To collect informed consent in an online survey, you put a plain-language information sheet at the very start, force an explicit Yes or No choice, route a No straight to the end without recording research data, and save a timestamped record of every agreement. A bare “I agree” checkbox next to a hyperlink is the most common version, and it is the weakest one that passes review. Here is the version that holds up.
Most consent problems are not ethical failures by the researcher. They are mechanical failures: a pre-ticked box, a consent item that is optional, a refusal path that still writes a partial response, or a claim of anonymity that quietly contradicts the IP address the platform logged at 9:14 a.m.
What follows is the whole workflow: what to gather before you open the survey builder, how to write the form, how to configure Google Forms, Qualtrics, SurveyMonkey, Microsoft Forms or REDCap, how to pilot it, and what proof of consent to keep afterwards.
Table of Contents
- 1What You Need
- 2Step-by-Step
- 3How to Collect Informed Consent in an Online Survey
- 4Write a Clear Online Consent Form
- 5Required consent elements and copy-ready phrasing
- 6Ready-to-adapt consent statement
- 7Configure Consent in the Survey Platform
- 8Pilot and Test the Consent Process
- 9Document and Store Consent Records
- 10Common Mistakes
- 11Frequently Asked Questions
- 12Is a consent checkbox alone enough for an online survey?
- 13Can informed consent be collected anonymously in an online survey?
- 14When does an online survey study require ethics review?
- 15How should consent be handled for minors or vulnerable participants?
- 16Do researchers need new consent after changing survey questions?
- 17How long should online survey consent records be retained?
- 18Conclusion
What You Need
Most consent problems trace back to something decided before the survey was ever built. Gather these seven things first and the drafting stage goes quickly.
- The study specifics. Research question in one sentence, who the participants are, what they will be asked to do, roughly how long it takes, and what happens to their answers.
- Your approved consent language. If your institution has a template or a previously approved form, start there rather than drafting from scratch. Review bodies and ethics committees tend to push back hardest on home-grown legal text.
- A survey platform. Google Forms, Microsoft Forms, Qualtrics, SurveyMonkey and REDCap all handle a consent gate. Their menus differ, and paid tiers differ more.
- Eligibility rules. Screening criteria such as age, location or membership need to run before or alongside consent, not after data collection, and minors need a different route entirely.
- Named contacts. A lead researcher with a working email, a faculty supervisor for student projects, and the relevant ethics committee or institutional review board contact. People ask for this constantly because it is the one thing they will always read.
- Response and storage settings. Decide whether you will collect email addresses, whether the platform logs IP addresses and device data by default, where files will be stored, and who can open them.
- Institutional requirements. Whether your study counts as human subjects research, whether an exemption or minimal risk determination is possible, and what your institution requires for secondary use or data sharing.
Confirm item seven before you write a word. Researchers regularly discover after collecting responses that their institution needed prior review, and the honest answer to whether work can be published after the fact is generally no.
Step-by-Step

The mechanics below hold for most studies. Five variants change the details, and it pays to know which one you are running before you build the gate.
Anonymous studies should log agreement status and a timestamp but no identifiers, which means withdrawal after submission is genuinely impossible and your consent text has to say so plainly. Identified studies store a participant ID or email alongside the agreement, so a withdrawal request can actually be carried out. Studies involving minors need parental or guardian permission plus child assent, which is usually two forms and two gates. Sensitive-topic studies need extra care over what the platform logs and where data lands. Institutionally reviewed studies must use the exact approved wording, so build the gate around the approved text rather than editing it into the builder.
How to Collect Informed Consent in an Online Survey
Seven steps, in order. Each one is a small decision you make before launch rather than a problem you fix afterwards.
- Check whether your study needs ethics review. Ask your institution or ethics board before collecting anything. Exempt or minimal risk categories exist, but you do not self-certify into them.
- Write the information in plain language. Aim for an eighth-grade reading level. Studies of real consent forms average around 3,110 words, a Flesch Reading Ease near 47 and a grade level close to 11.6, which is why people skip them.
- Place a hard consent gate first. The information sheet and agreement item come before every research question, so no data exists before agreement.
- Force an explicit choice. Use a required Yes or No multiple-choice item, not a bare “I agree” checkbox and never a pre-ticked box. Pre-ticked agreement is treated as invalid under GDPR.
- Branch on the answer. Send Yes to the survey and No to a thank-you endpoint that records nothing further. Researchers on Qualtrics forums and research forums consistently report this works better than any checkbox.
