Employee Survey and Internal Feedback Forms
Employees do not disbelieve your anonymity promise because they distrust you personally. They disbelieve it because HR chose the tool and IT administers it, and because a promise made by whoever controls the database is not a guarantee. End-to-end encryption is the only claim that survives that scepticism: answers are encrypted in the employee's browser, encrypted submissions are stored in Switzerland, and nobody without the Vault key can read a single response — not us, not IT, not the manager named in the free text.

Every employee survey rests on a promise that the people answering it have no way to verify. The invitation says the results are anonymous. The employee knows that HR chose the platform, that IT administers the account, and that somewhere there is a database with their answers in it. Whether or not anyone would ever look is beside the point: the guarantee is a policy, and policies are written by the same organisation the survey is asking them to criticise.
Schweizerform changes what the promise is made of. Every answer is encrypted in the employee's browser before it leaves the device, and only a holder of the Vault key can decrypt it. We are a Swiss company, encrypted submissions are stored in Switzerland with Infomaniak, and we cannot read a submission — not for support, not for analytics, not under legal process, because we do not hold the key. Your own IT department cannot read them either, because there is nothing readable on the server to read. Surveys run in German, French, Italian and English, which for a Swiss employer with sites in more than one language region is not a detail.
Who this page is for
HR and people teams running engagement, pulse, onboarding and exit surveys; works councils and employee representations consulting their constituency; health and safety officers running psychosocial risk assessments; management teams running 360° feedback; and small organisations that want one honest survey a year without buying a research platform. If your problem is incidents — grievances, harassment reports, whistleblowing — that is the HR and whistleblower use case, which is a different job.
Why Employee Surveys Are the Hardest Anonymity Problem in an Organisation
In almost every other form we handle, the person being protected is outside the organisation and the organisation is on their side. An employee survey inverts that. The person whose behaviour the survey is measuring is inside — often the direct line manager of the person answering, sometimes the head of the function that commissioned the survey, occasionally the person who administers the tool. The threat model is internal, and everyone answering knows it.
The scepticism is rational, not paranoid
Swiss employees weigh the downside precisely. Art. 336a CO caps compensation for an abusive dismissal at six months' salary, and awards in practice sit well below the cap — and the dismissal itself remains valid. There is no reinstatement. An employee who suspects that a candid answer could be traced is not weighing a lawsuit against a bad review; they are weighing a job against a survey question. That arithmetic is why participation rates collapse in exactly the teams you most need to hear from, and why the standard mitigations — a policy sentence, a vendor's assurance, an HR briefing — do not move it.
The survey is also, quietly, a health survey
The Job-Stress-Index — run since 2014 by Gesundheitsförderung Schweiz with the University of Bern and the ZHAW — put 28.2 % of Swiss employees in the critical range, with more job demands than resources, and found 30.3 % emotionally exhausted in its 2022 wave, above the 30 % mark for the first time in the series; it valued the associated loss of productivity at some CHF 6.5 billion a year. Those numbers are the reason employers run engagement surveys at all. They are also the reason the resulting data set is more sensitive than most HR teams assume: a scale asking how exhausted someone feels at the end of the working day is a question about their health.
Exhaustion, workload and stress questions are health data
Art. 5 lit. c nFADP lists data on health as sensitive personal data. A wellbeing scale, a burnout item, a question about sleep or about absence, and a free-text box in which somebody describes a mental-health episode all fall inside it — regardless of the fact that you asked in a survey rather than in a medical form. Sensitive data raises the bar on security under Art. 8, on transparency under Art. 19, and on whether a data protection impact assessment under Art. 22 is needed. See collecting health data in forms for the detail.
