Set up an anonymous survey | LimeSurvey

Set up an anonymous survey

An anonymous survey is one where nobody — including you as the administrator — can tell which answers came from which person. LimeSurvey does this properly: switch on Anonymized responses and the link between a participant and their response is never written to the database in the first place.

The single most important thing to know: anonymous and "open to anyone" are two different settings. You can invite a named list of people, send each a personal access code, chase the ones who haven't answered — and still not be able to see who said what. That combination is what most research ethics boards actually ask for, and it is the setup this article describes.

1. Switch on anonymized responses — before you activate

Open Settings (the gear in the left icon rail) → Participant settings and turn on Anonymized responses.

With it on, LimeSurvey stores responses with no reference to the access code that was used. The manual is unambiguous: there will be no way to connect answers and participants — even the admin will not be able to link response data and participant data.

Do this before you activate the survey. Response-recording settings are fixed at activation, and the only way to change them afterwards is to deactivate — which archives the responses you already have. Decide once, up front.

2. Turn off the other traces

Anonymised responses covers the access code. Everything else is a separate switch, in Settings → Notifications & data:

SettingSet toWhy
Save IP addressOffAn IP address is personal data in the EU and often identifies a household or a workplace
Anonymize IP addressOn, if you need IPs at allMasks part of the address — a middle ground when you want rough geography
Save referrer URLOffReveals which page — which course, which intranet link — the participant came from
Date stampOffA precise submission time can be matched against door logs, lecture times or your own sent-mail
Save timingsOffPer-page timings are a behavioural fingerprint, and rarely needed

These five lock the moment you activate the survey. On an active survey they appear greyed out. Everything on the Publication & access panel stays editable.

Note what switching on Anonymized responses does to timestamps: submission and token completion dates are set to 1980-01-01 00:00. That is deliberate — it removes the ordering information that could otherwise line responses up against your invitation list. It also means you cannot reconstruct when anything was answered, so if you genuinely need response dates for your analysis, decide that now, not later.

3. Choose how people get in

On the Share tab, the access-mode dropdown gives two options:

  • Anyone with link — one URL, no participant list. Simplest, but you cannot send reminders, cannot stop one person answering twenty times (beyond a cookie), and cannot report a response rate.
  • Link with access code — each person gets their own code from your participant list. You keep the ability to invite, remind and measure completion, and with Anonymized responses on you still cannot connect anyone to their answers.

With access codes, LimeSurvey records against each participant only whether they have completed — never what they answered. That is what lets you send a reminder to the right people without breaking anonymity.

4. Don't re-identify people with your own questions

This is where anonymity is usually lost, and no setting protects you from it.

  • Don't ask for names, email addresses, staff or student numbers. Obvious, but they creep into "any other comments" fields — say explicitly that people should not include personal details there.
  • Watch combinations. Department + role + gender + years of service will identify exactly one person in a small organisation, even though no single question does. Use broad bands ("1–5 years", "6–10 years") and merge small categories.
  • Apply a minimum group size when you report. Suppress any breakdown covering fewer than about five people. Promising anonymity and then publishing a chart with one respondent in a cell is a breach of the promise.
  • Free-text answers identify people. Someone describing their own role or an incident is recognisable to colleagues. Say so in advance, and consider summarising rather than quoting.

5. Save and resume, carefully

If participants need to interrupt and come back, Participant may save and resume later (in Notifications & data) asks them to set a name and password. Tell them to use a pseudonym and a new password — not their real name, not their work login, and not the email option, since an email address stored for resuming defeats the anonymity you just configured.

6. Tell participants what you actually do

An anonymity promise is only worth what your settings do. LimeSurvey has a Privacy policy panel in Settings — use it to state plainly: what is collected, what is not (no IP addresses, no timestamps, no link to the invitation), who sees the results, and how long data is kept. If you use access codes, explain why you can still send reminders without knowing who answered, because participants reasonably assume the opposite.

Good to know

  • Keep your participant list away from your results. Export responses and participant lists separately, and don't join them in a spreadsheet "just to check" — that recreates exactly the link you removed.
  • Anonymity is not the same as confidentiality. Confidential means you can identify people but promise not to. Anonymous means you cannot. Use the right word in your invitation.
  • Test it. Before inviting anyone, submit a test response and open the responses table. If you can see an access code, an IP address or a real submission time next to it, something is still switched on.

Going further

Participant settings reference: https://www.limesurvey.org/manual/Participant_settings