Consumer privacy is a top priority for NielsenIQ. We rely primarily on demographic and aggregated data from which we cannot directly identify people, and we maintain appropriate limits on access to data about specific individuals where we hold it.
Our internal policies and procedures conform to applicable laws and industry standards around the globe. They also incorporate the principle of Privacy by Design—a commitment to include appropriate privacy protections in the design and implementation of our products and services.
The practices described in this Privacy Statement are undertaken by NielsenIQ’s group of companies operating together around the world. Learn more about NielsenIQ’s family of companies.
We deploy consumer-friendly privacy controls that are easy to find and easy to use. We believe in responsible stewardship of data, and we are continually striving to improve our own practices and maintain a high standard for our industries. Take a look at the Privacy Information sidebar to the right to learn more about specific practices followed by different areas of NielsenIQ’s business.
NielsenIQ’s privacy principles include
Privacy by design
While developing our products and services, we assess their potential impact on personal data and embed appropriate privacy protections into our data processing activities, taking into account the other privacy principles described below.
Trust and accountability
We are committed to responsible stewardship of the data under our control and to compliance with all applicable data protection laws that regulate the collection, use and disclosure of data about individual people. NielsenIQ’s internal privacy team oversees compliance with applicable privacy laws, self-regulatory programs that we participate in, and our internal privacy policies.
We use tools and methods designed to prevent individuals from being identifiable in our reports and insights, and we take steps to prevent the data we collect from being reused in ways that have not been communicated to individuals and/or could negatively affect them.
The data NielsenIQ collects
NielsenIQ collects personal data from:
- Our panelists—individuals and households who agree contractually to participate in one or more of NielsenIQ’s panels. We also process personal data in order to recruit for panels that accurately represent the “total audience.”
- People we contact in regard to NielsenIQ surveys conducted online, in person, by telephone, email, or postal mail.
- Visitors to our websites and people who contact us via our websites, via email, or other means.
- Our employees, contractors, and business contacts at other companies in the course of conducting our business.
Meaningful notice and choice
We provide clear notice about what data we collect and how we use it. We offer choices about our data collection at a time and in a context that reflect the sensitivity of the data being collected. Panelists and survey respondents agree to the collection and processing of their data and may withdraw their participation at any time. Individuals also have the ability to opt out of our online and mobile data collection at any time.
We are continually working to maintain the personal data we collect so that it is complete, accurate, relevant and up to date.
Basis for processing
Many privacy laws require companies to establish a lawful basis for their uses of personal data. While NielsenIQ has established different lawful bases for different types of processing, in almost all cases our basis for processing personal data will be one of the following:
- Performance of a contract—NielsenIQ operates its research panels and conducts surveys on the basis of a contract—a panel membership or market research agreement between NielsenIQ and our research subjects. For many panels, these agreements cover all members of a household, because market research practices often require analysis of data at a household level.
- Consent—Where NielsenIQ bases its processing of personal data on consent, we may seek consent directly from individuals or, where NielsenIQ acts as a data processor (a service provider to another company), we may rely on consent obtained by the data controller (a third party who typically has a direct relationship with the individual and obtains consent).
- Legitimate Interests—In some cases, we may base the processing of personal data on our legitimate interest in performing market research or other services, because of its benefits in improving the efficiency of our clients and the markets in which they operate.
- Where we rely on this as our basis for processing, we make sure our activity is appropriately balanced by strong privacy protections designed to minimize the risks to data subjects.
Data minimization and collection limitation
Following the concept of data minimization, we limit the collection of personal data to the extent possible while still enabling us to derive meaningful and accurate measurements and insights.
- When we use direct identifiers, we limit access to such information both internally and externally and implement appropriate data security measures, which are designed to protect individuals’ privacy.
- Before we obtain third-party data, we review the third party’s data collection practices and the privacy notices that are made available to individuals to make sure that our use of the data is consistent with the commitments those companies have made to individuals.