What Swiss Law Actually Requires of an Employer Running Surveys
Art. 328b CO is the ceiling, and consent does not raise it
An employer may process employee data only where it concerns the employee's suitability for the job or is necessary for performing the employment contract. That is a narrower gate than the general proportionality rule of Art. 6 nFADP, and it is the provision that decides whether a survey question is allowed at all. The critical point, and the one most survey designs get wrong: Art. 362 CO makes Art. 328b mandatory law that cannot be departed from to the employee's detriment — the Federal Data Protection and Information Commissioner takes the position that this holds even with the employee's consent. You cannot consent your way into asking questions you are not allowed to ask.
Consent from an employee is weak by default
Both the FDPIC and the European Data Protection Board have repeatedly held that consent in an employment relationship is rarely freely given, because of the power imbalance. That does not make surveys unlawful; it makes consent the wrong load-bearing element. Participation must be genuinely voluntary and visibly so — no chasing lists, no completion rates published per team in a way that identifies who did not answer, no manager reminding an individual. The legitimacy of the exercise rests on necessity, transparency and data minimisation, not on a tick box.
Art. 26 ArGV 3: you may not build a monitoring system by accident
Art. 26 para. 1 of Ordinance 3 to the Labour Act prohibits surveillance or monitoring systems intended to observe employees' behaviour at the workplace, and it is not a rule the parties can contract around. Where such systems are needed for other reasons, para. 2 requires them to be designed so that employees' health and freedom of movement are not impaired; SECO's guidance to the article expects the purpose to be something other than behaviour monitoring, the system to be necessary and proportionate to that purpose, and employees to be informed and consulted before it is commissioned. A weekly pulse survey with per-person tracking, a named 360° tool that scores individuals continuously, or a manager dashboard that drills to one respondent are exactly the designs that walk into this article. An anonymous instrument does not.
Information and consultation duties: Art. 48 ArG and the Participation Act
Art. 48 of the Labour Act gives employees or their representation a right to be informed and heard on matters of health protection, the organisation of working time and shift schedules, and measures relating to night work. A survey about workload, stress and working-time arrangements sits squarely in that first category, which means the representation is a stakeholder in the design, not merely an audience for the results.
The Participation Act (SR 822.14) sets the frame. In businesses with at least 50 employees, staff may elect one or more representations; a secret ballot on whether to have one is triggered by one fifth of the workforce, or by 100 employees in businesses with more than 500. Art. 9 obliges the employer to inform the representation at least once a year about the effect of the business situation on employment and staff, and Art. 10 grants special participation rights in occupational safety and worker protection, transfers of undertaking under Art. 333/333a CO, mass dismissals under Art. 335d–335g CO, and affiliation to an occupational pension institution. Where no representation exists, those information and consultation rights belong to employees directly. Art. 14 binds the representatives themselves to confidentiality about the business's affairs.
If your group has entities in the EU, the survey has a second gate
German co-determination law treats technical systems that are capable of monitoring employee performance or behaviour as subject to works-council agreement, whether or not you intend to use them that way — which is why survey tools in German subsidiaries are usually covered by a works agreement. Art. 88 GDPR expressly leaves employment-context rules to member states, so there is no single European answer. A Swiss parent rolling one instrument across a group needs the local sign-off per entity, and it is cheaper to get it before the invitation goes out than after.
