
IT5 is the online research platform of DESAN Research Solutions. Users can use IT5 to create, manage, test, publish and monitor surveys.
Because this often involves the processing of personal data, sample data and research data, security and privacy are standard parts of the design, management and operation of IT5.
DESAN secures IT5 through a combination of technical, organisational and procedural measures. The protection of availability, integrity and confidentiality is central to this approach. Security is based on the principle of defense in depth: multiple layers of security work together to reduce risks.
ISO 27001 certified
DESAN is ISO 27001 certified. This means that information security is structurally organised, managed and periodically assessed. Security is therefore not a separate technical measure, but part of DESAN’s processes, policies, management, development and control mechanisms.
Within IT5, attention is paid to, among other things:
- access security;
- logging and monitoring;
- patch management;
- secure software development;
- backups and recovery;
- incident management;
- authorisations and segregation of duties;
- periodic control and improvement.
DESAN also periodically commissions penetration tests by independent parties that are CCV certified. Findings from these tests are assessed, followed up and used to further improve IT5.
Own Dutch infrastructure
IT5 is hosted and managed by DESAN on its own infrastructure in Dutch data centres. DESAN does not depend on Big Tech platforms or foreign cloud providers for the hosting of IT5.
This offers advantages in terms of control, privacy and digital sovereignty. DESAN retains control over:
- the hosting environment;
- the technical setup;
- the security measures;
- access to systems;
- the data storage location;
- the management of encryption keys and backups.
The infrastructure is designed redundantly. Important components are duplicated, so that the service remains available if one component fails. IT5 is designed for high availability, with a minimum uptime of 99.99%.
On-premise deployment available
In addition to hosting on DESAN’s own infrastructure, IT5 can also be deployed in an on-premise environment if required. This may be relevant for organisations with specific requirements regarding data storage, internal governance, compliance or network segmentation.
For an on-premise setup, the exact division of responsibilities is determined per situation. This includes which components are supplied, managed or supported by DESAN, and which responsibilities remain with the client. In this setup as well, the main principle is that IT5 is implemented in a secure, manageable and auditable way.
Separate databases for sample data and responses
An important privacy principle within IT5 is the separation between sample data and survey responses.
IT5 uses two separate databases:
- Sample database
This database contains the sample data. This may include privacy-sensitive data, such as contact details, routing characteristics or information needed to invite respondents. - Response database
This database contains the answers to the survey.
By separating these databases, personal data and survey responses are stored separately at a technical level. This enables DESAN to better safeguard respondent privacy and prevents privacy-sensitive sample data from being unnecessarily combined with survey responses.
This setup helps ensure that responses can be processed anonymously, or as anonymously as possible, for the client, depending on the project agreements. The client receives the research data without privacy-sensitive sample data being automatically included.
Data encryption
All communication with IT5 takes place via HTTPS with TLS encryption. This means that traffic between the user’s browser and IT5 is transmitted in encrypted form.
Data at rest is also encrypted. This is done both at database level and at infrastructure level. DESAN manages the encryption keys itself and keeps them under active control. As a result, DESAN remains in control of the technical protection of stored data and does not depend on external cloud providers for key management.
Roles and permissions
IT5 uses separate roles and permissions. Users only receive access to the parts of IT5 they need for their work.
This means, for example, that not every user automatically has access to all projects, surveys, response data, export options or management functions. By separating roles and permissions, IT5 applies the principle of least privilege: users are not granted more permissions than necessary.
DESAN recommends keeping the number of administrators limited and periodically reviewing which users have access to which projects.
Application security
IT5 is developed and managed with secure software development in mind. The application includes measures to reduce known security risks, such as unauthorised access, incorrect input, session misuse and vulnerabilities in web applications.
This includes, among other things:
- input validation;
- secure session management;
- protection against SQL injection;
- non-predictable identifiers, such as GUIDs;
- shielding of management functions;
- logging and monitoring;
- periodic security updates;
- controlled deployment of changes.
Changes go through a DTAP process: Development, Test, Acceptance and Production. New functionality and technical changes are tested before they become available in the production environment.
Monitoring and management
IT5 and the underlying infrastructure are actively monitored. DESAN monitors availability, response times, server load and technical deviations, among other things.
In the event of deviations, administrators receive automatic alerts. This allows DESAN to respond quickly to disruptions, performance issues or possible security signals.
Maintenance is planned as much as possible at times when users experience minimal disruption. During critical research periods, DESAN can apply increased monitoring and restrict non-essential changes.
Backups and recovery
DESAN creates backups of systems and data. These backups are intended to restore systems and data in the event of technical disruptions, errors or calamities.
Incident management
In the event of a security incident, or a suspected security incident, DESAN’s incident management process is activated. This process considers:
- the nature of the incident;
- the possible impact;
- the systems involved;
- the data involved;
- the required measures;
- communication with the parties involved
GDPR and privacy by design
For many research projects, DESAN acts as a processor under the GDPR. The client is then the controller and determines the purpose of the processing. DESAN processes the data in accordance with the agreements made.
Privacy by design is an important principle in IT5. This means that privacy is taken into account when setting up a research project. This includes:
- limiting the use of personal data;
- separating sample data and survey responses;
- working with minimum access rights;
- limiting exports to necessary data;
- applying retention periods;
- deleting or anonymising data after completion;
- supporting DPIAs where required.
DESAN can support clients with technical and organisational information for DPIAs, audits and privacy assessments.
Right to audit
Depending on the agreements made, clients may exercise a right to audit. This means they have the option to have the security, processes or compliance with agreements assessed.
DESAN is experienced in cooperating with audits, security questionnaires and assessments by clients or independent audit parties. Findings from audits are used to further improve processes and measures where necessary.
Recommendations for IT5 users
Security and privacy do not depend solely on the technical setup of IT5. The way project teams use the platform is also important. DESAN therefore advises IT5 users to pay attention to the following points for each project:
- only give users access to projects for which they need access;
- limit the number of administrators;
- periodically review user permissions;
- do not request more personal data than necessary;
- only include sensitive questions if there is a clear research reason;
- share exports only through secure channels;
- publish a clear privacy statement for the research project;
- agree on retention periods in advance;
- delete or archive data after completion in accordance with the agreements made;
- discuss in advance whether a DPIA is required.
