Survey Anonymity and Data Protection for Organisations
Overview
Every survey, form and questionnaire you send asks people to hand you something personal: an opinion, a preference, a piece of information about themselves. Anonymity is the setting that decides how much of that comes back attached to a name.
It is not a cosmetic choice. Seaty enforces it on the server, so the mode you pick governs what appears on screen, what appears in a downloaded spreadsheet, and what appears on a printed copy. It also governs what you promise the respondent, because Seaty shows them a plain statement of the mode before they answer.
At its simplest, anonymity answers one question: how much do I need to know about who said this?
Who uses this: Organisation administrators with the Surveys permission.
Key capabilities:
- Choose Identified, Confidential or Anonymous when you build a survey or questionnaire
- Show respondents a clear, honest statement of how their answers will be handled
- Keep the summary and responses table hidden until enough people have replied
- Reveal a single confidential respondent when you genuinely need to, with the reveal recorded
- Delete one person's responses on request
How It Works
At a glance: You pick a mode before the first response arrives, Seaty tells respondents what that mode means, and from then on Seaty limits what you can see everywhere the results appear.
1. Decide what you actually need to know
Before you write a single question, work out whether you need to contact people about their answers, whether you only need to group their answers, or whether you need nothing about them at all. That decision is the anonymity mode.
Asking for less than you need leaves you unable to act. Asking for more than you need makes people guarded, and gives you personal data you then have to look after.
2. Set the mode while the survey is still a draft
The anonymity picker sits in the Setup section, under the "Type and anonymity" heading alongside the type. Confidential is the starting point for a new survey or questionnaire.
Why is it set so early? Because the mode is frozen the moment the first response arrives. It sets the promise you made to everyone who has already answered, and Seaty will not let you quietly change that promise underneath them.
3. Respondents are told what the mode means
When somebody opens the link, Seaty shows the statement for your chosen mode underneath your introduction, along with a link to the Seaty privacy information. You do not have to write it, and you cannot accidentally contradict it.
4. Seaty limits what comes back
Once responses start arriving, the mode decides which columns exist on the responses table, what the individual response view shows, whether you can list who has not replied, and whether breakdowns are shown at all while numbers are small.
5. You handle the answers responsibly
Seaty controls what it shows you. What you do with the answers afterwards, who you share them with, how long you keep them and whether you told people the truth about their purpose, is yours to get right.
Think of it this way:
- Identified means you know who said it, and they know you know
- Confidential means you can group answers by date or ticket type, but not read them back to a name
- Anonymous means you are shown no name and no email address anywhere in the results
The Three Modes
The picker offers three modes:
| Mode | What it means | Use it when |
|---|---|---|
| Confidential | Results segmented, identities hidden | You want honest opinions but still need to break results down |
| Identified | You can see who answered | You need to reply to people, chase them, or record who told you something |
| Anonymous | No name, no email address, and no way to tell from the results screens who gave any answer | The subject is sensitive and you have no need to follow anything up |
Forms are different. A form always records who responded, and the anonymity picker is not offered for one. Why? Because a form exists to collect required details from named people (a cast list, a membership record, a volunteer sign-up), and an unattributable membership form is useless. See Building a survey for more on choosing a type.
What each mode shows you
| What you see | Identified | Confidential | Anonymous |
|---|---|---|---|
| Name and email columns | Yes | No | No |
| Whether the email address was verified | Yes | No | No |
| Membership column and bulk membership actions | Yes, when memberships are enabled | No | No |
| Event date and ticket type columns | Yes, where recorded | Yes, where recorded | No |
| Identity on an individual response | Yes | Hidden, with an audited reveal | No name or email address shown |
| A list of who has not responded yet | Yes, where it was emailed | No | No |
| Ability to erase one person's responses | Yes | Yes | No |
Two points worth being clear about.
These limits are not just hidden screen columns. The spreadsheet download and the printed copy come from the same restricted set of information as the screen. There is no export that quietly contains more than the results page.
Confidential is not the same as anonymous. On a confidential survey Seaty does hold the respondent's name and email address. It simply never shows them to you except through the deliberate, recorded reveal described below. That is what makes segmentation by event date and ticket type possible at all. If you need to be able to tell people that you are not being given their name or email address at all, choose Anonymous.
Why does Anonymous drop the event date and ticket type as well? Because on a small survey those details narrow the field. If only four people held a particular ticket type on a particular night, a breakdown by both would come close to naming them.
What respondents are told
Seaty shows one of these lines under your introduction, followed by a link to the storage and privacy information:
- Anonymous: "Your answers are anonymous. Your name and email address are not collected."
