With enterprise-grade security, compliance, and privacy controls, we protect your data like it's our own—just like we do for 260K+ organizations worldwide.
Security | Privacy | Certifications | AI | FAQs | Contact sales
BENEFITS
✔ Dedicated security team
✔ Annual third-party penetration tests
✔ Bi-annual privacy and security reviews
✔ 24/7 on-call security Incident response team
✔ Encryption at rest (AES-256) and in motion (TLS 1.2)
✔ Active bug bounty program
✔ AWS cloud security
✔ Annual security awareness programs for all employees and contractors
✔ Annual exec-level tabletop exercises
✔ Privacy by design
✔ Bi-annual audit for privacy compliance
✔ Data breach notification
✔ Customer control of data
✔ AI governance
✔ Standard Contractual Clauses (SCCs) by default
✔ Data Privacy Framework (DPF) self-certified
✔ Robust privacy impact assessment processes
✔ SOC 2 Type II
✔ ISO-27001
✔ CCPA
✔ HIPAA**
✔ PCI DSS
✔ GDPR (EU, UK, Switzerland)
**BAAs available as add-on with the Enterprise plan; must be purchased separately
✔ Single Sign-On (SSO)*
✔ Two-factor authentication (2FA)
✔ Account control*
✔ Data deletion on a self-service basis or upon request
*Available to SurveyMonkey Enterprise only
SECURITY
You need a survey platform you can trust with your sensitive data. That’s why SurveyMonkey delivers a comprehensive security program that safeguards your data at every level—from secure product development and employee training to robust global infrastructure management. We undergo regular third-party audits and security reviews to stay ahead of potential threats, ensuring your data remains protected at all times.
We take a security-first approach to building and maintaining our platform. Every product developer is trained in secure web application development practices when hired and completes annual refresher trainings to stay up to date on best practices.
Security threats don’t keep business hours, and neither do we. Our dedicated incident response team operates 24/7, conducting annual independent penetration tests and running a bug bounty program to proactively identify and address vulnerabilities.
We protect your data with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Customer data is securely stored on AWS servers in the US, Canada, and Ireland (EU), ensuring compliance with regional data protection standards.
PRIVACY
SurveyMonkey is built with privacy at its core, so you can collect insights with confidence. Our platform includes built-in features to help you meet GDPR (EU, UK, and Switzerland) and CCPA requirements effortlessly. We stay ahead of evolving regulations with ongoing updates, so your data continuously remains protected and compliant.
We are self-certified under the EU-US Data Privacy Framework, the UK Extension and the Swiss-US DPF Principles, ensuring strict adherence to privacy standards for cross-border data transfers. We also embed Standard Contractual Clauses (SCCs) in our customer and vendor contracts. See our Transfer Statement for more details.
Our AWS-based data centers in Ireland (EU), Canada, and the US give Enterprise users control over where their data is stored. No matter the location, our privacy and security settings ensure compliance with data protection regulations in regions such as Australia, Canada, the UK, Switzerland, and the EU.
We provide flexible data retention and deletion controls that align with your local regulatory requirements. With SurveyMonkey, you get strong privacy defaults, intuitive controls, and the flexibility to manage your data on your terms.
CERTIFICATIONS & STANDARDS
With certifications like SOC 2, PCI, ISO 27001, and bi-annual privacy audits, SurveyMonkey doesn’t just claim security—we have independent third parties verify and validate it. Our commitment to compliance is validated by rigorous external assessments and industry-recognized standards, so you can trust your data is always protected.
All SurveyMonkey plans include PCI DSS certification. Enterprise customers can also opt for HIPAA compliance or our Enhanced Sensitive Data Protection.
To ensure ongoing compliance and privacy maturity, we have an internal Dedicated Data Protection Officer (DPO) and work with an auditor to ensure we’re meeting GDPR requirements and adhere to industry best practices.
RESPONSIBLE AI
We built innovation and security into our AI capabilities, so you can benefit from the power of AI without compromising your data. Our partnerships with third-party providers ensure your data is never used to train their models, keeping your information safe, private, and fully in your control.
“SurveyMonkey checked off two buy-in factors: SurveyMonkey understands GDPR. SurveyMonkey gets Salesforce. That’s huge for us.”
Matt Schoolfield
Senior Manager of Commercial Analytics and Voice of the Customer
Greyhound

Find information on privacy, security, terms of use, and other important legal topics.