Which Survey Data Is Sensitive, Who Needs to Read It, and What Drives Retention
| Survey type | What it actually collects | Status under Swiss law | Who genuinely needs to read it |
|---|---|---|---|
| Engagement / climate survey | Satisfaction scales, trust in management, workload, intention to leave, plus free text | Ordinary data — but workload and exhaustion items are health data under Art. 5 lit. c nFADP | The analysis team, at aggregate level only; managers see team results above a threshold |
| Pulse survey (short, frequent) | Two to five recurring items, often per team, often weekly or monthly | The frequency is the risk: repeated small-team measurement approaches individual monitoring under Art. 26 ArGV 3 | The analysis team; team-level results only where the team is large enough |
| Onboarding, probation and exit surveys | Experience of recruitment, induction, management, reasons for leaving | Effectively identified in small organisations — one leaver a month is one respondent | HR, with a documented rule on whether the line manager sees anything at all |
| 360° feedback | Ratings and comments about a named individual, given by named or role-identified colleagues | Personal data about two people at once — the subject and, by inference, the rater | The subject and their coach or HR partner; raters must never be re-identifiable |
| Pay-fairness and salary-perception surveys | Perceived fairness, disclosed salary bands, sometimes actual figures, plus gender and function | Salary plus gender plus function in a small unit is a direct identifier — this is the easiest survey to de-anonymise | One or two named analysts, never a manager dashboard |
| Psychosocial risk assessment | Stress, harassment exposure, resources, recovery, sometimes absence | Health data, and it engages Art. 6 ArG and Art. 48 ArG consultation duties | The health and safety function plus the employee representation, at aggregate level |
| Works-council or representation consultation | Views on a restructuring, working-time model, pension affiliation | Ordinary data, but the representation — not the employer — is the natural controller of the raw responses | The representation. This is the clearest case for a Vault key the employer does not hold |
Two rows people get wrong
An exit survey in a 60-person company is not anonymous in any meaningful sense — HR knows exactly who left in March. Treat it as identified data collected with a confidentiality promise, and say so on the form, rather than printing the word «anonymous» over something everyone can see through. And a 360° instrument collects data about the rater as much as the subject: «my line manager» in a team of three is a name.
What Changes With Zero-Knowledge Intake
Concretely: the questionnaire is encrypted on the employee's device with a key we never receive. What reaches our servers is ciphertext. When the analysis team opens a response, decryption happens in their browser with the Vault key. There is no readable copy on the server, in a support tool, in a backup, or in anything a provider could be compelled to hand over.
- The anonymity claim stops being a policy and becomes a property. «Nobody at the vendor can read this» is verifiable from the architecture rather than promised in a privacy notice.
- Your own IT is out of scope. The most common internal objection — the admin who runs our survey account sits two desks from my manager — disappears, because there is no readable data in the account to administer.
- Security appropriate to the risk under Art. 8 nFADP comes from the architecture, not only from your access policy.
- The Art. 19 nFADP information duty is discharged once, on the form itself, in the employee's own language, including what will be reported and to whom.
- Nothing is collected that you would later have to explain. No analytics provider and no beacon runs on the public form page; there is no IP address, user agent, referrer, geolocation or cookie identifier attached to a response.
- Compulsion changes nothing. A court order, a discovery request in a foreign proceeding or a determined administrator all arrive at the same ciphertext.
The one claim that survives employee scepticism
Ask any survey vendor a single question: can your staff, or anyone holding your infrastructure, technically read a submitted response — and under what controls? Every conventional platform has to answer «yes, under controls», because their analysis features work on plaintext. That is not a scandal; it is what the architecture requires. It is also why «anonymous» from those platforms is a configuration, not a guarantee — a point made at length in privacy-compliant survey tools compared.
How Do You Give Managers Team Results Without Giving Them Individual Answers?
This is the question that decides whether an internal survey is trusted, and it has two halves: an arithmetic half and an access half. Most organisations solve the second and ignore the first.
The arithmetic half: group size, and why the threshold applies to cells
The convention that a result should not be reported for fewer than five respondents — sometimes ten — is a statistical-disclosure practice, not a Swiss legal threshold: no article of the nFADP names a number. What matters is that the threshold applies to the cell being reported, not to the survey. A survey with 400 responses is not anonymous if the report breaks down «women in the finance team» where there are three. Every filter you add multiplies the number of cells and shrinks each one. The arithmetic, with worked examples, is in how many responses before an employee survey is really anonymous.
The access half: separate the readers, not the encryption
- Put the survey in its own workspace. Only the members of that workspace can decrypt its submissions. If the works council or an external analyst is meant to be the only reader, that is achieved by who is in the workspace — not by a permission flag on top of a database everyone's admin can reach.
