Anonymising and Excluding Captured Data

Selected data captured by your forms can be anonymised when exported. This is helpful when handling sensitive personal data as required by various standards like GDPR or HIPPA.

Workflows can be configured such that authorised destinations receive valid data while un-authorised destinations will receive an anonymised version of the same data.

An additional measure allows fields to be prevented from appearing at all in exported data.


Handling Personal Data

When creating forms, you can mark fields as IS PERSONAL DATA. When this flag has been set on a field, the data contained for that field can be anonymised on export. How this works is dependent on other settings and how the data is exported.

Protecting Sensitive Data

Protecting sensitive data is a 2 step process:

  • Flag fields as Is Personal Data
  • Configure the Connector to Anonymise Personal Data

Flagging Fields as Personal Data

Fields that contain sensitive data must be flagged as Is Personal Data.

By itself, setting this flag does not grant or imply additional security, protection, and privacy of data. Data is still captured and uploaded to the Platform and without additional settings made within your forms and/or Connectors, can be exported.

To flag a field as Is Personal Data:

  1. Select the field
  2. Check the check-box IS PERSONAL DATA in the field’s Advanced Options

Configuring Connectors

Data can leave the platform in a number of ways. You might send an email to a number of recipients, or via Connectors to destinations like Google Spreadsheets. You should consider how each export point is configured to ensure sensitive data is kept private.

Each connector has a setting that will enable the anonymization of fields marked as Personal Data. The example is for an email connector; each connector will have the same settings. To make the setting:

  1. Navigate to the form’s Connectors page
    Either on the screens page when hovering over a screen, click the connect link, or when on a form’s design page, click the connectors link top-left under the page’s title.
  2. Add a new Connector or select an existing one.
  3. Give it a name that identifies it as being protected for easier form management
  4. Locate the checkbox Anonymise Personal Data and check it
  5. Click Save
Setting up multiple Connectors lets you send data to specific destinations, anonymised or not. For example, you could set up one email connector with recipients for anonymised data and a second with a list of people who can view the original data.

Result

Forms that are correctly protected will anonymise the set fields by replacing the data with meaningless characters. In the example below:

  1. Unprotected fields with all data readable
  2. Protected fields with anonymised data

Data that is destined for connectors like external data sources or other platforms will also have the anonymised data written for protected fields.

Excluding Sensitive Data from Export/Display

Some data must remain restricted to the extent of not being visible in any export or display. Marking fields as EXCLUDE FROM EXPORT/DISPLAY prevents them from appearing in any data exports, including PDF, CSV, or export via connectors, etc. These fields will still be available in Data Entry views like Feed, Table, or Map.

Flag a Field as Excluded

To flag a field as EXCLUDE FROM EXPORT/DISPLAY:

  1. Select the field
  2. Check the check-box EXCLUDE FROM EXPORT/DISPLAY in the field’s Advanced Options

Result

Fields marked as EXCLUDE FROM EXPORT/DISPLAY will appear as follows within the platform and once exported:

  1. A form with some fields set as Excluded – indicated by the arrows. Note that all data is visible
  2. The same form entry after being exported using the Generic PDF export.
    The fields indicated in (1) are excluded from the export.