Privacy

Opinion Matters Privacy Statement

Updated August 2026

At Opinion Matters (OM), we know that our success depends on our relationships with the people who take part in our research. This includes members of the public, employees, business owners, customers, and other groups we survey.

We follow Canada’s main privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA). This law sets out 10 rules for how organizations must collect, use, and share personal information. Because our work involves vendors, partners, and often clients located outside BC, PIPEDA is the law that applies to nearly everything we do.

BC also has its own privacy law, the Personal Information Protection Act (PIPA), which applies only when the collection, use, and sharing of information happens entirely within BC. Given how our work operates, PIPEDA is almost always the applicable law rather than PIPA — but our practices are built to meet both standards regardless, so the distinction rarely changes anything for you.

When we do work for a BC public body, such as a government ministry, a Crown corporation, or a government agency, we also follow BC’s Freedom of Information and Protection of Privacy Act (FOIPPA). FOIPPA adds a few extra rules, which we explain later in this document.

PIPEDA, PIPA, and the standards set by two research associations, the Canadian Research Insights Council (CRIC) and ESOMAR, all point in the same direction. Because of this, we apply the same privacy protections to everyone we work with, no matter which specific law applies to a project.

Canada’s Privacy Law: PIPEDA

PIPEDA says a company is responsible for protecting personal information at all times. This is true across the whole company, and even when we work with outside partners. PIPEDA is built on 10 principles. We follow all 10, and they work together as a whole.

Principle 1: Accountability

Every company must have someone in charge of privacy. At OM, that person is our most senior director. This shows that we take privacy seriously. Our privacy officer is responsible for making sure we follow PIPEDA.

Principle 2: Telling You Why We Collect Information

We tell you why we are collecting your personal information. We do this before or when we collect it.

Principle 3: Getting Your Consent

We only collect and use personal information when you know about it and agree to it.

We do not share personal information from a study with other companies. There is one exception. Sometimes a client who is paying for a research project wants to contact a participant directly, for example to ask about a specific answer. If this happens, we explain the reason to you first, and we only go ahead if you clearly agree.

Changing your mind. If you take part in a survey, you can ask us to remove your answers from that project. We can only do this while your answers are still linked to your name. That link is only kept for a short time, and how long depends on the project. Once we remove the link, we can no longer tell which answers were yours, so we are no longer able to remove them. If you want to make this request, please contact our privacy officer.

Principle 4: Only Collecting What We Need

We only collect the personal information we need for the reasons we have explained to you. We collect it in a fair and legal way.

Principle 5: Limiting How We Use, Share, and Keep Your Information

We do not use or share your personal information for anything beyond what we told you, unless you clearly agree to it.

We only keep personal information for as long as we need it. You can read more about this in the Freedom of Information and Protection of Privacy Act section and the Keeping Your Data Safe section below. Those sections explain the difference between information that can identify you and information that cannot.

Principle 6: Keeping Information Accurate

We keep personal information as accurate, complete, and up to date as it needs to be for how we use it.

Principle 7: Keeping Information Safe

We protect personal information with safeguards that match how sensitive it is.

Principle 8: Being Open About Our Policies

We make information about our privacy policies and practices easy to find.

Principle 9: Letting You Access Your Information

If you ask, we will tell you what personal information we have about you, how we use it, and who we share it with. We will also give you access to that information.

Fixing your information. If you think the personal information we have about you is wrong or out of date, you can fix it at any time. Just go to our website and fill out the registration questionnaire again. Your new answers will replace the old ones. You can also contact our privacy officer to ask for a correction.

Principle 10: If You Have a Concern

If you think we are not following one of these 10 principles, you can raise the issue with the person responsible for our privacy compliance.

If you have a question, comment, or complaint about our privacy practices, please email our privacy officer: privacyofficer@opinionmatters.ca.

If you are not happy with our response, you have the right to contact the Office of the Privacy Commissioner of Canada (OPC). The OPC oversees PIPEDA across the country. You can reach them at priv.gc.ca or 1-800-282-1376. If your concern is about a British Columbia public sector project covered by FOIPPA, you can also contact the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) at oipc.bc.ca.

British Columbia’s Freedom of Information and Protection of Privacy Act (FOIPPA)

We follow FOIPPA whenever we do work for a BC public body. This includes the BC government, Crown corporations, and BC government agencies. Under FOIPPA, personal information means any recorded information that could identify you, other than basic contact information.

In the past, FOIPPA said that personal information from a BC public body had to be stored and accessed only in Canada. In 2021, the law changed. Now, storing or accessing this kind of information outside Canada is allowed in some cases, as long as the organization first checks the privacy risks. This is the same rule that allows the BC government to use large cloud services like Microsoft 365, Teams, and Azure.

