As WMF's research efforts expand (great!), we're seeing more and more surveys. Some of those are being linked from MediaWiki itself, see for instance Qualtrics at T1005 and previously SurveyMonkey for MediaViewer.
It can't be given for granted that sending users to third party websites from our interface is allowed by the privacy policy. It would be nice to determine what service are fine to link and document the outcome, for instance at the master list of software used by WMF, https://meta.wikimedia.org/wiki/FLOSS-Exchange
Note that this matter is distinct from the questions 1) whether it's appropriate to use unfree software, 2) what software is statistically suitable, and 3) how multilingual they are/how good their i18n and integration with the Translate extension. The discussion about that was at http://thread.gmane.org/gmane.org.wikimedia.analytics/345/
Services used by WMF
- https://wikimedia.qualtrics.com/ has been vetted by WMF-Legal and it has gone through the Contracts team.
- http://www.allourideas.org/ has been vetted by WMF-Legal.
(Both are not usable by an EU entity due to lack of privacy policy and due to transfer of private data to USA soil.)
Not recommended but allowed
- Google Docs is sometimes used for events feedback etc. and by the community because it's very easy to set up, sometimes widely advertised e.g. id.wikipedia sitenotice. Google's privacy policy is not consistent with Wikimedia's since they collect much more information from users. That being said, if we clearly indicate to users that the survey they are taking will be on Google and thus subject to the Google privacy policy (preferably before they click on the link to the survey), you can use it to administer the services.
Not evaluated by the Wikimedia Foundation yet
- LimeService seems rather good but should be verified. https://www.limeservice.com/en/pricing/21-english/general-content/39-data-protection-statement They don't need Safe Harbor because they already are in EU (with Canada option).
- SurveyMonkey has some privacy policy, as well as certifications and EU branches for EU users plus special articles for Canada, Japan, Australia and Brasil users. https://surveymonkey.com/mp/policy/privacy-policy/ (Didn't read yet. They also use Google Analytics and other third party stuff, while I don't remember whether/when Qualtrics does.)
- https://opendatakit.org/ - self-hosted and cloud services available, including free for limited purposes (see http://www.kobotoolbox.org/#getstarted). An OSM integrated edition exists, by HOTOSM. Has Android app for offline collection. French Host of ODK derived solution: http://makina-corpus.com/realisations/application-mobile-makina-collect-nouvelle-version . More info about other ODK derivatives: http://carnet-terrain-electronique.fr/open-data-kit-odk/
- https://www.typeform.com/ - EU-based, has an EU-style privacy policy with an explicit section «(ii) Information we collect about the Respondent from other sources» and some information on What happens to my data; has a form to ask for data changes/removals (not found online as of 2017-03); asks for blanket permission to transfer data in USA