GDPR check

Is Webropol GDPR compliant? What researchers and universities should check

Webropol is a Finnish survey tool used by Finnish universities and universities of applied sciences, with local websites for Finland, Sweden, the UK and Ireland, Germany and Belgium. This page sets out what Webropol publicly documents about where survey data is stored, who processes it, anonymity and AI analysis, and what that means for research surveys at a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Webropol Oy is a Finnish company. Its privacy notice states that it does not transfer or process personal data outside the EU or EEA, and its Finnish website says its redundant, ISO 27001 certified servers are in Finland. Its privacy notice names its main suppliers and what each one does. A public data processing agreement, a full security description and details of the AI provider behind its text analysis were not found. Whether it suits a research survey depends on your institutional agreement, the link type you use and the anonymity settings.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers research surveys with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Webropol documents publicly

Everything in this table comes from Webropol's own websites in Finland, Sweden and the UK, read on 7 October 2026, with two university privacy notices used only where Webropol's own pages are silent. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the documentation statesSource
Company and establishmentWebropol Oy, business ID 1773960-2, Huovitie 3, 00400 Helsinki, Finland. It is the controller for its own customer and user register. No data protection officer is named in the privacy notice; requests go to the Helsinki address.[1] [2]
Where survey data is storedEU (Finland) The Finnish site says its redundant ISO 27001 certified servers are located in Finland. The Swedish site describes "ISO27001-certifierade servrar inom EU" and the UK site says "servers located in the EU". The privacy notice says Webropol "does not under any circumstance transfer or process personal data outside the EU or the EEA".[1] [3] [4] [5]
Data processing agreementNot public A data processing agreement or standard customer terms were not found in public documentation (checked 7 October 2026). Finnish university privacy notices, such as SeAMK's, describe Webropol Oy as a processor.[8]
SubprocessorsThe Finnish privacy notice names Telia Cygate Oy (infrastructure services), Qumio Oy (software development), DB PRO Services Oy (database maintenance, from 30 June 2025) and Brevo (email marketing). A separate subprocessor list for survey response data was not found. A SeAMK privacy statement says Microsoft Azure Nordic processes voice data where voice responses are enabled.[2] [8]
International transfersNone stated The privacy notice rules out processing outside the EU or EEA, so no transfer mechanism is needed on Webropol's own account.[1] [2]
Customer ownership of dataThe Swedish site says the customer owns its data and that it "is not shared with Webropol or third parties" (our translation).[5]
AI featuresPartly documented An AI Text Analysis module offers "automated sentiment analysis" with "top words and emotions". The AI model or provider, processing location and any training use were not found in public documentation (checked 7 October 2026).[6]
Retention and deletionBackups are kept for one month after the customer relationship ends and are then erased (privacy notice). University guidance tells users to delete outdated surveys themselves within the account.[1] [2] [9]
Security certificationsPartly documented ISO 27001 certified servers (Finnish and Swedish sites) and Cyber Essentials certification (UK site badge). The certificate scope, certification body and any audit reports were not found publicly.[3] [4] [5]
Institution controlsSingle sign-on with university platforms is offered for academic customers. SeAMK staff and students sign in with their HAKA identities. The UK site states WCAG 2.1 AA accessibility.[4] [7] [8]

Webropol deserves credit for a clear and unqualified statement that personal data stays in the EU and EEA, servers in Finland, an ISO 27001 certified environment, a privacy notice that names its suppliers and what each one does, and established use at Finnish universities and universities of applied sciences. For a European institution, avoiding third-country transfers removes one of the more time-consuming parts of a vendor assessment.

What this means for research and teaching

Validemic's analysis

Data location is a strength. Because Webropol says it does not process personal data outside the EU or EEA, a university does not need a transfer impact assessment for Webropol itself. It is still worth confirming in the agreement that the same applies to every subprocessor, including any AI provider and the voice response feature.

The contract sits with your institution. A university normally holds the agreement and acts as controller, with Webropol as processor under Article 28 GDPR [11]. Because the terms are not public, ask your procurement office for the signed data processing agreement and its subprocessor annex before approving a new research use.

Survey content decides the risk level. Questions about health, sexual orientation, religion, political opinions or trade union membership collect special category data under Article 9(1) GDPR [11]. The University of Lapland's Webropol notice, for example, lists allergies and diets as health data collected through event registration forms, and states that the system's servers are in Finland [10].

Anonymity depends on link type. Häme University of Applied Sciences' guidance explains that surveys sent with personal links can be set up in the survey's anonymity setting so that respondents' email addresses cannot be linked to their answers, and warns that answers themselves may still identify respondents [9]. Whether Webropol records respondent IP addresses was not found in public documentation (checked 7 October 2026). Data is only anonymous under the GDPR if individuals cannot be identified by any means reasonably likely to be used (Recital 26) [11], so participant information should promise anonymity only when the link type, settings and questions support it.

