Skip to content

Consulting and recruiting

Employee survey data held by consultants: confidentiality and reuse

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Employee survey data held by a consultant is usually controlled by the client employer, and the consultant's use is limited by the contract and by the confidentiality promise made to employees. A consultant can generally build aggregate benchmarks only where the contract allows it, results are de-identified and minimum reporting group sizes are enforced on every report.

Key takeaways

  • The survey invitation is a promise to employees, and it binds the consultant as well as the client.
  • Confidential and anonymous mean different things; use the word that matches how data is actually handled.
  • Minimum reporting group sizes stop managers from identifying individuals in small teams.
  • Benchmarks need a contract clause, de-identified aggregation and no client named or identifiable.
  • California's privacy law has covered employee data held by covered businesses since its exemption expired on January 1, 2023.

Who controls employee survey data a consultant holds?#

Employee survey data held by a consultant is usually controlled by the client employer, with the consultant acting as its service provider under a statement of work and often a data processing addendum. The consultant holds the response-level file precisely because employees were promised that their managers would not see it.

That arrangement creates two sets of duties. The contract tells the consultant what it may do for, and with, the client's data. The survey invitation tells employees what will happen to their answers, and the consultant is the party best placed to keep that promise.

Read the data processing addendum closely. If it names the consultant as a processor or service provider acting only on the client's instructions, any use for the consultant's own purposes, such as benchmarks or tool training, needs a separate written permission rather than an assumption.

Rules table: anonymity, ownership and benchmarks#

Most engagement, culture and pulse survey programs rest on the same set of rules. Write each one into the contract and the survey materials, and make sure the platform enforces it rather than relying on analysts to remember.

Rules table: anonymity, ownership and benchmarks
RuleWhat it means in practiceWhere it is set
Confidential versus anonymousConfidential: the consultant can link answers to people. Anonymous: nobody canSurvey invitation and FAQ
Minimum reporting group sizeNo results shown for groups below a set number of respondentsContract and platform settings
No individual data to the clientThe client receives aggregates only, never response-level filesContract and data processing addendum
Demographic cut limitsFilter combinations cannot narrow results to a few peoplePlatform settings and reporting rules
Comment handlingNames and identifying details scrubbed before comments are sharedReporting procedure
Client ownershipThe client controls its response data and reportsMSA and statement of work
Benchmark rightsThe consultant may include de-identified results in aggregate normsAn explicit contract clause
Retention and deletionResponse-level data deleted or returned at a defined pointContract and retention schedule

What the confidentiality promise to employees binds#

The confidentiality promise in the survey invitation binds the whole program, not just the client. If employees were told that only the consultant sees individual responses, sending a response file to HR, even at the client's request, breaks the promise and can undermine trust in every later survey.

Re-identification is the practical risk. A small team, a rare job title or a combination of tenure, location and function can point to one person even with names removed. Free-text comments are hardest to protect, because people describe their manager, their project and their own situation in words that identify them.

Linking survey responses to HRIS data, such as performance ratings or pay bands, changes the program. That can be useful analysis, but the invitation should say so, and the linked file needs tighter controls than the survey alone.

When can a consultant build benchmarks from client surveys?#

A consultant can usually build benchmarks from client surveys only where the contract grants an aggregated-use right, the inputs are de-identified and the published norms cannot reveal any one client. Benchmarks are often part of what clients pay for, so the clause is a normal request; where it is missing, raise it at renewal rather than assuming.

  • Use item-level scores aggregated across organizations, never response-level data.
  • Set a minimum number of organizations per benchmark cell and enforce it.
  • Never name or describe contributing clients in a way that identifies them.
  • Keep free-text comments out of benchmarks entirely.
  • Record which client surveys feed which norms, so a departing client can be removed.

Privacy laws that may apply to employee survey data#

Which privacy laws apply depends on where employees live and work. California's CCPA exemptions for employee and business-to-business personal information expired on January 1, 2023, so employee data held by covered businesses is now within the law. The California Privacy Protection Agency opened preliminary rulemaking on April 20, 2026 on how the CCPA applies to employees, job applicants and independent contractors.