- Use the viewer role for people who must see but not touch. Roles run owner, admin, member, viewer, with viewer read-only, so a sponsor or a representation delegate can follow the raw material without being able to edit or delete it.
- Managers get a report, not an inbox. The team-level summary is something a human writes after decryption and above the reporting threshold. There is no way to hand a manager a filtered live view of the answers, and that limitation is doing useful work.
- Write the reporting rule down before the survey opens — minimum cell size, which breakdowns exist, who receives what, and what happens to a team too small to report. Publish it in the invitation. A rule announced afterwards reads as a rule invented afterwards.
- Every read, export and deletion is recorded. The audit log is append-only and covers logins, exports and deletions, so «who opened the responses» is a question with an answer.
Free Text Is Where Anonymity Dies
It is not the demographics that identify people. It is the comment box, and it is not close. Employees write «after my return from parental leave in March», «as the only person in the team who works part-time», «when our new department head arrived» — and each of those is an identifier written voluntarily by the person the survey is protecting. No platform can prevent this, ours included; encryption stops the vendor and the administrator reading it, not the analyst who is supposed to.
- Say it on the form, immediately above the box. One sentence: «Please describe the situation without naming yourself, your team or individuals — we cannot make an identifying comment anonymous after the fact.» This single line does more than any technical control.
- Never circulate verbatim comments below the reporting threshold. Paraphrase and thematise. If a comment cannot be paraphrased without losing its point, it usually cannot be shared without identifying its author either.
- Decide in advance what happens to a comment that discloses a serious problem — a harassment allegation, a safety risk, a health crisis. You will get one. Anonymity means you cannot follow up with the author, which is precisely why an identified reporting channel has to exist alongside the survey and be named in the invitation.
- Do not run automated sentiment analysis over free text. It cannot work here anyway — the text is encrypted and no model ever sees it — but the deeper point is that it turns a comment into a score attached to a group, and the groups are small.
One Response Per Person Without Knowing Who — and the Trap Nobody Warns You About
Every survey owner wants the same two things at once: one response per employee, and no idea which employee. The honest answer is that you can approximate it, and that each mechanism costs a measurable amount of anonymity. The ranking, from cheapest to most expensive in anonymity terms, is a device marker, then a hashed network identifier, then a one-time token, then an email address, then a login — and the spam, bots and duplicate submissions guide sets out what each one actually buys you.
Do not switch on once-per-network for an internal survey
Our once-per-network control stores a per-form-salted, server-peppered hash of the submitter's network address and rejects a second submission that matches. It is the right tool for a public form. It is the wrong tool for an employee survey, because everyone in an office usually leaves the building behind a single shared address — the first colleague to answer would lock out the whole site. For internal surveys use the browser-level marker (best-effort, and honest about it) or one-time tokens generated outside the survey and handed out by someone who does not analyse the results.
The pattern that works for a workforce is «anonymous but verified»: someone who is not the analyst — the works council, an external trustee, a payroll administrator — issues single-use links or codes against the staff list, and never sees the responses; the analysis team sees the responses and never sees the list. Two roles, two sets of knowledge, and no single person holding both. It is more work than a mail merge from the HR system, and it is the only version of «one vote each» that an employee has any reason to believe.
What We Can Count Without Reading Anything
Encryption removes the answers from us, not the operational picture from you. Against the encrypted form we still count how many people opened it, how many responded, how long the median response took, and — per question — how many people who saw a question answered it. That last number is the most useful thing in a survey pilot: a question with a low answer rate is a question people are refusing, and refusal is a signal about the question, not about the person.
The design rule is that counters are flat and never cross-tabulated. Day, device, channel and question are separate tallies that cannot be intersected back toward an individual, because the cross-tab is exactly the join that re-identifies people in small response sets. Counters are also receive-time and never decremented, and there is no backfill — any product that can retroactively reconstruct perfect history kept something per person to reconstruct it from. The full account is in form analytics without tracking.
