Get a first impression, scheduled soon.
Request a demo to see how NIPO can help you meet your requirements with our smart survey solutions.
ISO/IEC 27001 is the world’s best-known standard for managing information security. Satisfying its stringent specifications is essential for any organization that is entrusted with large amounts of user data, as we are here at NIPO.
Security and compliance have been core pillars of NIPO’s Nfield platform ever since it was launched in 2011. Having secured our first ISO 27001 certification back in 2013, we have continuously maintained it through rigorous annual audits.
Following intensive work upgrading our systems to conform with the latest ISO standards, we’re delighted to announce that NIPO has transitioned to ISO 27001:2022, with certification confirmed by SGS on 17 July 2025.
This is not just a milestone for NIPO; it directly benefits all Nfield users. We know this certification is increasingly vital for securing new projects, as clients rightly demand assurance that their data is safe and secure. With Nfield, that assurance is guaranteed.
The ISO/IEC 27001:2022 standard represents a substantial upgrade from the previous 2013 version. While the core framework remains intact, the 2022 revision introduces refinements that better align with today’s digital landscape and emerging threats.
Achieving this strategic information security management systems evolution required NIPO to undergo full recertification. A massive thank you goes out to the dedicated NIPO ISO Champions team for their fantastic work. Now, our business and our clients can truly benefit!
The certificate can be downloaded on the Compliance section of the Nfield Trust Center.
Validity of NIPO’s ISO certificate can be checked here:
https://www.sgs.com/en/certified-clients-and-products/verify-certificate?id=8d288c95-5220-4c5d-9947-bbe9655f78d9
Keeping your Nfield domain clean, as in removing all outdated surveys and corresponding data, is essential for maintaining compliancy with data regulations. But that’s not the only reason to stay on top of things. Limiting what you store to what’s absolutely necessary is also better for both data security and efficient working. Here’s why.
Standards such as GDPR mean all kinds of businesses around the world need to ensure some form of data compliance. As these regulations typically include restrictions on how long you’re allowed to hold on to third-party data, having a regular clear-out is essential. This is especially the case for market research companies, whose business is all about third-party data!
The more data you have stored in your system, the more there is to steal. Which means any security breaches will have a bigger and further-reaching impact. Given the large amount of sensitive personal data that’s typically associated with market research, surveys are a highly prized target, as explained in our recent article about the value of Nfield logins on the Dark Web.
It therefore makes sense for your survey respondents and your business reputation to delete surveys, and all their corresponding data, as soon as you’re finished with them.
Good to know: Nfield upholds the highest security standards, adhering to the protocol established in ISO 27001:2022. Read more about Nfield security. However, users still need to take responsibility for protecting passwords, deploying 2-factor authentication and ensuring there are no unprotected “back doors” into their systems.
The less clutter there is within your system, the less likely it is that any of your team members will refer to the wrong information. Clearing out outdated surveys helps keep everybody on the same page, making it easier to work together on updating surveys and making decisions. A practice which can result in better teamwork, improved efficiency, and better outcomes for your business.
Nfield’s acceptable use policy includes domain limits on storage and the number of active surveys for each license level. Keeping your survey system clean can help you avoid exceeding your limits and incurring additional charges.
As solid as the reasons for keeping your system clean are, actually doing it can be a cumbersome task, especially when dealing with outdated or expired surveys. This is why Nfield introduced a new automatic survey clean-up feature which deletes inactive surveys that have reached their expiration date.
Further details about Nfield’s automatic clean-up feature can be found in our Nfield update published recently. Or see the NIPO Academy #39 session recording on this topic.
Market research is nothing without data. But unexpected events such as system failures, cyber-attacks or even natural disasters can result in data being compromised, lost or stolen. Having both robust security and a solid disaster recovery (DR) strategy are essential for protecting your data and maintaining its integrity.
Procedures related to Nfield’s internationally recognized ISO 27001:2022 certification for information security keep your data safe from unauthorized access. At the same time, Nfield’s highly disciplined approach to disaster recovery nothing is lost or damaged when the unexpected happens. In the event of prolonged downtime, whether caused by technical failure or external threat, your valuable data remains safe, secure, and readily accessible. So, you don’t need to worry about delayed project delivery, losing client trust, or missing opportunities.