Get an in-depth look at how we safeguard your data with industry-leading security practices.
Yes, SurveyMonkey is safe to use. We have implemented multiple levels of security controls to ensure that your data is kept safe and secure, including security-enhancing product features like SSO and multi-factor authentication technology. We also incorporate intrusion protections systems, data leakage prevention tools, and bug bounty programs.
SurveyMonkey is also compliant with ISO 27001, SOC2, and PCI-DSS.
Yes, we comply and help our customers comply with the General Data Protection Regulation (GDPR) applicable in the European Union and with similar rules in regions like the UK and Switzerland. We have implemented a variety of measures to ensure we meet the requirements of the GDPR. This includes features like data encryption, secure data storage in our EU-based data center, and robust privacy controls. We also provide tools that allow you to manage consent, data access, and data retention, helping you remain compliant.
SurveyMonkey data centers operate within a cloud-based architecture powered by Amazon Web Services (AWS), with locations in Ireland (EU), Canada, and the United States. Enterprise users can select the physical location for the storage of some of their data. Regardless of where your data is stored, our privacy and security settings ensure compliance with data protection regulations in regions such as Australia, Canada, the UK, and the EU.
Yes, we offer HIPAA-compliant features as an add-on to help you meet your compliance needs. This add-on is only available to SurveyMonkey Enterprise customers. Learn more about HIPAA compliance at SurveyMonkey, including how to sign a Business Associate Agreement with us.
Yes, we offer an enhanced sensitive data protection add-on which provides a higher level of security when using SurveyMonkey to collect or store sensitive information. This add-on is only available to SurveyMonkey Enterprise customers. This offering is currently not available to Apply or GetFeedback products.
Our approach is a privacy-by-design and data minimization-first approach. Following industry practice and consistent with our Privacy Notice, we use de-identified customer data or synthetically-generated data to train and build our proprietary AI models, while also protecting customer security and privacy.
We have spent many years developing a secure methodology for safely and securely improving our models with minimal invasiveness or human review. This involves a thorough automated method for aggregating and de-identifying data prior to use for model training. We exclude personal data from these data sets and we set strict retention limitations on all data used for this purpose, ensuring that it is deleted within a set time period after use. We also apply strict access controls for data, such that least privileged rules apply.
Several AI features use OpenAI or other third-party providers to generate insights. Data shared with these third-party providers is not used to train their AI models.
SurveyMonkey encrypts all data at rest in our data centers using AES 256 based encryption. Additionally, SurveyMonkey encrypts all data in motion using (i) RSA with 2048 bit key length based certificates generated via a public Certificate Authority, for communications with entities outside SurveyMonkey data centers, and (ii) RSA 256 certificates generated via Internal Certificate Authority, for all the data within the data centre.
Yes. We conduct annual third-party penetration tests to check for any vulnerabilities.
SurveyMonkey maintains the following security certifications: SOC II, ISO 27001, PCI DSS 3.2 and EU-US Data Privacy Framework Certification.
Since our customers act as controllers (or businesses) over their respondents’ personal data, we enable our customers to fulfill the data subject requests of their users.
No. See our Region-Specific Privacy Notice for more details.
Yes, we conduct bi-annual audits of our security and privacy practices to ensure compliance with applicable local and international regulations.
SurveyMonkey relies on Standard Contractual Clauses for international data transfers, including appropriate technical and organizational measures to protect EEA, UK, and Swiss personal data during and after transfer.
We have also self-certified under the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US DPF Principles, ensuring that we adhere to strict data protection standards when handling customer data.
Please see our EU Data Transfer Statement for more information.
When you are an Australian customer, you enter into a contract for SurveyMonkey services with our Irish entity, SurveyMonkey Europe UC. SurveyMonkey Europe UC complies with laws applicable to it in Ireland and the European Union to include the General Data Protection Regulation (GDPR). However, we have taken steps to ensure that our contract terms, data protection, and security controls are more broadly compatible with laws that are of concern to our customers where possible. This includes implementing transparent privacy notices, user controls in our products/privacy by design, industry standard technical and organizational security measures to protect data, and ethical AI development and governance practices. We also have an Australia addendum to our DPA which is available for our Australian customers.
Contact our sales team and get all your security and privacy questions answered, plus access to specific resources. Note that certain documents may require an NDA on file.