Sonder Portal: Privacy and Data Protection
Protecting member confidentiality is central to the design of the Sonder Portal. Reporting has been designed to ensure insights can be shared with organisations while protecting individual privacy.
Aggregated reporting:
Individual members can't be identified through portal reporting. All data displayed in the portal is:
-
aggregated
-
de-identified
-
displayed at a group level
Minimum reporting thresholds
Sonder has an anonymisation rule applied to all aggregated reporting: if you have a division or sub-division with fewer than 10 activation members on Sonder, nothing will appear to protect member privacy and prevent identification of individuals. Data is only displayed when a minimum reporting threshold is reached.
Responsible use of data
Data in the Sonder Portal should be used to understand population trends.
It should not be used to:
-
identify individuals
-
diagnose health conditions
-
replace formal workplace risk assessments
Frequently asked questions.
Can I see individual member data in the Portal?
No. All Portal data is aggregated and de-identified. You can't identify individual members through Portal reporting. If a data segment has too few members, it won't be displayed at all to protect privacy further.
Can I use Portal data to identify who needs help?
No. Portal data shows population trends, not individual member activity.
What does "de-identified" mean?
De-identified means personal information (names, contact details, role specifics) has been removed. Data is grouped together (aggregated) so individual members can't be singled out, even indirectly.
Portal dashboards can show trends by various segments (business unit, store location, campus, etc) if the minimum threshold is met for that division. If a division is too small, the data won't display.