{"id":910,"date":"2024-06-18T13:11:00","date_gmt":"2024-06-18T13:11:00","guid":{"rendered":"https:\/\/www.riddle.com\/blog\/?p=910"},"modified":"2025-11-12T14:51:51","modified_gmt":"2025-11-12T14:51:51","slug":"checklist-is-your-quiz-maker-gdpr-compliant","status":"publish","type":"post","link":"https:\/\/www.riddle.com\/blog\/use-cases\/data-collection\/checklist-is-your-quiz-maker-gdpr-compliant\/","title":{"rendered":"Checklist: Is your quiz maker GDPR compliant?"},"content":{"rendered":"\n<p>Quizzes are powerful marketing tools for zero-party data collection. Done well, you can easily qualify leads and potential customers through emails and quiz responses.<\/p>\n\n\n\n<p>However, the\u00a0<a href=\"https:\/\/gdpr.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">EU\u2019s GDPR<\/a>\u00a0is here to stay. We created this GDPR quiz maker checklist to help you make sure you and your online quiz maker are compliant. (We&#8217;re also 100% CCPA-compliant &#8211; <a href=\"https:\/\/www.riddle.com\/blog\/use-cases\/data-collection\/riddle-quizmaker-is-fully-ccpa-compliant\/\">check out our CCPA post<\/a> that covers California&#8217;s influential privacy regulation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-gdpr\">What is GDPR?<\/h2>\n\n\n\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"750\" src=\"https:\/\/www.riddle.com\/blog\/wp-content\/uploads\/2024\/06\/EU-fines-for-GDPR-violations.webp\" alt=\"GDPR violation fines can be very high\" class=\"wp-image-3012\" style=\"width:350px\"\/><\/figure>\n\n\n\n<p>Adopted in May 2020, GDPR was a major revolution in privacy and data protection regulations. Any site that collects personal information (name, email, even IP addresses) from EU visitors faces huge fines of up to 20 million euros ($23,000,000) \u2013 whether based in the EU or not.<\/p>\n\n\n\n<p>Online quizzes are especially high-risk. They are proven winners at engaging site visitors \u2013 especially to&nbsp;<a href=\"https:\/\/www.riddle.com\/blog\/category\/use-cases\/data-collection\/\" target=\"_blank\" rel=\"noreferrer noopener\">collect emails<\/a> and qualify potential customers. But collecting emails and personal data means you need to stay compliant with the latest data privacy rules.<\/p>\n\n\n\n<p>Read on to explore our GDPR quiz maker checklist below. It covers key questions every website should ask their online quiz maker to make sure they comply with the GDPR. From servers to opt-ins and data protection, we cover the 17 factors you should look at to make sure your quiz maker is safe.<\/p>\n\n\n\n<p>GDPR also inspired other privacy regulations around the world &#8211; including&nbsp;<a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/privacy-laws-in-canada\/the-personal-information-protection-and-electronic-documents-act-pipeda\/pipeda_brief\/\" target=\"_blank\" rel=\"noopener\">Canada&#8217;s PIPEDA<\/a>,&nbsp;<a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa#:~:text=The%20California%20Consumer%20Privacy%20Act,how%20to%20implement%20the%20law.\" target=\"_blank\" rel=\"noopener\">California&#8217;s CCPA<\/a>,&nbsp;<a href=\"https:\/\/www2.deloitte.com\/cn\/en\/pages\/risk\/articles\/personal-information-protection-law.html\" target=\"_blank\" rel=\"noopener\">China&#8217;s PIPL<\/a>, and many others.<\/p>\n\n\n\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"750\" src=\"https:\/\/www.riddle.com\/blog\/wp-content\/uploads\/2024\/06\/Sample-global-EU-GDPR-style-data-privacy-regulations.webp\" alt=\"The most common data privacy regulations\" class=\"wp-image-3013\" style=\"width:350px\"\/><\/figure>\n\n\n\n<p>The good news is that these countries use GDPR as a model. By complying with GDPR, you should then automatically comply with these other regulations as well.<\/p>\n\n\n\n<p>But, as with all things privacy-related, we encourage you to talk to your data protection officer or your legal team.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-17-point-gdpr-checklist-for-quiz-makers\"><strong>17 point GDPR checklist for quiz makers<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-key-steps-to-comply-with-gdpr\"><strong>Key steps to comply with GDPR:<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assign a designated data protection officer (DPO)<\/li>\n\n\n\n<li>Use GDPR-compliant vendors and sub-contractors<\/li>\n\n\n\n<li>Encrypt all personal data you collect and store<\/li>\n\n\n\n<li>Store data ONLY in the EU\n<ul class=\"wp-block-list\">\n<li>Don&#8217;t rely on changes like 2023&#8217;s&nbsp;<a href=\"https:\/\/www.crowell.com\/en\/insights\/client-alerts\/eu-us-data-privacy-framework-the-new-solution-for-eu-data-transfers-to-the-us#:~:text=On%2010%20July%202023%2C%20the,%2DU.S.%20Data%20Privacy%20Framework%E2%80%9D.\" target=\"_blank\" rel=\"noopener\">EU-U.S. Data Privacy Framework<\/a>. They are sure to be challenged (and potentially overturned) in court.