A note about where data sits versus who can reach it. Even with this updated rule, there is still a risk to think about. It comes from a US law called the CLOUD Act. The BC government’s own privacy guidance says this risk must be checked whenever an organization uses a cloud company that is not Canadian owned, even if that company stores the data in Canada. Storing data in a Canadian data centre tells you where the data physically sits. It does not tell you which country’s laws can reach that data. A company like Microsoft is based in the United States, so US law can still apply to it, no matter where its Canadian servers are.

FOIPPA’s rules only apply, by law, to information connected to BC public bodies. Even so, many of our government clients ask us to use the same level of care for every research project, not only the ones involving government data. We agree this makes sense, since it is their data and their reputation on the line. So, as our own policy, we apply the same protections to every project we run. In some ways, we go further than the law requires:

  • While we are actively working on a project, draft reports and other working documents may be stored on Microsoft 365 (OneDrive), using Microsoft’s Canadian data centres. By this point in a project, personal information has already been removed from these files, following our standard practice.
  • Once a project is finished, we move these files off Microsoft 365. This is a required step in how we close out every project, not an optional one. We move the files to Canadian owned storage: password protected staff devices, where the software also needs a second sign in step (called two factor authentication) and cannot be reached by anyone outside OM, and Sync.com, a Canadian cloud storage company that meets a recognized security standard called SOC 2. Once the move is confirmed, we delete the files from OneDrive. This means we only use a US based company during the working stage of a project, when the files hold no personal information. Once a project ends, the data we keep sits only on Canadian owned storage or OM controlled devices.
  • For work that would give an outside company ongoing access to raw research data, such as complex data processing, coding, or tabulation, we use Canadian owned companies. We avoid using the Canadian branch of a US owned platform for this kind of work, to further lower the risk of foreign legal reach.
  • Our staff and contractors sign confidentiality agreements. They understand their duties under federal and provincial privacy laws, including FOIPPA’s rules about keeping, accessing, and sharing BC public sector data outside Canada.
  • We remove personal information from raw survey data before we begin analysis. The working files we use for analysis and reporting do not contain identifying details such as your name, email address, or phone number.
  • We keep identifying information in the original raw data file, stored separately from the working files. We only keep it as long as we might need it, for example if we plan to invite you to a related focus group, something we would have already told you about. We rarely go back to this file, and only for this reason. To be clear: personal information means recorded information that, when combined, could identify you. For example, your name or contact details together with your survey answers. Once we remove the identifying details, the remaining survey data, tables, and reports are no longer personal information. See Keeping Your Data Safe below for more on how this affects how long we keep your data.
  • Some studies use paper surveys, for example by mail. We store completed paper surveys securely and have them professionally shredded, usually within a year of collecting them.

Our Promise to Research Participants

Taking part in real market, social, or public opinion research matters to us. We value your honest answers and your time. Your opinions help companies build better products and improve their service. Your views also help governments and non-profit groups create better laws and policies.

Our relationship with you is built on respect, trust, and honesty. When you take part in research with Opinion Matters, you can count on the following:

  • We will always tell you the first name of the person contacting you, the name of our company, and what the study is about.
  • You can check that an invitation from us is real by contacting our privacy officer: privacyofficer@opinionmatters.ca.
  • We will never try to sell you anything or ask you for money.
  • We will protect your privacy and keep your answers confidential, following our privacy policy and Canadian law.
  • We will contact you at reasonable times. If the time does not work for you, you can ask us to contact you again later.
  • We will tell you how long the survey or interview is expected to take.
  • We will respect your choice to take part, to skip a question, or to stop at any time.
  • We will tell you in advance if we plan to record an interview, and how we plan to use the recording. You can choose not to continue if you do not want to be recorded.
  • We hold ourselves to the highest standards of professional conduct at every stage of a study.
  • You can stop a survey at any time by closing it or choosing not to continue. You can also leave the Opinion Matters panel completely. Just reply to any email from us with the word “unsubscribe,” or another clear message telling us you want to be removed.