Getting Started With Employee Surveys
Decide what you will do with the answer before you ask the question
The fastest way to destroy a survey programme is to run it twice with no visible consequence. Cut every question you would not act on — that is Art. 328b CO and Art. 6 nFADP agreeing with basic survey practice for once.
Write the reporting rule, then design the questionnaire around it
Minimum cell size, which breakdowns exist, who receives which report, and what happens to teams below the threshold. Demographic questions come last and are cut hard: each one multiplies the cells.
Involve the employee representation early
Art. 48 ArG gives them a say on health-protection matters, and the Participation Act gives them standing in a business with 50 or more employees. A survey the representation co-signed is answered honestly; a survey it learned about from the invitation is not.
Set up the workspace and the Vault key custody
A dedicated workspace with the analysis team as members, viewer role for observers, two named key custodians and an offline copy. Read how the Vault key works first — if it is lost, the responses are unrecoverable, and that is the same property that keeps everyone else out.
Write the Art. 19 information text onto the form itself
Who is running the survey, the purpose, what will be reported and at what granularity, that participation is voluntary, how long responses are kept, and — the one everyone forgets — the separate, identified channel to use if something needs a response rather than a statistic.
Publish in every language your workforce actually uses
One survey, four language versions — German, French, Italian and English. A single-language survey in a multi-site Swiss employer measures language proficiency as much as engagement. Starting from a form template shortens this considerably.
Running One Survey End to End
Pilot with one team and read the answer rates
Ten to twenty responses is enough to see which questions people skip. Rewrite or delete those before the full launch, while nobody has yet been asked.
Distribute one shared link, not personalised invitations
No login, no email field, no tokens tied to an HR list. Where you need participation control, issue single-use codes through someone who does not analyse the results.
Let it run without chasing individuals
Publish an overall response counter if you want momentum. Never publish per-team completion in a way that identifies who has not answered, and never let a manager remind one person.
Analyse after decryption, in one place
The analysis team decrypts in the browser, exports what it needs — CSV is available on every plan, with Excel, PDF and ZIP on the paid tiers — and works in one controlled copy rather than mailing extracts around.
Report to the threshold, and say what you suppressed
Publish the aggregate, the team results above the minimum cell size, and an explicit note that units below it were not reported. Suppression that is announced builds trust; suppression that is discovered destroys it.
Delete on the schedule you promised
Raw responses have a much shorter useful life than the report drawn from them. Deletion here is a deliberate action — individually or in bulk — not an automatic per-form rule, so put the date in the project plan and assign it to a person.
Common Objections — and Realistic Answers
We already use a survey platform and it has an anonymous mode.
Then check two things rather than trusting the label. First, whether anonymous handling is a setting that has to be switched on per collector — in the mainstream platforms it is, it is off by default, and a survey distributed by both a web link and an email invitation may need it set twice. Second, whether the setting removes the identifier from the results export only, while network addresses remain in backend logs for a period measured in months. Neither of those makes a vendor dishonest. They make «anonymous» a configuration you have to verify, which is a different thing from a guarantee.
Our provider contractually promises never to report below five responses.
That is a promise about the report, not about the data. The underlying responses still exist in readable form on the provider's systems, still exist for anyone at the provider with production access, and still respond to a lawful order. A reporting threshold protects against casual re-identification by managers, which is the most likely scenario — genuinely worth having. It does not protect against the scenario employees are actually imagining when they hesitate over the comment box.
Someone will report harassment in a free-text box and we will not be able to act.
This will happen, and it is the strongest argument for running two channels rather than one. The survey measures; a named, confidential reporting channel handles cases. Say so in the invitation, put the link next to the comment box, and accept that a genuinely anonymous survey cannot be a case-management system. We describe the boundary in the HR and whistleblower use case and in the whistleblowing platform comparison, including where a dedicated case-management suite beats us outright.