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-quiz-makers-and-gdpr-nbsp-what-to-look-out-for\"><strong>Quiz makers and GDPR \u2013&nbsp;what to look out for<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Does your quiz maker fully comply with GDPR?\n<ul class=\"wp-block-list\">\n<li>You should screen them thoroughly. Most quiz makers claim they are GDPR compliant, but they are not.<\/li>\n\n\n\n<li>For example, we reviewed one popular quiz maker and discovered they a) sent personal data to the USA, and b) added 60+ cookies and trackers to any content created with their tool.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Is there a clear opt-out process if you don\u2019t want the quiz maker to collect data?<\/li>\n\n\n\n<li>Does all personal data collected by your quiz maker have to stay in the EU?<\/li>\n\n\n\n<li>Can you sign a data protection agreement (DPA) with the quiz provider (you can&nbsp;<a href=\"https:\/\/www.riddle.com\/legal\/data-processing-agreement\" target=\"_blank\" rel=\"noreferrer noopener\">check out Riddle&#8217;s DPA here<\/a>)?<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-your-responsibilities-as-a-business-owner\"><strong>Your responsibilities as a business owner<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You must quickly erase a user&#8217;s data if they ask without &#8216;undue delay&#8217; (generally in under a month).<\/li>\n\n\n\n<li>You must promptly respond to inquiries from EU users about using their data.<\/li>\n\n\n\n<li>You must report data breaches in&nbsp;<a href=\"https:\/\/gdpr-info.eu\/art-33-gdpr\/#:~:text=without%20undue%20delay%20and%2C%20where%20feasible%2C%20not%20later%20than%2072%20hours\" target=\"_blank\" rel=\"noreferrer noopener\">under 72 hours<\/a>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-riddle-is-a-100-gdpr-compliant-quiz-maker\"><strong>Riddle is a 100% GDPR-compliant quiz maker<\/strong><\/h2>\n\n\n\n<p>GDPR represents a fundamental reimagining of consumer privacy. It gives EU citizens significant control over their personal data, with the threat of significant financial penalties for companies that do not comply (including 2023 fines of&nbsp;<a href=\"https:\/\/www.eqs.com\/compliance-blog\/biggest-gdpr-fines\/\" target=\"_blank\" rel=\"noreferrer noopener\">1.2 billion euros for Meta and 345 million euros for TikTok<\/a>).<\/p>\n\n\n\n<p>If you plan to use quizzes to engage your audience and collect zero-party data with your marketing, here are five reasons to trust Riddle.com as your <a href=\"https:\/\/www.riddle.com\/quiz-maker\">quiz maker<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Riddle.com\u2019s servers are all based in the EU (Germany and Luxembourg).<\/li>\n\n\n\n<li>We do not use any external non-European cloud storage or software, so no personal data is ever sent outside the EU.\n<ul class=\"wp-block-list\">\n<li>This passion for privacy extends to all of our tools &#8211; we even built our own internal billing software to avoid needing a cloud-based option.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>We do not use Google Analytics or any other external tracking service in the Riddle embed code that we provide you with to run Riddles on your website.<\/li>\n\n\n\n<li>By default, we do not track an individual&#8217;s data, only the anonymous, aggregated metrics (e.g. 732 people took the quiz. 251 answered question 1 as &#8216;A&#8217;, 158 as &#8216;B&#8217;, etc.).<\/li>\n\n\n\n<li>Riddle.com does not drop cookies, collect IP addresses, or otherwise gather personal data from our quizzes or other content.<\/li>\n\n\n\n<li>You decide if you want to collect your users&#8217; responses, as well as name, email, and other personal information.\n<ul class=\"wp-block-list\">\n<li>This data can be sent directly to your marketing software, without being stored on Riddle.com&#8217;s servers.<\/li>\n\n\n\n<li>If you decide to also save this data on Riddle.com&#8217;s servers, it is double-encrypted so that only you can see it. No one from Riddle.com can view or access that data.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-take-our-gdpr-quiz\">Take our GDPR quiz<\/h2>\n\n\n\n<p>There&#8217;s a great deal to see and remember about GDPR. We created this quick quiz to test your understanding of the key concepts &#8211; so you can feel more confident about using a quiz maker to engage and collect zero-party data from your audience.<\/p>\n\n\n\n<div class=\"riddle2-wrapper\" data-rid-id=\"ByKkod06\" data-auto-scroll=\"true\" data-auto-scroll-offset=\"175\" data-is-fixed-height-enabled=\"false\" data-bg=\"#fff\" data-fg=\"#00205b\" style=\"margin:0 auto; max-width:100%; width:640px;\" ><script src=\"https:\/\/www.riddle.com\/embed\/build-embedjs\/embedV2.js\"><\/script><iframe src=\"https:\/\/www.riddle.com\/embed\/a\/ByKkod06?lazyImages=false&#038;staticHeight=false\" allow=\"autoplay\" referrerpolicy=\"strict-origin\"><section data-block=\"SingleChoice\"><h3>Who does the GDPR apply to?