Anonymous Employee Surveys: How Many Responses Before Anonymity Holds?
No Swiss law names a number. The working answer is a minimum reporting group of five, ten before manager-level breakdowns — but the threshold is the last line of defence, not the first. How k-anonymity actually works, why demographic cross-tabs re-identify people long before you hit the limit, why free text is the biggest leak, and what Art. 328b CO requires of a Swiss employer.

Every HR team that has ever launched an engagement survey has been asked the same question by a sceptical employee: «how do you know it is really anonymous?» The answers usually offered — «the tool is anonymous», «we don't look at individual responses», «results are aggregated» — are exactly the answers that do not survive scrutiny, because none of them is a property of the data. The question has a real answer, and it is arithmetic before it is legal.
The short answer
No Swiss statute names a number. The operational convention, borrowed from statistical disclosure control, is a minimum reporting group of five — never publish a result computed from fewer than five responses — with ten as the safer floor for anything broken down by team or manager. But the threshold only protects you if it is applied to every cell you publish, including every combination of filters. Five responses in a department of twelve, split by tenure and gender, identifies people at n = 5 just as reliably as at n = 1. And no threshold at all protects free-text answers.
This article gives the concrete numbers, the reasoning behind them, and the Swiss employment-law layer that sits on top — Art. 328b of the Code of Obligations, which constrains what an employer may process regardless of what employees agree to.
Can I Run an Employee Satisfaction Survey Anonymously?
Yes — and if you genuinely achieve it, the prize is larger than most people realise. Data protection law governs personal data, meaning information relating to an identified or identifiable natural person. Data that has been truly anonymised is no longer personal data, and the nFADP stops applying to it: no record entry for those responses, no access requests, no retention obligation, no breach notification. Anonymity is not merely an ethical nicety in surveys; it is the one route that takes the processing out of scope entirely.
The catch is that «anonymous» is a technical property, not a label you apply. A survey is anonymous when no one — including you, including the platform, including a determined analyst with the HR system open in another window — can link a response back to a person. Most surveys marketed as anonymous are in fact pseudonymous: the direct identifier has been removed, but enough attributes remain to re-identify. That distinction, and why it matters legally, is the subject of our post on anonymous versus pseudonymous forms.
How Many Responses Are Needed Before Anonymity Is Preserved?
The number everyone quotes: five
A minimum group size of five is the most widely used convention in employee survey reporting, and it comes from statistical disclosure control — the discipline national statistical offices use when publishing tables about small populations. The rule is simple: if a published figure is derived from fewer than five underlying records, suppress it. Many organisations raise the floor to ten for anything attributed to a named manager, on the reasoning that a manager reading their own team's results has more contextual knowledge than an anonymous member of the public, and therefore needs a larger crowd to hide in.
Five is a convention, not a legal threshold
Be precise about this when you communicate it. No provision of the nFADP, the Code of Obligations or the Participation Act sets a minimum survey group size. What the law requires is that the data actually not be attributable to an identifiable person, and proportionality in what an employer processes. The number five is a widely accepted way of achieving that; it is not a safe harbour you can point to if your reporting re-identifies someone anyway.
The threshold applies to cells, not to surveys
This is the mistake that undoes most well-intentioned survey programmes. «We had 340 responses, so it is anonymous» describes the survey. Re-identification happens in the cells — every figure produced by a combination of filters. The formal version of this idea is k-anonymity, introduced by Samarati and Sweeney in the late 1990s: a dataset is k-anonymous if every record is indistinguishable from at least k−1 others with respect to the attributes that could identify someone. Those attributes — department, tenure band, age band, gender, location, seniority — are called quasi-identifiers, and none of them identifies anyone on its own.
Combined, they collapse fast. Take a 340-person company with a dashboard offering four filters. Department (12 options), tenure band (4), age band (4) and gender (3) generate 576 possible combinations across 340 people. The average cell holds less than one person. It does not matter that the survey had 340 respondents — the moment somebody filters to «Finance, 0–2 years, 30–39, female», the tool is reporting on a group of one, and it will happily draw a chart of their engagement score.
| Group being reported | Rule | Why |
|---|---|---|
| Fewer than 5 responses | Suppress entirely — no scores, no counts, no charts | Any figure is attributable within a group that small |
| 5–9 responses | Headline scores only; no demographic breakdown, no free text | One filter more and the cell drops below the floor |
| 10 or more | Team-level reporting acceptable; still no cross-tabs below 10 | Manager context makes small groups riskier than they look |
| Any cross-tabulation | Apply the same floor to the combined cell, not the survey | Quasi-identifiers multiply; combinations shrink to single people |
| Free-text comments | No threshold makes these safe — treat separately | Writing style, incidents and details identify regardless of group size |
| Response counts and participation rates | Suppress below the floor too | «11 of 12 responded» plus one known absence identifies the twelfth |
Differencing: the attack nobody anticipates
Suppressing small cells is not enough if the surrounding totals are published. If the company-wide average is shown, and every department except one is shown, the missing department can be derived by subtraction. The same applies across time: publish a team's score in March with 12 people, publish it again in April after two leavers, and the difference narrows the possibilities sharply. Statistical offices handle this with secondary suppression — hiding additional cells purely so the suppressed ones cannot be reconstructed. Very few HR dashboards do.
