Legal/Compliance asks: How does Empatyzer protect aggregate anonymity for small teams?

TL;DR:

  • Anonymity of aggregates is protected by a minimum group size of five people.
  • The company only receives aggregated data, never raw individual results.
  • Data are aggregated and blended so individual answers cannot be identified.

How does Empatyzer protect anonymity in small-team data?

Empatyzer shows the organisation through group views, such as the affinity map, culture and motivators, so that the analysis can work without revealing the full profiles of individuals.

Features that can help:

  • Similarity map: Shows the pattern of similarities and differences within a group, helping you see clusters and where teams or departments may operate differently.
  • Organisational culture: Allows you to analyse preferred and actual culture at the group level, so conclusions apply to the aggregate rather than to the private profile of an individual.
  • Motivators: Show needs at a group level, allowing you to analyse differences between teams without revealing full individual performance.

Empatyzer protects aggregate results using product limits and data handling rules. The core visibility rule is that employers see only aggregates and trends, not raw individual responses. We enforce a minimum-group threshold: statistics are released only for teams of at least five people. For smaller groups the platform blocks detailed reports and instead shows broader summaries or suggests combining groups. Aggregation uses blending and averaging to prevent tracing single answers. Visibility is also controlled by user privacy choices: people can hide their profile so their responses are not used in an identifiable way. Empatyzer does not provide employers with raw individual results or full profiles; it supplies interpretations and recommendations at the aggregate level. Contractual terms and platform-level technical safeguards limit data use and make reconstructing individual answers difficult. In practice, even when analyzing smaller units the risk of re-identification is minimal thanks to thresholds, blending, and access controls. Company administrators see only aggregated data and any attempt to de-anonymize would require breaking multiple protection layers. If a client needs extra isolation, higher thresholds or additional anonymization can be applied. When an account is deleted, that person's data are removed according to the retention policy.

Empatyzer's aggregate anonymity relies on a minimum group size of five, data aggregation, and not sharing raw individual results.

Sources and research

  1. European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. Source
  2. European Data Protection Board. (2020). Guidelines 4/2019 on Article 25 Data Protection by Design and by Default (Version 2.0). Source
  3. National Institute of Standards and Technology. (2020). Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5 DOI: 10.6028/NIST.SP.800-53r5

Author: Empatyzer

Published:

Updated:

 

""