Blog
GDPR-compliant user research: a practical guide
July 5, 2026 · 7 min read
User research is, almost by definition, personal data: you are collecting what identifiable people said, did, and prefer. That puts it squarely under the GDPR. The reassuring part is that compliant research is mostly good research hygiene — here is a practical, non-legalese way to think about it.
What counts as personal data in research?
More than you might expect. Names, emails, and phone numbers obviously — but also job titles, employer, recordings, and even free-text notes and transcripts whenever they describe an identifiable person. Once a record relates to someone identifiable, treat the whole record as personal data.
The principles that matter
- Lawful basis and consent — know why you are allowed to hold the data, and record each participant's consent.
- Data minimization — collect only what the study needs; don't pad records with assumed fields.
- Purpose limitation — use the data for the research you described, not something else later.
- Storage limitation — keep it only as long as needed, with a retention period and a way to delete.
- Security — encryption in transit and at rest, with access limited to who genuinely needs it.
- Data-subject rights — be able to access, export, correct, and erase a person's data on request.
A practical checklist
- Capture consent per participant, with status and expiry you can see at a glance.
- Support anonymization — strip identifiers while keeping the de-identified findings.
- Offer export and full erasure to handle access and deletion requests.
- Enforce role-based access so only the right people see raw data.
- Host in a known region (for example the EU) under a Data Processing Agreement, and keep a sub-processor list.
- Set a retention policy — and actually apply it.
Where AI fits
If you add AI to research, treat the AI provider as a sub-processor and be deliberate: send only what is needed, prefer providers with clear data-handling terms, keep it off by default, and redact personal data where you can. AI that is grounded only in your own repository — rather than trained on it — keeps the surface area small.
How Lens helps
Lens treats research as personal data by default: EU-region hosting, encryption, tenant isolation, role-based access, and built-in consent, anonymization, export, and erasure — so data-subject requests are routine rather than a scramble. See the use cases for how research ops teams put this into practice.
This article is general guidance, not legal advice — validate against your own policies and GDPR obligations.
See Lens on your own research
Request access