AI analysis needs its own check. The AI Text Analysis module processes open answers, which in research often contain the most identifying detail. Until Webropol documents the model provider and processing location, treat the module as a separate decision and record it in the ethics application.

DPIA likelihood. Large surveys on special category topics, or surveys of children or other vulnerable groups, will often meet the criteria for a data protection impact assessment under Article 35 GDPR [11]. Our DPIA screening tool gives a first view.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Webropol before approving it

  1. Can we see the current data processing agreement and the full subprocessor list for survey and response data?
  2. Which AI model and provider does AI Text Analysis use, where does the processing happen, and is any customer data retained or used for training?
  3. Can AI features be switched off for all users in our organisation?
  4. Are respondent IP addresses recorded in survey data or server logs, and for how long?
  5. Which subprocessor handles voice responses, and in which region?
  6. Can we receive the ISO 27001 certificate with its scope and certification body?
  7. How long do deleted surveys and responses remain in backups?
  8. Can anonymity be enforced as the default for research surveys?

The EU AI Act angle

The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [12]. For a survey tool the points are brief. AI literacy under Article 4 has applied since 2 February 2025; the Digital Omnibus on AI, Regulation (EU) 2026/1744, reworded it in July 2026 as a duty to take measures to support staff AI literacy [12] [13]. Running research surveys is not one of the high-risk education uses in Annex III [12]. Webropol's text analysis refers to sentiment and "emotions" in written answers [6]. That is analysis of text, not emotion recognition, which the Act defines as inferring emotions from biometric data (Article 3(39)) and prohibits in education institutions under Article 5(1)(f), except for medical or safety reasons [12].

Sources

  1. Privacy Policy | Webropol UK, retrieved 7 October 2026
  2. Tietosuojaseloste | Webropol (Finnish privacy notice), retrieved 7 October 2026
  3. Webropol Finland home page, security and server statements, retrieved 7 October 2026
  4. Webropol UK home page, security, accessibility and certification statements, retrieved 7 October 2026
  5. Webropol Sweden home page, security and data ownership statements, retrieved 7 October 2026
  6. AI Text Analysis | Webropol, retrieved 7 October 2026
  7. Akateemiset ja oppilaitokset | Webropol (academic customers), retrieved 7 October 2026
  8. Webropol survey tools privacy statement | SeAMK, retrieved 7 October 2026
  9. Webropol-kyselyt ja tietosuoja | HAMK digipedagogy guides, retrieved 7 October 2026
  10. Webropol tietosuojailmoitus | University of Lapland, updated 25 August 2026, retrieved 7 October 2026
  11. Regulation (EU) 2016/679 (General Data Protection Regulation), Recital 26 and Articles 9, 28 and 35, retrieved 7 October 2026
  12. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(39), 4, 5(1)(f) and Annex III, retrieved 7 October 2026
  13. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
  14. Webropol international home page, list of local websites, retrieved 7 October 2026

About this page

We read Webropol's privacy notices, its Finnish, Swedish and UK websites and its AI Text Analysis page on 7 October 2026. Where Webropol's own pages were silent, we read privacy notices and guidance published by Finnish universities that use Webropol, and say so in the text. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.

This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Webropol and see an error, please contact us and we will correct it.

Frequently asked questions

Can I use Webropol for research surveys under GDPR?

Webropol is a Finnish company that states it never transfers or processes personal data outside the EU or EEA, and its Finnish website says its redundant, ISO 27001 certified servers are in Finland. Finnish institutions such as SeAMK and the University of Lapland publish privacy notices for their Webropol use. Check with your DPO that your institution has a processor agreement and that your survey settings match what you promise participants.

Where does Webropol store survey data?

Webropol's Finnish website says its redundant, ISO 27001 certified servers are located in Finland, and its privacy notice says it does not transfer or process personal data outside the EU or EEA. The infrastructure provider named in the privacy notice is Telia Cygate Oy.

Are Webropol surveys anonymous?

It depends on how the survey is sent and configured. University guidance (HAMK) explains that surveys sent with personal, respondent-specific links can be set up in the survey's anonymity setting so that email addresses cannot be linked to answers. Whether IP addresses are recorded was not found in Webropol's public documentation (checked 7 October 2026), so ask Webropol before promising full anonymity.

Does Webropol use AI on survey responses?

Webropol sells an AI Text Analysis module that offers automated sentiment analysis of open answers. Its public pages do not say which AI model or provider powers it, where that processing happens or whether data is used for training (checked 7 October 2026). Ask Webropol before switching it on for research data.

Does Webropol have a data processing agreement?

A Webropol data processing agreement or standard terms were not found in public documentation (checked 7 October 2026). University privacy notices describe Webropol Oy as a processor, which implies agreements are signed with customers. Ask your procurement or DPO office for the institutional agreement.