privacy
10 TopicsViva Insights - Setup, licensing, onboarding and privacy discussion forum
Hi community members! Please use this board for discussions on the below topics: Onboarding, licensing and setup: Such as HR data uploads, Organization File issues, or role assignment. Privacy: You can also use this forum to post questions about data privacy, i.e., where your data is stored and handled Please remember to review the general guidelines before posting. Note that this community is to share experiences and general questions only, please open a support ticket for specific questions on your organization's support issues.632Views1like0CommentsViva Insights Privacy Policies
How does Viva Insights anonymize data and ensure companies' data remains private? Supporting Documentation: Advanced insights privacy | Microsoft Learn Personal data (highest risk) - By default, Viva Insights does not include personal data. When it processes data, it obscures the email addresses from Microsoft 365 that would identify an individual. However, your organization can choose to also provide descriptive employee information for analysis. If that includes personal data (for example, employee names and identification numbers), that personal data can appear to analysts in advanced insights. De-identified data (higher risk) - Viva Insights automatically replaces email addresses with cryptographically obscured strings of numbers and letters when it processes Microsoft 365 data. These de-identified rows reduce the likelihood that an analyst can identify a specific person. However, the Insights Administrator can upload custom organizational data fields. These custom fields may contain new identifying information orprovide enough descriptive context that an analyst may be able to infer identity. The Insights Administrator should weigh the risk and benefit of custom organizational data fields. Aggregated data (lower risk) - Viva Insights often provides averages for groups within your organization. When these groups include many people, it's difficult to derive information about any specific person’s activity from these averages. However, if a user can see results for very small groups or compare averages for overlapping groups, they may still be able to identify a specific person from aggregated data. Aggregated data can be further protected to reduce the possibility of an individual being identified. Organization insights provide leaders and managers with protected results by enforcing three strategies: minimum group sizes, differential privacy, and masked distributions. You can learn more about these techniques inProtecting sensitive data.General questions about data processing
Does Viva Insights take into account information related to the geolocation of people who use outlook or teams? Does Viva Insights take into account information related to the device of people who use outlook or teams? (For example, if the activity carried out by a certain employee has been carried out from a mobile device or a computer? If so, is information obtained that allows identifying the specific device from which the activity is carried out (for example, if IMEI or IP address is registered) It has been indicated that, among the data to be processed from team meetings, is the “status” of the participants. What does it mean? Is it available/absent/busy or other? Is this information only about participants who are inside meetings? Or also as long as they have the application turned on? Regarding instant messages that are monitored through Viva Insights: is only the sender and the time of the first delivery monitored? or something else? Can the number of emails needed to close a message thread be tracked? What does the concept of “calendar metadata” refer to, which is supposed to be part of the information that is analyzed under the Viva Insights service?Solved3.1KViews1like6CommentsPrivacy Settings and Exclusions
How does a company exclude the following information from analysis: Certain email domains (eg, @gmail, @yahoo, etc.) Emails from external employees who have an account with the Company's domain The subject of emails Employee activity that took place on a certain date and time (eg exclude activity carried out at night or on weekends)Solved2.7KViews0likes4Comments