The Four Ways «Anonymous» Surveys Actually Leak
1. Free text — by a wide margin the biggest
Threshold rules operate on numbers. A comment box operates on language, and language identifies people: the incident only three people witnessed, the project only one person works on, the phrasing colleagues recognise, the second-language patterns of the only non-native speaker on a team. Anyone who has read a set of open comments from a department they know can usually name several authors, and they are usually right. Treat free text as a separate, higher-risk data category: never show it broken down below the reporting floor, consider having it summarised or redacted before managers see it, and tell respondents plainly that specific detail can identify them.
2. Demographic questions you did not need
Every demographic field is a quasi-identifier, and each one multiplies the number of cells. The honest test is whether you will actually act on the breakdown. If nobody will change anything based on the age-band split, the age-band question is pure re-identification risk with no analytical return. Cutting two demographic questions typically does more for real anonymity than any amount of platform configuration.
3. Metadata nobody remembers collecting
The survey may be anonymous while the delivery mechanism is not. Personalised invitation links, one-time tokens tied to an email list, IP addresses, device fingerprints, submission timestamps and completion times all sit outside the questionnaire and all can re-link a response. A timestamp is enough on its own in a small team where working hours differ. Ask your platform explicitly what it stores alongside a submission, and get the answer in writing before you promise anonymity to anyone.
4. The small-population problem
Some groups cannot be surveyed anonymously at all, and pretending otherwise is worse than admitting it. A four-person leadership team, the two people in a specialist function, the sole employee in a given canton: no threshold, no platform and no promise makes their answers unattributable. The correct response is to say so, merge them into a larger reporting unit, or run that conversation face to face instead.
Can Managers See Individual Answers?
In most survey platforms the technical answer is that somebody can — and that somebody usually reports to the same executive team the survey is assessing. Access to raw responses typically exists for the account administrator, for whoever exports the data, and for the vendor's own staff. «Managers cannot see individual answers» is therefore a statement about configuration and policy, not about capability, unless the platform is built so that no readable individual record exists in the first place.
Employees intuit this, which is why participation collapses after the first time results feel too specific. If you want the survey to be believed, be exact in what you promise: name who administers the tool, name who can export raw data, state the reporting floor as a number, and say what happens to free text. A precise, slightly unflattering description of your setup buys more trust than a confident «it's completely anonymous» that one sceptical engineer can disprove in a meeting.
What Swiss Law Requires of an Employer Running Surveys
Art. 328b CO limits what you may process at all
Art. 328b of the Code of Obligations permits an employer to process data concerning an employee only to the extent that the data concern the employee's suitability for the job or are necessary for the performance of the employment contract. The Federal Data Protection and Information Commissioner is explicit that this provision may not be departed from to the employee's detriment even with the employee's consent. That single sentence disposes of the most common survey design shortcut: you cannot cure an over-broad questionnaire with a consent checkbox.
Consent from an employee is weak by default
The FDPIC's guidance on employer data processing notes that employees are very rarely in a position to freely give, refuse or revoke consent, given the subordinate nature of the relationship. In practice, treat employee consent as a supporting formality rather than your justification, and rely on necessity for the employment relationship plus proportionality under Art. 6 nFADP — which is another way of saying: only ask what you will act on.
Engagement questions can be health data
This one is routinely missed. Questions about stress, exhaustion, burnout risk, sleep, mental wellbeing or workload-driven illness produce data about health, which is sensitive personal data under Art. 5 lit. c nFADP. That raises the bar: explicit consent where consent is the basis (Art. 6 para. 7 lit. a), and a data protection impact assessment under Art. 22 where such data is processed on a large scale. A 2,000-employee wellbeing survey is squarely in that territory. Genuine anonymisation is the cleanest way out, because anonymous data is not personal data at all — which is precisely why the threshold discipline in this article is worth the effort. Our nFADP compliance checklist for forms and surveys covers the surrounding duties.
Employee representation and works councils
In businesses with at least 50 employees, employees may request the appointment of an employee representation body under the Participation Act, and where one exists it has information and consultation rights on matters affecting employees — survey programmes and any monitoring dimension included. Involving the representation body early is not merely legally prudent; it is the most effective trust signal available, because the body can verify your reporting floor independently of HR.
Can I Run a Salary or Pay-Equity Survey While Protecting Identities?