Nfield’s disaster recovery approach is designed with both data protection and business continuity in mind.
Nfield operates exclusively on Microsoft Azure PaaS, which incorporates redundancy at every level: servers, networks, and databases. In the event of a server experiencing downtime, your data and operations automatically transfer to a different server in the same Azure data center. As a result, we are proud to report higher than 99.98% availability of our Nfield Interview Service.
Nfield users can always see what’s happening via a real-time status page, which shows availability of critical Nfield services across our four regional deployments in APAC, Europe and Africa, Americas and China.
Nfield fully enables automated backups of all project data, including survey responses and configurations. These backups are encrypted to the highest standards and stored in multiple secure locations in Azure, so that even in the event of a major system failure, your data can be recovered.
This backup process is aligned with industry best practices, providing you with peace of mind that your valuable data is always protected.
To further enhance data security, Nfield employs full, real-time geo-replication in Azure. To satisfy compliance requirements, this takes place within the same region as users’ primary Azure Data Centers. This means that, even in the event of the most extreme of disasters, such as an earthquake bringing down an entire Azure data center, no data is lost. And the latest data recovery technology enables operations to resume in as short a time as possible.
Nfield’s disaster recovery procedures are periodically tested, validated and safeguarded by our ISO procedures. A combination that ensures they will always work effectively, as and when needed. The routine tests allow our team to identify and fix any potential vulnerabilities, so both they and the platform are always ready to recover from any outages.
Nfield’s disaster recovery strategy follows ISO 27001:2022 guidelines. This is, however, just one aspect of a larger and more comprehensive approach towards security. The Nfield platform’s focus on protecting data from breaches, loss, and unauthorized access is central to its design, reflecting an ethos that runs through the NIPO team’s DNA. Your data remains completely safe during both normal operations and disaster recovery. Learn more about Nfield data security.
Disaster recovery is a critical consideration for any SaaS platform provider, and a top-priority when data collection and market research are your business. We understand the questions your teams will be asked by their customers, procurement teams and security officers, and are happy to provide all the information you need to respond.
Also worth knowing, is that Nfield’s comprehensive disaster recovery framework is continuously evolving and improving as it benefits from Microsoft’s own massive investments in Azure and its software development suites. For full information on Microsoft Azure security and compliance, please refer to the Microsoft Azure Trust Center.
In short, Nfield is designed to prevent any disruption to your (market research) work, thereby ensuring your business continuity and operational resilience. NIPO’s commitment to Nfield’s security, compliance and reliability means you and your customers can rest assured that data is maximally safe, and projects will be delivered on-time. No matter what disrupting challenges may arise.
Keeping your valuable data safe is an absolute priority for us. It’s an obligation that guides everything we do when shaping and powering Nfield’s features. Every conceivable measure is taken to ensure both our team and our software solutions comply with the highest security standards.
Keeping your data secure depends on a wide range of measures working harmoniously together. A good way to visualize this is to imagine Nfield as a physical office building, where all the different market research and security departments are based. As with all commercial buildings, it is itself protected and complemented with off-site operations.

(click image to enlarge)
Our Information Security Management System is ISO 27001:2022 certified. The same as followed by our platform provider, Microsoft.
We maintain a strong security policy that ensures both your data, and our products are safeguarded round the clock. Independent security experts (ethical hackers) scrutinize our security procedures every year to evaluate our tools, processes and people. The measures to conform with ISO 27001:2022 for our Information Security Management System, as certified by an auditor (Auditor), are strictly followed in every wire connection and by every person in our company. As a matter of principle, the smallest possible number of NIPO specialists have access to Nfield’s infrastructure for carrying out deployments and maintenance. See the Nfield Trust Center where you’ll find information about NIPO practices related to security, compliance, and privacy, in the form of documents that can be shared with your clients.
Nfield runs on Microsoft Azure, the highly secured cloud known for its flawless, trusted performance, extensive data storage and reliability. Microsoft’s engineers work 24/7 to protect the cloud, scale its powers and administer other services which run on it, including Office365. For more information, please visit the Microsoft Trust Center for up-to-date details on policies, processes, and practices that help you manage data control and comply with industry and government regulations.
Nfield provides a number of different features that enable you to secure your domain to the highest level.
