GDPR Compliant Survey Legal Basis, Consent, and Tool Requirements

GDPR Compliant Survey: Legal Basis, Consent, and Tool Requirements

Running a survey feels simple until you look at what GDPR requires. Names, email addresses, job titles, opinions, even IP addresses collected through a form all count as personal data. That means every survey, from a two-question customer satisfaction poll to a full employee engagement study, sits inside GDPR’s scope the moment it collects anything that can identify a respondent.

Most survey compliance failures come down to the same handful of gaps: no clear legal basis for collecting the data, sensitive questions asked without explicit consent, a survey tool that quietly stores or transfers data outside the EU, or no plan for how long responses will be kept. None of these requires a data breach to become a problem. A regulator or a complaint from a single respondent is enough to trigger scrutiny.

Key Takeaways

Every survey needs a lawful basis under Article 6 before collection starts. Consent and legitimate interests are the two most common choices, and each fits different situations.

Sensitive questions, including health, ethnicity, religion, or political opinion, need explicit consent under Article 9, not the standard consent used for ordinary survey questions.

Popular survey tools vary in how much compliance work they do for you. The data controller obligations stay with the organisation running the survey regardless of which tool is used.

Survey data has no fixed GDPR retention period. Organisations must set and document their own limit based on why the data was collected.

What Makes a Survey GDPR Compliant?

A GDPR compliant survey has four elements in place before the first response comes in: a documented lawful basis for processing, a privacy notice that tells respondents what happens to their data, appropriate security around collection and storage, and a retention limit that gets enforced rather than just written down.

Anonymous surveys that collect no identifying information at all fall outside GDPR’s scope, but true anonymity is harder to achieve than it looks. A survey that asks for job title, department, and length of service in a small company can still identify individuals even without a name field. If there is any realistic way to link a response back to a person, GDPR applies.

What Legal Basis Can You Use to Run a Survey?

GDPR requires a lawful basis under Article 6 before any personal data is collected, including survey responses. For most surveys, the choice comes down to consent or legitimate interests, though a contractual basis applies in narrower cases where the survey is essential to delivering a service.

When Is Consent the Right Basis?

Consent under Article 6(1)(a) fits optional surveys where the respondent has a genuine choice about whether to take part. Marketing surveys, product feedback requests sent to a mailing list, and research studies aimed at the public typically rely on consent.

The ICO’s guidance on consent sets a high bar: consent must be freely given, specific, informed, and given through a clear affirmative action such as ticking an unticked box. Pre-ticked boxes are banned outright. Respondents also need an easy way to withdraw consent after submitting the survey, which in practice means having a process ready to delete their response on request.

When Can You Rely on Legitimate Interests?

Legitimate interests under Article 6(1)(f) can apply to internal surveys where participation is something the respondent would reasonably expect, such as an employee engagement survey sent by an employer or a customer satisfaction survey following a purchase. This basis requires a documented balancing test weighing the organisation’s interest in the data against the impact on the individual.

Public authorities generally cannot rely on legitimate interests at all under Article 6(1). Employment surveys raise the opposite problem: consent is usually the weaker basis here, not legitimate interests. The EDPB has confirmed that the power imbalance between employer and employee means consent is rarely freely given, since employees may fear consequences for refusing. A properly documented legitimate interests basis is typically the more defensible option for employer-run surveys, provided participation carries no real detriment for opting out.

Do You Need Explicit Consent for Sensitive Survey Questions?

Yes. Any survey question touching special category data, meaning health conditions, ethnicity, religious or philosophical beliefs, political opinions, trade union membership, sexual orientation, genetic data, or biometric data, needs explicit consent under Article 9 on top of the standard Article 6 basis. Both conditions must be satisfied, not one or the other.

Explicit consent is a higher standard than ordinary consent. It requires an express statement, not just an affirmative action. A ticked box next to clear wording works; an assumption based on the respondent continuing to the next page does not. DEI surveys, health screening questionnaires, and workplace demographic surveys are the three contexts where this requirement gets missed most often, usually because the survey creator treats the sensitive questions the same way as the rest of the form.

If explicit consent is not realistic for a particular question, such as a mandatory health and safety survey, an alternative Article 9(2) condition needs to apply and be documented before the question goes live.

How Do You Write a GDPR-Compliant Consent Request?

A compliant consent request is separate from the survey’s terms and conditions, written in plain language, and specific about what the data will be used for. It names the organisation running the survey, states the purpose of processing, and tells respondents they can withdraw consent at any time.

The request should avoid bundling survey participation with other agreements. A single checkbox that covers both “I consent to this survey” and “I agree to receive marketing emails” fails the granularity requirement, since respondents need the ability to consent to each purpose separately. Where a third-party survey platform will also process the data, that platform should be named as well.

What Should a Survey Privacy Notice Include?

A GDPR-compliant survey privacy notice covers who is collecting the data, why, what legal basis applies, how long responses will be kept, whether any third parties (including the survey tool provider) will process the data, and what rights respondents have, including access, correction, and erasure.

This information needs to appear before the respondent starts answering questions, not buried in a general privacy policy linked at the bottom of the page. A short summary at the top of the survey with a link to the full notice covers both the transparency requirement and practical usability.

Are Popular Survey Tools GDPR Compliant?

Survey platforms vary in how they handle GDPR, and the compliance work does not disappear just because a well-known tool is used. The organisation running the survey remains the data controller. The survey tool is typically the data processor, which means liability for how the data is collected and used stays with the organisation, not the platform.

Is Google Forms GDPR Compliant?

