Data Security in AI Market Research: GDPR Guide
A step-by-step GDPR and security review for AI market research and synthetic audience tools: personal data, DPA, data location, transfers, model training, security and deletion.
AI market research tools, including synthetic audience and synthetic respondent platforms, can reduce the amount of personal data a research project needs, because no participants are recruited or recorded. They do not remove GDPR from the project. Uploaded files, customer data used for grounding, personas of named people, prompts and your team's account data can all be personal data, and the tool's provider usually processes them on your behalf. This guide sets out a step-by-step review that a CX or insights lead can run with the data protection officer before introducing such a tool.
This is general information, not legal advice.
The problem: what changes with AI market research
Traditional fieldwork processes participants' personal data: screeners, contact details, recordings, incentives and consent records. AI market research changes where the personal data sits rather than removing it:
- Participants disappear from the workflow, which removes most consent and recording obligations.
- Your own data moves to the centre: customer research, CRM extracts, interview transcripts and concepts you upload to ground or test a synthetic audience.
- New processors appear: the research platform and the AI model providers it sends prompts and files to, often outside the EU.
Why a standard vendor review is not enough
A security questionnaire built for survey software misses three questions specific to AI tools: which model providers receive your data, whether any of them may train on it, and whether the "EU hosting" on the website covers AI processing or only the application. Each needs a contractual answer.
The review in seven steps
1. Map the personal data (Art. 4 and Art. 5(1)(c) GDPR)
List every kind of data the tool would see: account data, uploaded files, grounding data, stimuli and prompts. Mark which are personal data. Then minimise: published statistics, aggregated results and properly anonymised survey data are usually enough to ground a synthetic audience. Avoid raw customer records unless the purpose requires them. See GDPR data minimisation.
2. Check the lawful basis and purpose
If you use customer data, check that your privacy notice and lawful basis cover using it to ground simulations. Building a persona of a specific, named person is processing of that person's data and needs its own basis.
3. Get a data processing agreement (Art. 28 GDPR)
If the provider processes any personal data for you, you need a DPA that names the subject matter, data categories, subprocessors and deletion terms.
4. Check data location and transfers (Art. 44 ff. GDPR)
Ask for the full subprocessor list with locations, not just where the application is hosted. AI model providers are often in the USA. Transfers outside the EU need a mechanism such as an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses.
5. Exclude model training
Get a contractual commitment that your inputs and outputs are not used to train, fine-tune or improve the provider's or any third party's general-purpose models.
6. Review security measures (Art. 32 GDPR)
Check encryption in transit and at rest, tenant separation, access control and credential handling. Distinguish the provider's own certifications from those of its hosting providers.
7. Confirm retention, deletion and data subject rights
Find out how long data is kept, how you delete it, and how the provider supports access and deletion requests.
Applying the review to Minds
As of October 2026, Minds' published legal documents answer these questions as follows:
| Review step | Minds |
|---|---|
| DPA | Offered under Art. 28 GDPR: data processing agreement |
| Hosting | Application on DigitalOcean, Frankfurt; database on Supabase, Stockholm |
| AI processing | OpenAI, Anthropic and Google Cloud Vertex AI in the USA, among others; full list on the subprocessors page |
| Transfer basis | The privacy policy names the EU Commission's Standard Contractual Clauses for these US providers |
| Model training | Customer data is not used to train general-purpose or third-party models (DPA) |
| Security | TLS 1.2+ in transit, AES-256 at rest, tenant separation: technical and organisational measures |
| Certifications | Hosting providers hold SOC 2 Type II and ISO 27001; Minds itself does not currently hold a SOC 2 report or ISO certification |
For a short summary, see is Minds GDPR compliant and secure, and for how GDPR applies to synthetic respondents in general, are synthetic respondents GDPR compliant.
Conclusion
AI market research can make projects faster and reduce the personal data involved, but only a review of the specific tool and the specific data tells you whether a use is compliant. Map the data, minimise it, get the DPA, look past "EU hosting" to the full subprocessor list, exclude model training in writing, and check security and deletion. Then decide which data may go into the tool and which should stay out.
Frequently asked questions
How do I check whether an AI market research tool is GDPR compliant?
Map which personal data the tool would process, then check the provider's data processing agreement, subprocessor list and locations, transfer mechanisms for any processing outside the EU, its policy on training models with customer data, its security measures and its deletion process. Compliance is a property of your use, not of the tool alone.
Does synthetic research avoid GDPR?
No. Simulated respondents are usually not personal data, but uploaded files, customer data used for grounding, personas of named people and the account data of your team can be. Synthetic research often reduces the amount of personal data involved, which helps with data minimisation, but it still needs a review.
What does hosting in the EU guarantee?
Less than it sounds. Many AI tools host their application in the EU but send prompts and files to AI model providers in the USA. Ask for the full subprocessor list with locations and the transfer mechanism, usually Standard Contractual Clauses or the EU-US Data Privacy Framework.
What should we ask about model training?
Ask whether your inputs, files or outputs are used to train, fine-tune or improve the provider's models or any third-party model, and get the answer in the contract or DPA rather than a marketing page.


