Are Synthetic Respondents GDPR Compliant?
Synthetic respondents are not real people, but the data used to build and run them can be personal data. What GDPR means for synthetic panels, personas and audiences.
No research method or tool is GDPR compliant by itself. Compliance depends on what personal data is processed, for what purpose, on what lawful basis and by whom. A synthetic respondent is not a real person, so its simulated answers are usually not personal data. The data used to build and run a synthetic study often is: uploaded files, customer records used for grounding, profiles of named people, prompts, and the account data of the researchers using the tool. Treat a synthetic research platform like any other processor of personal data, and review it with your data protection officer.
This page explains where GDPR applies in synthetic research, what to check before you use a tool, and how Minds handles data as of October 2026. It is general information, not legal advice.
Who this guide is for
This page is for data protection officers, compliance and procurement teams, and research leads who need to decide whether synthetic respondents, synthetic panels, AI personas or synthetic audiences can be used in their organisation. If you are looking for the research method itself, read what synthetic respondents and synthetic panels are.
How to think about synthetic data and GDPR compliance
GDPR applies to personal data: any information relating to an identified or identifiable natural person (Article 4(1)). In synthetic research, that question has to be asked separately for each kind of data in the workflow.
- Simulated answers from a synthetic respondent built for a segment, such as "German first-time parents", usually do not relate to an identifiable person.
- A persona built to simulate a specific, named individual, for example from their public profile or interview transcripts, does relate to that person and is personal data.
- Grounding data can be anything from published statistics (not personal data) to anonymised survey results (usually not personal data, if truly anonymised) to raw CRM exports (personal data).
- Account and usage data of the people using the tool, such as names, emails and logs, are personal data in every case.
- Stimuli and prompts may contain personal data if they mention customers, employees or other people.
Where the provider processes personal data for you, it acts as your processor and Article 28 requires a data processing agreement. Where that processing involves transfers outside the EU, Articles 44 and following require a transfer mechanism such as an adequacy decision or Standard Contractual Clauses. Data minimisation (Article 5(1)(c)) applies throughout: upload aggregated or anonymised data where that is enough. For the principle in detail, see GDPR data minimisation.
Synthetic research can still reduce privacy risk compared with recruited research. There are no participants to recruit, contact, pay or record, so the consent forms, recordings and panel databases of traditional fieldwork are not needed. That is a real benefit, but it is a reduction of risk, not an exemption from GDPR.
Comparing the realistic options
Teams usually compare three set-ups.
The first is recruited research through a panel or agency. It processes participants' personal data, so it needs consent or another lawful basis, privacy notices, retention rules and agency contracts. In return it gives real answers from real people.
The second is a general-purpose AI chatbot used to role-play customers. Consumer chat products may use inputs to improve their models and may not offer a data processing agreement on every plan, so check the terms before putting customer data or confidential concepts into one.
The third is a dedicated synthetic research platform with a data processing agreement, a published subprocessor list and documented security measures. That is the set-up a privacy review can assess properly. Check where data is hosted, which AI model providers receive prompts and files, whether customer data is used for model training, and how deletion works.
How Minds handles data
As of October 2026, according to Minds' legal documentation:
- Minds offers a data processing agreement under Article 28 GDPR.
- The application is hosted on DigitalOcean in Frankfurt, Germany, and the database on Supabase in Stockholm, Sweden.
- AI processing uses model providers in the USA, including OpenAI, Anthropic and Google Cloud Vertex AI. The privacy policy names the EU Commission's Standard Contractual Clauses as the basis for these transfers to the USA. All providers are listed on the subprocessors page.
- Customer data is not used to train, fine-tune or improve general-purpose or third-party models.
- Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256), and customer data is logically separated by tenant. Details are in the technical and organisational measures.
Minds does not claim that any use of the platform is automatically compliant. Whether your use is compliant depends on the data you upload, your lawful basis and your own policies. Read the privacy policy and review the documents above with your data protection officer. For a structured vendor review, use the GDPR guide to data security in AI market research.
When Minds is and isn't the right answer
Minds fits when you want directional research on concepts, messages and segments without recruiting participants, and your privacy review is satisfied with the processing described above, including the use of US-based AI model providers.
It is not the right fit if your policy forbids any transfer of the relevant data outside the EU, or if the research must be done with real people for regulatory, clinical or legal reasons. In those cases, keep personal data out of the platform, use only public or aggregated grounding data, or use a recruited study instead.
Frequently asked questions
Are synthetic respondents GDPR compliant?
No method or tool is GDPR compliant by itself; compliance depends on what data is processed, why and how. A synthetic respondent is not a real person, so its simulated answers are usually not personal data. But the files, customer data, prompts and account data used to build and run a synthetic study can be, and the provider then processes them on your behalf. Assess that processing like any other software vendor.
Is a synthetic persona of a real, named person personal data?
Usually yes. A profile built to simulate an identifiable individual, for example from their LinkedIn page, interviews or CRM history, relates to that person and is personal data under Article 4(1) GDPR. You need a lawful basis to create and use it, and the person keeps their data subject rights.
Do we need a data processing agreement for a synthetic research tool?
If the provider processes any personal data on your behalf, such as your users' account data, uploaded files that mention people, or customer records used for grounding, Article 28 GDPR requires a data processing agreement. Minds offers a DPA for its platform.
Can we upload customer data to ground a synthetic audience?
You can, but minimise it first. Aggregated results, anonymised survey data and research reports carry far less risk than raw customer records. Check whether your privacy notice and lawful basis cover using customer data for this purpose, and where the provider and its subprocessors process it.
Where does Minds process data?
As of October 2026, Minds hosts its application on DigitalOcean in Frankfurt and its database on Supabase in Stockholm. AI processing uses model providers in the USA, including OpenAI, Anthropic and Google Cloud Vertex AI, with transfers to the USA based on the EU Commission's Standard Contractual Clauses. The full list is on the subprocessors page.
Is synthetic research less privacy-intrusive than a recruited panel?
Often, because no participants are recruited, contacted or recorded. That removes consent forms, incentives and recordings, but it does not remove GDPR from the project: the data you use for grounding and the data in your account still need a lawful basis and a vendor review.


