2.5 Data Collection Strategies, Privacy & Confidentiality
Key Takeaways
- Active data collection requires intentional interaction (surveys, interviews, observation with awareness); passive collection harvests existing traces (mobile location, smart-card boardings, web analytics) and raises distinct consent and privacy issues.
- Method choice should match the research question: secondary data for scale, field observation for physical conditions, surveys for attitudes and behaviors, and participatory methods when local knowledge or trust is essential.
- Privacy protects individuals' control over personal information; confidentiality is the planner's duty to safeguard data entrusted in professional work—AICP ethics allow disclosure only for compelling public purpose or legal requirement.
- IRB-like ethics—informed consent, minimization, purpose limitation, secure storage, and careful sharing—apply to resident data even when a formal Institutional Review Board is not involved.
- Open data improves transparency and reuse, but sensitive data (precise locations of vulnerable people, health status, immigration indicators, child locations) require aggregation, access controls, or withholding.
Choosing How to Collect Evidence
Data collection is the bridge between research questions and defensible findings. For AICP, you are expected to match strategy to purpose, recognize active versus passive modes, involve communities appropriately, and handle privacy, confidentiality, and sensitive data with ethical care. Sloppy collection produces biased assessments; unethical collection can harm residents and violate professional rules even when the maps look polished.
Active vs. Passive Collection
Active data collection involves intentional interaction or designed observation:
- Household or intercept surveys
- Structured or semi-structured interviews
- Focus groups and listening sessions
- Windshield / walking surveys and systematic field observation
- Participatory mapping, photovoice, and community audits
- Traffic or parking counts staff deliberately schedule
Participants (or observers) generally know—or can be informed—that research is happening. Active methods support informed consent, tailored sampling, and questions that secondary sources never ask ("Would you use a protected bike lane here?").
Passive data collection harvests digital or administrative traces people leave while living their lives:
- Mobile-phone or app location traces for origin–destination patterns
- Transit smart-card or automatic passenger-count boardings
- Website, 311, or social-media activity logs
- Utility smart-meter or sensor streams
- Commercial "big data" mobility products
Passive methods can be continuous, large-scale, and behaviorally realistic, but people often did not consent specifically for planning research, samples can be biased toward smartphone users, and re-identification risk rises when fine-grained locations are retained.
| Mode | Strength | Primary risk |
|---|---|---|
| Active | Consent, tailored questions, qualitative depth | Cost, low response, self-selection |
| Passive | Scale, temporal detail, revealed behavior | Privacy, bias, weak consent, opaque vendors |
| Secondary (Census, ACS, open portals) | Efficient baselines, comparability | Currency, ecological fallacy, missing local nuance |
| Administrative (permits, 911, tax) | Real system performance | Access rules, incomplete coverage, misuse |
Exam cue: a city buying anonymized cell-phone OD data is classic passive collection with privacy and confidentiality as the first ethical concern—not that the data are "too accurate" or that community involvement is somehow excessive.
Community Involvement Methods as Collection Strategies
Community involvement is not only a democratic value; it is a collection method when the research question requires local knowledge:
- Use surveys for prevalence of opinions or reported behaviors across a sample.
- Use interviews / focus groups for meaning, trade-offs, and narratives behind the numbers.
- Use community mapping to locate assets, hazards, and desire lines staff cannot see from the office.
- Use walking audits with residents to ground-truth sidewalk, lighting, and access barriers.
- Use partner-led collection (CBOs administering instruments) when trust barriers block city staff.
Good design still applies: clear purpose, pilot-tested instruments, sampling that matches the population of interest, documentation of nonresponse, and a plan for returning results. Do not confuse a viral social-media poll with a representative survey.
Secondary and Field Methods You Must Recognize
- Secondary data review — efficient first pass; check currency, geography, definitions, and methodology before relying on it.
- Windshield / walking survey — rapid field observation of land use, building condition, streetscape, activity; preliminary, not a substitute for engineering surveys when precision is required.
- Inventory / audit tools — structured checklists (ADA curb ramps, park amenities, vacancy) improve reliability across observers.
