Guidelines for using confidential data

As of October 2023, Statistics Estonia deploys a more powerful RDP* research work environment. This allows researchers to work with all datasets over VPN, including those datasets that were previously only available on a secure workstation at Statistics Estonia.

The guide below sets out everything you need to know to log into the RDP environment, as well as all the rules and requirements for using the environment. The specifics of using Windows and macOS are highlighted separately where relevant.

If you wish, it is still possible to work on a secure workstation at Statistics Estonia, and instructions on how to do this are given at the end of the guide.

For questions, suggestions, and problems, please contact us at stat [at] stat.ee (stat[at]stat[dot]ee). We will reply as soon as possible.

*RDP (Remote Desktop Protocol) connects two computers over the Internet, allowing you to log in from one computer to another (remote) desktop and work with programs and files on it.

arvuti
Installing and configuring the Ivanti Secure VPN software (macOS)

To install the Ivanti Secure VPN software, go to the RMIT cloud service page at https://pilv.rmit.ee/s/xZWLefGiNniTy7w. From there, select the installation package compatible with the computer's operating system, download and install it.

Administrator rights are required to install the software. To install, open the downloaded DMG and PKG file. In the window that opens, click Continue > Install.

In the new window that opens, enter the administrator password and click Install Software.
 

To configure the software, open the Ivanti Secure application from the Launchpad menu. Click the plus symbol (+) to add a connection to the research work environment.

The Connections window opens. In the Name field, type a connection name of your choice. In the Server field, copy and paste the URL https://vpn-ext.rmit.ee/arendus, then click Add.

The connection with the chosen name appears in the Ivanti Secure window Connections.

Installing and configuring the Ivanti Secure VPN software (Windows)

To install the Ivanti Secure VPN software, go to the RMIT cloud service page at https://pilv.rmit.ee/s/xZWLefGiNniTy7w. From there, select the installation package compatible with the computer's operating system, download and install it.

Administrator rights are required to install the software. To install, open the downloaded package by double-clicking on it, or right-click and select Install from the drop-down menu. In the window that opens, click Next.

In the window that appears, click Install.

To configure the software, open the Ivanti Secure application. Click the plus symbol (+) to add a connection to the research work environment.

The Add Connection window opens. In the Name field, type a connection name of your choice. In the Server URL field, enter https://vpn-ext.rmit.ee/arendus, then click Add.

The connection with the chosen name appears in the Ivanti Secure window Connections.

Establishing the Ivanti Secure VPN connection (macOS)

To establish a VPN connection, make sure your ID-card is in the reader. Launch the installed and configured Ivanti Secure VPN. In the Connections window, select the appropriate connection and click Connect.

 

N.B. If you receive a Connection Error message, you will need to authenticate the connection via your browser.

 

To do this, copy and paste the URL https://vpn-ext.rmit.ee/arendus into the browser window, which will open the Select a certificate window. From there, select the user’s ID-card and enter PIN1 in the window that appears.

In the new page that opens, click Start > Open IvantiApplicationLauncher.app

A green tick after the connection’s name and the Disconnect button in the Ivanti Secure window indicate that the connection is established.

Establishing the Ivanti Secure VPN connection (Windows)

To establish a VPN connection, make sure your ID-card is in the reader. Launch the installed and configured Ivanti Secure. In the Connections window, select the appropriate connection and click Connect.

Connections

A window appears asking for your ID-card’s PIN1.

Smart Card PIN 1

A green tick after the connection’s name and the Disconnect button in the Ivanti Secure window indicate that the connection is established.

Disconnect
Password change, incl. temporary password change before first login to RDP (macOS & Windows)

Using the research work environment requires two-factor authentication, so in addition to authenticating with an ID-card over the Ivanti VPN, you will also need to authenticate with the research environment username and password.

The password can be changed on the researcher portal at https://teadus.rmit.ee/. Log in with your username and password. Click Reset Password to change the password.

PAROOLI VAHETAMINE

Create a new password and click Submit. The message "Your password has been successfully changed" will indicate that the password has been changed. Click OK.

Password requirements

  • A password is valid for 180 days, after which you are prompted to change it when logging in
  • The last 6 passwords are stored – this means recently used passwords cannot be reused
  • The password must be at least 12 characters long
  • The password must contain upper- and lower-case letters and numbers
  • The password must not contain a username or easily derivable sequences (e.g. qwerty, 12345, etc.)

If upon login the password is entered incorrectly for five consecutive times, the account is locked for 3 minutes.

Changing a temporary password

N.B. Before logging into the RDP research work environment for the first time, the temporary password must be changed, as you cannot log in with a temporary password.

To change your temporary password, log in at https://teadus.rmit.ee/ with your username and temporary password. Click the link here to change the password.

