Demographic data privacy

Collect demographic insight without giving the organization individual demographic responses.

Organizations may need demographic information to understand representation, experience and differences between populations. That does not automatically mean the organization needs access to each person's demographic response.

SafePorter separates those two needs. The organization invites participants while keeping their identity on systems it controls. SafePorter receives demographic responses without names or email addresses. The organization receives aggregate results, with small-group protections applied before publication.

Why removing names is not enough

Demographic information can become identifying when characteristics are combined. A location, role, age band or other characteristic may describe a large population alone. Several of them together may describe one person.

Privacy therefore depends on what can be inferred from the result, not simply whether a name appears in the record.

Why aggregation needs limits

A result is not safe merely because it is expressed as a percentage. If a percentage describes a group of one, it describes a person.

SafePorter therefore withholds results when the population is too small to report safely and constrains reporting that could expose an individual through combinations or changes over time.

The design principle

Collect the information the organization needs to understand the population. Do not give it information about individuals that it does not need to answer that question.

How small groups are protected →   Data minimization →