Skip to content
tezvyn:

GDPR for UX Research: Beyond the Consent Form

Source: testingtime.comHardHow cards are made

GDPR for UX Research: Beyond the Consent Form

GDPR forces you to treat user data with respect: collect only what you need for a specific purpose and keep it safe. It applies to all research involving personal data from EU residents. The biggest footgun is collecting data "just in case."

Why it exists

The EU created the General Data Protection Regulation (GDPR) to harmonize data privacy laws and give people control over how companies use their personal information. Before GDPR, rules varied across countries, creating confusion for both users and businesses. It establishes a single, enforceable standard for data rights across Europe.

The mental model

Think of GDPR as a strict contract for handling personal data. It's not just about getting a signature on a consent form. The contract has seven key clauses: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality, and accountability. As a researcher, you are accountable for upholding every clause, from collection to deletion. Breaking this contract can lead to massive fines, up to 4% of your company's global turnover.

How it works

GDPR defines "personal data" as any information relating to an identifiable person. For UX researchers, this includes names, email addresses, video recordings of faces, and even opinions shared in an interview. The regulation requires you to follow seven principles. First, be lawful and transparent about why you're collecting data. Second, limit collection to a specific, stated purpose. Third, minimize the data you collect to only what is necessary. Fourth, ensure data is accurate. Fifth, limit storage to only as long as needed. Sixth, ensure the data's integrity and confidentiality through security measures. Finally, be accountable by implementing policies and contracts.

When to use it

You must comply with GDPR whenever your UX research involves processing the personal data of individuals in the European Union, regardless of where your company is located. This applies to recruiting participants, conducting interviews, sending surveys, analyzing recordings, and storing research artifacts. Every step of the research lifecycle that touches personal data falls under GDPR's scope.

When not to use it

GDPR principles do not apply if you are working exclusively with fully anonymized data where the individual cannot be re-identified. However, true anonymization is difficult to achieve. If there's any chance of linking data back to a person, even indirectly, GDPR rules apply. It's safer to assume GDPR compliance is necessary unless data is aggregated and completely stripped of all personal identifiers.

One canonical example

Google was fined €50 million for not providing sufficient information to users in its consent policies, failing the "lawfulness, fairness, and transparency" principle. For a UX researcher, this is a clear warning: your consent forms must explicitly state what data you are collecting, precisely why you are collecting it, and how it will be used. A vague "for research purposes" is not enough.

Interview question

A UX researcher is preparing to conduct interviews with participants residing in the EU. To align with GDPR's core principles, which approach is most critical?

  • a.Ensuring all collected data is stored on servers located within the European Union.
  • b.Obtaining explicit, detailed consent from each participant for "research purposes."
  • c.Anonymizing all participant data immediately after the interview concludes to prevent re-identification.
  • d.Collecting only the personal data strictly necessary for the specific, defined research objectives.Correct
Why?

The card emphasizes 'purpose limitation' and 'data minimization,' stating researchers should 'collect only what you need for a specific purpose' and 'minimize the data you collect to only what is necessary.' While consent is crucial, the card warns that 'A vague "for research purposes" is not enough' and GDPR is 'not just about getting a signature on a consent form,' highlighting the importance of other principles from the outset.

Just read this? Test yourself on what you have been reading.

Read the original → testingtime.com

You just looked this up. Could you explain it out loud?

That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.

The iPhone app is on the way

We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.

Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.

Get it on Google PlayiPhone app coming soon

We are hiring for this. Open roles that interview on ux research — each one lists the topics its interview covers.

See open roles