Terms and conditions

ENSURESEC Participant Information Sheet

You have been invited to be a participant in a research activity carried out in the scope of the EU- funded project ENSURESEC. This document intends to provide you with detailed information concerning the research, in order for you to be able to take an informed decision on whether or not to participate.

Before making a decision, it is important that you clearly understand the purpose of the research and what it would involve for you. As such, please take time to read this document carefully and ask all the questions you may have so you can be completely sure that you understand all the proceedings of the research, including any potential risks and benefits it may entail.

This information document may include terms or concepts that you do not fully understand. If this is the case, please ask the contact person or any other member of the team coordinating the activity to fully explain it or clarify pieces of information.

At all times during the foreseen activities and afterwards, the ENSURESEC Consortium assures the compliance with the relevant national and European legislation.

1. Key Information About the ENSURESEC project

Project Title: ENSURESEC – End-to-end Security of the Digital Single Market’s E-commerce and Delivery Service Ecosystem

  • Funding Program: Horizon 2020
  • Grant Agreement No.: 883242
  • Start Date: 1st June 2020
  • End Date: 31st May 2022

Project Coordinator: INOV – Instituto de Engenharia de Sistemas e Computadores Inovação (PT) Website and contact: https://www.ensuresec.eu/

You are invited to take part in the testing of the ENSURESEC-solution. This form contains information which is intended to help you to make a decision if you join the study.

1.1. Key Information

1.1.1. What is the ENSURESEC project

ENSURESEC is an innovation project funded by the Horizon 2020 research and innovation programme of the European Commission, under Grant Agreement no. 833242. The project is being undertaken by a consortium of 22 organisations from 14 European countries, including large industrial partners, Small and Medium Enterprises (SMEs), research centres and universities. It will have a duration of 2 years, having started in June 2020 and being expected to end in May 2022.

ENSURESEC is a security solution which protects e-commerce operations from cyber and physical threats. In order to do this, it monitors the whole e-commerce operation, from browsing to delivery. It identifies cyber and physical threats, and responds to and mitigates those threats. The ENSURESEC project is a project funded and under the supervision of the European Commission, in order to develop and test the ENSURESEC solution.

1.1.2. Additional Information
  • If you choose to participate, you will be asked to be part of a series of experiments.
  • These activities will take place online.
  • Risks or discomfort from participating in the testing may include being initially unaware the experiment is not a scam.
  • The direct benefits of your participation derive from the feedback received by you as a user of the ENSURESEC solutions.

Taking part in this research project is voluntary. You do not have to participate and you can end your participation at any time. Please take the time to read this entire form and ask questions before deciding whether to take part in this research project.

2. Purpose of the study

The purpose of this study is to raise awareness about cyber-security in general, and specifically also information about ENSURESEC

3. Who can participate in the study

3.1. Who can take part in the study? The recruitment criteria for participation are the following:

Persons who are 18 years or older (non-minors according to the applicable national legislation)

4. Information about participation in the study

4.1. What will happen to me in this study?

  • You will be asked to read all the forms provided to you and to give explicit consent to the requests in it if you want to participate
  • You will be invited to fill the online questionnaire and you will receive some fake scams by email to test your awareness of cybersecurity after you enrol until May 2022
  • Feedback on your experience as a user will be collected.

4.2. How much of my time will be needed to take part in this study?

Responding to the survey would take 2-5 minutes and beyond this very minimal, we estimate at the very maximum 30 minutes of your time in total could be taken over the course of the full delivery of experiments. This assumes you engage with all our deliveries of fake scams.

4.3. Why am invited and how will my contribution be used?

You have been invited because you meet the recruitment criteria mentioned in Section 3 and your contribution will help us to improve our project.

4.4. If I decide not to take part in this study, what other options do I have?

You are not obliged to participate. Your participation is fully voluntary, and your consent to it can be withdrawn at any time. No consequences will follow your withdrawal. If you withdraw your consent after study and the researchers have already used your information in a research analysis, it will not be possible to extract the information and remove it.

5. Information about study risks and benefits

5.1. Your rights

If you agree to participate in this study, please understand that your participation is voluntary (you are not obliged to participate, nor will refusal to participate have any consequences). You have the right to ask questions and receive understandable answers before making any decision. You have the right to withdraw your consent or stop your participation at any time without penalty and without stating a reason. You may leave the meeting at any time.

You have the right to access, update, correct and erase all personal data. As to the qualitative information that you provide us with, you have a right to withdraw the same up to the point of publishing the information in the relevant deliverable. A member of the consortium will inform you as to the planned publication date.

You have a right to lodge a complaint, to do so please contact the project coordinator (details below).

