How to assess the storage area and equipment that can be used?
North has a guideline for classifying information. This also applies to students who process data in connection with their written work as students. Information must be classified as green/open, yellow/protected or red/confidential. Students shall not process data that is so sensitive that it is classified as black/strictly confidential data.
- Before you collect data, classify all information based its need to be protected. Use Nord University's guidelines for data classification. You can request assistance from your supervisor or data protection officer if you are unsure what classification your data should have.
- After you clarify the classification of your data, check which storage areas, tools and equipment you can use to process this data. An overview of this can be found in the Nord University Storage Guide. Among other things, it explains the current requirements for storage areas and equipment that will be used for yellow and red data.
Can students use private devices?
As a starting point, yellow or red data cannot be processed on private devices. This means, among other things, that you can never make audio recordings by mobile phone.
Using a private PC/Mac to log into Nord's cloud storage against OneDrive is not considered use of a private device provided the data is not downloaded to a private PC/Mac. This requires that data in your OneDrive cannot be synced to your PC/Mac. Therefore, check the settings in your OneDrive before storing yellow or red data in OneDrive.
If, for special reasons, you need to process data on a private entity, you must obtain written approval from your faculty. Private devices must then be encrypted in accordance with the requirements set by the North.
How to obtain information in a digital questionnaire – Web form?
If you are collecting information through a questionnaire, you must use Nettskjema - North Help.
You need to log in with your FEIDE user to access Nettskjema. You are not permitted to download data from Nettskjema to your own machine or any other unsafe storage areas. If there is a need to transfer the data to another storage area, you must follow the provisions of Nord's storage guide.
If you want to obtain information that will enable identification of the informants in the questionnaire, the form must contain explanatory information and a mandatory checkbox for consent. When creating the form, you must choose that informants log in via the ID-portal so that you have an overview of those who have filled out the form.
You can create anonymous questionnaires. If you do so, it is important that only questions be used with radio buttons/checkboxes or drop-down lists, and that no questions are asked that can indirectly identify individuals.
The form in Nettskjema must be deleted when the project is over.
How to make audio recordings of interviews?
A person's voice is to be regarded as personal data in itself, so all audio recordings of persons shall be processed in accordance with the data protection regulations.
Audio recordings must be made using the Nettskjema Dictaphone app (University of Oslo). This app is downloaded to your mobile phone. The audio recording is not saved on the mobile, but is sent directly to Nettskjema. To listen to the recording, you must log in to Nettskjema using your Nord FEIDE account. Tips and information can be found on UiO's website pertaining to Nettskjema.
If poor Internet access prevents you from using Nettskjema Dictaphone, an audio recorder without internet access may be used. Audio recorders can be borrowed from some departments at the University Library. Some faculties/research projects may also have audio recorders available. Audio recorder, cassettes, memory sticks, etc. containing audio recordings should be stored securely and should be encrypted if possible. Once data has been transcribed or transferred to secure storage, the recordings should be deleted. It is important to check that all recordings have been deleted before returning a borrowed audio recorder.
How to conduct a digital interview?
You can use Zoom or Teams to conduct an interview. To do this, you must ensure that the meeting link is given only to the person to be interviewed and that no outsiders attend the meeting.
It is not permitted to video-record the conversation. If you need to make audio recordings, Nettskjema Dictaphone must be used. You can do this by placing your mobile phone w/ Nettskjema Dictaphone app next to your PC speaker during the interview.
Can students make video recordings of the informants?
Students are not allowed to make video recordings of informants in Teams or Zoom.
If special circumstances indicate that it is necessary to make video recordings, the student, together with the project manager, must clarify how this can be carried out in a secure manner, and apply to the Faculty for approval. The Data Protection Officer at Nord can assist in the assessment.
Where can data be stored?
OneDrive
On Nord's website under "Student" you will find the tab Office 365 (can be downloaded for free by our students). It takes you to a page that has Microsoft's OneDrive cloud solution. Here you can store information classified as green, yellow, or red data.
Before you save data to OneDrive, it's important that you check the following:
- Make sure files/folders are not shared with others
- Make sure OneDrive doesn't sync to your private PC/Mac automatically
- Provide additional protection (encryption) if you need to store red data
How to prevent syncing in OneDrive?
If you've already installed the Office 365 (applications), all data in your OneDrive may sync to your machine automatically. To prevent certain types of data from being stored on a private PC, follow these steps:
- Find the blue OneDrive symbol in the tools menu in the lower-right corner of your PC.
- Tap Help & Settings. Continue on to Settings.
- A small window with the OneDrive account information should come up (Account). This shows the location (accounts) that are synchronized. Click "choose folders"/"select folders". De-select the folders that are not to be synchronized.
How to safeguard red data in OneDrive?
If you are processing red data, storage in OneDrive should be additionally protected by encrypting it. This will be especially relevant if you are processing sensitive personal data or other confidential information. You can contact IT Help for assistance.
How should the crypto-key be stored?
The crypto-key should be encrypted and should always be stored separately from the rest of the data. If you store pseudonymized/de-identified data in OneDrive, the crypto-key must be stored in a different secure location, such as an encrypted USB flash drive that is kept under lock and key.
Physical material
Flash drives and other portable media/devices containing yellow or red data should be encrypted.
Printouts, audio recorders, USB flash drives, etc. should be kept locked up so that others cannot access them.