<\/h3><ul><li>Only companies located in the EU<\/li><li>Any organization processing the data of EU residents<\/li><li>Websites collecting email addresses globally<\/li><li>Social media platforms with a European headquarters<\/li><\/ul><\/section><section data-block=\"SingleChoice\"><h3>How can consent for data processing be obtained under GDPR?<\/h3><ul><li>Including pre-ticking consent boxes on online forms <\/li><li>With clear language and giving users the option to freely choose<\/li><li>Putting data collection clauses in lengthy terms and conditions <\/li><li>Assuming silence or inactivity as consent<\/li><\/ul><\/section><section data-block=\"MultipleChoice\"><h3>What are some examples of personal data protected by the GDPR?<\/h3><ul><li>Usernames and password<\/li><li>Names<\/li><li>Email address<\/li><li>IP address<\/li><li>Company names and contact details<\/li><li>Publicly available information (e.g. phone numbers)<\/li><\/ul><\/section><section data-block=\"SingleChoice\"><h3>What is a lawful basis for processing personal data under GDPR?<\/h3><ul><li>There is only one lawful basis &#8211; user consent<\/li><li>There are six lawful bases, including consent and contractual necessity<\/li><li>The lawful basis depends on the specific data and industry regulations <\/li><li>Organizations don&#039;t need a lawful basis to process user data <\/li><\/ul><\/section><section data-block=\"SingleChoice\"><h3>What is the main purpose of the GDPR?<\/h3><ul><li>Restrict all online data collection<\/li><li>Give individuals more control over their personal data<\/li><li>Create a centralized data storage system in the EU<\/li><li>Increase the amount of data companies can collect<\/li><\/ul><\/section><\/iframe><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-if-you-have-any-further-questions-about-using-a-quiz-maker-under-gdpr-ask-us\">If you have any further questions about using a quiz maker under GDPR, ask us!<\/h2>\n\n\n\n<p>We hope you find this checklist useful. There is a lot to consider when choosing an online quiz maker, from features and formats to ensuring it complies the latest data protection laws and regulations.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>Disclaimer:<\/strong> The information provided in this article is for general informational purposes only and does not constitute legal advice. While we have extensive experience assisting leading publishers, brands, and sports organizations with their quiz marketing since 2014, we are not licensed attorneys. For advice regarding your specific legal situation, please consult with a qualified legal professional.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quizzes are powerful marketing tools for zero-party data collection. Done well, you can easily qualify leads and potential customers through emails and quiz responses. However, the\u00a0EU\u2019s GDPR\u00a0is here to stay. We created this GDPR quiz maker checklist to help you make sure you and your [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":3011,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[87],"tags":[],"class_list":["post-910","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-collection"],"author_meta":{"display_name":"Boris","author_link":"https:\/\/www.riddle.com\/blog\/author\/boris\/"},"featured_img":"https:\/\/www.riddle.com\/blog\/wp-content\/uploads\/2024\/06\/GDPR-compliant-quiz-maker-checklist.webp","coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.riddle.com\/blog\/category\/use-cases\/data-collection\/\" class=\"advgb-post-tax-term\">Data Collection<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">Data Collection<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 2 years ago","modified":"Updated 5 months ago"},"absolute_dates":{"created":"Posted on June 18, 2024","modified":"Updated on November 12, 2025"},"absolute_dates_time":{"created":"Posted on June 18, 2024 1:11 pm","modified":"Updated on November 12, 2025 2:51 pm"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/posts\/910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/comments?post=910"}],"version-history":[{"count":12,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/posts\/910\/revisions"}],"predecessor-version":[{"id":5809,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/posts\/910\/revisions\/5809"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/media\/3011"}],"wp:attachment":[{"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/media?parent=910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/categories?post=910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riddle.com\/blog\/wp-json\/wp\/v2\/tags?post=910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}