Share article

Most CX managers will tell you GDPR is a legal department problem, something that only matters when you’re sending a newsletter or setting cookies on a website. The reality is different, and less convenient: every satisfaction survey, every time you link an NPS (Net Promoter Score, a customer loyalty metric measured on a scale of 0 to 10) response to a name in your CRM, every “let’s see who gave us a low score and give them a call” is personal data processing. And GDPR (the General Data Protection Regulation, EU legislation in force since May 2018) applies to it exactly as much as it applies to email marketing.
Here’s a number that should give every CX leader pause: in 2024, European authorities issued GDPR fines totalling €1.2 billion, roughly 30 billion Czech koruna. That’s according to the seventh edition of the GDPR Fines and Data Breach Survey by law firm DLA Piper. It’s about a third less than the year before, but it’s also the first year-on-year drop since 2018. Cumulatively, since the regulation came into force, authorities have issued fines totalling almost €5.9 billion. The data points to a clear trend: regulators are increasingly focused on how companies handle customer data in everyday operations, not just on major data breaches.
And feedback collection is exactly the kind of “everyday operation” where most mistakes happen. There haven’t been fines specifically targeting CX practices, but comparable cases make the boundaries clear enough.
What it means to have a “legal basis” for collecting feedback
GDPR offers six legal bases for processing personal data, but in feedback practice, it really comes down to two: consent and legitimate interest (one of the six legal bases under Article 6 of GDPR).
Many expert sources, including analyses focused specifically on survey tools, agree that a post-purchase or post-support satisfaction survey typically falls under legitimate interest rather than consent. That makes sense: if someone has bought something from you, you have a legitimate reason to ask how satisfied they are. You don’t need a tick-box for that.
But legitimate interest isn’t a universal excuse. To hold up, it has to pass the so-called three-part test, popularised by the UK’s ICO (Information Commissioner’s Office, the UK’s data protection authority) and now used by continental regulators too:
- the purpose test (is the interest real and specific?)
- the necessity test (do you genuinely need this data, and this amount of it?)
- the balancing test (do the customer’s rights outweigh your interest?)
Here’s a key shift that CX teams often overlook. In October 2024, the Court of Justice of the European Union issued a ruling confirming that even a purely commercial interest, something like “we want to retain the customer” or “we want to improve the product”, can pass the purpose test. That sounds like good news for CX, and in a way it is. But the same ruling, together with follow-up guidance from the European Data Protection Board (EDPB), tightened documentation requirements. It’s not enough to believe you have a legitimate interest. You need a written assessment, a Legitimate Interest Assessment (LIA), that passes all three tests and that you can produce if a regulator asks for it.
The practical takeaway for CX teams: if you’re collecting feedback from customers you have an active relationship with (they’ve bought from you, they use your product), legitimate interest is usually enough. But once you want to reach people you have no relationship with, a cold database, a purchased contact list, a form enriched with emails from elsewhere, you’re on thin ice. Hungary’s data protection authority (NAIH) has already stepped in on this point: in an October 2021 decision, it examined a satisfaction survey sent to people where it wasn’t clear whether any business relationship with the company existed at all, and required the company to demonstrate in its LIA whether such a relationship genuinely existed.
Anonymous or identified feedback? It’s not just a statistics question
This is where CX theory and CX practice diverge most. An anonymous survey is the simplest path from a GDPR standpoint: if a response genuinely can’t be matched to a specific person, not via IP address, not via a timestamp, not via a combination of demographic details, it isn’t personal data and the regulation doesn’t apply. But “anonymous” is a word that gets heavily overused in practice. If you store a respondent’s email “just for the prize draw” alongside otherwise anonymous answers, the survey isn’t anonymous. It’s pseudonymised, which is a completely different category under GDPR: still personal data, just with an extra security measure on top.
So when should you actually go for genuinely anonymous collection? When you care about the aggregate trend, not the individual customer. Measuring satisfaction across branches, an annual industry benchmark, a broad market-mood survey, all of these work just as well anonymously, arguably better, because people are more honest when they know they can’t be traced.