- Identified: "Your response will be linked to your email address so the organiser can follow up."
- Confidential: "Your answers are confidential. [Your organisation] sees results grouped together, never who gave each answer."
Read those as commitments you are making. Do not write an introduction that contradicts them, and do not describe a confidential survey as anonymous in the covering email. The respondent will read both.
Why Anonymity Changes the Answers
On anything sensitive, people manage what they say to protect a relationship. A chorus member who thinks the musical director is running rehearsals badly, a volunteer who finds their supervisor difficult, a visitor who found the accessible entrance humiliating: all of them will soften or skip the honest answer if their name is on it. They are not being dishonest. They are weighing up whether the feedback is worth the awkwardness at the next rehearsal.
Remove the name and that calculation disappears. You will generally get lower scores and blunter comments on a confidential or anonymous survey than on an identified one, and the lower scores are usually the more accurate ones. If your last identified member survey came back glowing, treat that as an untested result rather than a verdict.
The trade is that you lose the ability to act on an individual case. An anonymous respondent who describes something genuinely worrying cannot be reached. Decide in advance which of those two things matters more for the question you are asking.
Keeping Small Numbers Hidden
Seaty will not show a breakdown of a survey that is not Identified until at least five responses have been collected.
Below that, the summary is replaced by a short message: no headline figures, no per-question breakdown, no responses-over-time chart. If a filter is active the message tells you the filter is too small and invites you to clear it. If no filter is active it tells you the survey itself is too small.
The suppression covers the breakdowns, not every number on the screen. The total number of responses stays visible, and where a survey has event date or ticket type filters those stay on screen with a count beside each option. So you can still tell how many people replied and roughly when, you just cannot see what any of them said.
The same floor applies to the responses table, so filtering down to a handful of people does not open the results up again. It is a floor on the summary and the responses table specifically. Clicking a bar or a rating on a chart opens the responses behind it, and that route can land on a single response. What it shows is still governed by the mode, so on a confidential or anonymous survey there is no name or email address on it.
The same floor also applies to a single question on its own. If a survey uses pathways, a follow-up question that fewer than five people were led to is hidden by itself, with a short note in place of its numbers, even when the survey as a whole is well above five. A branch that only two people reached would otherwise show those two people's answers in isolation, which is the very thing the floor exists to prevent.
Why suppress anything at all? Because with three responses a breakdown is barely a breakdown. If you know roughly who was invited, "two of three said the committee is not listening" is close enough to naming them. The threshold makes the promise you displayed on the response page hold in practice as well as in principle, particularly on the small audiences a community organisation typically surveys.
The one door through the floor is moderation. If a small anonymous survey collects something abusive, the protection would otherwise leave you unable to reach it at all. So the protection message offers Review answers for moderation, which shows the written answers on their own, with a Delete button against each. It shows no names, no email addresses and no other answers, on any mode. Seaty records that you opened it and when, and records any deletion separately. It exists for acting on a specific complaint, not for reading a confidential survey early, and it does not tell you who wrote anything: revealing a confidential respondent stays a separate, separately recorded action.
Practical consequences worth planning around:
- A small choir or committee survey may never reach five responses. If you send a confidential survey to seven people, you might see nothing at all. Consider whether the group is simply too small for a survey, and a conversation would serve you better.
- Filters are the usual cause. A survey with eighty responses will still suppress the view when you narrow it to one quiet matinee. Clear the filter to see everything again.
- Identified surveys are not suppressed, because there is no anonymity promise to protect.
Revealing a Confidential Respondent
Confidential surveys, and only confidential surveys, offer a reveal.
Open an individual response and, where identity was recorded, you will see the note "Confidential response. The respondent's identity is hidden." with a Reveal identity button. Using it shows that one person's recorded name and email address for that one response.
Three things to understand before you use it:
- It is recorded. Every reveal is written to the survey's audit log with the survey, the response, who did it and when, before the identity is returned. Seaty tells you so on screen: "This reveal has been recorded in the survey audit log." Deleting one response from the individual response view is recorded in the same way. Removing somebody through the Data requests section is not: that route writes no audit entry.
- Anyone with the Surveys permission can do it. There is no separate, higher permission for revealing. If that concerns you, control it by controlling who holds the Surveys permission. See Managing members.
- It is not available on Anonymous surveys, at all. No name or email address is recorded against the response, and Seaty refuses the request.
When is a reveal defensible? The honest answer is: rarely, and usually for the respondent's benefit rather than yours. A disclosure of a safeguarding or welfare concern that you cannot responsibly leave unaddressed is the clearest case. Curiosity about who left a critical comment is not, and the audit log exists precisely because that temptation is real.