Other states differ. A December 2022 law firm alert noted that the comprehensive privacy laws then enacted in Colorado, Connecticut, Utah and Virginia did not apply to employment-context data, though newer statutes need their own check. For employees in the EU or UK, the GDPR may apply. Counsel assesses these questions for each client program.

De-identification has its own legal test. Under the CPRA amendments, California treats information as deidentified only if the business takes reasonable measures against re-identification, publicly commits not to re-identify it and contractually binds recipients to the same rules.

Reuse for AI: internal tools versus licensing#

Reusing employee survey data for AI raises the bar again. Training an internal tool to code comments or suggest action plans uses employees' words for a purpose the invitation may not have described, and the client contract may not allow it. Licensing response-level data or comments to an outside developer is a further step that most programs would not support.

Privacy advocates have raised the same concern about workplace data more broadly. Marc Rotenberg of the Center for AI and Digital Policy told Forbes in April 2026 that the privacy issues in selling anonymized workplace messages are substantial. Survey comments sit close to that category. What a consultant can more often consider are its own instruments: item libraries it authored, action-planning guides and de-identified aggregate norms where contracts allow.

Illustrative: an OD consultancy tightens its survey practice#

Illustrative: a fictional organizational development consultancy runs engagement and culture surveys for mid-sized employers on a commercial survey platform. Its contracts include a benchmark clause, and its invitations promise confidentiality rather than anonymity.

A review finds that reporting thresholds were applied to standard reports but not to ad hoc demographic cuts requested by clients, and that a few client HR teams had received comment exports with names intact. The firm applies thresholds to every report type, scrubs comments before release and rewrites its invitation template to describe exactly who sees what.

The firm also concludes that its item library and action-planning playbooks are firm-owned records worth documenting, while response-level data and comments stay within each client engagement.

How SourceX approaches survey consultancies#

SourceX generally treats employee response-level data and comments as out of scope, because the client controls them and the privacy burden is high. In the SourceX five-step transaction, the Rights step separates client-controlled survey data from the consultancy's own records, such as authored instruments, playbooks and project records. Under the SourceX Enterprise Data Value Framework, those firm records are rated on drivers such as domain expertise, uniqueness and preparation cost, and the consultancy approves every step.

Frequently asked questions

Can we show a client results for a team below the threshold if they insist?

Not without breaking the promise to employees. Offer to combine the team with a larger unit or report a merged result. If the contract allows exceptions, they belong in the invitation in advance, not granted after employees have answered.

Does a client's deletion request reach our benchmark?

It depends on the contract. If the benchmark right survives termination and uses only de-identified aggregates, the client's past results may stay. If the contract requires deletion of all derived data, remove the client's surveys and recalculate the affected norms.

Are exit interviews and pulse surveys treated the same way?

The same principles apply with more risk. Exit interviews are often identified by design, and pulse surveys in small teams can fall below reporting thresholds quickly. Set rules for each instrument rather than assuming the main survey's rules carry over.

Can we use comments to train a classifier for our own tool?

Only if the contract and the employee-facing notice support it, and only after scrubbing identifying details. Training such tools on synthetic or specifically consented sample comments instead avoids the question for client data altogether. Document whichever route you choose, because clients increasingly ask how comment-coding tools were built.

What happens to survey data if the client is acquired?

The contract usually governs, including its assignment and change-of-control clauses. The acquirer may inherit the client's rights to reports and aggregate results, but the promise made to employees still applies to response-level data the consultant holds. Ask counsel before transferring any response-level file to the new owner.

Sources

  • The California legislature ended its 2022 session without extending the CCPA employee and business-to-business exemptions, so they expired on January 1, 2023. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 focused on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
  • A December 2022 Kutak Rock alert noted that the comprehensive state privacy laws then enacted in Colorado, Connecticut, Utah and Virginia do not apply to employment-context data. Source
  • Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, deidentified information requires reasonable measures against re-identification, a public commitment not to re-identify and contractual obligations on recipients. Source
  • Marc Rotenberg of the Center for AI and Digital Policy told Forbes that the privacy issues from selling anonymized workplace messages are substantial. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify