Prompt

How do I ensure my customer satisfaction studies with a survey platform are GDPR and CCPA compliant?

Latest observation

Jul 23, 2026 · OpenAI APIWeb search: off

To make customer satisfaction studies compliant with GDPR and CCPA/CPRA, you need to manage what data you collect, why you collect it, how you disclose it, and how you honor participant rights. A survey platform can help, but compliance is mostly about your process and contracts.

1) Minimize the data you collect

  • Collect only what you need for the study.
  • Avoid asking for direct identifiers unless necessary.
  • Don’t request sensitive personal data unless you have a clear legal basis and explicit safeguards.
  • Use anonymous or pseudonymous survey settings when possible.

2) Establish a lawful basis under GDPR

For GDPR, determine and document the legal basis for processing, such as:

  • Consent: best when participation is optional and you need explicit opt-in.
  • Legitimate interests: sometimes appropriate for customer research, but requires a balancing test.
  • Contractual necessity: usually not the basis for satisfaction surveys unless directly tied to a service contract.

If using consent:

  • Make it freely given, specific, informed, and unambiguous.
  • Let participants withdraw easily.

3) Provide clear notices at collection

Your survey intro or privacy notice should clearly explain:

  • Who is collecting the data
  • Why it’s being collected
  • What categories of data are collected
  • How long it will be kept
  • Who it will be shared with
  • Whether it will be transferred internationally
  • How people can exercise their rights
  • Contact details for privacy questions

For CCPA/CPRA, include a compliant notice at collection.

4) Set up a proper agreement with the survey platform

If the platform processes personal data on your behalf:

  • Under GDPR, sign a Data Processing Agreement (DPA).
  • Ensure the platform acts only on your instructions.
  • Confirm subprocessors, retention rules, security measures, and cross-border transfer safeguards.
  • If data transfers outside the EEA/UK, use appropriate transfer mechanisms such as Standard Contractual Clauses if needed.

Under CCPA/CPRA:

  • Ensure the vendor qualifies as a service provider or contractor and is contractually restricted from using data beyond your instructions.

5) Honor data subject rights

You need a process to respond to:

  • GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
  • CCPA/CPRA: right to know/access, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination.

Make sure you can identify survey records linked to a requester, or design the survey to avoid collecting identifying data where possible.

6) Be careful with “sale” or “sharing” under CCPA/CPRA

If the survey platform uses data for its own purposes, advertising, analytics, or cross-context behavioral advertising, that can create CCPA/CPRA issues.

  • Use contractual settings that prevent “sale” or “sharing” where possible.
  • If applicable, provide a “Do Not Sell or Share My Personal Information” mechanism.

7) Set retention and deletion rules

  • Define how long survey responses are kept.
  • Delete or anonymize data when the research purpose is complete.
  • Ensure the platform supports deletion and retention controls.

8) Secure the data

Use reasonable security measures:

  • Access controls
  • Encryption in transit and at rest
  • Role-based permissions
  • Audit logs
  • Secure exports and storage

9) Assess whether a DPIA or risk review is needed

Under GDPR, a Data Protection Impact Assessment (DPIA) may be needed if the study involves:

  • Large-scale profiling
  • Sensitive data
  • Vulnerable individuals
  • Automated decision-making
  • New or high-risk processing

10) If you use cookies or tracking links, handle those separately

If your survey uses:

  • tracking pixels
  • behavioral analytics
  • cookies
  • identifiable email-link tracking

you may need:

  • cookie consent under ePrivacy/PECR rules in the EU/UK
  • clear disclosure
  • opt-out options where applicable

Practical checklist

Before launch, confirm:

  • Survey questions are data-minimized
  • Privacy notice/notice at collection is ready
  • GDPR lawful basis documented
  • Consent flow works if used
  • DPA signed with the platform
  • Vendor transfer and subprocessor review completed
  • CCPA/CPRA service-provider terms in place
  • Rights request process defined
  • Retention/deletion timeline set
  • Security controls enabled
  • Cookie/tracking compliance reviewed if relevant

Best practice

If you want the easiest compliance path:

  • run the survey anonymously or pseudonymously
  • avoid sensitive data
  • use a reputable platform with strong DPA/service-provider terms
  • keep only aggregated results where possible

If you want, I can also provide:

  1. a GDPR/CCPA survey privacy notice template, or
  2. a vendor due diligence checklist for survey platforms.

Observation history

Unlock observation history

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.