This is the hardest case in the category, because salary combined with function and one demographic attribute is close to unique in most organisations, and because the data is exactly what employees least want circulating internally. Three practices make it workable.
- Collect bands, not figures. Salary ranges of CHF 10,000–20,000 width destroy far less analytical value than people expect and remove the single most identifying variable.
- Report only at aggregation levels with a real crowd. Pay-equity analysis by function family across the whole company works; the same analysis for a five-person function does not, and should be suppressed rather than caveated.
- Separate collection from analysis. Where the sensitivity is high, an external analyst or a platform the employer cannot read individual records in removes the internal-access question entirely — which is the question employees are actually asking.
Swiss employers with 100 or more employees have had to carry out equal-pay analyses under the Gender Equality Act, using a defined methodology and independent verification. That is a separate exercise from an internal opinion survey, and it deliberately keeps the analysis away from line management — a useful model for how salary data should be handled generally.
What the Platform Must Guarantee — and What It Cannot
Here is the part where a vendor is expected to say «our encryption makes your survey anonymous», and it would be untrue. End-to-end encryption protects submissions from the platform operator, from infrastructure compromise and from anyone in the middle. It does not protect an employee from their own employer, because the employer holds the key and decrypts the responses — that is the entire point of the product. If your survey collects the department, the tenure band and a free-text box, encryption changes nothing about whether HR can work out who wrote what.
So anonymity in an employee survey comes from design choices, and the platform's job is to make those choices possible and enforceable:
- No respondent identifier collected or derivable — no login requirement, no personalised link tying a response to a person, no email capture «just for the prize draw».
- Metadata minimised and documented — you should be able to state exactly what is stored beside each response, and IP addresses should not be among it.
- Reporting thresholds you control, applied to every breakdown rather than to the survey total, with suppression as the default rather than an option someone must remember to enable.
- Free text handled deliberately — separable from structured results, with a route to summarise or redact before distribution.
- No provider-side access to the content, so that «who else could read this» has a short and verifiable answer. This is what encryption genuinely delivers, and it removes the vendor from the trust equation without removing the employer.
Running One That Survives Scrutiny
Decide the reporting floor before you write the questions
Five as the minimum, ten for anything attributed to a named manager. Write it into the survey communication as a number. A stated threshold is checkable; «results are aggregated» is not.
Count your cells, not your headcount
Multiply the options of every demographic question. If the result exceeds your population divided by the floor, you have designed a survey that cannot be reported anonymously. Cut demographics until the arithmetic works.
Strip identifiers from the delivery mechanism
One shared link rather than personalised invitations, no login, no email field, no tokens tied to an HR list. If you must track participation, track it at the level of «invited group», never per person.
Decide the free-text policy in advance
Who reads raw comments, whether they are redacted before managers see them, and what happens to a comment naming an individual. Tell respondents the policy before they type.
Involve the employee representation body
Where one exists, give it the design, the threshold and the access list. Independent verification is the difference between a promise and a control.
Apply suppression to every published view
Including participation rates, trend comparisons and the residual you create by publishing all departments but one. Check the dashboard by trying to break it yourself before release.
Set a retention rule and delete the raw data
Once the report exists, the individual responses have served their purpose. Deleting them on a stated schedule is both an Art. 6 para. 4 obligation and the most persuasive proof that next year's survey is safe to answer honestly.
Bottom Line: How Many Responses Before Anonymity Holds?
Five per published figure, ten before anything is attributed to a named manager, and the floor applied to every cell rather than to the survey as a whole. That is the working answer, and it is a convention borrowed from statistical practice rather than a rule in any Swiss statute — which means it protects you only as long as it is actually applied to every breakdown you publish.
The deeper answer is that the threshold is the last defence, not the first. Anonymity is won earlier, in the design: how many demographic questions you ask, whether the invitation is personalised, what metadata is stored, and how free text is handled. Ask three fewer demographic questions and the arithmetic stops fighting you. And be honest in what you tell employees, because a survey that is believed is worth more than a survey that is technically defensible — and the only way to be believed twice is to have been exact the first time.
Schweizerform runs surveys without logins, without personalised links and without provider-side access to responses — so the list of parties who could read a submission is short and verifiable. For grievance and whistleblowing channels, where the requirement goes beyond anonymity in reporting, see our HR and whistleblower use case. For running the survey itself — workspace setup, works-council involvement and the settings that quietly break anonymity — see employee survey forms.
Disclaimer: This article is general information and marketing content, not legal advice. References to the nFADP, the Code of Obligations, the Participation Act and the Gender Equality Act are simplified and reflect the position at the time of writing (July 2026). The group-size figures given here are widely used professional conventions drawn from statistical disclosure practice, not statutory thresholds, and they do not guarantee anonymity in any particular dataset — re-identification risk depends on your population, your questions and what else is published. Have survey designs involving sensitive data or works-council obligations reviewed by qualified data protection and employment counsel.