Skip to content
Legiscope
Menu
Personal Data

How to Create a GDPR Compliant Questionnaire (Surveys, Satisfaction Inquiries, etc.)

Design a GDPR survey with a reasoned legal basis, proportionate questions, clear information and a practical collection-to-deletion acceptance record.

A survey should collect only the information needed for its defined purpose, explain the processing to respondents and provide a workable route for their rights. A short questionnaire is not automatically low risk: identifiers, free text and the audience can change the assessment.

In most cases, collecting data through a questionnaire, form, or web survey will trigger the application of the GDPR due to the use of the user’s IP address (which is considered personal data under the GDPR).

Therefore, there are certain important obligations to implement to ensure compliance (I). We will then see some practical examples (II).

2026 Update — Recent Developments

Before publishing, check whether responses, access logs or invitation identifiers allow a person to be identified. Assess the survey platform and subsequent use together.

Recent companion resources:

I. - Key Obligations to Comply With

There are a number of important obligations to comply with: adding the processing activity to the registry, minimizing collected data, and displaying GDPR information notices.

Step 1: Add the Processing Activity to the Registry

As soon as an organization sets up an activity that processes personal data (under the GDPR = any data that allows the identification of individuals, directly or indirectly), the organization must reference this activity in a registry.

Note, the data processed is not referenced, but the activity itself (e.g., conducting customer satisfaction surveys). The reason for this is that it then allows for knowing where the personal data processed by the organization are and subsequently verifying their compliance (e.g., their security, the periods during which the data are processed, etc).

Describe the activity in the record where Article 30 applies, then verify each field with the person responsible for the survey. Importing a template does not establish the accuracy of the description.

Indeed, the organization must detail:

  • a) the name and contact details of the data controller and, where applicable, the joint controller, the representative of the data controller, and the data protection officer;
  • b) the purposes of the processing;
  • a description of the categories of data subjects and the categories of personal data;
  • the categories of recipients;
  • transfers of personal data;
  • the envisaged time limits for the erasure of the different categories of data;
  • a general description of the technical and organizational security measures

Once the activity is added to the registry, it is then necessary to minimize the collected data.

Step 2: Minimize Collected Data

The GDPR requires the collection of the minimum amount of data from the data subjects through the data minimization principle (Art. 5):

adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimization)

Therefore, it is necessary to reflect on the questions asked and ensure that they are adequate in relation to the objectives of the processing.

For example, for a company operating a home cleaning service:

  • the quality of the cleaning: rating from 1 to 10
  • the punctuality of the person: rating from 1 to 10
  • the politeness of the person: rating from 1 to 10
  • the name of the client or their identifier

The ratings may support service evaluation; a client name or identifier requires a separate necessity assessment. An aggregate result may be possible without keeping that identifier. Note that the data here are well minimized by using a rating from 1 to 10 and carefully avoiding a free text field which would open the possibility for clients to enter all sorts of data (comments unrelated to the work performed).

This is an important element of implementation.

Step 3: Display GDPR Information Notices

GDPR information notices are also important to display to the user, as this is part of the transparency obligations that organizations have when collecting personal data - the french CNIL has very detailed prescriptions in this regard.

To simplify things, it is necessary to clearly inform the user about what is done with their data, the reason for collecting it, and a series of other information such as the duration for which the data will be retained.

Legal notices can be generated automatically using GDPR compliance management software or drafted manually.

It is not necessarily required to obtain the consent of individuals whose data is processed if the questionnaire is part of a service provided by the organization.

Indeed, what the GDPR requires is to have a legal basis. Consent is one legal basis, but it is not the only one!

Article 6 of the GDPR provides 6 legal bases that authorize the collection of personal data:

  • The consent of the individuals
  • The contract, or pre-contractual measures
  • A legal obligation
  • The protection of vital interests of a person
  • Public interest / public authority
  • The legitimate interests of the data controller

A survey being connected to a service does not make it necessary to perform the contract. Assess Article 6(1)(b) strictly against that necessity. Consent or legitimate interests may be relevant depending on the purpose and context, with their respective conditions. Do not select consent merely because participation is optional or assume that it resolves employment power imbalances.

