AI Methodology

GDPR-Compliant AI Surveys: What to Ask Before You Sign

Diagram showing a survey response flowing through a redaction filter into a locked database, then a shredder icon representing retention and deletion controls

A survey platform is not GDPR-compliant simply because it is hosted by a major cloud provider. Genuine GDPR-compliant AI surveys need documented controls covering data storage, personal data detection, model processing, retention, deletion, subprocessors and human access.

The procurement test is straightforward: can the vendor explain the complete journey of a guest’s comment, from submission to deletion, without hiding behind phrases such as “enterprise-grade security”? If the answer stops at “we use secure cloud hosting”, legal and InfoSec should keep asking.

Why does hospitality feedback create unusual data risks?

Free-text feedback collects whatever guests decide to type. That makes it useful, but unpredictable.

A restaurant guest might write: “Sarah handled my allergy brilliantly, but my husband became ill after the fish course. Please call me on 07700 900000.” One comment now contains a staff name, health information, an allegation about food safety, a relationship and a telephone number.

Another guest could name an employee while alleging discrimination, theft or harassment. Those comments need stricter handling than a score for service speed. Health data can be special category data under UK GDPR, while allegations involving criminal conduct create further legal and access-control concerns.

Free text is operationally valuable precisely because it contains details that fixed-choice questions miss, and those details create the privacy risk.

AI adds another processing stage. The comment can pass through personal data detection, sentiment analysis, classification, summarisation and alerting before appearing in a dashboard or email. Each stage can create logs, copies or derived data.

That does not make AI surveys unsafe. It means buyers assessing GDPR-compliant AI surveys must examine the whole workflow rather than treating the language model as a sealed box. Our guide to making open-ended survey responses useful with AI explains the operational benefit. Procurement must establish how that benefit is delivered without exposing unnecessary personal data.

Where is survey data actually stored and processed?

Ask the vendor to draw the data flow. A diagram is better than a paragraph in a security policy.

Start with the raw response. Which country receives it? Where is the primary database? Where are backups held? Then follow the comment through every service involved in analysis, email alerts, dashboard reporting, customer support and exports.

Data residency describes where processing happens, not merely where the supplier’s company is registered.

A useful answer distinguishes between:

  • Raw survey responses

  • Contact details collected for follow-up

  • AI prompts and outputs

  • Application and security logs

  • Backups and disaster recovery copies

  • Dashboard exports and emailed alerts

  • Support and monitoring tools

A vendor might host its application in London but send comments to a model endpoint elsewhere. It might keep the database in the UK while storing logs in another region. Support staff outside the UK or EEA might also have remote access. None of these arrangements is automatically prohibited, but they must be disclosed and supported by the correct transfer safeguards.

Do not ask only, “Is the data hosted in the UK?” Ask, “Can any survey content, prompt, output, log or backup leave the agreed region, and can anybody outside that region access it?”

You also need deletion timings. A claim that data is deleted “on request” says nothing about backups, cached exports, model logs or derived summaries. Require separate retention periods and a maximum backup deletion window.

How should PII redaction work in guest feedback?

PII is common procurement shorthand, although UK GDPR uses the broader term “personal data”. The distinction matters because a redaction tool that catches email addresses and phone numbers can still miss health information, employee allegations and indirect identifiers.

PII redaction is a risk-reduction control, not proof that data has become anonymous.

Ask when detection happens. The safest design minimises or redacts unnecessary personal data before text reaches the language model. If detection occurs after model processing, the original personal data has already entered that workflow.

Then ask what happens to the detected information. Is it deleted, masked, replaced with a placeholder or stored separately? Can an authorised manager recover it when a guest has explicitly requested contact? Hospitality workflows often need controlled separation rather than crude deletion.

Consider this response:

“I have coeliac disease. James said the chips were safe, but I became unwell. Email me at guest@example.com.”

A useful workflow retains the operational meaning, flags a possible safety incident and keeps the contact detail in a restricted follow-up field. A general dashboard does not need to display the email address to every site user.

Test the system with real hospitality examples before signing. Include names, phone numbers with spaces, booking references, uncommon medical conditions, allegations and contact details written in sentences. Ask for false-positive and false-negative handling, plus the process for updating detection rules.

Adaptive questioning creates further considerations because earlier comments shape later questions. See how adaptive survey software changes the question flow when assessing what information enters the AI workflow.

What belongs in the data processing agreement?

The data processing agreement is where claims about GDPR-compliant AI surveys become enforceable. It should describe the service you are buying, not a generic software relationship.

For most guest feedback deployments, the hospitality operator acts as controller and the platform acts as processor. The DPA should cover the Article 28 requirements, including documented instructions, confidentiality, security, subprocessor controls, breach support, data-subject rights, deletion or return of data and audit information.

A good DPA turns technical promises into contractual obligations.

Pay particular attention to these points:

  1. Purpose and scope: Survey collection, AI analysis, reporting, alerts and follow-up should be expressly covered.

  2. Types of data: The description should recognise free text, contact details, staff names and possible special category data.

  3. Subprocessors: Require a current list, processing locations, change notifications and an objection process.

  4. International transfers: Identify the mechanism, such as the UK International Data Transfer Agreement or UK Addendum where relevant.

  5. Training rights: The contract should state whether prompts, responses or outputs are used to train shared models. A vague privacy-policy assurance is not enough.

  6. Retention and deletion: Cover live systems, logs, backups, derived summaries and exports controlled by the supplier.

  7. Incident handling: Define notification routes and timings without waiting for a regulator’s 72-hour deadline to become the internal target.

