GDPR at SurveyRock
If you run surveys with EU respondents, GDPR isn't a checkbox — it's a working relationship between you, us, and the people answering your questions. Here's how that relationship works, in the terms your DPO will want.
Who's the controller, who's the processor
When you collect responses through SurveyRock, you are the data controller — you decide what to ask, why, and what happens to the answers. SurveyRock is your data processor — we process respondent data only on your instructions, only to provide the service, and never for our own purposes. For your own account data (name, email, billing), SurveyRock is the controller. This split defines whose obligations are whose, and it's exactly what your DPA with us documents.
What we do to comply
- Data Processing Agreement (DPA)
- Our DPA covers processing scope and instructions, confidentiality, security measures, sub-processor management, data subject request support, breach notification, and deletion on termination. Available on request. Request a DPA →
- Sub-processors
- Every third party that touches personal data is listed publicly, with what it does — including payment processing, support tooling, and AI providers. We notify customers of material changes in advance. View sub-processors →
- Data subject requests
- Access, deletion, and portability requests are handled within GDPR's timelines. As your processor, we also support requests you receive directly from your respondents.
- Breach notification
- In the event of a personal data breach affecting your data, we notify you without undue delay so you can meet your own obligations to supervisory authorities.
- Privacy by design
- Surveys collect what you ask for — nothing more. Response data is never used to train AI models.
Your side of the relationship
GDPR puts obligations on you as controller — a lawful basis for collection, informing respondents, honoring their rights. SurveyRock is built to make those obligations practical: export what a respondent submitted when they invoke access or portability, delete their responses when they invoke erasure, and document our processing through the DPA when your own records of processing require it.
Frequently asked
Is SurveyRock GDPR compliant?
We're GDPR-aligned: data-subject request handling and DPA support are in place today, with ongoing work to close remaining gaps. We'd rather tell you precisely where we stand than round up to "compliant."
Can I get a Data Processing Agreement?
Yes — request it and we'll turn it around quickly. Contact us →
How do I submit a data subject request on behalf of a respondent?
Contact us with the survey and respondent details — as your processor, we'll locate, export, or delete the data per your instruction, within GDPR's timelines. Contact us →
Questions?
EU procurement teams and DPOs: bring us your specific questions — processing records, sub-processor diligence, transfer mechanisms. Precise questions get precise answers.
Contact us