Two-factor Authentication (2FA): Nfield accounts secured with two-factor authentication require users to enter a code (a token) generated by a standard authenticator app on a mobile phone. This has the effect of complementing something you know (your username and password) with a code obtained through something you have (your phone). It effectively blocks any unauthorized access to your Nfield account, even from those who have obtained your username and password, as these people (or their machines) are unable to retrieve the second factor code from the phone. Your valuable Nfield fieldwork and respondent data is thereby protected from prying eyes. Learn more in our article Protecting your Nfield login with two-factor authentication.
Single-Sign-On (SSO): For enterprises, Nfield can be set up to use Office 365 accounts for Nfield login. Administration of your Nfield user accounts, for as many Nfield domains as you have, is centralized in your organization’s single-sign-on layer. In the case of an employee leaving the organization or other reason for revoking a person’s system access (e.g. because of a security breach), Nfield will automatically be included in the revoked permissions, with immediate effect from when the account in the single-sign-on layer is disabled or reset. With SSO, your password policy for accessing Nfield is automatically aligned with that of your organization.
Strong password policy: Nfield can easily be configured to comply with strong password policies. Domain administrators can set rules for things such as password expiration period, old password re-use and strong password requirements (e.g. minimum number of characters and different character sets). You should also regularly revalidate your authorized users and ensure immediate removal of departing employees.
Surveys contain valuable, and sometimes sensitive, information. It’s therefore essential to restrict access to certain parts of surveys to those who really need it to do their jobs. This is done by assigning users with specific roles which only allow access to designated areas and functionality. Find out more in our article Controlling access to survey rights. Setting the right access also limits the scope of risk in the case of data breach.
The hypothetical building we’ve used to illustrate Nfield’s operation is managed by NIPO, who take care of its security and facilities to ensure compliance with the highest security and privacy standards. Our Information Security Management System is ISO 27001:2022 certified. We have procedures for everything, encrypt your data everywhere, limit access across the board and continuously test for potential security flaws.
Your projects are stored in your own individual domain, inaccessible to anyone else – even our employees – unless explicitly requested by you for customer support purposes.
Nfield allows administrators to configure access on a user-by-user basis, defining the scope of activities every user is allowed to perform. Password requirements can also be set to enforce your chosen password policy, however strong you need it to be. All user actions are tracked and domain administrators can review them individually. The system automatically signs users out when inactive for more than 15 minutes.
Your collected data is stored in secure Microsoft SQL database servers and replicated in other data centers so it can be restored in the event of something going wrong. Microsoft security policies strictly regulate access to its data centers.
All your data is secured by SSL and encrypted, both at rest and during transfer, to protect it from sniffing.
Different countries and industries often have their own specific regulations when it comes to data storage. To comply with this, market research companies need to give careful consideration to where their respondent data is stored. To enable data storage compliance, we have developed the ability to separate survey deployment from storage of respondent data. This means it is now possible, for example, to deploy a survey from the Hong Kong SAR Microsoft Data Center and store the respondent data in the Singapore Microsoft Data Center. Find out more in our article Local Data Storage Compliance, around the World.
Tablet devices are desirable prizes for thieves. Their thin, lightweight nature also makes them easy to forget about and accidentally leave behind. Nfield therefore also deploys additional measures to limit the extent of data exposure risk due to being locally stored on a mobile device.
Nfield ensures the minimum amount of information possible is present on any mobile device at any given moment. Each device is only sent the surveys and associated respondent information specifically assigned to its user(s). Data that no longer needs to be accessible is removed as soon as possible.
The same mobile device can be shared by multiple interviewers. Each survey and its collected data is only accessible to the relevant interviewer, via their login credentials. Interviewers cannot review, start or modify any surveys not specifically assigned to them.
Nfield questionnaires are stored in an encoded proprietary format. The original script is never displayed in an interviewer’s device, so interviewers cannot make changes.
Fully compliant practices, means you can rest assured when it comes to data security. And with cloud-based operation delivering unbeatable cost-efficiency together with all the capacity you need, whenever you need it, Nfield is the ultimate solution for improving both your quality of work and your profit margins.
Trust is critical in market research, especially with regards to raw data. Your respondents trust you with all kinds of sensitive data about their lives, you need to be able to trust us to keep that data safe. That is why NIPO is committed to offering the most secure survey solutions for the professional market research industry. Our ISO 27001:2022 certification is strong and independent proof in how we are leading the area of data security.
