EP007
Publish only aggregated team metrics broadly and enforce access controls on individual-level data to meet GDPR data minimisation and purpose-limitation obligations.
CyberTRIZ analysis · Process contradiction EP007 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Greater Performance Transparency vs. Protection of Sensitive Operational Data
Business Context. Sharing process performance data broadly across the organization builds accountability and encourages improvement, but some performance data, such as individual employee productivity metrics, requires careful handling to avoid misuse or privacy concerns.
Process TRIZ Resolution. Rather than restricting all performance data to protect the sensitive minority, organizations should publish aggregate, team-level performance data broadly while restricting individual-level data to those with a legitimate management need to see it.
Applicable TRIZ Principles
Principle 3 (Local Quality) applies different access rules to aggregate versus individual-level performance data.
Principle 7 (Nested Doll) aggregates individual-level detail into broadly shared team-level reporting.
Principle 24 (Intermediary) uses an access-control layer to mediate who can view individual-level performance data.
Expected Outcome
Broad performance transparency
Protected sensitive individual data
Maintained accountability culture
Reduced privacy risk
Decision Indicators
Individual employee performance data is broadly accessible without a defined need.
Performance transparency initiatives have raised employee privacy concerns.
No aggregation exists between individual data and enterprise-wide reporting.
Access to sensitive performance data is not consistently controlled.
Employees report discomfort with how their performance data is shared.
If several of these indicators are present, the contradiction is likely active and the Process TRIZ resolution above should be evaluated.