We value your privacy

We and our third party partners may use cookies and similar technologies on this site to analyze usage, optimize our services, personalize content, tailor and measure ads and keep this site secure. Privacy Notice Cookies Notice
en
Contact SalesLog in
Contact SalesLog in

SurveyMonkey Trust Center

With enterprise-grade security, compliance, and privacy controls, we protect your data like it's our own—just like we do for 260K+ organizations worldwide.

American Express logo
Carrot logo
SmartHR logo
Customer logo for Kajabi in white
CVS Health logo
PayPal logo
Zeiss logo
zoomcare logo
KeyBank logo
MasterCard logo
Ryanair logo
Xsolis logo

BENEFITS

✔  Dedicated security team
✔  Annual third-party penetration tests
✔  Bi-annual privacy and security reviews
✔  24/7 on-call security Incident response team
✔  Encryption at rest (AES-256) and in motion (TLS 1.2)
✔  Active bug bounty program
✔  AWS cloud security
✔  Annual security awareness programs for all employees and contractors
✔  Annual exec-level tabletop exercises

✔  Privacy by design
✔  Bi-annual audit for privacy compliance
✔  Data breach notification
✔  Customer control of data
✔  AI governance
✔  Standard Contractual Clauses (SCCs) by default
✔  Data Privacy Framework (DPF) self-certified
✔  Robust privacy impact assessment processes

✔  SOC 2 Type II
✔  ISO-27001
✔  CCPA
✔  HIPAA**
✔  PCI DSS
✔  GDPR (EU, UK, Switzerland)

 **BAAs available as add-on with the Enterprise plan; must be purchased separately

✔  Single Sign-On (SSO)*
✔  Two-factor authentication (2FA)
✔  Account control*
✔  Data deletion on a self-service basis or upon request

*Available to SurveyMonkey Enterprise only

Woman typing on laptop, next to security icons that show AES-256 and TLS 1.2+

SECURITY

You need a survey platform you can trust with your sensitive data. That’s why SurveyMonkey delivers a comprehensive security program that safeguards your data at every level—from secure product development and employee training to robust global infrastructure management. We undergo regular third-party audits and security reviews to stay ahead of potential threats, ensuring your data remains protected at all times.

We take a security-first approach to building and maintaining our platform. Every product developer is trained in secure web application development practices when hired and completes annual refresher trainings to stay up to date on best practices.

Security threats don’t keep business hours, and neither do we. Our dedicated incident response team operates 24/7, conducting annual independent penetration tests and running a bug bounty program to proactively identify and address vulnerabilities.

We protect your data with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Customer data is securely stored on AWS servers in the US, Canada, and Ireland (EU), ensuring compliance with regional data protection standards.

PRIVACY

SurveyMonkey is built with privacy at its core, so you can collect insights with confidence. Our platform includes built-in features to help you meet GDPR (EU, UK, and Switzerland) and CCPA requirements effortlessly. We stay ahead of evolving regulations with ongoing updates, so your data continuously remains protected and compliant.

Map of the world with markers in the United States west coast, east coast Canada, and Ireland

We are self-certified under the EU-US Data Privacy Framework, the UK Extension and the Swiss-US DPF Principles, ensuring strict adherence to privacy standards for cross-border data transfers. We also embed Standard Contractual Clauses (SCCs) in our customer and vendor contracts. See our Transfer Statement for more details.

Our AWS-based data centers in Ireland (EU), Canada, and the US give Enterprise users control over where their data is stored. No matter the location, our privacy and security settings ensure compliance with data protection regulations in regions such as Australia, Canada, the UK, Switzerland, and the EU.

We provide flexible data retention and deletion controls that align with your local regulatory requirements. With SurveyMonkey, you get strong privacy defaults, intuitive controls, and the flexibility to manage your data on your terms.

Badges showing HIPAA compliant, SOC II complaint, ISO 27001 certified, GDPR compliant, and PCI DSS compliant

CERTIFICATIONS & STANDARDS

With certifications like SOC 2, PCI, ISO 27001, and bi-annual privacy audits, SurveyMonkey doesn’t just claim security—we have independent third parties verify and validate it. Our commitment to compliance is validated by rigorous external assessments and industry-recognized standards, so you can trust your data is always protected.

All SurveyMonkey plans include PCI DSS certification. Enterprise customers can also opt for HIPAA compliance or our Enhanced Sensitive Data Protection.

SurveyMonkey has been ISO 27001-certified since 2019, and SOC 2-certified since 2021. We undergo annual audits to ensure that our security controls are consistently met and continuously improved.

To ensure ongoing compliance and privacy maturity, we have an internal Dedicated Data Protection Officer (DPO) and work with an auditor to ensure we’re meeting GDPR requirements and adhere to industry best practices.

RESPONSIBLE AI

We built innovation and security into our AI capabilities, so you can benefit from the power of AI without compromising your data. Our partnerships with third-party providers ensure your data is never used to train their models, keeping your information safe, private, and fully in your control.

Screenshot of user enabling AI and machine learning features within SurveyMonkey

We prioritize privacy by minimizing data use, using de-identified data when building and training our machine learning proprietary models. Several AI features use OpenAI or third-party providers to generate insights. Data shared with them is not used to train their AI models.

Admins on Team and Enterprise plans can manage AI feature access for several AI-powered features such as Build with AI, Response Quality, and Sentiment Analysis–ensuring teams use AI in a way that aligns with their company policies.

Our AI policy, risk assessment, and management processes are built to align with emerging legislation, including the EU AI Act, so you can confidently use AI while staying compliant.

Greyhound logo

SurveyMonkey checked off two buy-in factors: SurveyMonkey understands GDPR. SurveyMonkey gets Salesforce. That’s huge for us.”


Matt Schoolfield
Senior Manager of Commercial Analytics and Voice of the Customer
Greyhound

Icon of Goldie, the SurveyMonkey mascot, in a security badge icon

Find information on privacy, security, terms of use, and other important legal topics.

SurveyMonkey and GDPR: How we are helping customer stay compliant

See how we prioritize compliance and protect your data.

Woman typing on laptop, next to lock icon

Get an in-depth look at how we safeguard your data with industry-leading  security practices.

  • Is it safe to use SurveyMonkey?
  • Is SurveyMonkey GDPR compliant?
  • Where does SurveyMonkey store data?
  • Can I use SurveyMonkey to collect protected health information (PHI)?
  • Can I use SurveyMonkey to collect sensitive data?
  • Is my data used to train AI models?
  • How does SurveyMonkey encrypt data?
  • Does SurveyMonkey undergo an external penetration test?
  • What security certifications does SurveyMonkey have and maintain?
  • How do I fulfill Data Subject Requests (DSRs?)
  • Do you sell my data or my respondents’ data?
  • What third-party vendors have access to my data?
  • Does SurveyMonkey have processes in place to ensure continuous compliance with local and international privacy and security regulations?
  • Which transfer mechanisms do you rely on when data crosses borders?
  • Does SurveyMonkey comply with the Australian Privacy Act to include recent reforms?


Contact our sales team and get all your security and privacy questions answered, plus access to specific resources. Note that certain documents may require an NDA on file.

Contact sales