SIISELOGIMINE

Create a new password and click Submit. The message "Your password has been successfully changed" will indicate that the password has been changed. Click OK.

Logging into the RDP research work environment (macOS)

In order to log into the RDP research work environment, an active Ivanti Secure VPN connection authenticated with an ID-card must be established.

To enter the research work environment, open the file named SA-Teadus.rdp, available for download  here:

In the modal window that opens, enter your username in the format teadus\forename.surname and password*. Click Continue.

A security warning window appears. As this is a secure server, you can continue logging in by clicking Continue.

N.B. It takes up to 2 minutes to log into the research work environment.

You are logged in when you see the research work environment desktop.

*Before the first login to the RDP research work environment, you need to change your temporary password, as this cannot be used to log in (see chapter “Password change, incl. temporary password change before first login to RDP (macOS & Windows)”)

Logging into the RDP research work environment (Windows)

In order to log into the RDP research work environment, an active Ivanti Secure VPN connection authenticated with an ID-card must be established.

To enter the research work environment, open the file named SA-Teadus.rdp, available for download here:

A security warning window appears. As this is a secure server, you can continue logging in by clicking Connect.

In the modal window that opens, enter your username in the format teadus\forename.surname and password*. Click OK**.

N.B. It takes up to 2 minutes to log into the research work environment.

You are logged in when you see the research work environment desktop.

*Before the first login to the RDP research work environment, you need to change your temporary password, as this cannot be used to log in (see chapter “Password change, incl. temporary password change before first login to RDP (macOS & Windows)”)

**If the login fails and you instead see the error message “This computer can’t verify the identity of the RD Gateway „sa.teadus.rmv“…”, you need to install the certificate certification-for-pc.cer, available for download here: https://pilv.rmit.ee/s/xZWLefGiNniTy7w. For more detailed instructions on how to install the certificate, see chapter “Installing the certificate before first use of the RDP research work environment”.

Installing the certificate before first use of the RDP research work environment (Windows)

To install the certificate, download the file named certificate-for-pc.cer and save it to your computer's hard drive. You can download the file here:

Open the file by double-clicking on it and in the modal window that appears, click Install Certificate.

The Certificate Import Wizard opens. Select Local Machine and click Next.

In the modal window that appears, select “Place all certificates in the following store” and click Browse.

In the modal window that appears, select Trusted Root Certification Authorities and click OK.

In the modal window that appears, click Next and then Finish.

Wait until you see the message “The import was successful”.

Try logging into the RDP research work environment again (see chapter “Logging into the RDP research work environment (Windows)”).

Session, terminating a session and disconnecting (macOS & Windows)

Your session starts when you log into the research work environment.

A session means that a computer in the research environment keeps your named account active and provides you with computing resources to do your work.

If you are not working, please log out of your account (Start menu → Your Name → Sign out), i.e. terminate your session to free up resources for other users.

Disconnecting means that the session remains running but the connection between your computer and the RDP research work environment is terminated.

You can disconnect by closing the RDP window by clicking the cross in the upper right corner or by selecting Start menu → Power → Disconnect. You will also be disconnected if you have been inactive for 15 minutes.

Disconnecting allows you to walk away from your computer and leave the software running in the RDP research work environment in order to come back later and resume the same session.

N.B. If your session remains active but you do not reconnect within 48 hours, the session will terminate automatically, and you will lose your unsaved work.

The following software is available in the RDP research work environment
  • Acrobat Reader
  • Anaconda
  • ArcGIS
  • EUROMOD
  • SPSS
  • STATA
  • R
  • LibreOffice
  • Notepad ++
  • Jupyter Notebook
  • Spyder
  • PyCharm
  • Python

 

Only a limited number of users can simultaneously use SPSS. In case of any problems, please notify Statistics Estonia’s contact person.

If you need to install additional packages or any other freeware, please notify Statistics Estonia’s contact person.

The RDP research work environment is connected to Statistics Estonia’s Intranet, there is no access to the Internet.

Structure of folders

Structure of folders

The research data folders and the users’ personal folders are stored on the drives This PC > Data_Terminal (T:) and This PC > Data_Local (L:) (the precise location will be delivered to the users along with the password), located on Statistics Estonia’s server.

The drives contain the following folders:

  • PROJEKTID – the users’ personal folders arranged by project for storing intermediate research results;
  • SAADA – for storing the files that the user wishes to receive;
  • UURINGUD – for research data and metadata.