If you expect to need to follow up as a matter of course, you have picked the wrong mode. Use Identified and say so.
Your Data Protection Duties
Seaty provides the mechanism. The answers belong to the organisation that collected them, and that organisation decides how they are used. Your organisation is the data controller for the answers it collects, which means the legal responsibility for how those answers are gathered, used, shared and kept sits with you, not with Seaty.
None of the following is complicated for a typical community organisation, but all of it is your job.
Tell people what the answers are for
Your introduction is where you do this. Say who is asking, what you want to learn, and what you will do with the responses. "This helps the committee plan next season" is enough. What you must not do is collect answers for one stated purpose and then use them for another, such as gathering feedback and then using the addresses for marketing.
Why does this matter more than it sounds? Because a person's willingness to answer honestly is based on the purpose you stated. Repurposing the data breaks that, and it is the kind of thing people notice and remember.
Ask for as little as you can get away with
Every extra field is data you then have to protect, and a small reduction in response rate. If you do not have a concrete use for a date of birth, a full postal address or a phone number, do not ask for it. If you are collecting names purely because it feels normal, that is a good sign the survey should be confidential or anonymous instead.
The same restraint applies to the questions themselves. Free text invites people to volunteer far more than you asked for, including things about other people. Expect it, and handle what comes back accordingly.
Take extra care with health and access information
Questions about disability, access requirements, dietary needs, medical conditions or mental wellbeing are a more sensitive category of personal information and deserve more caution than a question about which night somebody attended.
Practical guidance:
- Ask only where you will genuinely act on the answer. An access question that changes nothing about how you run the venue should not be there.
- Say in the question or its helper text exactly what you will use it for and who will see it.
- Prefer a free-text access field ("Is there anything we should know to make your visit easier?") over a tick list of medical conditions. It gets you what you need without recording a diagnosis.
- Think hard before making it identified. A named list of your members' health conditions is a serious thing to hold on a spreadsheet on somebody's laptop.
- Be aware of the small-numbers problem in reverse: on a small membership survey, an unusual access requirement can identify somebody even without a name attached.
Look after the answers once they leave Seaty
The moment you download a spreadsheet, the protections described on this page stop applying to that copy. A downloaded identified response list is an ordinary file on an ordinary computer. Share it narrowly, do not email it around the committee out of habit, and delete copies you no longer need.
Handle requests to be removed
A respondent can ask you to delete what they submitted. On identified and confidential surveys, the survey Overview has a Data requests section where you enter their email address and press Remove their responses. This is permanent.
Three limits to be honest about:
- Anonymous surveys cannot honour it. There is no email address recorded, so there is nothing to match against. This is worth mentioning if somebody asks.
- Removal covers the responses, not every trace. The record that they were sent the survey is kept. That record is what the send screen uses for Skip people who have already been sent this survey, which is ticked by default but can be unticked, so it prevents a repeat send only while it is left on.
- It is not recorded in the audit log. Unlike deleting a single response, removal through Data requests writes no audit entry. Keep your own note of the request if you need to evidence that you acted on it.
There is no automatic deletion of survey responses in Seaty. Responses stay until somebody removes them. If your organisation has a retention policy, you will need to apply it yourself.
Choosing a Mode for Common Situations
Audience feedback after a show
Confidential. You want candid opinions about the production, and you want to break them down by night and ticket type, which is exactly what confidential is designed for. Nobody needs to be contacted individually about how they rated the lighting.
Choose Identified instead only if you specifically intend to reply to people, for example running a prize draw among respondents, and tell them that is why.
Member or volunteer satisfaction
Confidential, or Anonymous. This is the case where the mode makes the largest difference to the answers you get. Members will not tell you plainly that the committee is unapproachable while their name is attached.
Use Confidential if you want to be able to segment or to reach one person about something serious. Use Anonymous if the group is small, the atmosphere is already tense, or you want to remove every doubt. On a small membership, remember that you may not reach five responses and see nothing at all.
Never run this one Identified. It looks like a request for feedback and reads like a loyalty test.
A complaint, grievance or wellbeing survey
Think carefully, and be explicit either way. The two options pull in opposite directions.
Anonymous gets the fullest disclosure, and leaves you unable to help the individual who discloses something serious. Confidential gets slightly more guarded answers, but leaves a route to reach somebody in a genuine welfare situation, at the cost of an audited reveal.
Whichever you choose, say so in the introduction in plain terms. If you choose Confidential, tell people that in a serious welfare situation an administrator may identify them, and that doing so is recorded. Do not let somebody disclose something on the assumption of anonymity that they do not actually have.
