TSIA Benchmarking Data Protection Measures
TSIA conducts primary research studies throughout the year in each of its Research Areas. These studies, collectively called “Performance Optimizers” and “Benchmarking,” include the Researcher Led Benchmark, Self Guided Benchmark, and Free Benchmark in each Research Area.
In addition to the several layers of security afforded all member companies' confidential information and Personally Identifiable Information (PII) handled by TSIA (see “Information Security Measures”), the following measures are enforced with specific regard to benchmarking data:
Technology
There are multiple technologies employed in TSIA benchmarking: data collection (Supabase); ETL (Alteryx); analysis (LLM); and visualization (Tableau).
a. Hosting for the data collection technology resides in Supabase’s cloud data centers.
b. Hosting for the ETL technology resides on the TSIA corporate network.
c. Analysis of anonymized response data occurs through a TSIA-licensed large-language model (LLM).
d. Hosting for the visualization technology resides in Tableau’s cloud data centers.
See technology supplier websites for information security-related documentation.
Encryption
All benchmarking data is encrypted from the point of collection through to transmission and storage:
a. HTTPS and Secure Socket Layer (SSL) at the end user data collection interface
b. 256-bit encryption for data at rest
c. Technology suppliers’ HTTPS REST API for data transfer
Access
All TSIA employees are bound by the company’s agreements and restrictions on the handling of member confidential data, including non-aggregated benchmarking data. Access to collection, ETL, and visualization technologies is controlled by one member of the Data Analytics Team. User accounts are deleted upon employee termination. All internal TSIA emails pertaining to a member company’s benchmarking response refer to alphanumeric codes instead of member company names; actual member company names are never mentioned in emails.
Aggregation
Depending on the study, benchmarking data can be aggregated at the total study level and at “industry” and “peer group” levels. The minimum number of data points reported out as an aggregate number at the industry level is nine (9), and at the peer group level is six (6). Benchmarking data points that do not meet these minimums are reported as “Not Enough Data” (NED).
Transmission
To ensure that benchmarking data is not shared with the wrong party, all benchmarking materials are securely accessed via the Benchmarking section of the TSIA Portal. Benchmarking teams are assembled within the TSIA Portal, and only the designated Benchmarking team members have direct access to view and update benchmarking data.
If another employee from a participating member company requests information about the benchmarking results, they must be added as a Benchmarking team member within the TSIA Portal.
Retention
Performance Optimizer benchmark data is retained for 60 months from the collection date. Data older than 60 months is flagged inactive and archived from the benchmark database. Inactive/archived data can be restored if needed but is not used for industry or peer comparisons. Inactive/archived data can be expunged upon request by the contributing member company.
Effective Date: December 8, 2025