The DPA cannot solve every issue. Your team still needs a lawful basis, an appropriate privacy notice, a retention policy and, where the risk justifies it, a Data Protection Impact Assessment. The supplier should make those obligations easier to meet, not pretend to assume them all.

How do you assess AI model governance?

AI model governance starts with a precise statement of which model processes which data for which purpose. “We use AI securely” is not an answer.

Ask whether guest data is used to train, fine-tune or improve any shared model. Include prompts, outputs, ratings and human corrections in that question. The vendor’s contract with its model provider matters just as much as the vendor’s own policy.

Customer feedback should not become training material by default.

Prompt logging needs separate scrutiny. Logs help diagnose failures, but they can silently become another store of personal data. Establish whether logging is enabled, what it captures, who can search it and when it is deleted.

Access should follow least-privilege rules. A support engineer should not have routine access to named allegations because it is convenient. Sensitive access needs authentication, role restrictions and an audit trail showing who viewed or exported the information.

Also ask how model changes are managed. A provider can change a model version, safety setting or prompt template without changing the user interface. Good governance includes version records, testing before release, monitoring after release and a rollback process.

This matters when AI labels comments as critical, generates summaries or triggers manager emails. The platform must preserve the source response so an authorised user can verify the output. AI classification should support operational judgement, not erase it. The same principle applies when checking whether AI sentiment labels can be trusted.

What should we put in an InfoSec questionnaire?

Copy these questions into your procurement document and require written answers. Yes-or-no boxes encourage evasive responses.

  1. Where are raw responses, contact details, prompts, outputs, logs and backups stored?

  2. Which services and subprocessors receive survey content?

  3. Can data be accessed or transferred outside the agreed data residency region?

  4. Is personal data detected before AI model processing? Describe the sequence.

  5. How are names, telephone numbers, email addresses, health information and allegations handled?

  6. Are customer prompts, responses or outputs used to train or improve shared models?

  7. What prompt and output logging is enabled, and what is the retention period?

  8. Which staff roles can access raw comments and contact details?

  9. Are administrative access and data exports recorded in audit logs?

  10. Can retention periods be configured by the customer?

  11. How quickly are live data, derived outputs and backups deleted after termination?

  12. What data-subject request support is included?

  13. How are subprocessor changes communicated?

  14. What contractual transfer mechanism covers processing outside the UK?

  15. How are model, prompt and classification changes tested and recorded?

  16. What happens when AI detects health, safety, misconduct or discrimination concerns?

  17. Can the platform provide its DPA, security documentation and data-flow diagram before signature?

A good answer names systems, regions, roles and time periods. A weak answer repeats that the supplier follows “industry best practice”.

What does a good vendor answer look like?

A credible response sounds like this: raw responses are stored in a named region; unnecessary personal data is detected before model processing; access is restricted by role and recorded; prompts and outputs are not used to train shared foundation models; subprocessors are listed; retention applies to live data and backups; and deletion has a documented maximum timeframe. That is what GDPR-compliant AI surveys look like in practice: named regions, named roles, named time periods.

AWS Bedrock-style separation is a useful example. The answer should identify the Bedrock region, explain the contractual treatment of prompts and outputs, state whether model invocation logging is enabled and show how personal data is protected before and after invocation. Saying “we use AWS Bedrock” is not sufficient by itself.

Active Insight is an AI-adaptive customer feedback platform built for hospitality businesses. It hosts data in AWS eu-west-1 (Ireland) and runs its AI processing on AWS Bedrock, with PII redaction and access controls designed to support GDPR compliance, and uses that pipeline to analyse open comments, ask relevant follow-up questions and identify serious issues without treating privacy as a footnote. Compliance is a shared responsibility: buyers should still review the DPA, deployment details and retention requirements for their own programme, because responsible procurement requires evidence rather than trust in a product page.

If you already run a guest survey, it does not need to be replaced from scratch. Active Insight can convert an existing survey into an adaptive AI survey, so get in touch through activeinsight.ai to see what that would look like for your current setup.

Frequently Asked Questions

Are AI surveys automatically subject to GDPR?

GDPR applies when the survey processes personal data, regardless of whether AI is involved. AI adds processing steps and suppliers, so the data flow, lawful basis, transparency and security controls need closer examination.

Does UK data residency make an AI survey GDPR-compliant?

No. UK data residency addresses location, but not excessive collection, insecure access, indefinite retention or unlawful model training. Buyers must also examine remote access, subprocessors, backups and international transfers.

Is PII redaction the same as anonymisation?

No. Redacted or pseudonymised data can remain personal data if an individual can still be identified or the removed information can be restored. Treat redaction as data minimisation unless the vendor can demonstrate irreversible anonymisation.

Should guest feedback be used to train AI models?

Guest feedback should not be used to train shared models by default. Any training use requires a clear purpose, contractual basis, transparent disclosure and careful assessment of personal and special category data.

What is the biggest warning sign in an AI survey DPA?

The biggest warning sign is generic wording that does not mention AI processing, free-text responses, model providers or derived outputs. If the DPA cannot describe the actual service, it cannot allocate its risks properly.

Do we need a DPIA for AI-powered guest surveys?

A Data Protection Impact Assessment is appropriate where processing is likely to create high risks, particularly with systematic AI analysis, special category data or large-scale monitoring. Your data protection adviser should assess the specific deployment rather than relying on the supplier’s general position.

Hear what your customers are not telling you

Book 15 minutes and we will show you Active Insight running on your topics, or start with a free audit of your public reviews.

Active Insight

Active Insight is built by Service Monitor, the UK customer experience company measuring service for hospitality, leisure, and retail operators every day. Our other services include:

© Service Monitor 2026. All rights reserved.

© Service Monitor 2026. All rights reserved.