For anything of this weight, also make sure people know how to raise a concern directly to a named person, rather than relying on a survey to surface it.
A membership, audition or volunteer form
Identified, automatically. Build it as a form and the question does not arise: forms always record who responded, and the picker is not shown. That is the right behaviour. A membership renewal you cannot attribute to a member is not a record of anything.
Because a form is always identified, Not responded becomes available in the survey section navigation, so you can see who has not returned theirs and chase them. It needs one more thing: the form has to have been emailed from Seaty, since the list is worked out from the people it was sent to. A form shared only by link or QR code shows no such list. Bear in mind too that somebody who answered through a plain shared link cannot always be matched back to the address it was sent to, so they can appear as not having responded when they have. See Sending and sharing.
Apply the data-minimisation point hardest here, since forms are where organisations tend to collect the most: ask for emergency contacts, medical information and photo consent only if you have a real process that uses them.
A funder monitoring survey
Anonymous, in almost every case. Grant monitoring typically asks about age band, ethnicity, disability, first-time attendance and postcode area. That is the most sensitive combination in this whole document, and funders want aggregate figures, not a list of individuals.
Anonymous gives you the totals you need to report, gives respondents the strongest reason to answer honestly, and means you are not holding a named demographic profile of your audience.
Two things to plan for. First, you will not be able to break results down by performance date, so if the funder wants figures for a specific run, send a separate survey for it. Second, the five-response floor applies, so a monitoring survey on a small event may show nothing. Tell people in your introduction that the answers are used only as totals for grant reporting, and that answering any question is optional.
Common Questions
Choosing and changing the mode
Can I change the anonymity mode after I have sent the survey? Only until the first response arrives. After that it is frozen, along with the type and all of the questions. The mode is the promise made to people who have already answered, so it cannot be altered retrospectively.
What if I picked the wrong mode and responses have started coming in? Your options are to carry on and accept the limitation, or to close that survey and build a new one with the correct mode. There is no way to convert responses from one mode to another.
Which mode is the default? New surveys and questionnaires start as Confidential. Forms are always identified and offer no choice.
Can different questions in one survey have different modes? No. The mode applies to the whole survey. If you need one sensitive question handled anonymously, ask it in a separate anonymous survey.
What you can see
Can I see who answered a confidential survey? Not in the ordinary run of things. Names and email addresses are absent from the results table, the individual response view, the spreadsheet download and the print view. You can reveal one individual response deliberately, and that reveal is recorded.
Why can I not see who has not responded to my confidential survey? Because listing who has not responded tells you who has, which is precisely what confidential and anonymous respondents were promised protection from. The non-responder list is only offered on identified surveys, and only where the survey was emailed from Seaty.
Does the spreadsheet download contain more than the screen? No. The same restrictions apply to the download and to the printed copy.
Why has my summary disappeared? Almost certainly the five-response floor. Either the survey has fewer than five responses in total, or you have filtered down below five. Clear the filter, or wait for more responses.
Why can I see a single response after clicking a chart? The five-response floor covers the summary and the responses table. Clicking through from a chart opens the responses behind that bar or rating, and on a small survey that can be one response. It still shows only what the mode allows, so no name or email address appears on a confidential or anonymous one.
Reveals and deletion
Who can reveal a confidential respondent? Anybody with the Surveys permission for your organisation. There is no second permission. Manage this by managing who holds that permission.
Is the reveal reversible? The act of looking is not. The record of it is permanent, and you are told so at the time.
Can I reveal somebody on an anonymous survey? No. No name or email address is recorded against the response, and Seaty refuses the request.
Can I delete a single response? Yes, from the individual response view. That deletion is recorded in the audit log. Removing somebody through the Data requests section is not recorded.
Does Seaty delete old survey responses automatically? No. Responses remain until somebody removes them, either one at a time or by removing everything for one email address. Any retention policy is yours to apply.
Responsibilities
Is Seaty responsible for the answers I collect? Your organisation is the data controller for the responses it gathers, which means the decisions about what to ask, what to do with the answers and how long to keep them are yours. Seaty provides the tool and enforces the anonymity mode you chose.
Do I need to write my own privacy wording in the introduction? Seaty already shows respondents the statement for your chosen mode and a link to how responses are stored. What Seaty cannot know is your purpose, so say in your own words what you are asking for and what you will do with it.
Can I use survey email addresses for marketing? No. People who agreed to be sent surveys have not agreed to be sent marketing, and Seaty deliberately does not offer marketing audiences when you send a survey. See Mail for marketing communications.
Where do I go next? Surveys and forms for the overview, Building a survey for question design, and Reading results for what the results screens show. Respondents can read Completing a survey.