Folder “PROJEKTID”

  • The subfolders in this folder include projects for which an agreement on the use of confidential data has been signed. The title of a given subfolder contains the abbreviated form of the name of the agency having applied for the use of data, a word characterising the relevant project, and agreement number (e.g. TY_NAME_16).
  • In the folder of each specific project, there are the personal folders of the users related to the particular project, and the folder “YHIS.”
  • Personal folders can be accessed only by the relevant user, while the folder “YHIS” can be accessed by all users working on the same project.
  • The folder “YHIS” can be used by the members of the project team for exchanging files. A researcher's own files, which he or she wishes to use in a secure computing environment, are placed in this folder (see chapter “Sending files necessary for work”).

N.B. Intermediate research results are to be stored in the folder “PROJEKTID”, not the My Documents folder or on Desktop. Files in a folder other than “PROJEKTID” will be deleted. Backup copies are made of the “PROJEKTID” folder.

Folder “UURINGUD”

This folder has survey-specific subfolders, the titles of which contain the name of the survey or an abbreviated form thereof (e.g. REL 2011 – data of the 2011 Population and Housing Census). Under every survey, there are the following subfolders:

  • META – descriptions of the survey databases, questionnaires, methodology specifications, other necessary metadata;
  • CSV – survey datasets in CSV format; 
  • TXT – survey datasets in text format;
  • SPSS – data of the respective survey in the SPSS format;
  • STATA – data of the respective survey in the STATA format.

All databases might not be available in all formats.

The user has access only to the survey databases which are, according to the agreement signed, necessary for the particular project.

The user has only the right to read the material in the folder. Any file where the user wishes to insert changes should first be copied into the user’s own folder or into the folder “YHIS”.

Receipt of results

What is a result?

A result can consist in frequency or volume tables, the results of a statistical test, regression analysis and other statistical analyses, figure, or any other type of text (e.g. an analysis or scientific article).

  • A frequency table contains the results of object enumeration, ordered by background characteristics.
  • A volume table contains totals, indexes, and ratios, calculated based on the individual data of some objects and ordered by background characteristics.
  • A figure (graph) is the result together with the table it is based on.

A frequency or volume table that is sent for reviewing can be multidimensional and hierarchical. A table can contain up to 2,000 cells, a text document can be up to 10 pages long. A raw data file does not constitute a result.


Saving a result for reviewing 

Statistics Estonia’s employees are able to review a maximum of 25 tables or figures per month. In order to have a result reviewed and sent to you, you will need to save the final non-confidential results (those which preclude indirect identification, i.e. are public) to the folder “SAADA” (see the rules in the section “Rules of statistical disclosure control”).

The result is to be submitted as a LibreOffice or Microsoft Office file. To save in Microsoft Office format, select Save As in LibreOffice and in the File Type window select the appropriate Microsoft Office format. The result needs to be supplemented with sufficient explanations, so that it would be clear which characteristics have been used in the analysis and in which way. The headings of rows and columns cannot be codes but need to be the actual names of characteristics (see Annex 1 – “Example of correctly formatted results”). If you still wish to use codes in the interest of brevity, the meaning of the codes is to be added as a separate table.

Results that you wish to have sent to you need to be copied or saved to the folder “SAADA.” The name of the result needs to feature an identifiable project name and the name of the user, so that it would be clear to whom the result is to be sent.

Once an hour, the files saved to the folder “SAADA” are transferred to Statistics Estonia’s server, after which the folder “SAADA” is emptied (files currently open are not transferred). In order to avoid any problems, keep a copy of the file in your personal folder as well. The file containing the program code will not be reviewed by Statistics Estonia’s employees and the file will be made available to the user only if it does not contain the result. If you have accidentally copied a wrong file to the folder, please notify Statistics Estonia at microdata [at] stat.ee (microdata[at]stat[dot]ee) and the specialists of Statistics Estonia will not review the file.


Rules of statistical disclosure control

Before making a result available to the user, Statistics Estonia’s employees will check whether the content of the result meets the confidentiality requirements and apply disclosure control methods.

  • In frequency tables containing personal data, frequencies 1 and 2 are confidential if they characterise a sample consisting of fewer than 2,000 persons. In the case of personal data of special categories, frequencies 1 and 2 are always confidential.
  • Tables which contain aggregate data on economic units may not contain figures which have been calculated based on the raw data of one or two units.
  • A table of aggregates may not have the value of one economic unit dominate a cell value, i.e. the share of the value of the largest unit in the figure presented in the cell may not exceed a certain percentage. The employees of Statistics Estonia will check the dominance criterion. Therefore, each aggregate table needs to be accompanied by a table with an analogous structure, containing the data of the largest unit of each cell in the aggregate table.
  • The minimum and maximum of the raw data are confidential and cannot be included in the result. The quantiles (median, quartiles, deciles, percentiles, etc.) may be confidential if found on the basis of a small number of units.
  • The salvage values of regression analyses and the figures of salvage values will not be published.

