For years, GDPR was the single compliance conversation a European university’s IT, legal, and procurement teams needed to have with a research software vendor. The EU AI Act adds a second, related but distinct, conversation, and it is one that DACH institutions in particular are starting to ask about earlier in the procurement process.
Here is why this matters now: GDPR governs how personal data in a survey is collected and processed. The EU AI Act adds scrutiny to how that data moves through any AI-powered feature layered on top of it, from sentiment analysis to automated text coding. A platform can be fully GDPR-compliant on data residency and still raise new questions once AI-assisted analysis enters the picture. [VERIFY: confirm current EU AI Act implementation timeline and applicable risk-tier classification for research/survey AI features against the latest official guidance before publishing]
Quick takeaways
- GDPR and the EU AI Act are separate requirements. Meeting one does not automatically satisfy the other.
- AI-assisted features inside a survey platform, like automated sentiment analysis or open-text coding, are the part of the stack the AI Act specifically brings into scope.
- German, Austrian, and Swiss university data protection offices frequently apply internal policies stricter than the EU baseline, particularly around hosting region.
- Procurement teams should ask vendors to document both data residency and the specific AI processing steps applied to research data, not just one or the other.
Why GDPR compliance alone is no longer the full conversation
A research survey platform that stores and processes data entirely within the EU, with a signed data processing agreement in place, has traditionally cleared the main procurement hurdle for European higher education. That baseline still matters, but it addresses where data lives and how it is handled by people and standard software logic. It does not address what happens when an AI feature, built into the platform, analyzes that data in ways that go beyond straightforward processing.
What actually changes for DACH institutions specifically
German, Austrian, and Swiss data protection offices have historically applied some of the most conservative internal interpretations of EU-wide data rules, often exceeding the GDPR baseline in practice. It is reasonable to expect the same pattern with the EU AI Act: DACH institutional review boards and IT security teams are likely to ask more detailed questions about AI-assisted features earlier in a vendor evaluation than institutions in some other member states.
Institutions that document both data residency and AI processing steps upfront tend to move through procurement and ethics review meaningfully faster than those that address AI questions only when asked.
What procurement and research offices should actually ask vendors
Beyond the standard GDPR checklist, hosting region, sub-processors, a signed DPA, and a lawful transfer mechanism, research offices should now also confirm which specific features in a platform involve automated analysis of personal or research data, where that processing occurs, and whether it can be disabled or scoped for a given study if a research ethics board requires it. This is a joint conversation between IT, institutional research, legal, and procurement, not something any one office should resolve alone.
Why this matters beyond compliance risk
The institutions that fare best in a regulatory review are not necessarily the ones with the most features. They are the ones with the clearest paper trail connecting a specific data process to a specific compliance justification. For research offices managing multi-country projects, like a consortium or shared-procurement model, that documentation discipline becomes even more important, since it needs to hold up across more than one institution’s review process.
Where this fits into a platform decision
Data governance should be treated as a core architectural decision when selecting a research platform, not a settings menu item addressed after the contract is signed. QuestionPro’s Academic solution is built around EU data residency, signed DPAs, and role-based governance controls designed for exactly this kind of institutional procurement scrutiny.
Building this into the procurement timeline, not after signing
The EU AI Act and research data questions raised here are easiest to resolve before a contract is signed, not after. Building AI processing disclosure into the standard vendor evaluation questionnaire, alongside the existing GDPR checklist, avoids a second, slower review cycle once a research ethics board asks the same questions independently.
For institutions running multi-country research programs, this documentation also needs to travel. A DPIA and AI processing disclosure prepared for one institution’s review should be reusable, with minor adaptation, for a partner institution’s own procurement process.
Frequently asked questions
Does the EU AI Act apply to a standard survey with no AI features at all?
If a platform’s AI-assisted features, like automated theme coding or sentiment scoring, are not enabled for a given study, the AI Act’s scope on that specific processing activity is narrower. Confirm with your vendor whether such features can be scoped off per project.
Is GDPR compliance enough to satisfy a DACH institution’s data protection office?
Not on its own for platforms with AI-assisted features. Expect data protection offices to ask separately about AI processing transparency, on top of standard GDPR documentation.
Who should own the AI Act conversation during procurement: IT, legal, or research administration?
All three, working jointly. IT typically owns technical hosting questions, legal owns contractual and DPA language, and research administration owns the ethics review implications for specific studies.
The bottom line
GDPR compliance is no longer the finish line for European research procurement. It is the baseline. For DACH universities weighing a survey platform in 2026, the more forward-looking question is whether a vendor can clearly document not just where data lives, but exactly how any AI-assisted feature touches it.
Talk to our team about EU data residency and governance controls for your institution’s research programs.