Google Forms can be used in a GDPR-compliant way, but it depends on configuration and how responses are shared. Google acts as the processor, and the organisation using Forms remains the controller responsible for the legal basis, privacy notice, and retention decisions. Businesses relying on Google Forms for anything beyond low-risk internal use should review Google’s data processing terms and confirm where response data is stored.

Is SurveyMonkey GDPR Compliant?

SurveyMonkey offers customers with qualifying accounts a Data Processing Agreement with Standard Contractual Clauses, which covers the international transfer element that concerns many EU-based organisations. As with any processor, signing the DPA is a step the controller has to take; it is not automatic.

Is Typeform GDPR Compliant?

Typeform provides the processor-side building blocks: a Data Processing Agreement built into its Privacy Policy, Standard Contractual Clauses for EU-to-US transfers, and ISO 27001 and SOC 2 Type II certifications, with data encrypted in transit and at rest. Adding a consent question to the form itself is not automatic. That remains the responsibility of the organisation building the survey. Standard plans also store response data in the United States by default; EU data residency is only available on higher-tier plans, which matters for organisations that need to keep data within the EU.

Can You Survey Children Under GDPR?

Surveying children requires either parental consent or reliance on a legal basis other than consent, depending on the child’s age. Article 8 sets the default age of digital consent at 16, but EU member states can lower this to as young as 13, so the applicable threshold depends on which country’s respondents are involved.

Below the relevant age threshold, consent must come from whoever holds parental responsibility, and the organisation running the survey has to make reasonable efforts to verify this. Surveys distributed through schools typically rely on parental consent gathered by the school itself, which needs to be confirmed and documented rather than assumed.

How Long Should You Keep Survey Data?

GDPR does not set a fixed retention period for survey data. Article 5(1)(e), the storage limitation principle, requires that personal data be kept no longer than necessary for the purpose it was collected for. In practice, this means setting a specific retention period before the survey launches and building in a process to delete or anonymise responses once that period ends.

A customer satisfaction survey tied to a single product launch might justify keeping identifiable responses for a few months while the results are analysed, then anonymising or deleting them. A longitudinal research study following the same participants over years needs a different justification, documented separately, and typically relies on pseudonymisation to reduce risk during the study period.

Should Survey Responses Be Anonymised or Pseudonymised?

Anonymising survey responses removes them from GDPR’s scope entirely, provided the anonymisation is genuinely irreversible. Pseudonymising them, replacing names or emails with reference codes, keeps the data within GDPR’s scope but reduces risk if the dataset is exposed. Our guide on pseudonymisation versus anonymisation covers the legal distinction and the techniques involved in more depth.

For most surveys, aggregating and anonymising responses once analysis is complete is the simplest way to retain useful insights without carrying ongoing GDPR obligations for the raw data. Where individual responses need to stay traceable, for example to follow up with specific respondents, pseudonymisation with a securely stored key is the safer middle ground.

What Happens If a Survey Breaches GDPR?

A survey platform breach, an unsecured export file, or a leaked spreadsheet of responses is treated the same as any other personal data breach under GDPR. If the breach is likely to result in a risk to respondents’ rights, it must be reported to the relevant supervisory authority within 72 hours, and affected individuals may need to be notified directly if the risk is high.

Non-compliance with the underlying survey requirements, such as running a sensitive-data survey without explicit consent, falls under GDPR’s higher enforcement tier and can carry fines of up to €20 million or 4% of global annual turnover. Our breakdown of GDPR fines and penalty structures explains how regulators calculate these amounts and what factors increase or reduce them.

Conclusion

A GDPR compliant survey depends on decisions made before the first question is written: choosing the right legal basis, treating sensitive questions with the stricter Article 9 standard, giving respondents a real choice, and setting a retention period that gets enforced. The survey tool matters less than the design choices behind it. Google Forms, SurveyMonkey, and Typeform can all support compliant surveys, and all three can also host non-compliant ones, depending on how they are configured and what consent language sits in front of the first question.

Organisations running surveys at scale, particularly ones touching employee data, health information, or international respondents, often benefit from involving a data protection officer at the design stage rather than after responses start coming in. Our overview of the DPO’s role in GDPR compliance explains what that involvement typically looks like.

Frequently Asked Questions

Do anonymous surveys need to comply with GDPR?

If a survey collects no information that could identify a respondent, directly or through combination with other data, it falls outside GDPR’s scope. Genuine anonymity is harder to achieve than removing a name field, particularly in small groups where indirect details like job title or department can still identify someone.

Can I use a US-based survey tool for EU respondents?

Yes, provided the tool has appropriate transfer safeguards in place, most commonly Standard Contractual Clauses included in a Data Processing Agreement. The organisation running the survey should confirm this agreement is in place rather than assuming it by default.

Do I need a Data Protection Officer to run surveys?

Only if the organisation already meets GDPR’s DPO thresholds, such as large-scale processing of special category data or systematic monitoring of individuals. Most one-off customer or product surveys do not trigger a DPO requirement on their own, though organisations running frequent or sensitive surveys may choose to involve one regardless.

Is it legal to make a workplace survey mandatory?

It can be, but the legal basis needs to reflect that the survey is not optional. Consent is not appropriate for mandatory employee surveys because employees cannot freely refuse without consequence. A legitimate interests basis, backed by a documented balancing test, is typically used instead.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

Zlatko Delev

About the Author

Zlatko Delev

Country Manager & Head of Commercial — GDPRLocal

Zlatko specialises in data protection compliance, ISMS strategy, and AI law. With a legal background and hands-on experience supporting organisations globally, he helps businesses navigate GDPR, the EU AI Act, and international privacy frameworks.