Learn what insights you can share internally and potentially externally that are compliant with the General Data Protection Regulation (GDPR). Read more about UserTesting's GDPR notice. |
This article applies to: UserTesting
On this page:
- What can I share internally?
- What can I share externally? Can I share a clip as part of a marketing campaign?
- What can’t I share?
- Who can I share insights with?
- What do participants agree to when being tested?
- What happens if a participant accidentally shares PII in a recording?
- Can a participant ask for a video to be deleted?
- What happens if I get a GDPR request related to UserTesting videos?
What can I share internally?
You can share any insights with your internal teams; however, it is critical that such content refrains from containing prohibited contributor PII. Note that participants are not expected to share PII. Sensitive PII can be collected and shared with the participant's permission; depending on your internal policies and applicable data laws, you may want to follow these guidelines for concealment. Protected Health Information (PHI) can be shared internally but only if your organization has a signed BAA with UserTesting.
What can I share externally? Can I share a clip as part of a marketing campaign?
You can share sensitive PII for business purposes with the participant's consent. You may choose to follow these guidelines for concealment. If you have a BAA signed with UserTesting, PHI should only be shared with individuals working on projects related to the topics covered in the test; it should not be shared publicly. Participants are informed that their videos may be used for public display, as outlined in this code of conduct.
What can’t I share?
You should not capture or share any video containing prohibited participant PII. View our best practices article for a list of prohibited PII to avoid collecting. Note that categories of PII data vary by jurisdiction. Please review our Data Processing Agreement, Content Policy, and Privacy Policy for more information.
Who can I share insights with?
You can share insights with any of your teams and for any business purposes.
What do participants agree to when being tested?
Participants agree to our terms of service, which tell them that the videos they are in will be used by UserTesting customers. They give additional consent related to the capture of their face in Live Conversations and in face recordings associated with unmoderated tests. Participants also understand that they are not supposed to share PII, but they can consent to share Protected Health Information (PHI).
What happens if a participant accidentally shares PII in a recording?
If a participant accidentally shares prohibited PII (for example, the participant accidentally exposes their credit card number in a web form), or they share PII without knowing, you can reach out to Support to remove the video. Do not share videos or clips that include that information.
Can a participant ask for a video to be deleted?
Once a participant has consented to be recorded, they cannot ask for the video to be deleted or not used. If a participant asks to be removed from UserTesting, we delete their PII from our records, but we do not delete any videos they may have been in.
What happens if I get a GDPR request related to UserTesting videos?
UserTesting leaves it up to the customer to decide if they want to act on the notice. We will delete any videos upon request by the customer.
Related Content
|
|
Want to learn more? Check out these Knowledge Base articles... |
Interested in growing your skills? Check out our University courses... |
|
|
Need hands-on training?
|
Can't find your answer?
|