- Mixed methods — combine quantitative scale with qualitative explanation; mixed designs often outperform single-method assessments for complex urban questions.
Privacy and Confidentiality
Two related but distinct duties:
- Privacy — individuals' interest in controlling personal information and limiting unwanted observation or disclosure about themselves.
- Confidentiality — the professional obligation to protect information entrusted to the planner or agency and to limit use to the legitimate purpose for which it was obtained.
Under the AICP Code of Ethics, planners must maintain confidentiality of privileged information obtained in professional activities, with the important caveat that disclosure may be warranted when it serves a compelling public purpose (for example, imminent public health or safety risk) or is required by law. That is not a license for casual sharing of survey microdata, address-level vulnerability lists, or client strategy documents.
Practical controls:
- Collect only what you need (data minimization)
- Prefer aggregate reporting (block-group or larger) over household or person-level maps when possible
- De-identify or code responses; store keys separately
- Restrict access on a need-to-know basis; use secure storage
- Set retention limits and destroy or archive under policy
- Be careful with small-cell tables that re-identify rare populations
- Scrutinize vendor contracts for secondary use of resident data
IRB-Like Ethics Without Always Having an IRB
University researchers often need Institutional Review Board (IRB) approval. Municipal planning studies may not always trigger a formal IRB, but the ethical principles still apply when collecting information from or about people:
- Respect for persons — voluntary participation, informed consent where appropriate, extra care with vulnerable populations.
- Beneficence — maximize benefits of knowledge, minimize risk of harm, stigma, or retaliation.
- Justice — fair distribution of research burdens and benefits; do not over-research the same marginalized neighborhoods without returning value.
In practice, planners should explain purpose, use, voluntary nature, and confidentiality limits in plain language; avoid coercive "you must answer to get services" designs unless legally required and carefully bounded; protect minors and other vulnerable groups; and plan for harm (for example, do not publish a map of undocumented households' addresses).
Open Data vs. Sensitive Data
Open data policies publish government datasets for transparency, innovation, and accountability—parcel maps, budget tables, aggregated crash counts, zoning layers. Openness is a public value, but not all planning data should be open.
Sensitive data typically include:
- Precise locations of domestic violence shelters, safe houses, or at-risk individuals
- Health, disability, or substance-use details tied to persons
- Immigration / documentation indicators
- Data on children (schools + home locations in fine detail)
- Individually identifiable survey responses on income, trauma, or legal status
- Infrastructure details that create security risks when combined
Strategies for sensitive content: aggregate, suppress small cells, shift or generalize points, use secure data rooms, require data-use agreements, or withhold. Anonymized is not always anonymous—mobility traces can re-identify people when linked with other datasets.
Worked Scenario
A transportation division wants to know evening bus reliability in a low-income corridor.
- Passive: automatic vehicle location (AVL) and fare-card boardings → strong operational performance measures; scrub or aggregate personal identifiers; watch for underrepresentation of cash payers if the system is card-heavy.
- Active: intercept surveys at stops + focus groups with night-shift workers → explains why missed trips matter (childcare pickups, safety while waiting).
- Community method: riding audits with riders and a community organization → documents lighting and waiting conditions AVL never captures.
- Ethics: publish route-level on-time performance as open data; do not publish person-level card histories; report survey results in aggregate; disclose purpose at the stop interview.
Common Exam Traps
- Treating passive big data as automatically superior or ethically clean
- Confusing privacy (individual control) with confidentiality (professional safeguarding)
- Assuming open-data culture means every layer can be public
- Using windshield surveys as engineering-grade measurements
- Collecting sensitive attributes "just in case" without a purpose or protection plan
Bottom line for AICP: Choose collection methods that fit the question, combine community knowledge with technical sources when needed, and treat resident data as an ethical trust—actively protecting privacy and confidentiality while distinguishing what should be open from what must stay protected.
A city purchases commercial mobile-phone location products to estimate origin–destination patterns without surveying residents. Which characterization is most accurate?
Under the AICP Code of Ethics approach to privileged information, when may a planner disclose confidential information obtained in professional work?
Which dataset is most appropriate to publish as open data without additional protection, assuming standard aggregation practices?