Privacy and security

In summary

  • Who sees my answers? The research work always takes place in a research database that contains no directly identifiable information such as names or personal ID numbers, only encrypted personal identifiers.
  • Can the data be traced back to me? An encryption key exists, but it is kept separately from the data by the University of Iceland’s IT Service. It can be used to convert encrypted personal identifiers into personal ID numbers. It is only used when necessary, for example to activate a pass, to make a payment to you or to send you your own feedback.
  • What can I do? You can contact us at any time and ask that your data not be used further. Contact details are at the bottom of this page.

The study is carried out in accordance with Act No. 90/2018 on Data Protection and the Processing of Personal Data. You can read the study’s informed consent in full before you begin.

Data security

Handling of personal data

All information about participants and all data from the study are stored pseudonymously, using encrypted personal identifiers, in a research database. Analysis always takes place in that database, which contains no directly identifiable information such as names or personal ID numbers. The encryption key is stored separately from the data and securely by the University of Iceland’s IT Service, and it is only used for the purposes described below. Researchers do not have access to the key. No personally identifiable information appears in published results. All data are treated as confidential.

Linking with usage data

Information from the study will be linked to databases on the usage of the services that participants purchase. Since usage data are stored on personal ID numbers, linking requires the identifiers in the research data to be temporarily decrypted while the linking takes place. The strictest security is maintained throughout that process.

Other possible data linkage

In the future, we may seek to link your pseudonymized responses to other records for research purposes, for example educational, tax or health records, Icelandic genetic or genealogical data, or surveys. Any such linkage will only be carried out where there is a lawful basis for it and after obtaining the approvals required under applicable law. Linkages involving particularly sensitive information, such as genetic information, require the approval of the National Bioethics Committee before they take place. If the study in question falls under the Act on Scientific Research in the Health Sector No. 44/2014, the approval of the National Bioethics Committee or another competent health-research ethics committee will be obtained before the linkage takes place. Carrying out such a linkage requires the identifiers to be temporarily decrypted while the linking takes place.

You will generally not be contacted again to obtain consent for such linkages, but you can withdraw your authorization for future linkage at any time by contacting the research team.

Information needed to create the pass

If a purchase takes place, the information necessary to create the pass (such as personal ID number, name, email address, home address, phone number and gender) will be provided to the relevant collaborator.

Information provided to participants

At the end of their own participation, participants can choose to receive information about their own results regarding behavior. If a participant chooses to receive such information, their identifier must be temporarily decrypted so that the results can be sent.

Access and international data sharing

To promote scientific transparency and reproducibility, pseudonymized data from the study will be made available to qualified researchers worldwide through a controlled-access repository. Researchers affiliated with recognized research institutions can apply for access. This means that your pseudonymized data may be transferred outside the European Economic Area (EEA), including to countries that may not provide the same level of data protection as Iceland or the European Union. Any such transfer will be carried out in accordance with Chapter V of Regulation (EU) 2016/679 (GDPR), using appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or relying on adequacy decisions where applicable, for example the EU-US Data Privacy Framework. No directly identifiable information will be shared.

Payment security

Payment card information

As part of their participation in the study, participants will be required to provide payment card information in a secure interface in connection with the possible purchase of a pass at a discounted price. Payment card information will not be stored by the research team; it is deleted as soon as payment is complete (if a purchase takes place) or the authorization has been canceled (if no purchase takes place), through the secure gateway of the payment processor.

Payment authorization

Before a purchase is made, participants specify the maximum price they are willing to pay. The system obtains authorization for that amount on the payment card the participant has provided. Participants can only continue if authorization is in place, since they commit to paying up to that amount. If a purchase is made, the amount charged is always equal to or lower than the maximum price stated.

Personal ID number (kennitala) and bank account number

If a participant receives a payment in the study, they will be required to provide a bank account number. The unencrypted personal ID number and bank account number are stored securely until all transfers to the participant have been completed, which may be up to four months after participation in the study. As soon as all payments have been made, the participant’s bank account number is deleted.

Security and confidentiality

We place strong emphasis on security and confidentiality in the handling of all information. Payment card information is handled securely by our payment processor, Verifone (acting on behalf of Landsbankinn as the acquirer). Landsbankinn complies with international PCI DSS security standards to ensure privacy and data security.

Data controller and contacts

The person responsible and principal investigator is Tinna Laufey Ásgeirsdóttir, professor of economics at the University of Iceland. The data controller for the processing of personal data is the University of Iceland.

Questions about the study and about participation can be directed to the research team: rannsoknin.val@hi.is or telephone 525 4545.

Questions about data protection can be directed to the Data Protection Officer of the University of Iceland, Magnús Jökull Sigurjónsson: mjs@hi.is or telephone 525 4052.