- When we have removed identifying elements from the data that we collect, we take steps to prevent the data from being re-associated with identifiable data.
Limited use and retention
We restrict access to and use of personal data to NielsenIQ associates and service providers with a legitimate business purpose. We have established records retention policies to limit how long we keep personal data.
Access, correction, erasure and portability
We provide individuals with reasonable opportunities to access the personal data NielsenIQ holds about them and correct it if it’s inaccurate. Depending on your country or state (US) of residence, under applicable law individuals may have various additional rights with respect to personal data processed. Rights may include one or more of the following:
- To request confirmation as to whether or not personal data is processed, and, where that is the case, access a copy of the data we hold and to request it is updated or corrected where it is inaccurate;
- To object to processing of personal data;
- To propose other restrictions on the processing of personal data; and
- To request that personal data is deleted (where applicable).
Individuals that are interested in exercising one or more of the rights described above can submit a request using the form here or contact us at firstname.lastname@example.org. NielsenIQ does not discriminate against individuals who exercise their rights under applicable law.
Only the individual data subject or an “Authorized Agent” permitted to act on their behalf may submit a request. An “Authorized Agent” means a natural person or a business entity that has been properly authorized to act on the individual’s behalf. Please note, we may deny a request from an Authorized Agent if they do not submit proof that they have been authorized by the individual data subject to act on their behalf.
A request must:
Provide sufficient information that allows us to reasonably verify that the requestor is the person about whom we collected personal data or their Authorized Agent; and include sufficient detail to allow us to properly understand, evaluate, and respond to it.
We cannot respond to a request or provide personal data if we cannot verify the identity of the requestor or their authority to make the request. To verify a requestor’s identity, we will match data provided when the request is submitted to any personal data we already maintain.
Additional information for users in the EU/EEA:
Individuals that have questions or concerns about NielsenIQ’s collection and processing of personal data can contact our EU Data Protection Officer at email@example.com. Individuals that are dissatisfied with the way NielsenIQ has processed personal data or any privacy query or request that they have raised to us have the right to complain to the Supervisory Authority in their country of residence or the location where the issue that is the subject of the complaint occurred. The contact details of all the EU national Supervisory Authorities can be found by visiting: EU National Data Protection Authorities.
We comply with applicable laws regarding the collection of data about children. When we collect personal data from children, we do so with parental consent, which can be withdrawn at any time.
We respect applicable local laws regarding cross-border transfers of and access to personal data.
Disclosure’s of data to third parties
We do not sell data that directly identifies individuals, and we contractually prohibit our clients from re-identifying individuals from the de-identified data that we provide them (e.g., survey statistics).
Furthermore, we contractually prohibit recipients of our data from using it to make decisions regarding credit, insurance, housing, employment or other legal effects on individuals. We contractually require service providers that have access to our data to keep it secure and use it to perform only the services they have been engaged to provide.
We will provide data to government and law enforcement entities to the extent required by applicable law, to protect NielsenIQ’s legal interests and, where needed, to protect the health or safety of others.
We implement multi-layered organizational, technical and administrative measures that are designed to protect the personal data under our control.
These include, among other things: limiting access to data; using technology measures like firewalls, encryption, malware protection and intrusion detection; maintaining policies that are aligned to a wide variety of legal requirements; and holding our associates accountable for maintaining safe data-handling practices and adhering to our internal policies.
We have a global organization of qualified data security professionals and engage in regular system testing and updating of our controls to keep pace with changing technology and security threats.
Global reach, local touch
We are committed to respecting the diverse cultures and local laws of the countries in which we operate.
If you have any comments or questions regarding this Privacy Statement or our data handling practices, please email firstname.lastname@example.org. You can also send us a letter at the following addresses:
From EU Countries:
Attn: Legal Dept.
Oxford Business Park South
John Smith Drive
Oxford OX4 2WB
In Other Countries:
85 Broad Street
New York, NY 10004