Is SurveyXact GDPR compliant? What researchers and universities should check
SurveyXact is a survey platform developed by Ramboll in Denmark and used across the Nordics and Germany, including by public-sector bodies. This page sets out what SurveyXact publicly documents about hosting, contracts, subprocessors, anonymity and deletion, and what that means for research surveys at a university.
Short answer
SurveyXact is part of Ramboll and run from Denmark. It documents servers at the hosting company Fuzion in Aarhus, a data processing agreement included with every licence, a single subprocessor used only for SMS distribution, ISO 27001 certification and anonymised respondent IP addresses. It also provides built-in tools for anonymising and deleting response data. The data processing agreement and certificate details are not published. Whether it suits a research survey depends on your licence, the survey design and how the anonymisation tools are used.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers research surveys with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What SurveyXact documents publicly
Everything in this table comes from SurveyXact's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | "Surveyxact is part of Ramboll", developed by Ramboll Stakeholder Intelligence, Olof Palmes Allé 20, Aarhus, Denmark. The website privacy policy is published by Ramboll Management Consulting in Copenhagen. SurveyXact describes operations "entirely in Europe" across the Nordics and Germany. | [1] [2] [6] |
| Where survey responses are stored | Denmark Servers "are physically located at the hosting company Fuzion in Aarhus, Denmark". The home page states "All data is stored on servers in the EU." Daily full backups go to tape and to a server at a different address. | [3] [4] [7] |
| Data processing agreement | Documented "A data processing agreement is included when you purchase a Surveyxact license." SurveyXact says it is adapted to the customer's use and evaluated annually during security audits. The text is not published. | [3] |
| Subprocessors | "A sub-processor is only used in connection with SMS distribution." The SMS provider's name and location were not found in public documentation (checked 7 October 2026). | [3] |
| International transfers | Restricted SurveyXact says that where it uses subprocessors, data is not sent to "insecure third countries". The website privacy policy says Ramboll only uses processors in the EU or in countries with sufficient protection. | [3] [6] |
| IP addresses | "All respondents' IP addresses are anonymized. Therefore, neither you nor the employees of Surveyxact have access to view or use the IP addresses." IP addresses are used to block repeated failed logins. | [3] [4] |
| Anonymisation and deletion | A GDPR anonymisation feature with filters by time, background data, system data (such as phone numbers) and text fields. Data can be deleted at the level of variables, single responses, surveys or all survey data. A respondent search supports access, rectification and erasure requests. | [3] |
| Staff access and logging | Support staff get access to customer data only with explicit permission. Every action is logged, and a user session can be reconstructed to show exactly which data was accessed. | [4] |
| Security certifications | Documented ISO 27001 certified. SurveyXact says PwC regularly reviews its IT security. The certificate scope and certification body were not found publicly. | [4] [5] [7] |
| Accessibility | WCAG 2.1 AA support is listed among SurveyXact's compliance topics. | [2] |
| AI features | Not found AI features applied to survey responses were not found in public documentation (checked 7 October 2026). | [1] [3] [4] |
SurveyXact deserves credit for naming its data centre and city, stating that respondent IP addresses are anonymised, including a data processing agreement in every licence, keeping subprocessors to a single SMS use, documenting session-level logging and an explicit-permission rule for support access, and providing anonymisation and deletion tools designed around GDPR rights. For European universities, Danish hosting and a stated restriction on third-country transfers simplify the assessment.
What this means for research and teaching
Validemic's analysisHosting and transfers are straightforward. With servers in Aarhus and a statement that subprocessors do not send data to insecure third countries, a transfer impact assessment is not normally needed for SurveyXact itself. If you send invitations by SMS, ask which provider handles them, since phone numbers are personal data even when answers are anonymous.
The contract comes with the licence. Because the agreement is included with a licence, the university's own licence is the route to use. A researcher who buys a separate licence enters the agreement outside the institution's procurement. For research data, the institution normally needs to be the controller with a processor agreement under Article 28 GDPR [8].