You can read more about the information that will be collected about you in Section 7 and in the Data Protection Policy.

5.2. What risks will I face by taking part in the study? What will be done to protect me against these risks?

The risks related to participating in the testing are minor, but we are required to inform you about any potential risks included. In principle, risk of breach of confidentiality in the handling of your personal data may lead to personal data breaches. Because this study collects information about you, one of the risks of this research is a loss of confidentiality. See Section 7 of this document and the Data Protection Policy for more information on how the study team will protect your confidentiality and privacy.

The following measures will be taken by the researchers to minimize the risks described above:

  • Voluntary participation. Participation in the ENSURESEC resting is voluntary, and will be carried out free from any coercion or risk.
  • Acknowledgement of ethical and legal framework by partners. All partners involved will acknowledge the principles and the legal framework that apply to responsible research and innovation.
  • Explicit acknowledgment of mitigation measures against imbalance of power employer – employee. An explicit and expressed acknowledgment will be provided to you. This acknowledgment will confirm the commitment of the employer to avoid every potential detrimental effect for you and the appraisal of your performance in the case you want to abstain or suspend your participation to the testing.
  • Data Protection policy. A Data Protection Policy will be applied to the testing of the ENSURESEC solution.
  • Accountability and documentation. Informed consents (participants of the study), and acknowledgments of the power imbalance (consortium partners) and of the mitigation measures will be signed by the involved partners and subjects and made available upon request for auditing purposes.
  • Security of retention. Relevant documentation (including your personal data) will be stored securely and access will be provided on a need-to-know basis only. Retention periods of consent forms will last [until the termination of the project/to be specified].
  • Awareness raising. Employees and employers are made aware of risks and mitigation measures foreseen for the participation in the testing. Awareness campaign may include information notices

5.3. What are the benefits of the participation in the study?

None of the participants will be paid for their participation.

1) Complementary Cyber Security training

6. Ending the study

<6.1. If I want to stop participating in the study, what should I do?

You are free to end your participation in the study at any time. There will be no consequences to you for leaving the study before it is finished, even id mid-testing. If you decide to leave the study before it is finished, please tell one of the persons in charge of conducting the testing. If you choose to tell the researchers why you are leaving the study, your reasons may be kept as part of the study record. The researchers will keep the information collected about you for the research until the end of the project, unless you ask us to delete it from our records. If the researchers have already used your information in a research analysis it will not be possible to extract the information and remove it.

7. Protecting and sharing research information

7.1. How will the researchers protect my information?

Every effort will be taken to protect your identity. You will not be identified in any report or publication of this study or its results.

Please consult data protection policy (attached here) for a full picture on how we process and protection your personal information. However, please note, that the following considerations apply.

7.2. What information about me will be collected?

If you agree to take part, any personal information (e.g., name, contact details) that will be collected from you is for our internal processing and administrative purposes only, and to enable us to contact you if we require further information. Your details will be kept for a maximum period of 12 months following the end of the research project. Unless you prefer otherwise, we will not publish any information in reports or communications materials that would enable you to be directly or indirectly identified.

7.3. Who may access my information?

We will disclose your information if the European Commission, who is funding this research, requests information for auditing purposes or to evaluate our procedures.

Within the consortium partners, your information will only be accessible on a need-to-know basis. Please also consult our Data Protection Policy, which will be provided to you by the partner.

7.4. What will happen to the information collected in this study?

We will keep the information we collect about you during the research period (until June 2022). If required, we may retain the information for a year after its termination. By then, all personal data will be deleted. Your name and other information that can directly identify you will be stored securely and separately from the research information we collected from you. However, it is not in our objectives to identify you. We will therefore apply anonymization and minimization techniques in order to minimize any risk of confidentiality breach or unintentional data breach.

7.5.Will my information be used for future research or shared with others?

We do not plan to share your identifiable information with other researchers for future research. If otherwise, we will ask for your consent.

7.6. Where can I find more information?

Please consult our data protection policy and our consent form for processing of personal data for more information about how we handle personal data. You will also be asked to consider our data protection policy and provide your consent thereto, before participating in the study.

8. Confidentiality of the Research/Pilot Study

The reports on the execution of the pilots will be confidential. However, the report on the evaluation of the pilots will be public.

Your data will always be kept confidential.

9. Contact information

9.1. Who can I contact about this study?

Please contact the researchers listed below to obtain more information about the study:

  • Ask a question about the study procedures
  • Leave the study before it is finished
  • Express a concern about the study

If you have questions about your rights as a research participant, or wish to obtain more information, ask questions or discuss any concerns about this study with someone other than the researcher(s), please contact the following:

ENSURESEC Coordination team email – ensuresec.coordination@inov.pt