Data protection isn't a setting you forget at the end. It's a decision made at the beginning.
Online surveys often collect personal data such as email address, occupation, highest educational qualification, marital status and so on. Such data, however, is subject to strict data protection rules that provide for heavy fines in the event of a breach. In this article we therefore explain what you need to keep in mind for your online surveys to make them data-protection-compliant, and we give you examples of how to word the consent and privacy statements for your respondents.

About the General Data Protection Regulation (GDPR)
Since May 25, 2018, the General Data Protection Regulation (GDPR) has applied across Europe. The GDPR governs in particular how companies and public authorities process personal data. On the one hand, this regulation is meant to strengthen consumer rights by better protecting personal data. On the other hand, it should nevertheless ensure the free movement of data within the European single market.
For a breach of the GDPR, companies face heavy fines of up to 20 million euros, or up to 4% of worldwide turnover — whichever is higher. Although to this day no clear classification of breaches and the corresponding penalties has been worked out in official case law, the considerable size of the maximum penalty makes it clear that lawmakers take data protection seriously.
That makes it all the more important to engage with the aspects of the GDPR relevant to online surveys, so as to be able to fully meet the GDPR's rules within your surveys and give any potential cease-and-desist warnings nothing to latch onto.
What is personal data?
Under Article 4(1) GDPR, personal data is any information relating to an identified or identifiable natural person or at least attributable to one, thereby allowing conclusions to be drawn about who they are.
A natural person is considered identifiable if they “can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
In addition to general personal data, special categories of data are singled out separately, for which a higher level of protection applies. Data particularly worthy of protection includes genetic, biometric and health data, as well as personal data revealing a person's racial and ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership.
As you can see, the legal definition of personal data is fairly broad. An exhaustive list of the types of personal data can hardly be drawn up. The following examples therefore give an impression of what can be regarded as personal data:
- Personal details that relate directly to the person: name, address, age, date of birth, place of birth and so on.
- Identification numbers: phone number, vehicle registration number, account number, credit card number, ID card number, tax identification number, health insurance number, student enrollment number, personnel number and so on.
- Online data: email address, login name, IP address, location data and so on.
- Physical characteristics: photos, gender, skin color, eye color, body and clothing size, birthmarks, illnesses and so on.
- Economic data: income, ownership of vehicles or real estate, debts and so on.
- Cultural and social data: nationality, religion, language, party affiliation, occupation, education, marital status, number of children and so on.
- Data particularly worthy of protection: genetic, biometric, health data, racial and ethnic origin, political opinions, religious or philosophical beliefs, trade union membership
- and much more.
In the eyes of case law, the same type of collected data isn't always personal. Conversely, data that on its own isn't personal can become personal in connection with other data.
The most important feature that makes data personal within the meaning of the GDPR is the possibility of identifying a person using this data.
Let's look at an example:
Are company contacts personal data?
Yes and no! In principle, the GDPR applies only to natural persons. Individual details about legal persons such as corporations, registered associations, public bodies, foundations, institutions, authorities and so on therefore do not count as personal data.
Unless these details carry over to the natural persons behind the legal person — that is, they make it possible to draw conclusions about them. That can be the case, for example, with a single-person GmbH or a sole proprietorship.
The same applies to the contact details of the contact persons within the company, e.g. name, personalized email address — especially one from which the first and last name are apparent —, position within the company and so on. This, in turn, is personal data, since a natural person is identifiable.
Consent to the storage or processing of personal data
Under data protection law, the collection and processing of personal data without the data subject's consent is in principle prohibited. Therefore, in the context of an online survey, you must obtain consent from your respondents for the storage or processing of data — and do so before you collect the personal data. Under Art. 4(11) GDPR, this consent is subject to certain requirements. Namely, it must
- Have been given freely. You may not force respondents to provide their data — especially not when it isn't necessary at all to fulfill the purpose of the data collection. For example, if you want to raffle off a prize among your respondents as a thank-you for taking part in your survey, it is perfectly permissible to obtain consent to process the email address. However, this consent must not be tied to the email address simultaneously being used for advertising purposes, since the latter isn't necessary to fulfill the purpose (determining the winner).
- Have been given in an informed manner. This is only the case if the respondent is clearly and plainly informed about why they should provide their data and what happens to the data.
- Have been given unambiguously. By this we mean that the respondent must actively agree — e.g. by clicking a checkbox or selecting the answer «I agree». Tacit consent, where consent is preselected so that the respondent has to untick it in order to object to the consent, is not permitted.
- Have been given for one or more specific purposes only. A general consent without naming concrete purposes is ineffective.
