Lens

Blog

GDPR-compliant user research: a practical guide

July 5, 2026 · 7 min read

Data-classification tiersTier 1 — Direct identifiersname, email, phone, recordingsTier 2 — Quasi-identifiersjob title, employer, countryTier 3 — Free-text / researchnotes, summaries, transcriptsTier 4 — Non-personaltags, themes, counts
Once a record relates to an identifiable person, treat the whole record as personal data.

User research is, almost by definition, personal data: you are collecting what identifiable people said, did, and prefer. That puts it squarely under the GDPR. The reassuring part is that compliant research is mostly good research hygiene — here is a practical, non-legalese way to think about it.

What counts as personal data in research?

More than you might expect. Names, emails, and phone numbers obviously — but also job titles, employer, recordings, and even free-text notes and transcripts whenever they describe an identifiable person. Once a record relates to someone identifiable, treat the whole record as personal data.

The principles that matter

A practical checklist

Where AI fits

If you add AI to research, treat the AI provider as a sub-processor and be deliberate: send only what is needed, prefer providers with clear data-handling terms, keep it off by default, and redact personal data where you can. AI that is grounded only in your own repository — rather than trained on it — keeps the surface area small.

How Lens helps

Lens treats research as personal data by default: EU-region hosting, encryption, tenant isolation, role-based access, and built-in consent, anonymization, export, and erasure — so data-subject requests are routine rather than a scramble. See the use cases for how research ops teams put this into practice.

This article is general guidance, not legal advice — validate against your own policies and GDPR obligations.

← All posts

See Lens on your own research

Request access