- Log the agreement. Capture a timestamp, the consent version, and agreement status. Add a participant ID only where the study design and the law allow it.
- Explain withdrawal honestly. Tell people how to withdraw and where the limit sits: anonymous responses that have been submitted usually cannot be retrieved.
Write a Clear Online Consent Form
Consent is not a privacy notice, and mixing the two confuses both jobs. Consent asks whether a person agrees to take part. A privacy notice explains how an organisation handles personal data it already holds, often because of a commercial relationship or a legal obligation.
The distinction matters most around identity claims. Anonymous means no link between a response and a person exists anywhere, including in platform logs. Confidential means the link exists but is protected. Say which one you have, and never promise absolute anonymity when you are retaining identifiers or when the platform logs IP addresses by default.
Required consent elements and copy-ready phrasing
| Element | What it must cover | Phrasing you can adapt |
|---|---|---|
| Purpose | Why the study exists, in one or two sentences | “This study looks at how people manage their time during the working week.” |
| Procedures | What the participant will actually do | “You will answer 20 questions in one sitting and can skip any of them.” |
| Duration | A realistic time estimate | “The survey takes about 7 minutes. Our own test runs ranged from 5 to 9 minutes.” |
| Voluntary nature | That skipping or stopping costs nothing | “Taking part is voluntary. You may stop at any time and you will not be penalised.” |
| Risks and benefits | Discomfort, no direct benefit, or benefit if it exists | “Some questions mention stressful situations. There is no direct benefit to you.” |
| Anonymity or confidentiality | Which one, stated honestly | “Your answers are not linked to your name. The platform stores a completion timestamp only.” |
| Data use and storage | Who sees responses, where they are kept, how long | “Responses are stored on university-secured servers for 12 months, then deleted.” |
| Withdrawal | How to withdraw, and where the honest limit is | “You can withdraw until you press Submit. After that, anonymous data cannot be retrieved.” |
| Contacts | Lead researcher and ethics board | “Questions? Contact the lead researcher at [email]. Ethics complaints: [board] at [email].” |
| Review details | Approval reference and review type | “This study was reviewed by [board] under reference [number] on [date].” |
A separate research ethics question from the “What are the 5 requirements for informed consent?” people search on usually expects five conditions rather than ten elements: the agreement has to be voluntary, informed, comprehensible, documented, and revocable. The table above is how you satisfy those five online.
Weak wording and strong wording fail differently. The weak version hides the decision inside fine print; the strong version cannot be misunderstood and still fits on a phone screen.
| Topic | Weak | Strong |
|---|---|---|
| Risks | “Participants assume a small risk of psychological discomfort.” | “Some questions ask about stressful experiences. Answering may feel uncomfortable. Skip any question.” |
| Data storage | “Data will be stored securely.” | “Responses are stored on university servers, seen only by the named research team, and deleted after 12 months.” |
| Withdrawal | “You may withdraw at any time.” | “You can close the tab before submitting. After Submit, anonymous data cannot be pulled back out.” |
| Identity | “This survey is completely anonymous.” | “We do not ask for your name. The platform records a timestamp and your device’s IP address unless we disable logging.” |
Ready-to-adapt consent statement
Adapt this rather than drafting from scratch. Change the bracketed parts, delete any line that does not apply, and have your review body approve it before use.
[Study title]
You are invited to take part in a study about [research question in one sentence]. We are [researcher name] at [institution]. Before you decide whether to take part, here is what you need to know.
Why this study is being done. We want to understand [purpose in plain language]. Around [number] people are taking part.
What you would do. You would answer [number] questions about [topics] in one sitting. There are no wrong answers, and you may skip any question you do not want to answer.
How long it takes. About [duration] minutes. Our own testing found the survey took between [min] and [max] minutes.
Risks and benefits. [Describe any discomfort, for example: some questions mention stressful situations. You may skip them.] There is no direct benefit to you. [State any benefit, or delete this sentence.]
Voluntary participation. Taking part is entirely voluntary. You may stop at any point without giving a reason and without any consequence to you, your course grade or your employment.
Your data. [Choose one: We do not collect your name or email. Your responses are not linked to you.] / [Or: We store your responses under the code P[number], and the key linking that code to you is held separately by [name].] The survey platform records the date, time and, unless we disable it, your IP address. Responses are stored on [secure location], accessible only to [named team], and deleted after [retention period].