Nfield includes features to assist you in your efforts to address GDPR controls. Such features include the ability to search cross surveys for respondents, to delete or pseudomize interviews and to anonymize data in surveys.
Our goal is simple: To provide functionality in nfield so our customers can address GDPR controls without having them compromise on data collection efficiency.
For this we created a booklet, we call it our Nfield GDPR toolkit, that highlights the Nfield features that can help you to address GDPR. A guide like this can never be 100% complete, so please feel free to reach out to your sales representative with any questions you might have around Nfield and its functionality.
Download your copy of the toolkit now:
https://support.nipo.com/Nfield/Nfield-GDPR-Toolkit_v2_18July2025.pdf
Please note that this toolkit is not a replacement for legal advice. We recommend that, in case you have not done so yet, you seek legal advice on how GDPR applies specifically to your organization, and how best to ensure compliance.
In the NIPO Academy 60 sessions we introduced new Quality Control features that were in preview mode at the time. Since then, we have added new options and have released all functionality to every user. In this session we cover all facets of Quality Control in Nfield, relevant to both Online and CAPI projects.
These Online features include:
After that, we end section specific to CAPI. Topics included here:
Keeping an eye on who has access to your Nfield domain, and which permissions they each have, may not always seem like a high priority. But this is key to maintaining security and operational efficiency. Why? Because the fewer people can get into your data and settings, the lower the risk of things going wrong.
Over time, team structures change, new users join your organization, and others leave. The number of people with unnecessary access to sensitive information and operational abilities can easily get out of control.
Failure to keep on top of this can leave you exposed to security threats and operational errors, whether accidental or malicious. From the curious team member who unwittingly alters an important setting, to the temporary external contractor whose devices are maybe less secure, or even the ex-employee with a grievance, every authorized user is a potential gateway to significant problems. But by minimizing your permissions and being vigilant about who has them, you can go a long way to protecting your interests.
Here are some easy-to-implement tips for keeping your Nfield access permissions up to date.
Set up a recurring task in your calendar to review user access and roles. For example, you could conduct a monthly or quarterly check to ensure only authorized personnel have access, and that their permissions align with their current responsibilities.
Former employees, contractors, or temporary users may no longer need access to your Nfield environment. Keeping these accounts active is a potential security risk and creates unnecessary clutter that impedes efficiency.
Steps to follow:


Roles should always be based on necessity. Nobody should be given permissions they don’t absolutely need to do their jobs. For a detailed list of permissions associated with each role, refer to the official Nfield documentation: Nfield Roles and Permissions.
You should regularly check the email setting for the DA (Domain Administrator) system login to ensure the details are still correct, in case there has been a change of personnel or responsibility. You can find this in Nfield Manager under Access. If Single Sign-On (SSO) is in use for logging in, the information in this setting should still be checked regularly. At the present time, this is used to determine where automatic cleanup emails are sent.

Ensure all stakeholders are informed about any changes to access permissions. Transparency helps maintain efficiency and prevents workflow disruptions.
We recommend you
Access to your Nfield domain is a highly valuable thing. If it falls into the wrong hands, however unintended the route, your operation can be thrown into complete disarray. Our article Your Nfield Login’s Value on the Dark Web explains the temptation for bad actors to get into your data.
As well as keeping a tight grip on who has access at different permission levels, users are urged to also strengthen login security as described in our article Protecting Your Nfield Login with Two-Factor Authentication.
The best practices described in this article shouldn’t take up much time, but will contribute a lot to your Nfield environment’s security.
Start today by setting a reminder for your next access review, and make it a regular habit!
To be of real value, market research has to be cleaned of invalid responses, such as non-genuine answers and submissions from outside a required geographic region. While you can’t (yet!) put responses through a lie detector test, there are still many ways to identify rogue submissions.
Following the Quality Control tips below will help you catch responses that are deliberately or accidentally invalid. And, thanks to recent improvements to Nfield’s Quality Control feature, taking action is easier than ever.
Here are measures you can take to safeguard survey response quality, followed by a guide to using Nfield’s improved Quality Control feature.
