Is QuestionPro GDPR compliant? EU hosting, DPA and anonymity for universities
QuestionPro is a US survey platform with an academic licence for universities and EU data hosting options. This page sets out what QuestionPro publicly documents about where responses are stored, its contract terms, transfers, anonymity and AI, and what that means for research surveys at a university.
Short answer
QuestionPro provides a standard GDPR data processing agreement, offers EU data hosting options, holds ISO 27001:2022 and says it is certified under the EU-U.S. Data Privacy Framework. GDPR compliance settings are switched on by default for accounts on its EU servers. IP addresses are stored for security even when location capture is off; its Respondent Anonymity Assurance setting hides them from reports and exports. Its blog says customer data is never used to train base models. Whether it suits a research survey depends on the data centre, the licence and the anonymity settings.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers research surveys with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What QuestionPro documents publicly
Everything in this table comes from QuestionPro's own pages, read on 7 October 2026. The official Data Privacy Framework list could not be queried on that date, so DPF status is taken from QuestionPro's privacy policy. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | QuestionPro, Inc., Beaverton, Oregon, USA, operates the regional sites, including the German and EU domains. The privacy policy, effective 18 June 2026, names a privacy compliance officer. The GDPR page says QuestionPro "has selected the Dutch DPA as the lead supervisory authority". | [1] [2] |
| Where survey responses are stored | Plan-dependent The academic page refers to "EU data hosting options". The security page says servers are co-located at off-site data centres but does not list their locations; the countries it names (the US, India, the UAE, Germany, Mexico and the UK) are where QuestionPro's teams are based. "For users on our EU servers, GDPR compliance is turned on by default"; users in other data centres must turn it on. The EU data centre location and which plans can choose EU hosting were not found in current documentation (checked 7 October 2026). | [2] [3] [4] |
| Data processing agreement | Documented A standard GDPR agreement for all customers: "No changes to this agreement are allowed." Clients may request changes to the standard DPA through sales; QuestionPro says approval takes 30 to 60 days. | [2] |
| Subprocessors | Not public QuestionPro says it has DPAs with all companies that process GDPR survey data, including cloud infrastructure and service centres. The privacy policy mentions unnamed chat support, payment and research panel providers. A named subprocessor list was not found in public documentation (checked 7 October 2026). | [1] [2] |
| International transfers | The privacy policy states certification under the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF, with JAMS as the dispute resolution body. Standard Contractual Clauses were not mentioned in the pages read. | [1] |
| AI and training | A February 2026 blog post answers "No. Your data is never used to train base models." and describes zero-retention processing, regional AI hosting and PII redaction. The AI providers behind its features were not named in the pages read (checked 7 October 2026). The academic licence includes "AI analytics". | [4] [5] |
| Retention and deletion | Data is kept while the account is active and paid. After cancellation there is a 30-day grace period, then all data is removed from servers. Deleted data remains in backups for 7 days. A right to be forgotten tool can delete an individual response, all responses or a respondent completely. | [1] [2] [6] |
| IP addresses and anonymity | Setting Turning off location capture does not stop IP logging, because IP addresses are "stored for platform security and fraud-prevention purposes". Respondent Anonymity Assurance removes identifying metadata, including IP visibility, from reports and exports, but "the platform may still temporarily log the IP internally". | [7] |
| Security certifications | Documented ISO 27001:2022, SOC 2 audits of data centres (the academic page says "SOC 2 Type II audited"), HIPAA, PCI DSS, Cyber Essentials, and a Federalwide Assurance registered with the US Department of Health and Human Services. | [3] [4] |
QuestionPro deserves credit for a ready-made GDPR agreement available to every customer, EU hosting options, GDPR settings turned on by default for EU-hosted accounts, a built-in right to be forgotten tool, ISO 27001:2022 certification, a short 7-day backup retention after deletion, a clear statement that its AI does not train base models on customer data, and frank help documentation explaining that IP addresses are still logged when location capture is off.
What this means for research and teaching
Validemic's analysisThe data centre decides the transfer analysis. On an EU-hosted account, response data stays in the EU, although access from the US parent and support centres may still count as a transfer. On a US-hosted account, the DPF certification provides the transfer mechanism. Confirm which data centre your account uses before approving it, and ask for the DPF entry, since we could not verify it on the official list on the check date. Our guide to the EU-U.S. Data Privacy Framework explains what to check.
Academic licence or personal account. QuestionPro markets institutional academic licences [4]. A researcher who signs up personally accepts the standard terms outside the university's procurement. For research data, the institution normally needs to be the controller with a processor agreement under Article 28 GDPR [8].