Withdrawing. You can close the survey before you press Submit and nothing will be saved. [Choose one: Once you press Submit, anonymous responses cannot be retrieved or deleted.] / [Or: Contact [email] with your participant code within [timeframe] and we will delete your data, unless analysis has already begun, which we will tell you plainly.]
Questions or complaints. Contact the lead researcher, [name], at [email]. If you want to raise a concern about how this study is run, contact [ethics board or institutional review board] at [email] and quote reference [number].
Choosing to take part. Selecting “Yes, I agree to take part” means you have read the information above and decided to take part. Selecting “No” ends the survey here and records nothing.
Offer a downloadable or printable copy. Participants ask for this and most templates omit it, which costs you nothing to add.
Never bundle a newsletter or marketing opt-in into research consent. It is treated as a GDPR violation and it undermines every other promise you made in the form.
Configure Consent in the Survey Platform
Every platform below can enforce a consent gate. None does it by default, and the label positions move between versions, so check the menus in the version you actually have rather than trusting a screenshot.
| Platform | Explicit Yes or No item | Branching on refusal | Consent record kept | IP or device logging control |
|---|---|---|---|---|
| Google Forms | Required multiple choice | Sections routing on the answer | Response row with timestamp | Not controlled from the form; adjust in Workspace admin |
| Qualtrics | Choice question set to required | Logic blocks, standard in paid tiers | Per-choice metadata and timestamps | Controllable in survey and platform settings |
| SurveyMonkey | Matrix or single choice, required | Logic pages on paid tiers | Response metadata | Controllable per survey |
| Microsoft Forms | Choice question with required setting | Branching questions | Response summary and timestamps | Limited control in default settings |
| REDCap | Yes or No field with data validation | Action tags and record status | Consent field plus audit trail | Configurable per project |
Set the consent item as a required field. If it is optional, someone can complete the whole survey without ever agreeing, and your consent record will not cover the response.
Make the options Yes, I agree to take part and No, I do not agree. Never default the first option to Yes, and never use a design where the agree button is the only visible path forward.
Route the No branch to an endpoint that thanks the person and stops. Test that it writes no research data at all. If your platform will not let you block storage outright, record the refusal in a separate, clearly labelled field rather than a response row you later forget to exclude.
Turn on timestamps so you have a defensible audit trail linking agreement to response. Decide on identifiers deliberately: collecting email addresses makes follow-up possible but makes the study identified rather than anonymous.
Check what the platform logs by default. IP addresses, device data and location metadata are frequently on unless you disable them, which means a survey advertising itself as anonymous often is not.
Vet the vendor, not just the features. Ask whether responses are used to train models, where servers sit, whether you can export and delete your data, and how a deletion request is honoured. These answers matter more each year as platform data practices shift.
Pilot and Test the Consent Process
Run this checklist before you share the link.
- Read the form aloud to yourself once. Anything you stumble over, a respondent will too.
- Test every link, especially the ethics board and contact addresses.
- Confirm the consent item is required and that neither option is pre-selected.
- Open the survey on a phone. Most people will read it on one.
- Check contrast, font size and that your screen reader reads the consent text sensibly.
- If you require scrolling before agreement is possible, verify that it actually blocks.
- Submit a No and confirm zero research data is recorded.
- Test duplicate submissions if you are handing out raffle entries or course credit.
- Export a test response set and confirm you can read the agreement field and timestamp in the export.
Then give the link to someone who knows nothing about your study and watch them without helping. Where they hesitate tells you more than any readability score. In one test I ran, a colleague stalled for a full minute on the phrase “de-identified”, which is exactly the sort of word that needs replacing with a plain sentence.
For studies where comprehension genuinely matters, add a short teach-back check. Ask two or three plain questions about what participation involves, offer a wrong answer alongside the right one, allow two or three attempts, and stop the survey with a neutral message if they cannot pass. Community discussion of this pattern supports the idea that more refusals sometimes mean the consent process is doing its job.
Document and Store Consent Records
Consent is only evidence if you can point to it later. What you keep depends on the design.
For an anonymous study, retain the consent version, the agreement status, the timestamp and your final survey configuration. There is no participant identifier, and your withdrawal statement has to reflect that.
For an identified or linked study, also retain the identifier or participant code, the consent record linking that code to the agreement, and any re-consent after you change the questions.
Version your consent text. Save a dated copy of the exact wording shown, and record which version each participant saw. Without that, a complaint about what was promised cannot be answered.
