How to Create GDPR-Compliant Interactive Content in 2026

How to create GDPR-compliant content

We prepared this guide as a summary of the key areas to focus on if you want to create GDPR-compliant interactive content with Riddle’s quiz maker. In 2026, GDPR-compliance is more important than ever, with Google being fined €403 million and Meta €360-€430 million – and over €7.1 billion in fines since 2018.

A graphic showing the advantages and disadvantages of using interactive content in this era of GDPR compliance

Interactive content like quizzes, polls, personality tests, and mini-games are powerful engagement tools. But they are equally useful for collecting personal data from users for lead generation, contests, leaderboards, and more.

However, collecting personal information (PII) is serious business. To keep your business GDPR-compliant content, it’s crucial to follow the guidelines below.

Adding videos, images, or other content

Adding multimedia, such as videos, makes your online content much more effective. However, there are pitfalls to avoid since many services will collect personal data from your audience.

In particular, you should avoid these three services:

  1. YouTube
  2. Vimeo
  3. X (Twitter)

If you are using these services, it’s crucial ask the user for permission to load the content as these tools will load a cookie.

To make this easy for you, Riddle lets you create and show a permission screen before content from these networks is loaded.

Check out this help article to learn how to use this feature.

GDPR-compliant consent opt-in settings for YouTube, Vimeo, and Twitter on Riddle's quiz maker.

Want to use videos in your Riddle?

We recommend uploading MP4 video files, as they will be hosted on our Riddle servers. Riddle will not set any cookies or trackers because we value your and your quiz takers’ privacy, ensuring GDPR compliance in your multimedia content.

(Plus they also look much better – without YouTube, Vimeo, or Twitter adding their own branding and controls to your Riddle.)

Collecting email and personal data

You have to pay special attention when dealing with personal data:

  • Please make sure to ask for permission – check out our templates for some sample legal language to remain GDPR compliant.
  • Use double opt-in (DOI) either via email or via a one-time code to stay compliant with GDPR.
  • Save lead data to Riddle or to an integration like Brevo.com which is also GDPR compliant.
  • The “Save to Riddle” option is easy for people who don’t want to send data to another email tool or marketing software.
  • Save lead data to your tool.
    If you save your lead data using another method, ensure it is GDPR compliant. (Most popular U.S.-based companies are probably problematic). (List of GDPR-compliant tools)
  • Meta (Facebook) Pixel
    Using FB Pixel is controversial in GDPR terms. We recommend against using it.
A guide to the GDPR-compliant options for collecting and storing personal data using Riddle's quiz maker

Riddle defaults that make your interactive content GDPR-compliant

  • We serve all Google fonts from our servers, ensuring GDPR compliance by avoiding third-party trackers.
  • All lead data stored on our servers is encrypted.
  • We never use trackers or cookies for your quiz takers — only completely anonymous local storage for features such as limiting how often someone can take part in a quiz, poll, or other Riddle content.
  • Our servers are in a banking-grade data center in Germany, operated by ourselves with backups in Luxembourg, and strictly adhere to GDPR regulations.
  • We do not use Cloudflare or any other CDNs operated by U.S. companies. Instead, we manage our Germany-based CDN ourselves, keeping your content GDPR compliant.

Common questions that your privacy or legal team will ask

Deciding to use Riddle as your quiz maker for your engagement and data collection objectives is just the start of the process. The next step is to ensure your legal and data privacy colleagues are comfortable with Riddle’s information security and privacy set up, especially in the face of the EU’s GDPR.

Let’s tackle them one by one:

Who’s the data processor – and who is the controller?

This is the most critical question for GDPR compliance. Riddle makes it easy – in this case, you are the controller and Riddle is the processor. You’re the controller – in that you are fully in control of how, when, and for what lawful basis, personal data is collected. Riddle, by comparison, processes the data based on your instructions and in compliance with our data processing agreement (DPA) using our quiz maker software.

Our standard DPA works well for the vast majority of our customers. However, as part of Riddle’s Enterprise plan, you can choose to use your organization’s own data processing agreement.

Two key details:

  1. As the controller, you’ll receive and handle any requests from your audience for the deleting, correcting, or accessing of their information. We’ll help you out with this on request. Our platform includes options to include an opt-in flag (and corresponding timestamp) for all PII collected, as well as options to delete personally identifiable information from your audience.
  2. Riddle is also a controller for the billing and account details of our quiz maker creators – just like any other vendor.

Where is Riddle’s data stored?

Ahead of the launch of the GDPR in 2018, we made a key strategic decision a – we would only use our own servers, based in the European Union, and never cloud-based options like US-owned AWS or Google Cloud. The risk that data might leave the EU was simply too great.

Riddle operates our primary servers in Tier 1, banking grade data centers – with the primary location in Germany, and mirrored back up servers in Luxembourg.

Further, we operate our EU-based CDN – which means we do not need to use Cloudflare or any other U.S. CDNs.

We even went as far as creating our own invoicing software, so that all of our customers’ billing and invoice details would remain entirely in the European Union.

Does Riddle use any sub-processors? Are there any transfers to the U.S.?

