GDPR-Compliant Customer Feedback Software: 2026 Checklist
Any company collecting customer feedback digitally is processing personal data — and that brings the GDPR directly into play. For marketing and CX leaders in Europe, the question of GDPR-compliant customer feedback tools isn’t a formality; it’s a real selection criterion with legal consequences. This article explains what matters in tool selection, provides a practical checklist, and compares relevant providers on the criteria that actually count in practice.
Table of Contents
- What Makes a Customer Feedback Tool GDPR-Compliant?
- Checklist: 10 Criteria for GDPR-Compliant Customer Feedback Tools
- Comparison Table: GDPR-Compliant Customer Feedback Tools 2026
- Third-Country Transfers: Why US Providers Require Extra Diligence
- zenloop as a GDPR-Compliant Customer Feedback Tool
- Data Processing Agreement (DPA): What the Contract Must Cover
- ISO 27001 and GDPR: Understanding the Difference
- Practical Recommendations for CX Teams
- FAQs
What Makes a Customer Feedback Tool GDPR-Compliant?
GDPR compliance isn’t a single feature — it’s a bundle of technical and organizational requirements. Four dimensions matter most:
Hosting location: EU/Germany vs. third-country transfer
If data is stored or processed on servers outside the European Economic Area (EEA), this constitutes a third-country transfer. Under Art. 44 ff. GDPR, this is only permitted under certain conditions — for example, via Standard Contractual Clauses (SCCs) or an adequacy decision. EU hosting, ideally on German servers, avoids this issue structurally.
Data Processing Agreement (DPA) under Art. 28 GDPR
As soon as an external provider processes personal data on a company’s behalf, a DPA is legally required. Without this contract, using the tool is unlawful — regardless of how secure the infrastructure is. The DPA must regulate, among other things, the purpose and duration of processing, the processor’s obligation to follow instructions, and the list of sub-processors.
Encryption at rest and in transit
Data should be encrypted both during transmission (TLS/HTTPS) and at rest. Both are standard practice today, but should be explicitly confirmed in the provider’s data protection documentation.
Certifications as proof of an ISMS
ISO 27001 is the best-known international standard for information security management systems. A corresponding certification demonstrates that a provider organizes information security systematically and undergoes regular audits. It doesn’t replace GDPR compliance, but it’s a recognized proof of technical and organizational measures (TOMs) under Art. 32 GDPR.

Checklist: 10 Criteria for GDPR-Compliant Customer Feedback Tools
The following checklist helps evaluate providers systematically. Each point should be actively raised with the provider, with answers documented.
1. EU or German server location
Is all data stored and processed exclusively on servers within the EEA? Is there a clear commitment to EU hosting without silent outsourcing to third countries?
2. DPA under Art. 28 GDPR available
Does the provider offer a DPA covering the legally required minimum content? Can it be signed without lengthy negotiation, or is it only available at the enterprise tier?
3. Sub-processor list transparent and current
Which third-party providers does the vendor itself use — for email delivery, analytics, or infrastructure? Are these listed in the DPA or a publicly accessible list? Are changes communicated in advance?
4. Encryption at rest and in transit
Is customer data encrypted during transmission (TLS 1.2 or higher) and at rest? Is this documented in the technical data protection documentation?
5. Deletion policy and retention periods
Does the tool offer configurable deletion periods? Can data be fully and verifiably deleted on request, in line with the right to erasure under Art. 17 GDPR?
6. Certifications and ISMS proof
Does the provider or the data center it uses hold ISO 27001 or a comparable certification (e.g., SOC 2, TISAX)? Are current certificates available on request?
7. Support for data subject rights
Does the tool enable efficient handling of access, rectification, and deletion requests under Art. 15–17 GDPR? Are there workflows for this, or at least clearly defined processes on the provider’s side?
8. Data export and portability
Can all collected feedback data be fully exported at any time (Art. 20 GDPR)? In which formats? Is export guaranteed even after contract termination?
9. Standard Contractual Clauses (SCCs) for US providers
If the provider is a US company or uses US infrastructure: does it use the European Commission’s current 2021 SCCs? Is a Transfer Impact Assessment (TIA) in place?
10. Accountability and documentation
Does the provider supply documentation that supports your own accountability obligations under Art. 5(2) GDPR — such as records-of-processing templates, support for a Data Protection Impact Assessment (DPIA), or technical documentation?