IP anonymisation helps, but anonymity is broader. SurveyXact's anonymised IP addresses remove one common identifier. Responses linked to a named respondent list, background variables or free-text answers can still identify people. Data is only anonymous under the GDPR if individuals cannot be identified by any means reasonably likely to be used (Recital 26) [8]. The built-in anonymisation filters are useful for removing contact details once data collection ends.
Survey content decides the risk level. Questions about health, sexual orientation, religion, political opinions or trade union membership collect special category data under Article 9(1) GDPR [8]. Large surveys on such topics, or surveys of children or other vulnerable groups, will often meet the criteria for a data protection impact assessment under Article 35 [8]. Our DPIA screening tool gives a first view.
Logging supports accountability. Session-level logging and the explicit-permission rule for support staff are the kind of measures a DPO looks for under Article 32 GDPR [8]. Ask whether the university can obtain access logs for its own account if a participant asks who has seen their answers.
Retention is your decision. SurveyXact gives tools for deletion but the research data management plan should set when responses are anonymised or deleted. How long deleted data stays in backups was not found in public documentation (checked 7 October 2026).
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask SurveyXact before approving it
- Can we see the data processing agreement and the name and location of the SMS subprocessor?
- Which Ramboll entity is the contracting party for our licence?
- Can we receive the ISO 27001 certificate with its scope and certification body, and any PwC assurance report?
- How long do backups of deleted responses and surveys remain on tape and on the secondary server?
- At what point are respondent IP addresses anonymised, and are they kept in any server logs?
- Are any AI features planned for analysing responses, and would they use external providers?
- Can institution administrators enforce anonymisation settings across all research surveys?
The EU AI Act angle
The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [9]. For a survey tool the points are brief. AI literacy under Article 4 has applied since 2 February 2025; the Digital Omnibus on AI, Regulation (EU) 2026/1744, reworded it in July 2026 as a duty to take measures to support staff AI literacy [9] [10]. Running research surveys is not one of the high-risk education uses in Annex III [9]. As no AI features applied to responses were found in SurveyXact's public documentation, the AI Act adds little to the assessment today. That would change if AI analysis of responses is added.
Sources
- About Surveyxact, retrieved 7 October 2026
- Compliance | Surveyxact, retrieved 7 October 2026
- GDPR | Surveyxact, retrieved 7 October 2026
- Data management | Surveyxact, retrieved 7 October 2026
- ISO certification | Surveyxact, retrieved 7 October 2026
- Cookie and privacy policy | Surveyxact, retrieved 7 October 2026
- Surveyxact home page, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Recital 26 and Articles 9, 28, 32 and 35, retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 4 and Annex III, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
About this page
We read SurveyXact's home page, its compliance pages on GDPR, data management and ISO certification, its about page and its cookie and privacy policy on 7 October 2026. SurveyXact is a Danish service with Danish hosting, so the EU-U.S. Data Privacy Framework is not relevant. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for SurveyXact or Ramboll and see an error, please contact us and we will correct it.
Frequently asked questions
Can I use SurveyXact for research surveys under GDPR?
SurveyXact documents servers in Aarhus, Denmark, a data processing agreement included with every licence, a subprocessor used only for SMS distribution, ISO 27001 certification and anonymised respondent IP addresses. Check with your DPO that your institution holds a licence and that the survey settings match what you tell participants.
Where does SurveyXact store survey data?
SurveyXact says its servers are physically located at the hosting company Fuzion in Aarhus, Denmark, and that daily backups go to tape and to a server at a different address. It states that all data is stored on servers in the EU.
Does SurveyXact record respondents' IP addresses?
SurveyXact states that all respondents' IP addresses are anonymised, so that neither the customer nor SurveyXact staff can view or use them. IP addresses are used to block repeated failed logins to the platform itself.
Does SurveyXact have a data processing agreement?
Yes. SurveyXact says a data processing agreement is included when you buy a licence, adapted to your use and evaluated annually during security audits. The agreement itself is not published on the website.
Does SurveyXact use AI on survey responses?
AI features inside the survey platform were not found in SurveyXact's public documentation (checked 7 October 2026). SurveyXact markets a separate AI Maturity offering, which it describes as helping organisations assess the value of their AI efforts, not as an AI feature applied to responses.