GDPR, CCPA and Survey Data: A Compliance Checklist
What research teams need in place before fielding in Europe and the US: lawful basis, consent, retention, transfers and respondent rights.

In this article
Nobody gets into market research because they love data protection paperwork. But one sloppy consent screen in a German study can cost more than the whole project. This is the checklist our PMs run before anything goes to field in Europe or the US.
(Standard disclaimer: this is practical guidance, not legal advice. Talk to your DPO or counsel for anything unusual.)
Key takeaways
- Decide your lawful basis before writing the questionnaire.
- Write consent and privacy notices a normal person can read in 30 seconds.
- Collect only what the analysis needs, and delete on schedule.
- Paper your vendors and cross-border transfers properly.
1. Lawful basis
Under GDPR, most survey research runs on consent. Some operational processing (like fraud checks) may rely on legitimate interest. If you're collecting special category data (health, ethnicity, religion, sexual orientation), you need explicit consent, and you should ask whether you really need it.
In California, CCPA/CPRA focuses more on notice and the right to opt out of sale or sharing. Other US states are following with their own versions.
2. Consent people understand
Who's collecting the data, what it's for, how long you'll keep it, and how to withdraw. Four lines, plain English (or plain German, Portuguese, Thai). Record the consent with a timestamp. "By continuing you agree to our 14-page policy" is not good enough anymore.
3. Minimize and set retention
If the report doesn't need date of birth, ask for an age band. If you don't need an email, don't collect it. Set a deletion date for raw files and PII the day the project starts, and put it in the project tracker so it actually happens.
4. International transfers
EU data going to the US needs a valid mechanism, such as the EU–US Data Privacy Framework or Standard Contractual Clauses. Know where your survey platform, sample provider and analytics tools host data. We process on secure servers in the US and EU; details are in our security policy.
5. Respondent rights
People can ask to see or delete their data. Have a named inbox and a process to answer within the legal deadline (one month under GDPR in most cases). It happens rarely, which is exactly why teams aren't ready when it does.
6. Vendor agreements
Every processor touching respondent data needs a DPA. That includes panel partners, survey hosts and coding vendors. When you evaluate a sample provider, ask for theirs up front.
FAQ
Do surveys need GDPR consent?
Most survey research with identifiable respondents in the EU relies on consent, yes. Fully anonymous surveys may fall outside GDPR, but true anonymity is harder to achieve than it looks.
How long can survey data be kept?
Only as long as needed for the stated purpose. Many research teams delete PII within months of project close and keep anonymized datasets longer for trend analysis.



