Ethics and GDPR in market research: how to collect data in compliance with legal and industry standards?

Monika

You have collected hundreds of survey responses, only to find that the consent form did not cover profiling, interview recordings were saved to the moderator’s personal drive, and the client wants to receive a database containing respondents’ names and phone numbers. Each of these scenarios poses not only a risk of fines but also undermines the credibility of the entire project. GDPR in market research is not a formality added at the end – it is a layer designed alongside the research tool. This article explains how to collect and process respondent data in compliance with the law and industry standards.

How does GDPR in market research affect the design of the entire process?

Before the first questionnaire question is drafted, a legal question must be answered: on what basis will respondents’ data be processed? In practice, GDPR in market research is most often based on the respondent’s consent or the controller’s legitimate interest. The chosen legal basis determines the entire project architecture – from the content of the invitation and the way recordings are stored to the point at which data are deleted. If the study involves special categories of data, one of the conditions set out in Article 9 of the GDPR must also be met, for example by obtaining explicit consent.

The key distinction is whether the study handles personal data at all. If only aggregated responses are collected from the outset, without identifiers, the risk is limited. The issue arises when metadata are added to the response set: an IP address, phone number, voice recording, video interview image, or panel identifier. These elements mean that an apparently “anonymous” survey becomes a collection of personal data subject to the full requirements of the Regulation.

For a manager commissioning research, this has a specific implication: the roles must be established. Who is the data controller, who may be a joint controller, and who is the processor? In a common arrangement, where a research institute acts on the documented instructions of the commissioning party, the parties enter into a data processing agreement specifying the scope, purpose, and duration of processing. Under other models, the institute may act as an independent controller or joint controller. Without such an arrangement and the appropriate agreement or legal basis, transferring respondents’ contact details between the parties is flawed from the outset.

The ethical dimension extends beyond the letter of the law. Market research ethics covers situations in which an action is formally lawful but breaches the respondent’s trust – for example, collecting data “just in case,” concealing the actual purpose of the study, or using an interview as a pretext for selling products or services, a practice known as sugging. Industry standards consider such practices unacceptable regardless of whether the respondent has given technical consent.

How can consent be obtained, data anonymized, and ESOMAR standards applied in practice?

A lawful study begins with properly drafted information and, where this legal basis has been chosen or ethical standards require it, consent. Respondent consent as a GDPR legal basis must be freely given, specific, informed, and unambiguous. This means it cannot be pre-selected, cannot be a condition for receiving a reward unrelated to the research, and must clearly indicate exactly what will happen to the data. Informed acceptance of participation is documented separately, as is consent to recording and consent to the potential use of identifiable quotations or images.

In research design practice, it is worth separating the information that respondents must receive before participation begins. The following list sets out the minimum that should be included in the privacy notice:

  • The identity and contact details of the data controller and, where a data protection officer has been appointed, their contact details as well.
  • The purpose of the study and the scope of data collected, including information about audio or video recording and the recipients or categories of recipients of the data, including entities conducting fieldwork.
  • The legal basis for processing and the period for which the data will be retained.
  • Information on the right to withdraw consent at any time without consequences where processing is based on consent, or on the right to object where the legal basis is legitimate interest.
  • Contact details enabling respondents to exercise their rights, including the right of access, rectification, restriction of processing, and erasure in cases provided for by the GDPR.
  • Information on any data transfers outside the EEA and the right to lodge a complaint with a supervisory authority.

The second pillar is data anonymization. Two concepts must be distinguished here. Pseudonymization replaces identifiers with a code but retains the ability to reassign data to an individual – pseudonymized data remain personal data. Anonymization is a process that is irreversible in practice, taking into account the means reasonably likely to be used. Once it has been carried out, it is impossible even for the researcher to link responses to a specific person, which removes the dataset from the scope of the GDPR. In qualitative reports, this means removing company names, job titles that could identify a single individual, and biographical details that may reveal a respondent in a small sample.

It is worth remembering that an interview transcript may contain more identifying data than the survey itself – in a free-flowing conversation, respondents provide names, locations, and figures that were not included in the discussion guide. This is why anonymizing transcripts is a separate stage of work, not an automatic result of deleting the recording.

As Hume’s Institute experts point out, respondent trust is a one-time opportunity – once the principle of confidentiality has been breached, it closes doors that no budget can reopen. This observation has a practical dimension: a respondent panel that has experienced a data breach or the use of responses in a manner inconsistent with the stated purpose will stop responding reliably, and sample quality will decline in every subsequent project.

The third pillar is ESOMAR standards. The international ICC/ESOMAR Code sets out principles that in many respects go beyond or complement legal requirements. The most important include the obligation not to harm respondents, the prohibition against misleading them about the purpose of contact, protection of children’s data and of people requiring special care, and the separation of research activities from sales and direct marketing. In Hume’s Institute projects, applying the ESOMAR Code as an operational standard has been found to simplify discussions with clients’ legal departments because it provides a shared, recognized point of reference.

