1. Inventory every data field
List visible questions, hidden fields, URL parameters, device data, timestamps, calculated scores, inferred results, contact properties, tags, and integration payloads. Teams often review the visible form but miss metadata and derived values.
2. Record purpose and necessity
The GDPR data minimisation principle is a useful design test: data should be adequate, relevant, and limited to what is necessary for the stated purpose.
| Field | Purpose | Required? | Retention |
|---|---|---|---|
| Deliver requested report | Only for delivery path | Delete or retain under stated rule | |
| Quiz result | Explain and route the response | Yes for result workflow | Refresh when superseded |
| Company size | Check service fit | Only if fit truly changes | Remove when no longer relevant |
| Tracking parameter | Attribute campaign | No for quiz result | Use a defined reporting period |
3. Explain the exchange at the point of collection
State what the person will receive, why contact information is requested, whether follow-up is optional, and where to find the privacy information. A distant privacy link cannot repair a misleading or unclear form interaction.
4. Review sensitive questions and inferences
A harmless-looking answer set can infer health, finances, politics, identity, or other sensitive information. Review both raw answers and derived segments. Remove sensitive processing unless there is a clear lawful, necessary, and appropriately protected use.
5. Map every recipient and processor
Document which fields each system receives. “Connected” should not mean every answer is copied everywhere.
- Quiz hosting and content delivery
- Email delivery and marketing automation
- CRM or contact database
- Analytics and advertising systems
- Webhooks, automation platforms, and internal notifications
- Backups, exports, and support access
6. Test access, correction, deletion, and suppression
Use a test contact to verify that the team can find all copies, correct mapped properties, stop future messages, delete or anonymize data under the applicable process, and document what remains in logs or backups.
7. Complete the pre-launch review
Repeat the review when questions, scoring, vendors, destinations, or follow-up purposes change.
- Every field has a purpose and owner
- Required and optional processing are distinguished
- The result does not expose sensitive data unexpectedly
- Retention and deletion steps are documented
- Integrations receive only the required fields
- Labels, instructions, and error messages are understandable
- A qualified legal or privacy reviewer has checked the specific use case where required
Evidence
How to reproduce the method
The checklist produces a field inventory, data-flow map, purpose register, retention schedule, and rights test. Those artifacts allow a reviewer to verify the implemented flow rather than relying on a generic policy statement.
Limitation
Where this conclusion stops
This is a general implementation checklist, not legal advice or a complete compliance program. Applicable duties vary by jurisdiction, audience, data category, purpose, contractual role, and organizational context.
Sources and verification
What this guide relies on
- The Lead Quiz Review editorial methodology
- EUR-Lex, General Data Protection Regulation
- W3C, Understanding labels or instructions
- W3C, Form instructions
Sources and method checked August 7, 2026. External standards are linked to their primary publishers.