GDPR Compliant Surveys: A Practical Compliance Guide

by
on
May 8, 2025

A GDPR compliant survey collects only the personal data you actually need, on a clear legal basis, and keeps that data secure. Where you rely on consent, respondents must give a positive opt-in with no pre-ticked boxes. Many surveys need no consent at all, because they collect no personal data in the first place.

Key takeaways

  • Consent needs a positive opt-in. Pre-ticked boxes and default consent are not valid under GDPR.
  • Consent is not always required. An anonymous survey with no personal data often needs no consent.
  • Collect only the personal data you need, and delete it once it has served its purpose.
  • Secure your data with encrypted links, anonymisation, and a provider that stores data in the UK.
  • Respondents can ask to access, move, or delete their data. Build surveys so you can honour that.

What makes a survey GDPR compliant?

Compliance comes down to a simple principle: hold and process only the data you genuinely need, protect it properly, and be able to account for what you hold. The General Data Protection Regulation (GDPR) calls this privacy by design, and it applies from the moment you start writing questions.

In practice, three things decide whether a survey meets the standard. You need a lawful reason to collect the data. You need to keep it secure in transit and at rest. And you need to be able to find, export, or delete a respondent's data on request. Get those right and the rest follows.

Do you always need consent to run a survey?

No. Consent is one lawful basis for processing personal data, but it is not the only one, and it is not always the right one. In some cases asking for consent is inappropriate or even misleading, and another legal basis fits better. If a survey asks for no personal data at all, no consent is required, because there is nothing personal to process.

This matters because over-asking for consent creates friction and can lower your response rate for no compliance benefit. The first question to settle is whether your survey collects personal data at all. If it does not, you have far less to worry about.

How to capture valid consent in a survey

When you do rely on consent, it has to be a positive opt-in. Respondents actively agree; they are never opted in by default. Do not use pre-ticked boxes or any other method that assumes agreement.

The cleanest approach is a single, clear question at the start of the survey that explains what you will do with the data and asks the respondent to agree before they continue. That one step gives you a documented, freely given opt-in and sets the right tone for the rest of the survey.

Collecting and storing sensitive survey data

Sometimes a survey has to collect sensitive information, and that raises the bar for how you protect it. A few measures do most of the work.

  • Secure survey links (HTTPS): also called encrypted links, these protect responses with end-to-end encryption from the moment someone submits an answer to the point it reaches your account.
  • Anonymous surveys: respondents can answer without exposing details such as email address, IP address, or location, so that sensitive data never appears in your responses.
  • An encrypted database: responses should be held on an encrypted survey database rather than in the open.

Used together, these steps reassure respondents that their answers are safe, which is often the difference between a completed response and an abandoned one.

Respondent rights, and how to honour them

GDPR gives individuals rights over their data, and your survey platform needs to let you act on them. The three you will meet most often are access, portability, and deletion.

RightWhat it meansWhat you doAccessThe respondent can ask to see the data you holdFind and export their specific responsesPortabilityThe respondent can move their data elsewhereProvide it in a usable format, which online survey data supports instantlyErasureThe respondent can ask you to delete their dataDelete the questions holding personal data, or delete the survey outright

If your platform lets you find, edit, export, and delete individual responses, you can satisfy every one of these rights without a technical project each time.

Data security and where your data is stored

Strong survey compliance rests on strong security underneath it. Look for a platform with independent certification and clear encryption, not just a policy page that says the right things.

SmartSurvey is ISO 27001 certified, the internationally recognised standard for an information security management system, backed by staff training and documented policies. Data is encrypted with TLS while it moves from respondent to server, and encrypted at rest, so it is protected at both ends of its journey. You can read the detail on our survey security page.

For UK organisations, and especially those in the public sector or handling sensitive data, where your data lives matters as much as how it is encrypted. SmartSurvey stores all data in the UK, which simplifies GDPR compliance and meets data sovereignty requirements that US-hosted platforms cannot.

Who is responsible for compliance?

Two roles sit behind every survey. The data controller decides why and how the data is collected. That is you, the organisation running the survey. The data processor handles the data on the controller's behalf, which is the role a platform like SmartSurvey plays. If a respondent has a question about their data, they contact the controller, because that is who is accountable for it.

Some organisations also need a Data Protection Officer (DPO), who can be a member of staff, a new hire, or a contractor. Not every organisation is required to appoint one. Full GDPR compliance across a whole organisation is a job for your DPO; the part that relates to sending online surveys is the part we can help you get right. The ICO website is the authority for wider guidance and updates.

See how SmartSurvey keeps your survey data compliant and secure, with UK hosting and ISO 27001 certification built in. Book a demo to see it with your own data.

Frequently asked questions

Are anonymous surveys automatically GDPR compliant?

An anonymous survey that collects no personal data falls largely outside GDPR, because there is no personal data to protect. Take care that answers cannot be combined to identify someone indirectly. True anonymity removes most of the compliance burden.

Do I need consent for an internal employee survey?

Not always. Consent can be the wrong basis for employee surveys, because the power imbalance between employer and employee can make it hard to call consent freely given. Another lawful basis is often more appropriate, and an anonymous format avoids the question altogether.

How long can I keep survey responses?

Only as long as you need them for the purpose you collected them for. Once responses have served that purpose, delete them. Keeping personal data indefinitely, with no reason, works against the principle of holding only what you need.

Where should survey data be stored for UK GDPR compliance?

Storing data in the UK is the simplest route for UK organisations, and it is often a requirement for public sector and healthcare work. SmartSurvey hosts all data in the UK, which removes the international transfer questions that come with US-based platforms.

Does using a survey platform make me compliant on its own?

No single tool makes you compliant by itself. A secure, UK-hosted, certified platform gives you the foundation, but you remain the data controller. You still decide what to collect, choose your lawful basis, and honour respondent requests.

Categories:
None