Set clear data quality benchmarks
Establish predefined criteria for acceptable completion durations, location accuracy, and logical consistency within sets of answers. See below for examples.
Check completion durations
Check for questionnaires that have been completed within an unreasonably short time. For example, if a survey is estimated to take 10 minutes, any that are completed in under two minutes should be flagged for review.
Leverage location data
Verify that respondents are within the target geographical area. For example, if a CAPI survey delivers responses from Birmingham when the target area was London, those responses should be flagged for further review.
Monitor response patterns
Identify anomalies such as straight-lining (choosing the same answer for all questions), contradictory responses, or unusual answer distributions. For instance, if a respondent selects both “Strongly Agree” and “Strongly Disagree” for similar questions, their responses should be reviewed.
Use attention checks and red herring questions
Embed control questions to detect (unintentionally or deliberately) inattentive respondents. For example, a question could instruct, “Select ‘Strongly Agree’ as your answer for this question.” If a respondent fails this check, their survey submission can be flagged as potentially low quality.
Review open-ended responses
Ensure meaningful engagement by analyzing open-text answers. Responses like “asdasd” or “12345” indicate respondents are not making an effort to answer properly.
Combine automated and manual reviews
For optimum results and efficiency, use a mix of manual and automated Quality Control techniques. For example, automated tools can be developed to detect questionnaires that were completed too quickly, while researchers can manually verify the status of flagged responses.
Act fast on low-quality responses
Ensure unreliable responses are filtered out before finalizing data analysis. Removing inconsistent data promptly prevents derivation of misleading insights and improves overall research quality.
With Nfield’s updated Quality Control feature, market researchers can drill down into each interview to see details such as responses, location, duration and other key insights. Any interviews that appear suspicious can easily be flagged for further quality control checks and possible removal.


NOTE: Nfield doesn’t currently include automated Quality Control tools. However, custom scripts for these can be inserted into Nfield.
This latest enhancement reflects NIPO’s commitment to helping market researchers collect and manage the highest-quality data. With greater transparency into individual interviews, you can improve data integrity, identify potential issues faster, and enhance the reliability of your research.
Try the new Quality Control feature in Nfield today and experience the difference! If you have any questions or feedback, feel free to reach out to our support team!
Nfield has introduced new capabilities for conducting quality checks on interviews, allowing users to approve or reject interviews based on quality status. While the development of these features is ongoing, they are already available for user feedback, with options for additional features upon request. This series of NIPO Academy sessions will guide users through the new quality states, paradata for checks, and accessing interview answers directly from the Nfield Manager.
Our CAPI client has always supported an interviewer login with a username and password. As we noticed that many users treated this logon as access to a tablet rather than for a single interviewer, we decided to facilitate this use by creating a specific device logon. In this series of NIPO Academy sessions we will explain the pros and cons of both logon methods and explain how to configure the device logon for your devices.
Nfield CAPI for Android is the leading face-to-face interviewing app for conducting high-quality market research surveys in conjunction with the Nfield data collection platform. Nfield CAPI for Android is normally downloaded from Google Play and other recognised app stores. However, because these app stores are becoming less accessible in China, Chinese market researchers are finding it difficult to download the Nfield CAPI app.
To solve this problem, NIPO created the Nfield CAPI Android Client Download Center, from where our Chinese users can easily obtain Nfield CAPI for Android and update it with the latest version.
Outside of China, Nfield CAPI for Android remains available for download via Google Play.
The China-specific version of the Nfield CAPI app will automatically prompt users to download updates when they become available. So you don’t have to worry about missing out on the latest enhancements.

The Nfield CAPI app for Android is designed to make professional market research fieldwork easier, faster and more secure.
Follow the guidance below to avoid problems with the Nfield CAPI Android app (China), and benefit from new features and performance improvements as they are introduced:
The Nfield CAPI Android Client Download Center is a significant step that ensures market research interviewers in China get to enjoy the same seamless experience as other Nfield users around the world. This dedicated platform provides reliable access the latest app versions for China, even when regular app stores are not accessible or do not function properly. Visit https://capi-app.nfieldcn.com/ today to keep your Nfield CAPI app updated!
For further assistance, reach out to your market research company or contact our helpdesk.
With the *ID command you can add an extra (descriptive) id to ODIN questions and codes; and then use this identifier in your script and/or reporting instead of question/code numbers.