Research with Young People Under 18

Sometimes our research includes people under the age of 18. When this happens, we follow the guidelines for research with children set out by the Canadian Research Insights Council (CRIC), along with the CRIC and ESOMAR Code and this privacy statement. We check for the most current CRIC, ESOMAR, and provincial rules before starting any project like this, since these standards can change over time. Here is what we do:

  • We first contact the parent or another responsible adult, not the young person directly. This way, we get consent as the very first step.
  • We tell the parent or responsible adult what the study is about, including any topics that may be sensitive, and how we will use the information we collect.
  • We confirm consent through a meeting with the parent or responsible adult, usually by video call, sometimes by phone, followed by a signed consent form. We keep a record of the adult’s name and how they gave consent.
  • We also explain the study to the young person themselves, in a way that fits their age. They can choose not to take part, or to stop at any time, even if a parent already agreed.
  • For children under 13, a parent or responsible adult stays close by, for example in the same room or the room next door, for the whole research session.

Text Message (SMS) Terms

We may text panelists who have opted in, to let them know about new research opportunities. If you give us your phone number and agree to receive texts, here is what you should know:

  • Purpose: We only use text messages to let you know about survey opportunities and to ask you to check your email for details. We never sell, market, or promote anything by text, and we never collect survey answers by text.
  • How often: How many texts you get depends on the studies you qualify for.
  • Cost: Your phone plan’s message and data rates may apply.
  • Opting out: Reply STOP at any time to stop getting texts. Reply HELP if you need support.
  • Sharing your number: We do not share your phone number with other companies for marketing.
  • Checking we are real: You can confirm that a text from us is legitimate by contacting our privacy officer (see above).
  • Carriers: Phone carriers are not responsible for delayed or missed messages.

Keeping Your Data Safe

Opinion Matters is committed to running one of the most secure web based research operations. We take security seriously in three areas: our people, our processes, and our technology.

Our People

Our team works hard to keep every survey and every piece of client information secure.

  • All staff, whether full time, part time, or contract, sign confidentiality agreements. We regularly remind them of their duties under these agreements, under PIPEDA, and under the standards set by CRIC and ESOMAR.
  • Limited access: staff and consultants can only see the information and files they need to do their job.
  • Staff training: we teach our team to spot phishing emails, social engineering tricks, and other threats. We stay up to date on best practices for using the internet safely, handling and disposing of client data, reporting lost or stolen devices, and using strong passwords.

Our Processes

Every routine at OM is built with security in mind. We use different levels of access, monitoring, and backup to keep confidential data confidential.

  • We back up all data carefully. We stand behind the accuracy and safety of everything in our care.
  • We only keep information that can identify you, such as your name, email, or phone number, for as long as we need it for a specific study, and always separately from the working files used for analysis. In most cases, this is a matter of months. In some cases, such as when a follow-up study or related focus group is planned, we may keep it longer. Once we remove identifying details, information such as tables, coded comments, and final reports is no longer personal information. We may keep this information, without identifying details, to help clients track trends over time, always under our usual confidentiality and security rules.
  • If you’re a member of the Opinion Matters panel, your information stays in our panel database for as long as you remain part of the panel. You’re free to leave the panel at any time by letting us know, and in some cases, we may also remove a panelist from the database at our discretion.
  • Access to our systems is limited by usernames, passwords, and admin permissions.
  • Any outside company that works with us, such as a data processor or software provider, only receives the information they need to do their specific job.

Our Technology

We use strong technical safeguards to protect your personal information and our clients’ data. These include:

  • Up to date firewalls and antivirus software on every staff device, along with network security from our certified cloud providers;
  • Regular maintenance and testing;
  • Password protected devices and accounts;
  • A file transfer service with end to end encryption for sending sensitive documents and recordings;
  • Secure, password protected access to our online client reports;
  • A unique web link for viewing live survey data securely. We never share this link with anyone outside the people who need it;
  • Backup systems using Canadian cloud infrastructure, so lost data can be recovered without affecting our work;
  • Clients only see combined, grouped survey results, unless you have clearly agreed to let them see more.

What Happens If There Is a Data Breach

Every system and platform we use stands alone, with its own login and either two factor authentication or an authenticator app. If one system is broken into, for example our survey platform, our panel, or our file storage, that breach cannot spread to our other systems. This separation limits how far any single breach can reach.

If we detect or suspect a breach, here is what we do:

  • we immediately cut off the affected system and change its passwords and logins;
  • we look into what happened, to figure out what data, if any, was affected;
  • we notify affected clients right away;
  • if the breach could cause real harm to a person, we notify the people affected directly and report the breach to the Office of the Privacy Commissioner of Canada, as PIPEDA requires;
  • if needed, we also report the incident to the Office of the Information and Privacy Commissioner for British Columbia, as FOIPPA requires; and
  • we keep a record of every breach, even small ones, for at least 24 months, as PIPEDA requires.

Cookies and Website Tracking

Our website may use a small number of technical cookies needed to make the site work. We do not use cookies to track you across other websites. We do not sell or share any information collected through our website with other companies for advertising.