Consent and research governance
Status: accepted
The platform runs educational research on real learners. Research data is governed by capture-all, gate-use: operational telemetry sufficient to run adaptive learning (ADR-0005/0007) is captured for everyone under a legitimate/contractual basis; research is secondary use of that data, gated at use time.
Conditions that make capture-all-gate-use sound (GDPR Art. 5(1)(b) + Art. 89)
Section titled “Conditions that make capture-all-gate-use sound (GDPR Art. 5(1)(b) + Art. 89)”- Operational purpose at capture. Every captured field has a declared operational purpose. Data with no operational purpose, captured purely for speculative research, requires consent at capture — that line is not crossed.
- Research access only via a de-identified, minimized projection — never the raw
operational tables. This projection is the Art. 89 technical safeguard (built on the
existing pseudonymous
account-IFI identity). - Interventional ≠ observational. Assigning a non-default Variant/condition is intervention and always requires consent; analyzing already-captured data is observational.
- Sensitive corners are ring-fenced — minors and special-category signals get stricter handling (below).
Lawful basis for observational use — authority-scoped
Section titled “Lawful basis for observational use — authority-scoped”Observational secondary use is backed by a recorded Governance Authority, not a platform self-assertion:
- Org-delegated authority. An Organization that asserts research authority — with its ethics/IRB approval and an upstream guardian-consent-at-enrollment chain on file — backs observational use including sensitive/minors, under Art. 89 + transparency + honored opt-out, no per-person opt-in. Risk sits on the institutional consent chain where it belongs.
- Open/consumer context (no such authority): sensitive/minors fall back to explicit consent for observational use.
Art. 89 is a fragmented national-derogation regime; the recorded authority + scope make each basis auditable per jurisdiction rather than self-certified.
Withdrawal
Section titled “Withdrawal”Withdrawal stops future capture-for-research and manipulation and excludes the person from ongoing/new analyses. Already-frozen published cohorts retain their pseudonymized data for reproducibility (Art. 17(3)(d) research carve-out), with a hard-erase path where law requires it.
Entities & consequences
Section titled “Entities & consequences”- New: Governance Authority (who authorizes; Org-delegated or external ethics), Study/Protocol (approval record, population scope, interventional flag, retention, data-use scope), Consent (per-Person, versioned, withdrawable, references the authority/delegation), Research Projection (the de-identified access layer).
- Consent/authority state must sync to the client so offline Selection respects it — a non-consented/ineligible learner is never assigned a non-default Variant, even offline.
- The Interaction Event log needs a research-exclusion flag + tombstone to honor withdrawal without corrupting frozen cohorts.
- The use-gate checks
(authority, scope, consent, eligibility, sensitivity)before any research use or manipulation.