Best practices

GDPR-compliant surveys: a practitioner's checklist

June 9, 20266 min read

A GDPR-compliant survey has a clear lawful basis for collecting personal data, asks for only what it needs (data minimization), tells respondents who you are and how their data is used, gets valid consent where consent is the basis, keeps the data only as long as necessary, and lets respondents exercise their rights (access, erasure, and more). If you can run the survey anonymously, much of GDPR's burden falls away — because GDPR governs personal data, not truly anonymous responses.

This is a practical checklist, not legal advice. GDPR is nuanced and your obligations depend on your role, your data, and your jurisdiction. For anything consequential, get advice from a qualified data-protection or legal professional. The goal here is to help you ask the right questions before you launch.

Does GDPR apply to my survey?

GDPR applies when you process personal data of people in the EU or UK — and personal data is broader than names and emails. IP addresses, device identifiers, and even a combination of demographic answers that could single someone out can count. If your survey is genuinely anonymous (no identifiers collected, no way to link answers to a person, demographics too coarse to identify anyone), GDPR largely doesn't apply to those responses, which is the simplest path to compliance when you don't actually need identity.

Establish a lawful basis

Every collection of personal data needs a lawful basis. For surveys, the two most common are consent (the respondent freely agrees) and legitimate interests (you have a genuine need that doesn't override their rights, documented in advance). Pick the right one before you launch rather than defaulting to consent for everything.

  • Consent — appropriate when you're collecting personal data the respondent isn't obliged to give; must be freely given, specific, informed, and unambiguous
  • Legitimate interests — may apply for, say, customer feedback tied to an existing relationship, but requires a documented balancing assessment
  • Contract or legal obligation — relevant in narrower cases where the survey is necessary to fulfill one

Get consent properly (when consent is your basis)

  • Use a clear, specific opt-in — no pre-ticked boxes and no bundling consent with unrelated terms
  • Separate consents for separate purposes (e.g., 'use my answers for this research' vs. 'add me to your mailing list')
  • Tell respondents what you collect, why, who sees it, and how long you keep it before they consent
  • Make consent as easy to withdraw as it was to give, and say how

Minimize what you collect

Data minimization is one of GDPR's core principles and also just good survey design: collect only the personal data you genuinely need for the stated purpose. Don't ask for a name, email, or precise demographics out of habit. Every identifying field you add raises your compliance burden and lowers respondents' willingness to answer honestly — so for each one, ask whether the analysis actually requires it.

Be transparent

Respondents have a right to know who's processing their data and why before they provide it. In or alongside the survey, make plain: who you are (the data controller), what you collect, the purpose and lawful basis, who you share it with (including any third-party tools), how long you keep it, and how to exercise their rights. A short privacy notice or a link to one, shown up front, covers this.

Set a retention period

You can't keep personal data forever 'just in case'. Decide before launch how long you need the data for the stated purpose, document it, and delete or anonymize responses when that period ends. Anonymizing data you want to keep for long-term analysis — stripping identifiers so it's no longer personal data — is often the cleanest way to retain insight without retaining risk.

Honor respondents' rights

GDPR gives people rights over their personal data, and you need a way to act on requests within the required timeframes.

  • Access — provide a copy of the personal data you hold about them
  • Rectification — correct inaccurate data
  • Erasure — delete their data on request (the 'right to be forgotten'), subject to exceptions
  • Restriction and objection — pause or stop certain processing, including withdrawing consent
  • Portability — provide their data in a usable, machine-readable format where it applies

Practically, you need to be able to find and delete an individual's responses on request — which means knowing which export rows belong to which person, or having run the survey anonymously so there's nothing to find.

Default to anonymous unless you have a concrete reason to collect identity. A truly anonymous survey — no name, email, IP, or unique per-person links, and demographics too coarse to single anyone out — sidesteps most of GDPR because there's no personal data to govern. Only collect identifiers when the analysis genuinely requires them, then apply the full checklist.

Watch your tools and data transfers

Your survey platform processes the data on your behalf, so it matters where and how it stores responses and whether data leaves the EU/UK. Check the provider's data-processing terms and where data is hosted. Note that Formkii does not hold enterprise compliance certifications, so for surveys with strict regulatory or contractual compliance requirements you should evaluate a platform that offers the specific guarantees you need. For lower-risk or anonymous surveys, the bigger levers are usually the design choices in this checklist — minimization, transparency, retention, and rights — rather than the tool alone.

A pre-launch GDPR checklist

  1. 1Decide whether you can run the survey anonymously — if so, much of this drops away
  2. 2Identify your lawful basis and document it
  3. 3Collect only the personal data the purpose actually requires
  4. 4Show a clear privacy notice and, if relying on consent, a specific opt-in before any personal data is collected
  5. 5Set and document a retention period, and a plan to delete or anonymize after it
  6. 6Make sure you can locate and delete an individual's data to honor rights requests
  7. 7Review where your survey tool stores data and whether that meets your obligations

Frequently asked questions

Do I need GDPR consent for a survey?

Only if consent is your lawful basis and you're collecting personal data — and that consent must be a clear, specific, freely given opt-in. Other lawful bases like legitimate interests can apply in some cases. If the survey is genuinely anonymous, GDPR largely doesn't apply, so no consent for data processing is needed. This is general guidance, not legal advice.

Is an anonymous survey GDPR-compliant by default?

A truly anonymous survey collects no personal data, so GDPR's obligations around lawful basis, consent, retention, and subject rights largely don't apply to it. The catch is making it genuinely anonymous: no names, emails, IP addresses, or unique per-person links, and demographics coarse enough that no individual can be singled out.

How long can I keep survey data under GDPR?

Only as long as you need it for the purpose you stated, which you should decide and document before launch. When that period ends, delete or anonymize the data. Keeping personal data indefinitely 'just in case' isn't compliant; anonymizing responses you want for long-term analysis is the cleaner option.

What data counts as personal data in a survey?

More than names and emails. IP addresses, device identifiers, and combinations of demographic answers detailed enough to identify one person can all count as personal data. That's why minimizing what you collect — and keeping demographics coarse — both reduces your GDPR burden and protects respondents.

This article was drafted with AI assistance. Third-party pricing and plan limits can change. Consult the linked official sources for current details.

Start building for free in under a minute

No credit card. No trial limits. Unlimited surveys, quizzes, polls, and responses — all free.