Anonymity needs Respondent Anonymity Assurance and careful wording. Because IP addresses are logged for security even with location capture off, and may be kept internally with Respondent Anonymity Assurance on, the honest wording for participants is that responses are anonymous to the research team. Data is only anonymous under the GDPR if individuals cannot be identified by any means reasonably likely to be used (Recital 26) [8].
Survey content decides the risk level. Questions about health, sexual orientation, religion, political opinions or trade union membership collect special category data under Article 9(1) GDPR [8]. Large surveys on such topics, or surveys of children or other vulnerable groups, will often meet the criteria for a data protection impact assessment under Article 35 [8]. Our DPIA screening tool gives a first view.
AI statements belong in the contract. The no-training statement comes from a blog post. For research data, ask for the same commitment and the list of AI subprocessors in the agreement itself.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask QuestionPro before approving it
- Where is the EU data centre, can all our institution's accounts be hosted there, and on which licence?
- Which data still leaves the EU data centre (support access, backups, AI processing, account data), and under which mechanism?
- Can we have the named subprocessor list, including AI providers and their regions?
- Will the commitment not to train AI models on our data be written into the agreement?
- How long are respondent IP addresses kept in internal logs when Respondent Anonymity Assurance is on?
- Can Respondent Anonymity Assurance be set as the default for research surveys?
- Can we receive the ISO 27001 certificate and SOC 2 report?
- Can AI features be switched off for all users in our organisation?
The EU AI Act angle
The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [9]. For a survey tool the points are brief. AI literacy under Article 4 has applied since 2 February 2025; the Digital Omnibus on AI, Regulation (EU) 2026/1744, reworded it in July 2026 as a duty to take measures to support staff AI literacy [9] [10]. Running research surveys is not one of the high-risk education uses in Annex III [9]. If QuestionPro's AI analytics classify sentiment in written answers, that is analysis of text and is not emotion recognition, which the Act defines as inferring emotions from biometric data (Article 3(39)) and prohibits in education institutions under Article 5(1)(f), except for medical or safety reasons [9].
Sources
- Privacy Policy | QuestionPro, effective 18 June 2026, retrieved 7 October 2026
- GDPR | QuestionPro, retrieved 7 October 2026
- Security | QuestionPro, retrieved 7 October 2026
- Academic | QuestionPro, retrieved 7 October 2026
- QuestionPro blog: AI co-pilot training, February 2026, retrieved 7 October 2026
- GDPR compliant survey tool | QuestionPro, retrieved 7 October 2026
- Why are IP addresses still captured after disabling Capture Location Data? | QuestionPro Help, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Recital 26 and Articles 9, 28 and 35, retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(39), 4, 5(1)(f) and Annex III, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
About this page
We read QuestionPro's privacy policy, GDPR pages, security page, academic page, help centre and blog on 7 October 2026. The official Data Privacy Framework list API returned errors on that date for every search, including well-known participants, so the DPF status above is QuestionPro's own statement. A 2015 QuestionPro blog post described data centres in Amsterdam and Toronto; we did not rely on it because the current security page lists different locations. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for QuestionPro and see an error, please contact us and we will correct it.
Frequently asked questions
Can I use QuestionPro for research surveys under GDPR?
QuestionPro offers a standard GDPR data processing agreement, EU data hosting options, ISO 27001:2022 certification and a Respondent Anonymity Assurance setting, and says it is certified under the EU-U.S. Data Privacy Framework. Check with your DPO which data centre your account uses and whether your university holds an academic licence.
Does QuestionPro have an EU data centre?
QuestionPro's academic page says it offers EU data hosting options, and its GDPR page refers to users on its EU servers. The location of the EU data centre, which plans can choose it, and how existing accounts move were not found in current public documentation (checked 7 October 2026).
Are QuestionPro surveys anonymous?
Not fully by default. Switching off location capture still leaves IP addresses stored for security and fraud prevention. Respondent Anonymity Assurance removes identifying metadata, including IP visibility, from reports and exports, but QuestionPro says the platform may still log IP addresses internally for a time.
Does QuestionPro use survey data to train AI?
A February 2026 QuestionPro blog post states that customer data is never used to train base models and describes zero-retention processing and PII redaction for its AI features. The AI providers it uses were not named in the public pages we read (checked 7 October 2026).
Can I change QuestionPro's data processing agreement?
QuestionPro provides a standard GDPR agreement to all customers and says no changes are allowed to that template. Its GDPR page also says clients may request changes to the standard DPA, that approval takes 30 to 60 days, and that the sales team handles such requests.