Which mistakes most often undermine a study’s GDPR compliance?

Most issues with GDPR in market research do not result from bad intentions, but from routine and from carrying habits over from one project to another without verification. The following are the pitfalls that occur most frequently in fieldwork practice:

  • Blanket consent. A single general consent “for everything” rather than separate consent for participation, recording, and publication of identifiable quotations or images. Such an approach does not meet the requirement of specificity and is easy to challenge.
  • Retaining data indefinitely. The absence of a defined retention period means that recordings and databases remain on drives for years. The GDPR requires data to be deleted once the purpose of processing has ceased.
  • Confusing pseudonymization with anonymization. Providing a client with an “anonymized” database that still contains reversible identifiers means transferring personal data without an appropriate legal basis or agreement.
  • De-anonymization through a small sample. In B2B research, the combination of industry, company size, and region may clearly identify a respondent even after their name has been removed.
  • Unauthorized dataset matching. Adding data from a CRM system or panel to responses without informing the respondent about such matching breaches the principle of transparency.
  • Fieldwork outside the data processing agreement. Instructing interviewers or subcontractors to contact respondents without regulating the processing arrangement, where they act as processors, creates a gap in the chain of accountability.

It is also worth comparing two approaches to data protection. The first involves adding compliance at the end, once the tool is ready – notices are then attached hastily, and anonymization is performed manually after the data have been collected. The second is a “privacy by design” approach, in which data minimization, the method of obtaining consent, and the anonymization procedure are designed alongside the questionnaire. The latter approach takes more time at the outset, but it eliminates most of the risks that, under the first model, emerge only at the reporting stage, when it is already too late to make corrections without repeating fieldwork.

One limitation to be aware of concerns data transfers outside the European Economic Area. Using foreign survey tools or transcription platforms may involve transferring data to a third country or providing access to them from a third country, which requires additional safeguards such as an adequacy decision, standard contractual clauses, and a transfer risk assessment. This is an element that can easily be overlooked when choosing a tool based solely on its features rather than server locations and data access policies.

What should be included on the checklist before research begins?

Before launching fieldwork, it is worth reviewing a concise checklist that brings together the requirements of GDPR in market research and industry standards in one place. The following points represent a practical minimum for verification:

  1. The legal basis for processing has been established, and the roles of the controller, any joint controller, and processor have been assigned.
  2. A data processing agreement has been signed with all subcontractors that have access to the data, where they act as processors.
  3. Separate consent forms or confirmations have been prepared for participation, recording, and publication of identifiable quotations or images where required.
  4. A retention period and a procedure for deleting data after the project has been completed have been defined.
  5. A process for anonymizing responses and transcripts has been designed, taking into account the risk of de-anonymization in small samples.
  6. The location of tool servers, data access policies, and any data transfers outside the EEA have been verified.
  7. The process has been checked for compliance with the ICC/ESOMAR Code, including the separation of research from sales.
  8. A process has been prepared for enabling respondents to exercise their rights, including withdrawal of consent, objection, and requests for erasure in cases provided for by the GDPR.

Reviewing these points before a project begins shifts risk from the reporting stage, where mistakes are costly, to the design stage, where corrections are inexpensive. It is the simplest way to ensure that legal compliance and market research ethics are built into the methodology rather than added after the fact.

Frequently asked questions

What consent is required from respondents?

Consent is not always the legal basis for processing data under the GDPR – in some studies, the controller’s legitimate interest may serve as the legal basis. Regardless of the legal basis, respondents should knowingly accept participation after reviewing the privacy notice. If the study involves audio or video recording, separate consent for recording should be obtained, and if identifiable quotations or images are planned for publication, further separate consent is required. Consent as a legal basis for processing must be withdrawable at any time without negative consequences for the respondent.

How should data be anonymized in a study?

Anonymization involves the removal, in a way that is irreversible in practice, of all elements that allow an individual to be identified, taking into account the means reasonably likely to be used. This distinguishes it from pseudonymization, which retains a linkage key. In qualitative research, this includes removing names, company names, job titles, and biographical details from transcripts. In quantitative research, it also includes checking whether a combination of characteristics in a small sample clearly identifies a respondent. Transcript anonymization is treated as a separate stage of work because free-flowing conversations contain more identifying data than the questionnaire itself.

What do ESOMAR standards say about research ethics?

The ICC/ESOMAR Code requires researchers not to harm respondents, to be honest about the purpose of contact, and to protect people requiring special care, including children. It prohibits using research as a pretext for sales and requires research activities to be separated from direct marketing. The Code serves as a recognized international operational standard that complements GDPR requirements with an ethical dimension extending beyond the letter of the law itself.

Consult your study’s compliance with the GDPR and industry standards. The Hume’s Institute team will help verify the legal basis, consent design, and anonymization process before fieldwork begins – get in touch to discuss your project assumptions.