Even if all of this sounds complicated, the practical implementation of the legal requirements in the questionnaire isn't that hard.
Example:
Alternatively, consent to the storage and processing of personal data can be obtained right at the start of the survey. In fact, this can even be the preferred place for it. As a rule, the purpose of the survey is described in detail at the beginning. The explanation of what data is stored and how it is handled fits organically into the concept at this point. Most academic studies proceed exactly this way.
Here you can see an example of such an approach: click.
When is collecting personal data permitted without consent?
Under current case law, the collection and processing of personal data without the data subject's consent is permitted only in the following exceptional cases:
- The data processing is permitted by law. This applies, for example, to employment records or occupational safety records.
- The data processing is necessary for the performance of a contract or the initiation of a contract. For example, knowing the customer's address is necessary to deliver their order. It can therefore be collected without consent. The same applies to the contact details of a prospective customer who wants to find out about your services.
- There is a legitimate interest that outweighs the data subject's interest in protecting their data. Such an interest can also be economic in nature. For example, it is argued that the economic interest of a retailer sending direct advertising to its existing customers may, under certain circumstances, outweigh the protection of privacy (see e.g. GDPR, Recital 47/7).
In these cases, no consent from the data subject is required for the storage and processing of their personal data.
Although it isn't required by law, it has nevertheless become common practice to obtain consent even in such cases, particularly in order to comply with the accountability and documentation obligation mandated by the GDPR. In any case, it is good manners to inform the data subject about the purpose of storing their personal data before they share their personal data with you.
Do you need consent to store IP addresses?
Under current case law, the IP address is regarded as personal data. However, since storing the IP address is technically necessary for the functioning of websites (and online questionnaires), the European Court of Justice assumes that consent to store the website visitor's IP address is already automatically in place the moment they access it.
In addition, there is a legitimate interest on the part of the survey owner in storing the IP address, e.g. to be able to prevent manipulation of the survey results through a respondent completing the questionnaire multiple times, or to enable the function of pausing and resuming the completion of a survey.
All of this means that a separate consent to store IP addresses in online surveys is generally not required. A note about anonymized analysis is entirely sufficient in this case.
It should be noted, however, that IP addresses may not be stored as a precaution and must be deleted once the purpose has been fulfilled — usually after a few weeks. If this condition isn't met, i.e. if you intend to store and/or process your respondents' IP addresses over a longer period, then it becomes necessary to explicitly obtain the respondents' consent to store the IP address.
Privacy statement: yes or no?
The GDPR contains no rule as to whether an online survey should include a privacy statement — of the kind familiar from websites generally. It isn't necessary, then, to set up a separate web page specifically for a survey that captures all the nuances of data protection and must be accessible on every page of the survey.
Nevertheless, the GDPR requires that in the event that personal data is collected in the survey
- Respondents are informed about the purpose, form and scope of the collection and processing of personal data.
- Personal data is only collected and used if the respondent gives a corresponding declaration of consent.
- Respondents are informed about their rights (right to information, deletion, withdrawal).
- Respondents are informed about the duration of data retention and processing as well as the whereabouts of the data after the deadlines have expired.
- The collected data is adequately protected against access by unauthorized persons. This requires that the persons authorized to process the data be determined from the outset.
- In the case of processing on behalf of the controller, information about the processor is disclosed.
- In addition, the contact person responsible for data protection during the data collection must be named. After all, requests regarding information, deletion and withdrawal must be able to be directed to someone.
All this information can be placed organically in the introduction to a survey. Sometimes, however, describing all these facts can take up far too much space. In such cases, creating a privacy statement on a separate website that is linked from the questionnaire is entirely justified. What's important here is that this link is placed before the data is collected and as close as possible to the point at which the respondent gives their consent to the collection of personal data.
Example with integration into the introduction: click.
Example with a link: click.
Do I need consent and a privacy statement if I don't collect any personal data?
The GDPR applies exclusively to personal data. As long as you don't collect any personal data in your survey, or you collect it in such a way that with realistic effort it isn't possible to attribute this data to a specific person (see the example above), you need neither consent nor a privacy statement.
Nevertheless, you may decide, even in this case — for ethical reasons or to increase transparency, say — to integrate a consent and privacy statement into your questionnaire.
A possible wording for this could look like this (introduction without a declaration of consent):
When is the survey anonymous, and what is pseudonymization?
The survey is considered anonymous if the data collected in it does not relate to a natural person or is not attributable to one — i.e. does not allow conclusions to be drawn about a specific person.
This is the case if
- You don't collect any personal data, or
- you collect data that on its own is personal but cannot be related to a specific person.
