Privacy impact assessment for collecting information from people who use Aotearoa Data Explorer.
Download the document below, or read the recommendations and summary online.
Stats NZ's privacy team's recommendations
We recommend that:
- you continue to work with the Stats NZ Security team on the C&A to enable it to be completed before go-live
- you contact Technology Service Outputs to discuss a process for removing inactive users from Azure B2C. For example, inactive users are removed every three or six months
- if the data of the 195 best test users is not migrated, you need to delete it from Salesforce once it is no longer required for testing.
Summary
With the deployment of the new data tool Aotearoa Data Explorer (ADE), there are some additional features that require a privacy impact assessment. These additional features are being produced by the 'Registration and Analytics' stream of work, and include all cases where data is collected from customers using the data tool.
We intend to collect information from customers in two main ways - registration and analytics.
Registration
- API customer registration
Subscription
- Optional subscription for all customers using ADE
Analytics
- Through a customer segmentation survey
- Analytics of customers using the data tool
We will be collecting analytics about all customers who come to ADE or who use the API Portal. This will happen through their participation in the customer segmentation survey and through information collected from Google Analytics. The customer segmentation survey will have a "maybe later" button that will enable customers to exit the survey without completing it. The next time the same user visits ADE they will be presented with the survey again.
We will require registration from all customers who want to use our API. This will involve collecting some mandatory fields and the optional collection of other fields. These are detailed later in the report.
For customers who just want to use the data tool and are not planning to use the API, subscription will be optional. This means they will not have to sign in or provide log in details, but will just be able to enter their email address. They will receive notifications/emails for releases. We are unsure how many individuals or businesses will choose to sign up for further updates via this method.
The API Portal will have a link in ADE. When customers navigate to this page they will be presented with the option to either sign up or sign in.
ISBN 978-1-991307-03-3