Identified feedback makes sense where you want to act on the response: closing the loop with a customer who gave a poor rating (a standard CX practice of responding immediately to negative feedback), linking a response to purchase history for personalisation, or passing a specific complaint to a sales rep. That’s a legitimate reason to identify someone, but it comes with stricter transparency rules, covered below, and should be limited to what’s genuinely needed for that purpose.
A mistake I see repeatedly: companies promise anonymity at the start of a survey, then quietly match the response to a customer ID behind the scenes for internal reporting. That’s not just an ethical problem, it’s a direct breach of the transparency principle under Article 5 of GDPR. If you promise anonymity, tracking participation or matching data back to a person afterwards simply isn’t allowed, and survey-methodology guides agree on this point. Either don’t promise anonymity, or honour it to the letter.
Trust can’t be ticked off in a cookie banner
Here’s a number everyone working with feedback should know: according to Cisco’s 2024 Consumer Privacy Survey (covering more than 2,600 respondents across 12 countries), 75% of consumers said they won’t buy from a company they don’t trust with their data. That’s not an abstract compliance metric, it’s a direct hit to business results.
An even more interesting number from the same survey: people who know their data protection rights trust companies significantly more than those who don’t. Specifically, 81% of informed respondents feel their data is protected, compared to just 44% of those who know nothing about their rights. In other words, transparency isn’t just a legal obligation, it’s a direct lever on trust. A company that clearly tells the customer why it’s asking, what it will do with the answer, and how long it will keep it doesn’t just gain legal compliance. It gains a respondent who’s more willing to answer honestly, and to answer again next time.
This also plays into a generational dynamic CX teams should factor into form design. According to the same survey, 49% of people aged 25 to 34 have already switched to a competitor because of how their data was handled, compared to just 18% of people over 75. If your target audience skews younger, non-transparent data collection will cost you more than you’d think.
In practice, this means every feedback survey or form should include three things: who the data controller is (the actual company, not just a logo), the purpose for which the response is collected and how long it’s kept, and how the respondent can exercise their rights, meaning access, correction, and deletion. This doesn’t need to be a paragraph of legalese. Two or three plainly written sentences, ideally right above the “submit” button, not buried in a separate privacy policy nobody clicks on.
Checklist: what to run through before you send a survey out
Before launching another round of feedback collection, run through this list. It’s not exhaustive and doesn’t replace a proper legal assessment of your specific case, but it covers the points where things most often go wrong.
- The legal basis is clear and documented. Do you know whether you’re relying on consent or legitimate interest, and do you have a written record of it? If it’s legitimate interest, is there an LIA that’s passed the purpose, necessity, and balancing tests?
- The relationship with the respondent is verifiable. If you’re relying on legitimate interest, can you show that a genuine business relationship exists between you and the respondent, not just a purchased contact?
- The scope of data collected matches the purpose. Are you collecting only what you actually need to evaluate the feedback, not demographic data “just in case it comes in handy”?
- Anonymity is real, not just declared. If you claim a survey is anonymous, are you avoiding storing an email, IP address, or any other identifier alongside it that could match the response back to a person?
- Sensitive data categories are handled with care. If the survey has free-text fields where respondents can write anything, are you prepared for the occasional mention of health, ethnicity, or another sensitive category? Do you have a process for that?
- Processors are under control. If the survey runs through an external tool (SurveyMonkey, Typeform, Qualtrics, etc.), do you have a data processing agreement under Article 28 of GDPR with the vendor, and do you know where the data is physically stored?
- Retention periods are defined and enforced. Have you set how long you keep responses, and is there a mechanism that actually deletes or anonymises them once that period ends?
- Information for the respondent is visible at the point of collection. Does the respondent already know, the moment they open the survey, who the controller is, why you’re asking, and how to exercise their rights, without having to dig through the website menu?
- The right to object actually works in practice. If a respondent decides to opt out of further contact, is there a clear, fast process for handling that request, not just a formal line of text?
So the real question for CX teams isn’t whether they can afford to ignore GDPR. Asking customers for their opinion without their trust defeats the purpose from the start: poorly designed data collection doesn’t just risk a fine, it leads to worse, less honest answers. In this case, legal compliance and feedback quality pull in the same direction.