So if you post a survey publicly on Facebook and ask for age and gender in it, then a personal reference can hardly be established for individual records. In this case, the survey is therefore also to be regarded as anonymous, even though personal data is collected in it (see also the example above). The GDPR does not apply to such surveys.
There is, however, a special case in which, applying the GDPR, the personal data collections are nonetheless regarded as anonymous. This case is called “pseudonymization.”
Article 4(5) GDPR defines pseudonymization as “the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.”
For the collected personal data to be considered pseudonymized, the following conditions must therefore be met:
- Separate data storage: the personal data that can be related to specific persons must be kept separately from the personal data that does not allow any reference to specific persons.
- There must be technical and organizational measures that ensure the two data sets are not linked with the intent of establishing personal references. It must therefore be established from the outset which persons are authorized to process the data, that they are organizationally obligated not to establish personal references from the available data, and that both data sets are prevented from being passed on to third parties.
A real-world example from QUESTIONSTAR:
Who is responsible for GDPR compliance, and what are processing on behalf of the controller and a DPA?
Under Article 4(7) of the GDPR, the controller responsible for GDPR compliance is that natural or legal person which decides on the purposes and means of processing personal data. In the case of conducting an online survey, that is the survey owner. Accordingly, responsibility for the storage, processing of personal data and its protection formally falls within your area of responsibility.
Technically speaking, however, the data collected as part of your surveys is stored on QUESTIONSTAR's servers. In addition, the collected data is made available to you by QUESTIONSTAR for download in tabular form (raw data) or as an aggregated analysis. Current case law sees this as the act of data processing, for which you, in turn, are responsible as the survey owner.
However, from your point of view QUESTIONSTAR is an external service provider that, strictly speaking, you do not control and whose actions you therefore cannot be responsible for. So that you can nonetheless conduct your online surveys in this case while at the same time complying with the law, Article 28(3) of the GDPR provides for the conclusion of what is known as a data processing agreement (DPA). Accordingly, the data processing by QUESTIONSTAR is carried out on your behalf, whereby QUESTIONSTAR assumes the part of the responsibility for the storage, processing and protection of personal data that falls within its area of responsibility. In this way lawmakers ensure the fair distribution of responsibility within the framework of the GDPR.
In short, if you collect personal data in your online surveys, you as the survey owner are responsible for GDPR compliance. If you conduct your online survey with the help of an external service provider such as QUESTIONSTAR, you should, to be on the safe side, conclude a data processing agreement with them.
For this you are welcome to use our DPA template, which was drafted in full accordance with the GDPR. Please download this template, fill in your company's details, and send us the signed document at support@questionstar.com — we'll then send you the countersigned agreement in return. Alternatively, you can send us your own DPA. After review by our lawyer, we'll sign it and send it to you at the email address you provide.
How does QUESTIONSTAR help me comply with the GDPR?
With its tools and settings, QUESTIONSTAR helps you comply with the provisions of the GDPR in the context of your surveys. These include in particular
- Separate storage of contact lists.
- Separate storage of personal data.
- Anonymization of personal data.
- Aggregated data analysis without reference to individuals.
- Automated double opt-in procedure when collecting email addresses in the questionnaire.
- Server location Germany.
- Encrypted connection and data transmission.
- Conclusion of a data processing agreement (DPA).
Examples of consent and privacy statements
The examples of consent and privacy statements used in this article are implemented as standalone questionnaires. You are welcome to copy these questionnaires into your user account at QUESTIONSTAR and, if necessary, adapt them to the circumstances of your data collection. To do so, simply click the corresponding button in the questionnaire.
- Example declaration of consent within the questionnaire
- Privacy statement (detailed version)
- Prize draw terms of participation
- Consent and privacy statement in the introduction to the survey
- Privacy statement long version
- Privacy statement long version 2
- Introduction for anonymous collection with a declaration of consent (Example 1)
- Introduction for anonymous collection with a declaration of consent (Example 2)
- Introduction for anonymous collection without a declaration of consent (Example 3)
- Introduction with a link to a longer privacy statement
- Employee satisfaction questionnaire
Disclaimer
This article was created with the greatest care after thorough research and consultation of legal advice. Nevertheless, the author makes no claim to completeness of the matters presented or freedom from errors.
The examples of consent and privacy statements listed in this article are intended primarily to serve as an initial orientation and likewise make no claim to accuracy and completeness. The author strongly advises that you have your individual consent and/or privacy statement created or reviewed by a data protection officer.
Should you have become aware of factual errors or inaccuracies while reading this article, the author would be grateful for a note. Please send an email for this to support@questionstar.com.
Date: 09.11.2020
Author: Dr. Paul Marx
This text is protected by copyright. All rights reserved.