Comparison Table: GDPR-Compliant Customer Feedback Tools 2026
The table below gives an overview of relevant providers against the key GDPR criteria. Note: Certifications and hosting configurations can change. Always request current proof directly from the provider.
Provider | Hosting location | Certifications / evidence | Notable feature |
| zenloop | Germany / EU | DPA under Art. 28 GDPR available; EU hosting | German company (headquartered in Schönefeld, Berlin region); GDPR-compliant: data stays within the EU, German law applies directly — least effort for you |
| easyfeedback | Germany | TISAX certification; data center Cronon GmbH ISO 27001-certified | Explicitly targeted at German SMEs; data center in Germany |
| LimeSurvey | Variable, including Germany or Finland (for cloud hosting) | Depends on hosting model | Cloud customers can choose Germany/Finland as an EU location; for self-hosting (Community Edition), location is entirely the user’s own responsibility |
| Qualtrics | USA (EU options available) | ISO 27001, ISO 42001 | US company; EU data centers available, but third-country transfer risk depending on configuration; SCCs required |
| Medallia | USA (EU options available) | Certifications per provider claims — please confirm directly | US company; similar setup to Qualtrics |
Third-Country Transfers: Why US Providers Require Extra Diligence
US providers are subject to the CLOUD Act, which allows US authorities access to data under certain conditions — even if that data is physically stored on EU servers. The EU-US Data Privacy Framework (DPF), in effect since 2023, does provide a new adequacy decision for certified US companies. However, the legal situation remains volatile: the DPF has already been challenged politically and legally on multiple occasions.
For CX teams in Germany and Europe, this means concretely: a US provider can be used in a GDPR-compliant way, but only with greater effort. SCCs, a Transfer Impact Assessment, and complete documentation are mandatory, not optional. With an EU provider using EU hosting, this overhead is structurally avoided.
This isn’t a fundamental argument against US providers — but it is a real difference in the compliance burden placed on your own team.

zenloop as a GDPR-Compliant Customer Feedback Tool
zenloop is a German company headquartered in Schönefeld, in the Berlin region. The platform captures customer feedback — primarily via NPS surveys — at critical points in the customer journey and uses AI-driven analysis to identify and automatically trigger action options: for example, proactively reaching out to dissatisfied customers or activating promoters for advocacy programs.
From a GDPR perspective, the following points are confirmed:
- EU hosting: Data is stored and processed within the EU.
- German company: Headquartered in Germany, and therefore directly subject to German and European data protection law.
- DPA under Art. 28 GDPR: A Data Processing Agreement is available.
- GDPR-compliant architecture: The platform is designed for use by European companies.
What zenloop doesn’t claim: a proprietary ISO 27001 certification is not publicly confirmed. CX teams for whom such a certification is a selection criterion should ask the provider directly and request the current technical data protection documentation.
For companies looking for an NPS-focused feedback tool with German hosting and an available DPA, zenloop is a relevant candidate — with a clear structural advantage over US providers, where third-country transfer requirements create additional compliance overhead.

