FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. SurveyMonkey
S

SurveyMonkey

Preferences

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SurveyMonkey do?

SurveyMonkey is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. SurveyMonkey integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, SurveyMonkey enhances satisfaction by ensuring tailored browsing experiences for every visitor.

SurveyMonkey, founded in 1999 and now part of Momentive Inc., is one of the most widely used SaaS survey platforms. Surveys are designed and hosted on surveymonkey.com and distributed by direct link, email, embedded JavaScript snippet, popup or iframe. Responses are stored on SurveyMonkey infrastructure by default in the United States, with an optional EU data residency for Enterprise customers.

What SurveyMonkey does

SurveyMonkey provides a question builder with 16 question types, branching logic, randomisation, multilingual surveys, NPS and CSAT templates, advanced analytics with crosstabs and text analysis, and integrations with Salesforce, HubSpot, Microsoft Teams, Slack and Zapier. The Audience marketplace also lets customers purchase responses from a panel of paid participants.

Data and cookies set

The embedded collector loads JavaScript from www.surveymonkey.com or its CDN and sets third party cookies including ep202 (anonymous identifier, two years), ep203, sm_uuid, ajs_anonymous_id and __cf_bm. Visitor IP, user agent and the page that triggered the collector are sent with each response. The platform records the response duration, the device type and, with the IP enabled option, an approximate geolocation.

GDPR and ePrivacy implications

SurveyMonkey acts as a processor on behalf of the survey author. The author must sign the SurveyMonkey Data Processing Addendum, document SurveyMonkey as a sub processor and choose a lawful basis for the response data. For embedded collectors, prior consent under Art. 5(3) ePrivacy is required for the third party cookies. SurveyMonkey is self certified under the EU US Data Privacy Framework.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and residency options

Standard accounts store responses in the US. SurveyMonkey Enterprise customers can opt for the European data residency (Dublin, AWS eu west 1) at account level. Transfers from EU collectors to the US rely on the EU US DPF or on Standard Contractual Clauses plus supplementary measures. A Transfer Impact Assessment is mandatory either way for surveys that include identifiable personal data.

Practical compliance steps

Block the embed until consent is granted. Sign the SurveyMonkey DPA. Activate EU data residency on Enterprise. Disable IP collection or anonymise it in the collector settings. Add a privacy notice and an opt in checkbox to each survey. Set a retention rule per project. Document SurveyMonkey as a sub processor and the relevant transfer mechanism in your records of processing.

GDPR consent category

Preferences

Websites using SurveyMonkey must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive) for the third party cookies set by the embedded collector and for the survey response when it includes personal opinions or feedback. Public task (Art. 6(1)(e)) or legitimate interest (Art. 6(1)(f)) may apply for internal employee surveys.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TDDDG, LSSI CE, CCPA/CPRA, EU US Data Privacy Framework, HIPAA (US healthcare)

Technical details

Tracking methodSaaS survey platform. Surveys are hosted on surveymonkey.com or embedded via iframe and JavaScript snippet. Responses are collected and stored on SurveyMonkey infrastructure; the embedding website only loads the survey widget and an optional collector tracker.
Server locationOperated by Momentive Inc. (rebranded back to SurveyMonkey) in San Mateo, California, United States. Enterprise customers can opt for the European data centre (Dublin, Ireland) under the SurveyMonkey Enterprise plan. Servers in the US and EU are operated through AWS and Google Cloud.
Data transferred outside the EUBy default, SurveyMonkey stores responses on US infrastructure. Enterprise customers can elect the EU data residency (Dublin) to keep data within the EEA. US transfers rely on the EU US Data Privacy Framework (SurveyMonkey is certified) or on Standard Contractual Clauses with a documented Transfer Impact Assessment.

Third-party domains contacted

surveymonkey.comwww.surveymonkey.comeu.surveymonkey.comcdn.smassets.netmomentive.ai

Cookies placed

NameTypeDurationPurpose
ep202third_party2 yearsAnonymous visitor identifier set by SurveyMonkey for analytics and survey completion tracking.
ep203third_partySessionSession identifier used by the SurveyMonkey collector to follow the current response.
sm_uuidthird_party1 yearUnique cookie used by SurveyMonkey to deduplicate responses and to remember partially completed surveys.
ajs_anonymous_idthird_party1 yearAnonymous identifier from the Segment analytics SDK used inside SurveyMonkey.
__cf_bmthird_party30 minutesCloudflare bot management cookie used to distinguish humans from bots on surveymonkey.com.

SurveyMonkey uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does SurveyMonkey set?

The embedded collector loads cookies on the surveymonkey.com third party context: ep202 (anonymous identifier, two years), ep203 (session), sm_uuid, ajs_anonymous_id (Segment based analytics) and __cf_bm (Cloudflare). All require prior consent in the EEA.

Is consent required to use SurveyMonkey?

Yes for the embedded collector that sets third party cookies (Art. 5(3) ePrivacy). The response data itself may be processed under Art. 6(1)(b) GDPR for customer feedback, Art. 6(1)(f) for legitimate interest or Art. 6(1)(a) consent for marketing surveys.

What is the legal basis for processing SurveyMonkey data?

It depends on the survey purpose. Customer satisfaction: legitimate interest (Art. 6(1)(f)) or contract (Art. 6(1)(b)). Marketing or research: explicit consent (Art. 6(1)(a)). Employee surveys: legitimate interest or labour law obligation. Sensitive data (Art. 9): explicit consent.

Is data transferred to the United States?

By default yes. Enterprise customers can activate EU data residency in Dublin. Without EU residency, transfers rely on the EU US DPF (SurveyMonkey is certified) or on Standard Contractual Clauses with supplementary measures and a Transfer Impact Assessment.

Do I need a DPIA for SurveyMonkey?

A DPIA is recommended for surveys collecting health data, political opinions, religious beliefs, biometric data; for employee monitoring; or for surveys at large scale. The DPIA must cover the lawful basis, the residency, the transfer mechanism and the rights workflow.

How do I implement SurveyMonkey correctly?

Block the embed behind a marketing consent category. Sign the SurveyMonkey DPA. Activate EU residency in Enterprise. Disable IP collection in the collector settings if not strictly necessary. Add a privacy notice and consent checkbox to each survey. Set a retention rule. Document SurveyMonkey as a sub processor.

Which alternatives to SurveyMonkey should I consider?

EU based: Typeform (Spain), Tally (Belgium), Qualtrics (US with EU residency), Sphinx (France), Drag'n Survey (France), LimeSurvey (Germany, self hostable). US based: Microsoft Forms, Google Forms, Qualtrics, Forsta, Alchemer.

How do I update the cookie policy when SurveyMonkey changes?

Subscribe to the SurveyMonkey trust centre notifications. When the DPA, sub processor list or residency offering changes, update the cookie table, the data transfer section and the records of processing, and bump the consent banner version.