GDPR for UX Research: Beyond the Consent Form

GDPR forces you to treat user data with respect: collect only what you need for a specific purpose and keep it safe. It applies to all research involving personal data from EU residents. The biggest footgun is collecting data "just in case."
Why it exists
The EU created the General Data Protection Regulation (GDPR) to harmonize data privacy laws and give people control over how companies use their personal information. Before GDPR, rules varied across countries, creating confusion for both users and businesses. It establishes a single, enforceable standard for data rights across Europe.
The mental model
Think of GDPR as a strict contract for handling personal data. It's not just about getting a signature on a consent form. The contract has seven key clauses: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality, and accountability. As a researcher, you are accountable for upholding every clause, from collection to deletion. Breaking this contract can lead to massive fines, up to 4% of your company's global turnover.
How it works
GDPR defines "personal data" as any information relating to an identifiable person. For UX researchers, this includes names, email addresses, video recordings of faces, and even opinions shared in an interview. The regulation requires you to follow seven principles. First, be lawful and transparent about why you're collecting data. Second, limit collection to a specific, stated purpose. Third, minimize the data you collect to only what is necessary. Fourth, ensure data is accurate. Fifth, limit storage to only as long as needed. Sixth, ensure the data's integrity and confidentiality through security measures. Finally, be accountable by implementing policies and contracts.
When to use it
You must comply with GDPR whenever your UX research involves processing the personal data of individuals in the European Union, regardless of where your company is located. This applies to recruiting participants, conducting interviews, sending surveys, analyzing recordings, and storing research artifacts. Every step of the research lifecycle that touches personal data falls under GDPR's scope.
When not to use it
GDPR principles do not apply if you are working exclusively with fully anonymized data where the individual cannot be re-identified. However, true anonymization is difficult to achieve. If there's any chance of linking data back to a person, even indirectly, GDPR rules apply. It's safer to assume GDPR compliance is necessary unless data is aggregated and completely stripped of all personal identifiers.
One canonical example
Google was fined €50 million for not providing sufficient information to users in its consent policies, failing the "lawfulness, fairness, and transparency" principle. For a UX researcher, this is a clear warning: your consent forms must explicitly state what data you are collecting, precisely why you are collecting it, and how it will be used. A vague "for research purposes" is not enough.
Interview question
A UX researcher is preparing to conduct interviews with participants residing in the EU. To align with GDPR's core principles, which approach is most critical?
- a.Ensuring all collected data is stored on servers located within the European Union.
- b.Obtaining explicit, detailed consent from each participant for "research purposes."
- c.Anonymizing all participant data immediately after the interview concludes to prevent re-identification.
- d.Collecting only the personal data strictly necessary for the specific, defined research objectives.Correct
Why? this is the answer
The card emphasizes 'purpose limitation' and 'data minimization,' stating researchers should 'collect only what you need for a specific purpose' and 'minimize the data you collect to only what is necessary.' While consent is crucial, the card warns that 'A vague "for research purposes" is not enough' and GDPR is 'not just about getting a signature on a consent form,' highlighting the importance of other principles from the outset.
Just read this? Test yourself on what you have been reading.
Read the original → testingtime.com
- #ux research
- #gdpr
- #data privacy
- #compliance
You just looked this up. Could you explain it out loud?
That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.
The iPhone app is on the way
We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.
Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.
We are hiring for this. Open roles that interview on ux research — each one lists the topics its interview covers.
See open roles