Forms

Anonymous survey best practices

An anonymous survey collects nothing that ties an answer to a person: no name, no personal link, no sign in, and no mix of questions that points to one individual. Most promises of anonymity break on the questions and the reporting rather than the software, so the practices below start there.

· Co-founder

7 min read · Published

Anonymous survey best practice comes down to five habits: decide whether the survey is truly anonymous or only confidential, strip every identifier from the link and the questions, keep segments broad enough that no answer points to one person, tell people exactly who reads what, and report in groups large enough to hide individuals. Software settings help, but the questions and the report are where anonymity usually fails.

Anonymous or confidential: decide first

An anonymous survey cannot tell who answered. A confidential survey can, but restricts who sees the link between a person and an answer. The difference matters because each one allows different things: a confidential survey can chase non respondents and follow up a serious concern, and an anonymous one cannot. The note on anonymous versus confidential surveys sets out the test in detail, so this guide assumes the decision is anonymous and focuses on keeping that promise.

Write the promise as one sentence before writing a single question. The employee pulse survey from a fictional logistics company does this on its welcome screen: the same six statements as last month, and nobody sees individual answers. Every later choice, from the link to the team question, is then tested against that sentence.

What to strip from the form

Direct identifiers are the obvious part: name, email, phone, employee number. Less obvious is the way the survey arrives. Survey platforms record a surprising amount by default. SurveyMonkey’s own help page says its web links record respondent IP addresses by default, and that email invitations include each respondent’s email address in the results unless anonymous responses are switched on before sending. Other tools differ, so check what yours stores rather than assuming.

The route in matters as well. A shared link is anonymous; a personal link, a tracked invitation or a required sign in ties the response to someone even if the survey never asks a name. If you need to keep outsiders away, a password shared with the whole group does that without identifying anybody.

Then read every question as if you were trying to work out who wrote it. Date of birth, exact job title, start month and site name each look harmless. Together they often describe one person.

The small group problem

The Australian privacy regulator treats information as personal when a person is reasonably identifiable from it, and its de-identification guidance stresses that the risk has to be judged in context, including what the reader already knows. In a workplace survey the reader is often a manager who knows every person in the team, which is the hardest context there is.

The fix is to keep segments broad and to refuse to report small groups. The pulse survey asks for team only, from five broad options, and its team question says a team under five responses is never reported on its own. The thank you screen repeats the rule, so the promise is made twice at the moments people decide whether to be frank.

The 360 feedback form uses the same idea for a harder case. Its welcome screen says the person being reviewed gets a report only once at least four people have replied, and never a single response on its own. The exit interview form goes further in the other direction: team level is as specific as it gets, and a separate question asks whether the answers may be shared with the manager, with a named, an unnamed summary or a no option. Exit surveys are the hardest case for anonymity because the leaver is often the only person who left that month, which is why the guide on running an exit interview survey recommends promising confidentiality there rather than anonymity.

The Australian Bureau of Statistics describes two kinds of breach that apply directly to small surveys: re-identification, where the person is worked out, and attribute disclosure, where something about them is revealed without formally naming them. A table showing that the only two people in a site both rated their manager poorly is the second kind.

Telling respondents what happens

People answer honestly when they know the rules. Put these points on the first screen, in plain sentences:

The course evaluation form from a fictional training institute is a good model for length. Its welcome screen says three rating grids and two open questions, nothing identifies you, and results go to the trainer as averages. It segments by class, never by trainer, so nobody has to rate a named colleague.

Avoid words you cannot stand behind. “Completely anonymous” is a claim one respondent can disprove by spotting a tracked link, and that person will tell everyone else.

Reporting without exposing anyone

Most anonymity is lost after the survey closes. Four reporting rules prevent it.

Apply the threshold everywhere. If teams under five are hidden in the summary, they must be hidden in every chart, filter and export shared beyond the analyst.

Summarise open comments. A phrase, a project name or a date can be recognised. Group comments into themes and paraphrase them. The pulse survey makes both open questions optional, so the six rated statements always get answered even by people who have nothing they want to put in writing.

Watch the timing. A response submitted at 11.40 on the one morning a small team was offsite narrows the field. Do not share raw submission times with anyone who knows rosters.

Limit the raw file. The raw export should stay with one or two named people, and be deleted on the date you promised.

The checklist

The table at the end of this article turns the practices above into ten checks, each with the reason and a way to test it before the link goes out. Work through it with the draft form open. The two rows most often skipped are the add-on check and the deletion date, because neither shows up while the survey is being built.

Common mistakes

A required email “for the prize draw”. This turns every response into an identified one. Run the draw from a separate form linked on the thank you screen.

Too many demographic questions. Each extra segment multiplies the chance that a combination points to one person. Ask only the segment you will actually report on.

