Confidentiality and data protection
This section sets out how data collected through this survey will be used and respondents’ rights under Articles 13 and/or 14 of the UK General Data Protection Regulation (GDPR). Further information can be found at Medicines and Healthcare products Regulatory Agency privacy notice - GOV.UK.
Data controller
The Medicines and Healthcare products Regulatory Agency (MHRA) is the data controller.
What personal data we collect
You can respond to this survey online.
We will collect data on:
• whether you are responding on behalf of a department and/or organisation
• what department and/or organisation you are responding on behalf of (if any)
• the name of your department and/or organisation
• the country and region your department and/or organisation provides services in the UK (if any)
With your consent, we will also collect data on:
• your email address; and
• any other personal data you volunteer by way of evidence or example in your response to open-ended questions in the survey; therefore, to remain anonymous, please refrain from disclosing any personally identifiable information in these questions.
How we use your data (purposes)
Your data will be treated in the strictest of confidence. We collect your personal data as part of the survey process:
• for statistical purposes, for example, to understand how representative the results are and whether views and experiences vary across demographics
• so that MHRA can contact you for further information about your response (if you have given your consent).
Legal basis for processing personal data
The legal basis for processing your personal data is to perform a task carried out in the public interest, or in the exercise of official authority vested in the controller.
Data processors and other recipients of personal data
All responses to the survey will be seen by:
• Professionals within MHRA who are working on this survey and policy area
• MHRA’s third-party supplier (SocialOptic), who is responsible for running and hosting the online survey
No personally identifiable data will be shared
MHRA may also share your responses, when anonymised, with Department of Health and Social Care, Government Legal Department, Office for Life Sciences, and any other government body identified to be part of this survey.
International data transfers and storage locations
Storage of data by the MHRA is provided via secure computing infrastructure on servers located in the UK. Our platforms are subject to extensive security protections and encryption measures. Storage of data by SurveyOptic is provided via secure servers located in the United Kingdom (UK).
Retention and disposal policy
Personal data will be held by the MHRA for 3 years and disposed of sooner if possible. SurveyOptic will securely erase the data held on their system 5 years after the online survey closes, or when instructed to do so by MHRA if the data has served its intended purpose (whichever happens earlier). Data retention will be reviewed on an annual basis. Anonymised data may be kept indefinitely.
How we keep your data secure
The MHRA uses appropriate technical, organisational and administrative security measures to protect any information we hold in our records from loss, misuse, unauthorised access, disclosure, alteration and destruction. We have written procedures and policies which are regularly audited and reviewed at a senior level. SurveyOptic is Cyber Essentials certified.
You can find further information on MHRA Privacy Notice here.
© Crown copyright 2026
Produced by the Medicines and Healthcare products Regulatory Agency www.gov.uk/mhra. This publication is licensed under the terms of the Open Government Licence. To view this licence, visit http://www.nationalarchives.gov.uk/doc/open-government-licence or email: psi@nationalarchives.gov.uk.
The names, images and logos identifying the Medicines and Healthcare products Regulatory Agency are proprietary marks. All the Agency’s logos are registered trademarks and cannot be used without the Agency’s explicit permission.