Step 5: Watch the Free-Text and Special-Category Trap

An open comment box is an important collection risk. A free-text field invites respondents to volunteer health details, political opinions, or complaints naming third parties — all of which can turn ordinary feedback into special category data under Art. 9 GDPR, which requires a stricter legal basis (a relevant Article 9(2) condition as well as an Article 6 basis). If you keep a free-text field, state clearly that respondents should not enter sensitive information, and review responses before storing them. Better still, prefer closed-scale ratings that make disproportionate collection structurally impossible. The official text of Regulation (EU) 2016/679 is on EUR-Lex, and the EDPB publishes guidance on when profiling from survey answers triggers additional obligations.

II. Practical example and acceptance record

The following scenario is hypothetical. A home-services company wants to compare satisfaction across service areas. It asks three optional ratings, records the broad service area and omits the customer’s name. It removes invitation tokens before analysis once their short operational purpose is complete. It separately checks whether logs or small groups could still identify someone, so it does not label the survey anonymous without evidence.

A short notice links to the full information and identifies the controller, research purpose, chosen basis, recipient platform, retention approach and rights contact. The form explains that participation does not affect the service. A separate callback option lets a respondent request contact without putting their number into the main analysis dataset.

Before launch, submit an invented response and follow it through export, reporting and deletion. Check which platform administrators can access raw answers, whether the supplier uses responses for its own purposes and whether exports retain hidden identifiers. If the survey is addressed to employees or collects sensitive information, reassess the basis and safeguards before using this example.

The release record should contain the approved question set, notice version, selected legal basis and reasoning, access list, platform contract, retention trigger and person responsible for closing the collection. At closure, confirm that reports use the intended aggregation and that obsolete raw files and mailing lists follow their respective rules. A dashboard total alone does not show what happened to the identifiable responses.

FAQ

Do GDPR rules apply to online surveys and questionnaires?

Yes. Any survey that collects personal data (name, email, opinions that can identify someone) is subject to GDPR. You need a legal basis, must inform respondents, and must respect data minimisation.

Typically consent (Article 6(1)(a)) for optional surveys, or legitimate interests (Article 6(1)(f)) for internal research where participation is reasonable to expect. Public authorities may rely on public task (Article 6(1)(e)).

What must the privacy notice in a GDPR survey include?

Identity of the controller, purpose and legal basis, retention period, whether data is shared with third parties, and respondents’ rights (access, deletion, objection). It must be provided before data collection starts.

Can you use survey responses for a different purpose than stated?

Only if compatible with the original purpose, covered by a new consent, or required by law. Re-using anonymous survey data for research is generally permitted. Re-using identifiable responses for marketing without consent is not.

The legal basis, transparency and special-category conditions are set out in GDPR Articles 5, 6, 9 and 12–14.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Personal Data

Article 28 of the GDPR: Obligations Imposed on Processors

Article 28 of the GDPR is arguably one of the most important provisions in practical terms, as it imposes a series of practical obligations on data controllers (DC) in managing the processors (PR)…

02Personal Data

DPO or compliance officer ?

It's very important to understand the difference between a Data Protection Officer and all other titles such as Data Privacy Officer, compliance officer, GDPR compliance officer, and for one reason :…

03Personal Data

EU Representative GDPR Compliance Guide 2024

Navigating the complexities of the European Union's General Data Protection Regulation (GDPR) is essential for businesses operating within or targeting the EU market. GDPR, which came into effect on…

04Personal Data

GDPR and AML: 5 Compliance Conflicts + Resolution Guide 2026

In one sentence. GDPR and AML (Anti-Money Laundering) regulations pull in opposite directions: AML mandates 5-10 year retention of identity and transaction data, sanctions screening of every…

November 29, 2022
05Personal Data

GDPR and Outbound sales : €500,000 fines for non-compliance

Commercial prospecting is undoubtedly one of the risk areas of the GDPR, where it is important to be rigorous to ensure compliance with the law. Enforcement in this area continues to intensify: by Q1…

06Personal Data

GDPR Audit Guide: Step-by-Step Compliance Checklist

- A GDPR audit is essential for identifying compliance gaps and mitigating data protection risks. - Comprehensive data mapping and inventory are foundational steps in the GDPR audit process. -…

07Personal Data

GDPR Data Storage Requirements: Retention, Security and Hosting

GDPR data storage requirements cover lawful purpose, limited retention, appropriate security and accountability. The Regulation does not prescribe one retention period, one encryption algorithm or a…

08Personal Data

GDPR DPO Designation: Article 37 Requirements Explained

Under GDPR Article 37, a DPO is mandatory for public authorities or bodies other than courts acting judicially; for core activities requiring regular and systematic monitoring on a large scale; and…

February 19, 2024