Quoting comments word for word. Even a short quote can be recognised by the person it describes or the colleague who heard the story.

Forgetting the inbox. An email alert that copies each response to a manager’s address has quietly changed who reads raw answers.

Changing the promise mid survey. Adding a name question after some people have answered means earlier respondents agreed to rules that no longer apply.

For wording the questions themselves, the guide on how to write survey questions covers leading and double barrelled questions, which matter just as much in an anonymous survey.

Build it

A form here has one of four access types: public, secret key, login required or domain restricted. For an anonymous survey, public or secret key keeps the route in shared rather than personal, and the page on controlling who can fill in a form compares all four. A stored response holds the answers, the time it was submitted and the form version it was submitted against; it has no field for a name, account or network address unless the form itself asks for one.

Be deliberate about add-ons. Email alerts send the submitted values to one address, and webhooks post each response to another system, so either one widens who sees raw answers. Partial responses are not stored, so an abandoned survey leaves no record. The tutorial on viewing, exporting and managing responses covers the responses table and the CSV export, which is where the reporting rules above are applied.

Anonymous survey checklist: each practice, why it matters and how to check it before the link goes out.
PracticeWhy it mattersHow to check
Decide anonymous or confidential before writing questionsThe promise shapes every later choice, from the link to the reportWrite the promise in one sentence and test each question against it
Use one shared link, not personal invitationsA personal link or a tracked invitation ties a response to a personOpen the link from two accounts and confirm it is the same address
Ask no name, email or employee numberDirect identifiers defeat anonymity on their ownRead every label for anything that names a person
Keep segments broadTeam, role and tenure together can point to one personCount the smallest group any combination of answers produces
Set a minimum group size for reportingSmall groups can be identified from their resultsWrite the threshold on the first screen and in the report
Make open comments optionalSpecific stories identify their authorsConfirm every open question can be skipped
Check what each add-on copiesAlerts and integrations send answers to other systemsList every inbox and system that receives a response
Say who reads the raw answersTrust depends on knowing the audienceName the role or team on the welcome screen
Summarise comments before sharingExact wording can be recognised by a managerParaphrase or group comments into themes in the report
Decide how long raw responses are keptOld raw data is a standing riskSet a deletion date and put it in the calendar

A finished example

A pulse survey only works if the questions never change, because the point is the line on the chart, not the answer this month. These six statements are the whole instrument, the team question is the only segment, and the open questions are optional so the six always get answered.

Read the employee pulse survey that can be trended month to month

Questions people ask

Can a survey be anonymous if I send the link by email?

Yes, if every recipient gets the same link and the survey itself asks nothing identifying. The email only proves who was invited, not who answered. Anonymity breaks when the link is personalised, when the platform records the address that opened it, or when the form asks for a name or email. Send a single shared link, and say in the email that it is the same link for everyone.

Should I let people leave an email for a follow up?

You can, as an optional question placed at the very end, with a sentence saying that answering it makes that response identifiable. From that point the response is confidential rather than anonymous, and the report should treat it that way. Many teams prefer a separate short form for follow up requests, so the main survey stays anonymous for everybody who does not want contact.

What minimum group size should I use for reporting?

There is no single legal number, but the examples on this site use thresholds of four or five responses before a group is shown on its own. The right number depends on how well the reader knows the people in the group. In a workplace where a manager knows every member of a team of six, five is the smallest figure that still hides one person.

Are open comments ever safe in an anonymous survey?

They are safe enough when they are optional, when the question asks about the organisation rather than a named person, and when the report groups comments into themes instead of quoting them. Warn respondents on the screen that specific examples can identify the writer. Anyone with a serious individual complaint should be pointed to a proper reporting channel instead.

Does a prize draw break anonymity?

It does if the entry details sit in the same response as the answers. Run the draw through a second form that opens after submission, or a link on the thank you screen, so the name and email for the prize are stored separately with no connection to the survey answers. Say on the first screen that the two are kept apart.

Can I send reminders only to people who have not answered?

Not in a truly anonymous survey, because nobody knows who has answered. Send the same reminder to everyone, with a line thanking those who already responded. Targeted reminders need a confidential design, where identities are known to a small named group. That trade is sometimes worth making, but it has to be stated honestly rather than described as anonymous.

Written by

Nuwan Madhusanka · Co-founder

Works across the builders and the export paths: how a form becomes a PDF, how a flyer canvas becomes a print file, and how a signed document carries its audit trail.

LinkedIn profile

Sources

Written and checked by the OneCraft team. Last checked .

Make your own form

Describe what you need and the generator writes and designs it, then you edit anything you like.

See what it can make

Read next

For the steps inside the builder, read the guideon this topic.