Data Processing Agreement (DPA): What the Contract Must Cover
The DPA isn’t an optional document — it’s a legal requirement. Art. 28 GDPR specifies what it must include:
- Subject matter, duration, nature, and purpose of processing
- Type of personal data and categories of data subjects
- Obligations and rights of the controller
- The processor’s duty to follow instructions
- Confidentiality obligations for staff
- Technical and organizational measures (TOMs)
- Provisions on sub-processors
- Support obligations for data subject rights and data breaches
- Deletion or return of data after contract termination
A DPA that doesn’t fully cover these points doesn’t protect your company. Before signing a feedback-tool contract, the DPA should therefore be reviewed by your own data protection team or Data Protection Officer.
ISO 27001 and GDPR: Understanding the Difference
The two terms often come up in the same breath — but they describe fundamentally different things.
ISO 27001 is an international standard for information security management systems. It certifies that a company organizes information security systematically, assesses risks, and implements measures. A corresponding certification is a strong signal of technical and organizational maturity.
GDPR is European data protection law. It regulates how personal data may be processed, what rights data subjects have, and what obligations controllers and processors carry.
ISO 27001 can serve as evidence of TOMs under Art. 32 GDPR, but it doesn’t replace GDPR compliance. A provider can be ISO 27001-certified and still transfer data to third countries without a sufficient legal basis. Conversely, a provider without ISO 27001 certification can operate in a GDPR-compliant way if it documents and demonstrates the requirements by other means.
For provider selection, the rule is: certifications are helpful, but they don’t replace your own review of the DPA, hosting location, and sub-processor list.

Practical Recommendations for CX Teams
Before selection: Create an internal requirements list covering hosting location, DPA requirements, and certification needs — and align it with your Data Protection Officer.
During evaluation: Actively request the DPA draft, the sub-processor list, and current certificates from every provider. Marketing claims like “GDPR-compliant” without evidence aren’t sufficient proof.
For US providers: Check whether the company is certified under the EU-US Data Privacy Framework, which SCCs are used, and whether a Transfer Impact Assessment is in place.
After selection: Document the signed DPA in your records of processing activities. Review annually whether the hosting configuration or sub-processors have changed.
FAQs
What does GDPR-compliant customer feedback software mean?
A customer feedback tool is GDPR-compliant if it processes personal data only on a valid legal basis, provides a DPA under Art. 28 GDPR, demonstrates technical and organizational data protection measures (e.g., encryption, access controls), and supports data subject rights such as access, rectification, and deletion. Hosting location plays a central role: EU hosting structurally avoids third-country transfer risks.
Can a US provider be used in a GDPR-compliant way with Standard Contractual Clauses?
Generally, yes — but with greater effort. The European Commission’s 2021 SCCs create a legal basis for data transfers to the US. A Transfer Impact Assessment (TIA), which evaluates the specific risks in each case, is also recommended. The EU-US Data Privacy Framework offers a further option for certified US companies. Since the legal situation isn’t politically or legally stable, the use of US providers should be reassessed regularly.
What is a Data Processing Agreement (DPA), and why is it mandatory?
When a company engages an external provider to process personal data on its behalf, this constitutes processing under Art. 28 GDPR. The DPA contractually governs this relationship: it specifies which data is processed for which purpose, what security measures apply, and which sub-processors may be used. Without a DPA, data processing by the provider is unlawful and can result in fines.
Is ISO 27001 sufficient proof of GDPR compliance?
No. ISO 27001 demonstrates a structured information security management system and can serve as evidence of TOMs under Art. 32 GDPR — but it doesn’t replace full GDPR compliance. An ISO 27001-certified provider can still transfer data to third countries without a sufficient legal basis, or fail to provide a complete DPA. ISO 27001 is an important quality signal, but not a substitute for your own GDPR review.
What questions should I ask a provider before signing a contract?
At minimum, these five: (1) Where is data stored and processed? (2) Do you provide a DPA under Art. 28 GDPR? (3) Which sub-processors do you use, and where are they located? (4) What certifications do you or your data center hold? (5) How do you support us in fulfilling data subject rights?
Curious to see the full scope of the new zenloop platform?
CX teams who want to review zenloop’s GDPR documentation — DPA draft, hosting evidence, and technical data protection documentation — can request a demo via zenloop.com and review the materials as part of their evaluation.
sales@zenloop.com | +49 30 91739927