We need to cross-tabulate tenure by department by gender.
You can, after decryption, in your own spreadsheet — and you should think hard about whether you should. We cannot do it server-side: there is no query engine over ciphertext, no live filtered dashboard, no weighting, no panel management and no longitudinal linkage of the same person across waves. For a research-grade study with quotas and weighting, a specialist platform is the honest recommendation. For an annual engagement survey in a 200-person organisation, the cross-tab you are asking for is usually the one that would have identified somebody.
Our works council wants to hold the results, not HR.
That is the cleanest configuration this architecture supports, and it is worth designing for deliberately: the representation owns the workspace and the Vault key, HR receives the report, and the technical guarantee matches the political arrangement instead of contradicting it. Art. 14 of the Participation Act already binds the representatives to confidentiality about the business's affairs; the encryption makes the reverse direction true as well.
Employees still will not believe us.
Some will not, and the honest thing is to say what is verifiable rather than to reassure. What you can put in the invitation, in one sentence each: the answers are encrypted in your browser and the provider cannot read them; the survey page loads no tracker and records no IP address; the people who can decrypt are named, and here they are; results below N responses will not be reported; the raw data is deleted on this date. Every one of those is checkable by a sceptical employee with a browser's network inspector, which is more than any assurance paragraph has ever offered.
Where Schweizerform Is Not the Right Answer
- No server-side analytics over answers. No cross-tabs, no filtered live dashboards, no weighting, quotas or panels, no sentiment analysis, no benchmark database. Everything happens after decryption, in front of a person.
- No longitudinal linkage. We cannot connect the same respondent across waves without an identifier, and an identifier is the thing you are trying not to have. Trend analysis works at aggregate level, not per person.
- Not a case-management system. No anonymous mailbox the author can return to, no deadline tracking, no investigation workflow. If you need those, buy a whistleblowing platform and use the survey for measurement.
- No automatic per-form retention rule. Deletion is an action you take, individually or in bulk. Diarise it.
- Key loss is unrecoverable. Two named custodians and an offline copy, agreed before the survey opens, are a precondition rather than a footnote.
- No single sign-on, which some enterprise IT departments require before they will approve any tool. Ask us where we are rather than assuming.
The Bottom Line for Employee Survey Forms
An employee survey collects health data under Art. 5 lit. c nFADP, sits under the ceiling of Art. 328b CO that consent cannot raise, engages consultation duties under Art. 48 ArG and the Participation Act, and can drift into the monitoring prohibition of Art. 26 ArGV 3 if it is run per person and often enough. Every one of those is manageable. What is not manageable by policy is the thing that actually suppresses honest answers: the knowledge that somebody inside the organisation could look.
End-to-end encryption is the only response to that which does not depend on being believed. Answers are encrypted in the employee's browser, encrypted submissions are stored in Switzerland, the reader set is a workspace you control, and the analytics that remain are counts rather than content. What we give up — cross-tabs, weighting, longitudinal linkage, live dashboards — we would rather you know before you choose than after your first survey has already been answered cautiously.
Run your next pulse survey on the free plan — encrypted in the employee's browser, published in German, French, Italian and English, with no tracker on the page and no readable copy anywhere — and put the reporting threshold in the invitation instead of in a policy nobody reads.
Disclaimer: this page is general information and marketing content, not legal or HR advice. References to the nFADP/nDSG and the DPO, Art. 328b, 336a and 362 CO, Art. 6 and 48 ArG, Art. 26 ArGV 3, the Participation Act (SR 822.14), the Gender Equality Act and EU works-council rules are summarised at a conceptual level, reflect the position as of July 2026, and are subject to cantonal practice, collective agreements and judicial interpretation. Responsibility for the lawful processing of employee data remains with the employer. Consult a qualified Swiss employment or data-protection adviser before relying on any summary here.