You can also use this *ID on *PAGE and *MATRIX which makes it possible to directly refer to this *PAGE or *MATRIX, which means that you can now directly translate these too.
In this series of NIPO Academy sessions we will take you through all the details of this new command.
This NIPO Academy session is organized to bring you up to date with what information Android nowadays returns and how to use the new continuous tracking function in your reporting and scripts.
GPS logging is a game-changer when it comes to improving accuracy, reliability and relevance of market research surveys. From conducting face-to-face interviews to mystery shopping and retail store auditing, GPS logging brings additional layers of insight that let you work smarter and deliver more meaningful results.
Here’s an overview of what GPS logging is, and how it benefits market research.
GPS logging is the process of capturing and storing geolocation coordinates at the point where market research interviews are conducted. These coordinates are tied to the survey responses, providing precise geographical context.
GPS logging leverages existing GPS functionality in the smartphones and tablets used to record interview responses.
GPS logging provides a powerful means of validating survey data and assuring its integrity. It enables researchers to track exactly where fieldwork is being carried out, to ensure it’s taking place in the intended locations. For example, in mystery shopping or retail audits, GPS coordinates can confirm that interviewers actually visited the specified stores or locations. Using GPS logging thereby reduces the risk of fraudulent or fabricated data, which is the case when surveys are filled out remotely instead of at the designated site.
Because GPS logging enables researchers to map survey responses geographically, it also delivers insights into regional or location-specific trends. For example, a beverage company may discover that consumer preferences vary significantly between urban and rural areas, and this helps them fine-tune their distribution strategy.
For studies involving large-scale field teams, GPS logging enables real-time tracking of interviewer activity. This is helpful for ensuring full coverage of assigned areas, as supervisors can monitor progress and adjust fieldwork schedules dynamically to optimize efficiency.
GPS data can also be enriched with external geospatial datasets, such as demographics, traffic patterns, or weather conditions. This adds another dimension to market research insights, revealing correlations that might otherwise go unnoticed.
In summary, GPS logging enhances market research survey quality and efficiency in many ways, making the results even more valuable.
GPS logging is easily applied in Nfield surveys via three different options:

Learn more about GPS logging and how to integrate it in Nfield surveys
To explore GPS logging in deeper detail and learn how to integrate it effectively into your market research activities, check out our NIPO Academy session Academy 57: GPS location fix.
At NIPO, we’ve always prioritized the principles of security, privacy, compliance, and transparency in everything we do. These values form the foundation of the Nfield platform, ensuring every user can confidently entrust us with their data. The Nfield Trust Center supports our commitment to these principles by providing access to all relevant documentation.
The Nfield Trust Center is a central repository for all information related to our practices around security, compliance, and privacy. It facilitates full transparency into how we handle and protect our users’ data, providing documentation that can also be shared with market research clients to demonstrate Nfield’s reliability.
The Nfield Trust Center provides access to essential documents and resources covering:
The Nfield Trust Center is a practical resource that market researchers can turn to for information, reassurance and guidance. It provides transparency which can be shared with clients, to breed the trust that is a cornerstone of successful partnerships and supports business growth.
Confidence-building transparency
Providing centralized access to all key documents and information, the Nfield Trust Center ensures researchers can obtain everything needed for building client confidence. Whether it’s a security policy, compliance certification, or privacy guidelines, it’s all here to view and share.
Authoritative reassurance
When market research clients have questions about data security, compliance, or privacy, the Nfield Trust Center equips Nfield users with clear and authoritative answers. As well as providing reassurance, this helps market research businesses demonstrate their own commitment to ethical and secure research practices.
Alignment with global standards
The Nfield platform is designed to meet or exceed international standards for data protection, including GDPR and ISO certifications. The Nfield Trust Center enables market researchers to confidently navigate and comply with these regulations, thereby reducing risk and fostering compliance.
NIPO is committed to continually enhancing the Nfield Trust Center, ensuring it remains a valuable resource for researchers worldwide. As we expand and refine our offerings, you can look forward to even greater transparency and support. Take a moment to explore the Nfield Trust Center and find out for yourself how it can benefit your market research business.
Request a demo to see how NIPO can help you meet your requirements with our smart survey solutions.