We use just one – Brevo (formerly known as SendinBlue) – for our support chat software. The integration is framed – meaning that the service is a direct window to Brevo’s online offering. All of the resulting chatbox communication takes place via a Brevo/Sendinblue GmbH server – and Brevo exclusively processes all data, with no data being passed on to Riddle.

The integration takes place within the framework of framing. Framing is providing content or services from a third-party provider within a so-called “frame.” These frames are a “direct window” to the third-party provider’s online offering. As a result, all communication within the chatbox takes place via a sendinblue GmbH server. Data collected by Sendinblue GmbH during use is processed exclusively by Sendinblue GmbH (privacy policy) and is not passed on to Riddle.

And rounding things off – this strict limiting of sub-processors means zero transfers are made to the U.S.

What about cookies? Would we need to add Riddle to our cookie banner?

Riddle does not drop any cookies or place trackers in audience-facing Riddle content. Instead, we give the option to use local storage – which means Boolean flags are stored on a person’s device, indicating if they have already completed the ‘how to play’ onboarding for these three Riddle formats (Order it, Swiper, Flashcard).

Besides that, we only use local storage if you have enabled our ‘one vote per browser’ security feature or the ‘remember user’ option. The remember user option may store personal identifiable information in a device which will allow in-Riddle forms to be automatically filled out.

The short summary? If you would prefer to not save any data to local storage, follow these steps:

To help with compliance, you can also use Riddle’s project presets (or global project presets) to automatically apply these settings – and our detailed user roles to prevent users from overriding them.

Will our data be used to train AI models?

The short answer? No… absolutely not. Any audience data from Riddle’s customers is never used to train AI.

We do use AI when helping our customers, as well as for some marketing. This might include contact information, plus support chat and emails information, as well as the basic metadata such as the marketing channel, date, and time.

Why? AI helps us identify customer support issues that occur more than once, sort product enquiries into our CRM software, as well as operating our marketing communication software.

The legal basis for this? For support, this is covered by contract performance (Art. 6(1)(b)) while legitimate interest (Art. 6(1)(f)) for other users. Finally, certain email marketing comes under (Art. 6(1)(a)) where the law requires your consent. (More info in the AI section of our privacy policy)

Specialist providers do provide some AI work, which falls under Article 28 agreements. In the even data does leave the EU/EEA, Riddle uses EU SCC (standard contractual clauses) as well as any necessary supplemental measure. All details can be provided on request.

Finally, we do not use AI to make decisions about you based entirely on automated profiling or processing. All matters with real consequences is decided by a Riddle employee.

What InfoSec and privacy documentation is available?

Riddle is ISO 27001-certified and 100% GDPR-compliant.

We have a full information packet for InfoSec/privacy teams – including data handling, detailed security FAQ, plus network architecture, our security white paper, ISO certification, and more.

Please ask us on support chat or by email (hello@riddle.com) – and we would be happy to send that to you for your review.

Any questions about creating GDPR compliant content?

If you have any questions about using Riddle to collect personal information – for example, for lead generation, quiz contests, or other interactive activations – we’re here to help.

As an EU-based company, we understand the importance of GDPR compliance and data privacy. Our entire team – from founders and product managers to developers – actively supports customers with questions like these. You can reach us via our support chat or by emailing hello@riddle.com. We’re also happy to arrange a support or Teams call to discuss your specific use case in more detail.

Riddle is trusted by some of the world’s leading publishers and brands, including Immediate Media/Burda (case study), 20 Minuten (case study), Club Med (case study), Tate Modern, and many others.

Founded in 2014, Riddle powers 2.8 billion quiz and survey questions every year for publishing partners. We bring deep experience helping organizations harness the power of interactive content while staying fully compliant with GDPR and other privacy regulations.

Frequently Asked Questions (FAQ)

Can I collect personal data through quizzes and polls under GDPR?

Yes – as long as you obtain explicit consent. Always include a clear opt-in form before collecting any personal data such as names or emails. Riddle offers GDPR-friendly lead forms and double opt-in options to make data collection safe and compliant.

How should I handle email collection and lead generation forms in quizzes?

Always use explicit consent and double opt-in (DOI). You can save leads securely in Riddle or send them to GDPR-compliant email tools like Brevo. Avoid U.S.-based platforms unless you have additional safeguards in place, as many don’t fully meet EU privacy standards.

What makes Riddle’s quiz maker GDPR-compliant by default?

Riddle is EU-owned and operated, with all data stored on encrypted servers in Germany and backups in Luxembourg. The platform doesn’t use cookies, trackers, or U.S.-based CDNs, and even serves Google Fonts locally — all to ensure full GDPR compliance by design.

How can I make sure consent screens are GDPR-compliant?

You should always ask for permission before loading external media or cookies. Riddle provides built-in consent screens that let users choose whether to load third-party content. This helps you stay transparent, gain proper consent, and maintain GDPR compliance.

Why is GDPR compliance so important for interactive content in 2026?

With over €7.1 billion in GDPR fines since 2018, compliance is more critical than ever. Interactive content often collects user data, so following GDPR ensures you avoid fines and build audience trust. Platforms like Riddle are fully EU-based, helping you stay compliant automatically.

You might also like

Scroll to Top