:27:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-12-21T09:43:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/Header-GDPR-Lady@2x-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1488\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jessica Fender\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@testingtime\" \/>\n<meta name=\"twitter:site\" content=\"@testingtime\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jessica Fender\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\"},\"author\":{\"name\":\"Jessica Fender\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/6802123c4c1ea7b282c7c263ca63f476\"},\"headline\":\"Everything UX researchers need to know about GDPR\u2014An ultimate guide\",\"datePublished\":\"2021-06-30T08:27:12+00:00\",\"dateModified\":\"2021-12-21T09:43:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\"},\"wordCount\":2164,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/#organization\"},\"articleSection\":[\"Research methods\",\"Research strategy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\",\"url\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\",\"name\":\"Everything UX researchers need to know about GDPR\u2014An ultimate guide - TestingTime\",\"isPartOf\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/#website\"},\"datePublished\":\"2021-06-30T08:27:12+00:00\",\"dateModified\":\"2021-12-21T09:43:08+00:00\",\"description\":\"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"TestingTime\",\"item\":\"https:\/\/www.testingtime.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Everything UX researchers need to know about GDPR\u2014An ultimate guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#website\",\"url\":\"https:\/\/www.testingtime.com\/en\/\",\"name\":\"TestingTime\",\"description\":\"Wir rekrutieren Testpersonen\",\"publisher\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testingtime.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#organization\",\"name\":\"TestingTime\",\"url\":\"https:\/\/www.testingtime.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testingtime.com\/app\/uploads\/2017\/04\/logo.svg\",\"contentUrl\":\"https:\/\/www.testingtime.com\/app\/uploads\/2017\/04\/logo.svg\",\"width\":1,\"height\":1,\"caption\":\"TestingTime\"},\"image\":{\"@id\":\"https:\/\/www.testingtime.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/testingtime\",\"https:\/\/twitter.com\/testingtime\",\"https:\/\/www.instagram.com\/testingtime\/\",\"https:\/\/www.linkedin.com\/company-beta\/9231506\/\",\"https:\/\/www.youtube.com\/channel\/UCpnMUgCz5FiiCUXU-U8ub1w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/6802123c4c1ea7b282c7c263ca63f476\",\"name\":\"Jessica Fender\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.testingtime.com\/app\/uploads\/2021\/03\/JessicaFender-130x130.jpg\",\"contentUrl\":\"https:\/\/www.testingtime.com\/app\/uploads\/2021\/03\/JessicaFender-130x130.jpg\",\"caption\":\"Jessica Fender\"},\"url\":\"https:\/\/www.testingtime.com\/en\/blog\/author\/jessica-fender\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Everything UX researchers need to know about GDPR\u2014An ultimate guide - TestingTime","description":"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/","og_locale":"en_US","og_type":"article","og_title":"Everything UX researchers need to know about GDPR\u2014An ultimate guide","og_description":"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.","og_url":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/","og_site_name":"TestingTime","article_publisher":"https:\/\/www.facebook.com\/testingtime","article_published_time":"2021-06-30T08:27:12+00:00","article_modified_time":"2021-12-21T09:43:08+00:00","og_image":[{"width":1488,"height":800,"url":"https:\/\/www.testingtime.com\/app\/uploads\/2021\/06\/Header-GDPR-Lady@2x-1.png","type":"image\/png"}],"author":"Jessica Fender","twitter_card":"summary_large_image","twitter_creator":"@testingtime","twitter_site":"@testingtime","twitter_misc":{"Written by":"Jessica Fender","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#article","isPartOf":{"@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/"},"author":{"name":"Jessica Fender","@id":"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/6802123c4c1ea7b282c7c263ca63f476"},"headline":"Everything UX researchers need to know about GDPR\u2014An ultimate guide","datePublished":"2021-06-30T08:27:12+00:00","dateModified":"2021-12-21T09:43:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/"},"wordCount":2164,"commentCount":0,"publisher":{"@id":"https:\/\/www.testingtime.com\/en\/#organization"},"articleSection":["Research methods","Research strategy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/","url":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/","name":"Everything UX researchers need to know about GDPR\u2014An ultimate guide - TestingTime","isPartOf":{"@id":"https:\/\/www.testingtime.com\/en\/#website"},"datePublished":"2021-06-30T08:27:12+00:00","dateModified":"2021-12-21T09:43:08+00:00","description":"This guide gives you an overview about each and every aspect of GDPR that may affect the work of UX researchers.","breadcrumb":{"@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testingtime.com\/en\/blog\/gdpr-guide-for-ux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"TestingTime","item":"https:\/\/www.testingtime.com\/en\/"},{"@type":"ListItem","position":2,"name":"Everything UX researchers need to know about GDPR\u2014An ultimate guide"}]},{"@type":"WebSite","@id":"https:\/\/www.testingtime.com\/en\/#website","url":"https:\/\/www.testingtime.com\/en\/","name":"TestingTime","description":"Wir rekrutieren Testpersonen","publisher":{"@id":"https:\/\/www.testingtime.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testingtime.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testingtime.com\/en\/#organization","name":"TestingTime","url":"https:\/\/www.testingtime.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testingtime.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.testingtime.com\/app\/uploads\/2017\/04\/logo.svg","contentUrl":"https:\/\/www.testingtime.com\/app\/uploads\/2017\/04\/logo.svg","width":1,"height":1,"caption":"TestingTime"},"image":{"@id":"https:\/\/www.testingtime.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/testingtime","https:\/\/twitter.com\/testingtime","https:\/\/www.instagram.com\/testingtime\/","https:\/\/www.linkedin.com\/company-beta\/9231506\/","https:\/\/www.youtube.com\/channel\/UCpnMUgCz5FiiCUXU-U8ub1w"]},{"@type":"Person","@id":"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/6802123c4c1ea7b282c7c263ca63f476","name":"Jessica Fender","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testingtime.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/www.testingtime.com\/app\/uploads\/2021\/03\/JessicaFender-130x130.jpg","contentUrl":"https:\/\/www.testingtime.com\/app\/uploads\/2021\/03\/JessicaFender-130x130.jpg","caption":"Jessica Fender"},"url":"https:\/\/www.testingtime.com\/en\/blog\/author\/jessica-fender\/"}]}},"_links":{"self":[{"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/posts\/27774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/users\/82"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/comments?post=27774"}],"version-history":[{"count":25,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/posts\/27774\/revisions"}],"predecessor-version":[{"id":28221,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/posts\/27774\/revisions\/28221"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/media\/27915"}],"wp:attachment":[{"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/media?parent=27774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/categories?post=27774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testingtime.com\/en\/wp-json\/wp\/v2\/tags?post=27774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}