Skip to content

Privacy

Ryan Wold edited this page Nov 17, 2020 · 3 revisions

References

Touchpoints Privacy Risks and Mitigations

For this document, “customers” refers to federal agencies utilizing Touchpoints for collecting user feedback on public services, and “users” refers to members of the public.


Risk

Unauthorized information collection

Mitigations
  • Feedback Analytics Program maintains Privacy Impact Assessment documentation
  • Provide training for Touchpoints’ agency customers
    • Use of approved sampling protocols
    • Structured information collections (PRA)
  • Training/in-application affordances for Touchpoints users:
    • Data minimization: Touchpoints collects minimal metadata with submissions such as IP address, browser name, referrer in addition to survey response
    • Protections against unauthorized information collection: instructions and notices to users, limiting the use of open text fields, help text reminding users not to enter sensitive information in survey fields.

Risk

Inappropriate information collection

Mitigations
  • Training for Touchpoints’ agency customers
    • The PRA approval process for new form instruments are required to explain the nature and purpose of their information collection from survey respondents

Risk

Inappropriate information disclosure (e.g. a survey respondent includes their social security number in a free-text response field)

Mitigations
  • Training for Touchpoints’ agency customers
    • Appropriate information disclosures on form instruments
    • Ensuring the OMB PRA clearance under which collection occurs allows for publication or release before distributing, publishing, or otherwise sharing
    • De-identification as a risk mitigation
    • How to flag inappropriate submissions in Touchpoints admin interface to prevent download of unnecessary sensitive info by customer

Risk

Misuse of information

Mitigations
  • Training for Touchpoints’ agency customers
    • Partner agency administrative user data is never shared.
    • Access to survey response data in Touchpoints is shared on a need-to-know basis, as determined by agency’s Organization Manager.
    • Customers are informed of the application of records retention rules for all Touchpoints records (currently via Touchpoints’ Terms of Service).

Risk

Use limitation

Mitigations
  • Data submitted by survey respondents is hosted and stored by GSA on behalf of Agency Customers. Submission data may be viewed in a simple tabular format within the Touchpoints Administrative Interface, or downloaded for analysis via common tools, e.g. Excel or Tableau. Data exports are available via file download only, not sent as email attachments. Data exports are recorded in Touchpoints' application logs for audit purposes.

Clone this wiki locally