A survey tool is GDPR compliant when it lets you run surveys in line with the EU General Data Protection Regulation: a signable data processing agreement, transparent hosting, configurable deletion, encryption, and honest anonymity options. The part vendors do not put on the pricing page: compliance is a property of your setup, not of the logo. The same tool can be compliant in one team and a liability in the next, depending on what you ask, whom you invite and what you configured. This guide is the checklist for getting it right — no legal advice, but the questions your data protection officer will ask.
What GDPR Actually Requires of a Survey
Short answer: GDPR applies as soon as personal data is in play — and in surveys it usually is, even when you think it is not. Email invitations, IP addresses in logs, and free-text answers where someone names a colleague all count. Four duties follow: a legal basis (consent or legitimate interest), transparency (who processes what, where, how long), data minimization (ask only what the purpose needs), and deletion when the purpose ends. Everything on the vendor checklist below exists to make these four duties executable.
The 7-Point Checklist
| # | Check | How to verify |
|---|---|---|
| 1 | Data processing agreement (Art. 28) — offered as a signable standard document | Find and sign it before the first survey. Not offered = disqualified. |
| 2 | Hosting location & sub-processors — named, not implied | The DPA lists sub-processors. Check where AI features process data, too. |
| 3 | Retention & deletion — configurable, not on request | Can you set auto-deletion or anonymization per survey? |
| 4 | Real anonymity option — technically enforced, not cosmetic | Anonymous mode must not store IP, email or invite-link mapping alongside answers. |
| 5 | Encryption — TLS in transit, encryption at rest | Stated in the security documentation; standard for serious vendors. |
| 6 | Respondent transparency — privacy notice shown at the survey | Can you link your own privacy notice on the first page? |
| 7 | No training on your data — for AI-assisted tools | The DPA or AI terms must state answers are not used to train models. |
The overrated item: EU hosting. It matters — but it is the item vendors advertise precisely because it is easy to advertise. The compliance holes that actually surface in audits are unsigned DPAs, free-text questions that invite personal data nobody minimizes, and retention set to "forever" because nobody touched the default. Check the boring items first.
Anonymity: The Underrated Lever
GDPR governs personal data — data relating to an identifiable person. Truly anonymized data falls outside it (Recital 26). That makes anonymity the most elegant compliance move available: an anonymous survey has no data subjects among its answers, no access requests to fulfil, no retention debate. Two conditions: the anonymity must be technical (no IP or invite-token stored with the answer), and it must survive small groups — in a five-person team, "the answer from the only person in accounting" is not anonymous, which is why serious tools suppress results below a minimum group size. When feedback concerns individuals or you need to follow up per case, attribution is the better design — the customer feedback guide covers that trade-off.
Google Forms, SurveyMonkey and the US Question
Short answer: US tools are not automatically unlawful, but they carry a structural risk EU tools do not. Since the Schrems II ruling struck down Privacy Shield in 2020, transfers rest on the EU-US Data Privacy Framework and standard contractual clauses — a foundation that has been overturned twice before and is under legal challenge again. The deeper issue: US surveillance law can compel access regardless of where the server stands. In practice this means the free consumer tier of Google Forms is not defensible for personal data at all, the enterprise tiers of US vendors are defensible-with-caveats, and choosing an EU provider simply removes the whole discussion from your audit. Data protection authorities publish guidance on exactly this — the EDPB recommendations on transfer tools are the reference document.
Employee Surveys: Two Extra Rules
Surveying your own employees raises the bar twice. First, consent is shaky as a legal basis in employment relationships because of the power imbalance — anonymity plus legitimate interest is the more robust construction, which is why serious employee engagement surveys are anonymous by design. Second, in Germany and Austria the works council typically has a say in systematic employee surveys and the tools used for them; involve them before the invite goes out, not after. Small-group protection matters most here: a pulse survey that shows team results only above a minimum response count is protecting both your employees and your legal position.
Tool Categories Compared
| Category | Examples | GDPR posture | Best for |
|---|---|---|---|
| US consumer tools | Google Forms (free), Typeform free tier | Not defensible for personal data without an enterprise contract | Anonymous quick polls without personal data |
| US enterprise platforms | SurveyMonkey, Qualtrics | DPA + SCCs available; transfer risk remains a footnote in every audit | Large research programs already on these platforms |
| EU/DE specialists | LamaPoll, easyfeedback, QuestionPro EU | EU hosting and DPA as the core selling point | Classic static surveys with clean paperwork |
| EU AI-interview platforms | teamazing AI Interview | EU-hosted, DPA, technically enforced anonymous mode, no model training on answers | Feedback where the why matters: follow-up questions instead of static forms |
GDPR-compliant AI interviews — EU-hosted
Conversational surveys with automatic follow-ups, a technically enforced anonymous mode, and no respondent accounts. EU hosting, data processing agreement included, free for 14 days.
A Compliant Survey Setup in 6 Steps
Sign the DPA before the first survey
Download or accept the vendor's data processing agreement and file it. This is the document your data protection officer asks for first.
Decide anonymous vs. attributed per survey
Anonymous when honesty matters more than follow-up (employee topics, sensitive feedback); attributed when you need to act per case. Never pretend one is the other.
Minimize: cut every question without a purpose
Demographics you will not analyze are liability, not insight. Warn in free-text fields not to name third parties.
Set retention before launch
Configure auto-deletion or anonymization of raw responses after evaluation. Aggregates without personal data can stay.
Link your privacy notice at the survey start
Who processes what, where, how long, and which rights respondents have — one short page, linked on the first screen.
Clear the invitation channel
Survey invitations to customers ride on the existing-customer exemption or consent; employee invitations may need the works council first. The survey can be perfect and the email still the violation.
The takeaway. "GDPR compliant" is something your setup is, not something a tool has. Sign the DPA, minimize the questions, configure deletion, and use technically enforced anonymity wherever honesty matters more than follow-up. EU hosting removes the US-transfer footnote from your audit — but the unsigned AVV and the forever-retention default are the holes auditors actually find.



![Customer Interview Questions: 25 Questions That Get Honest Answers [2026]](https://www.teamazing.com/wp-content/uploads/2026/07/client-customer-interviews.jpg)
![NPS Survey: Create, Calculate and Actually Learn Something [2026]](https://www.teamazing.com/wp-content/uploads/2026/07/nps-survey-feedback-tool.jpg)
![GDPR & EU AI Act: The Compliance Checklist for AI Team Assistants [2026]](https://www.teamazing.com/wp-content/uploads/2026/03/ai-governance-in-companies.jpg)