Restrict access to the consent records to the named research team, store them in your approved institutional location rather than a personal drive, and use encryption where your platform offers it. Document a retention schedule and the date you plan to delete.
Write down how a withdrawal request would actually be executed, including who receives it and how quickly. For identified data, that is a lookup and a deletion. For anonymous data, it is a refusal you can only honour up to the point of submission, and your form should already say so.
Common Mistakes
These are the errors that cost researchers the most, roughly ordered by how often they turn up.
- Bundled agreement. Asking for research consent and a newsletter opt-in in one item. Fix: separate them completely. Bundling is treated as invalid under GDPR.
- Pre-ticked or default-agreeing checkboxes. Agreement that is not freely given is not agreement. Fix: no default selection, and an explicit Yes or No item.
- Vague contact details. “Contact the research team” tells a worried participant nothing. Fix: a named person with a working email, plus the ethics board contact.
- Promising absolute anonymity while retaining identifiers. Fix: describe what the platform actually stores, including timestamps and any logged IP addresses.
- Collecting identifiers you never use. An email field added out of habit turns an anonymous study into an identified one. Fix: only collect what the analysis needs and the ethics approval covers.
- Treating page views or survey starts as consent. Someone who opened the link did not agree to anything. Fix: record agreement only through the explicit item.
- Not versioning the form. Fix: save dated copies and record which version each respondent saw.
- Collecting consent after data collection. Asking at the end is not informed consent, it is a form. Fix: gate the survey at the start.
- Leaving the refusal path recording a partial response. Fix: branch on No and confirm by testing that no research data is written.
- Publishing identifiable agreement records. A shared spreadsheet of names and consent statuses is a re-identification risk. Fix: store records separately from the data, restrict access, and delete on schedule.
Three practical tips. Readability is the cheapest intervention you have, so rewrite before you complain about response rates. Layered consent, a short bulleted summary with the full text one click away, respects participants who want the detail without punishing the many who do not. And vet your platform’s data practices once a year, not once at launch.
Frequently Asked Questions
Is a consent checkbox alone enough for an online survey?
Usually not on its own. A single I agree checkbox next to a hyperlink is weak because a preselected or pre-ticked box does not prove a person actively agreed, which matters under GDPR. Stronger practice is a required multiple-choice item offering Yes, I agree to take part and No, I do not agree, followed by branching so a No records nothing. Check with your ethics board, since requirements vary.
Can informed consent be collected anonymously in an online survey?
Yes, and it is common. In an anonymous study you record agreement status, the consent version and a timestamp, but no identifier that could link a response to a person. The trade-off is honest withdrawal: once an anonymous response is submitted, it usually cannot be retrieved or deleted, and your consent text should say that plainly rather than implying a right you cannot honour. Confirm requirements with your institution.
When does an online survey study require ethics review?
Review is generally required when a survey collects data from human participants for research purposes, especially once responses are identifiable or the topic is sensitive. Some minimal risk categories may qualify for exemption or expedited review, but the determination is made by your institutional review board or ethics committee, not by the researcher. Ask before collecting anything, since retrospective approval is rarely available and journals commonly require prior review.
How should consent be handled for minors or vulnerable participants?
Minors usually need two things: parental or guardian permission and the childs own agreement or assent, with different wording for each. Vulnerable populations such as patients, employees or students in your own course need extra care about pressure, since a person may feel unable to refuse. Many platforms can ask for age or guardian status first and branch accordingly. Your ethics board will specify the process it accepts.
Do researchers need new consent after changing survey questions?
It depends on what changed. Correcting a typo or fixing a broken item usually does not need fresh consent, but adding new questions, changing what data is collected, extending the time commitment or altering the retention period generally does, because participants agreed to a specific set of conditions. Save dated versions of every form, record which version each person saw, and ask your ethics board before relaunching with substantive changes.
How long should online survey consent records be retained?
There is no single universal period, and the answer depends on your funder, your institution and the law that applies to your participants. Many protocols keep consent records for at least the length of the study plus a defined period afterwards, often several years. Whatever you choose, document the retention schedule, restrict access to the named research team, store records separately from the research data, and delete them on schedule.
Conclusion
Start by confirming whether your study needs ethics review, because that decision constrains everything after it and cannot be undone once responses are in. Then finalise the participant-facing language, add it to the top of the survey as a hard gate, and pilot the refusal path before you share the link. Collecting informed consent in an online survey is mostly a matter of making the agreement explicit, the record retrievable, and the promises in the text true.