 

Making results available

Generally, a result will be sent to the user’s email address within three working days. In the case of extremely bulky files, the reviewing process may take up to ten working days.

According to the agreement of using confidential data, the user shall grant the publication of the result in a way which precludes the identification of a statistical unit.

Example of correctly formatted results
Table 1. List errors
  New sampling fraction Old sampling fraction Total
Persons % Persons % Persons %
Deceased respondents 6 5.9 17 38.6 23 15.8
Institutionalised persons 17 16.7 5 11.4 22 15.1
Persons abroad for at least one year 79 77.5 22 50 101 69.2
Total 102 100 44 100 146 100

Table 2. Regression analysis

The REG Procedure

Model: MODEL1
Dependent Variable: REG_MAKS

Number of Observations Read

5730

Number of Observations Used

69

Number of Observations with Missing Values

5661

Analysis of Variance
Source DF

Sum of

  Squares

Mean

Square

F Value Pr > F
Model 6 12949193 2158199 1.25  0.2940
Error 62  107113673 1727640    
Corrected Total 68 120062866      

Root MSE

 1314.39716

       R-Square

 0.4079

Dependent Mean

1558.74406

       Adj R-Sq

0.4005

Coeff Var

84.32412

 

 

Parameter Estimates

Variable

Label

 DF

Parameter

Estimate

Standard

Error

 t Value

Pr > |t|

Intercept

Intercept

1

884.58534

625.02961

1.42

0.0620

maakond37

1

556.12224

1454.27103

0.38

0.38

lk_tyyp_2

 

1

461.20247

598.68637

0.77

0.0040

lk_tyyp_4

 

1

-704.58534

1455.43873

-0.48

0.0630

eltyyp_4

 

1

-660.53787

516.23332

-1.28

0.0255

toimetulek_1

1

-423.43462

476.57359

-0.89

-0.89

arvuti

 

1

893.11491

614.38481

1.45

0.151

Explanation of characteristics

REG_MAKS – regular payments made to another household
Maakond37 – Harju county
Lk_tyyp_2 – one-member household with the member aged under 65
Lk_tyyp_4 – two-member household with both members aged 65 or over
Eltyyp_4 – apartment or a room in a residential building with fewer than 10 dwellings
Toimetulek_1 – household is having great difficulties with coping in terms of expenses
Arvuti –  household has a computer

Finishing work

After finishing work, please log out of the RDP research work environment using the Sign out command to free up computing resources for other users. If for some reason it is not possible to log out via the Start menu, you can alternatively use the key combination CTR+ALT+END (Windows) or CTRL+OPTION+BACKSPACE (macOS) and select Sign out from the view that opens.

Sending files necessary for work

If you wish to obtain a copy of your personal files necessary for work, send them to the address microdata [at] stat.ee (microdata[at]stat[dot]ee), specifying which project folder and which user folder the files need to be copied to. You can also have the files copied into the folder "YHIS". If a file with the same name already exists in the folder, it will be overwritten with the newer file.

Working on a secure workstation at Statistics Estonia

Booking of work sessions and cancellation of bookings

If you wish to use a secure workstation at Statistics Estonia, you can book and cancel a work session as follows:

  • by sending an email to the address Teadlasearvuti [at] stat.ee (Teadlasearvuti[at]stat[dot]ee), indicating the location where you wish to use a secure centre computer (Tallinn or Tartu), the date and time (start and end time);
  • by calling +372 625 9345; a booking confirmation will be sent to your email address.

On the basis of advance registration, workstations are available for use from 9 a.m. to 4 p.m. on working days. The next day’s workstation reservation must be submitted no later than by 12 p.m on the previous day.

If you are not able to be present at the agreed time, please cancel your booking using the above-mentioned email address or telephone number.

If the user does not cancel his/her reservation in advance on 2 consecutive occasions, further bookings will be cancelled.
 

Showing visitors to a workstation

In Tallinn, your visit will be registered based on a photo ID at the reception desk in the lobby and you will be given Statistics Estonia’s visitor card, which is to be returned to the reception desk at the end of your visit. A receptionist from Statistics Estonia will guide you to a researcher's workstation.

In Tartu, you will be received by an employee of Statistics Estonia who will register your visit based on a photo ID.


First-time use of researcher’s workstation

In order to log into the computer, you will be given a username and a password, which will be sent to you in an encrypted format after all the users listed in the agreement have sent a signed copy of the confidentiality agreement to Statistics Estonia.

If you have forgotten your password, please inform Statistics Estonia’s contact person at stat [at] stat.ee (stat[at]stat[dot]ee).

Contact us

For any problems, questions, or suggestions, please call +372 625 9300 or email stat [at] stat.ee (stat[at]stat[dot]ee)