Guide · Surveys

Survey anonymity thresholds: what the minimum-n rule protects, and the limits of anonymity

Most employee survey tools promise that results for small groups are hidden. Fewer explain what “small” means, why, and how a hidden number can still be recovered — from the groups around it, or from the options published beside it. This guide is the explanation — including the part that is usually left out.

About a 11-minute read · Not legal advice · Last reviewed

What a threshold is

An anonymity threshold (also minimum n, minimum group size, reporting floor) is the smallest number of respondents a group must have before its results are shown. The name is a term of art — the answers behind it are usually confidential, not anonymous, as the next section explains. If a team of four answers and the floor is five, the team’s numbers are not reported — they roll up into the unit above, or are dropped.

The threshold exists because a group average with very few people in it is close to an individual answer. With one respondent the average is their answer. With two, anyone who knows their own answer can subtract it and read the other person’s. The floor is the point at which that arithmetic stops being useful.

A threshold is a statistical protection. It is not the same as anonymity — which is an effort, never a guarantee — and it is not a legal number.

Anonymous, confidential, and the difference that matters

The words are used interchangeably in marketing and mean different things in practice.

Anonymous versus confidential survey designs
RowAnonymousConfidential
Is the answer linked to a person anywhere?No — not even in the databaseYes, so someone can finish later and nobody answers twice
Can the vendor identify a respondent?Not by designTechnically, yes; policy and access controls prevent it
Can the employer?NoOnly if the vendor lets them — the honest question to ask
Can you send reminders to non-responders?Not without a separate tracking mechanismYes
Can results be tied to a manager or unit?Only if the respondent self-reports itYes, from the roster

Almost every modern employee survey is confidential, not anonymous — the roster-based reporting that makes results useful requires it. The honest claim is therefore “we keep your answers private on purpose, and here is how”, not “nobody can know”. A vendor that promises anonymity outright while emailing you a personal link is describing a policy, not a property — confidential, not anonymous.

Why five, and why not three

Thresholds in the industry cluster between three and five — an observation from vendor documentation, not a measurement. The reasoning behind the two ends:

  • Three is the smallest group where no single respondent can recover another’s answer by subtracting their own — with three, you know your answer and the average, which leaves two unknowns.
  • Five adds margin against two things three does not cover: a group where two people compare notes, and a group with a known outlier (“everyone knows who was unhappy”) where the average moves visibly with one answer.

Five is the more common floor for engagement surveys where results are broken down by manager, because the manager often knows their people well enough to guess. Three is common in team-level peer instruments, where the raters are peers and the subject is one person.

Is there a legal minimum? Not that we have been able to find, in any jurisdiction we have looked at. Data-protection regulators ask whether a person is identifiable by means reasonably likely to be used, which is a question about the whole reporting design, not a count. A threshold helps you answer that question; it does not answer it for you. Nothing here is legal advice.

The subtraction problem

This is the part most reporting gets wrong, and it is the reason a threshold on its own is not enough.

Suppose a division of 30 people publishes a mean of 3.8. It has four teams: A (10), B (9), C (7) and D (4). D is under the floor of five, so it is hidden. But A, B and C are published, and a division mean is just a weighted average of its teams. Anyone with the four numbers and the four headcounts can solve for D:

30 × 3.8 = (10 × A) + (9 × B) + (7 × C) + (4 × D) D is recoverable to two decimal places.

Hiding the small team while publishing everything around it protects nobody. The fix is to withhold one more group — a sibling large enough that D can no longer be isolated — or to withhold the parent’s total. Done properly, this rule has to be applied recursively up the hierarchy, and it has to consider every published slice (by unit, by manager, by tenure band) that shares the same people, because two different breakdowns of the same group are two equations in the same unknowns.

Why hiding one small team is not enoughTwo panels. Left: a division of thirty publishes its mean and three of its four teams; the fourth, with four people, is hidden, but it can be recovered by subtracting the published teams from the division total. Right: the same division also withholds the next-smallest team, so the hidden one can no longer be isolated.What most reports doDivision · n = 30 · mean 3.8Team An = 10publishedTeam Bn = 9publishedTeam Cn = 7publishedTeam Dn = 4withheldD = (30 × 3.8 − 10A − 9B − 7C) ÷ 4. Recoverable.What has to happenDivision · n = 30 · mean 3.8Team An = 10publishedTeam Bn = 9publishedTeam Cn = 7withheldTeam Dn = 4withheldTwo unknowns, one equation. Protected.A threshold protects a group only if the groups around it cannot be subtracted from the total.
Left: what most reports do — the small team is hidden, but the division total and the three visible teams recover it. Right: what has to happen — the next-smallest sibling is withheld as well, so there are two unknowns and one equation.

The same problem, in a distribution

Averages are not the only thing that subtracts. A question answered by picking from a list reports a count per option, and those counts sum to a number the reader already has — how many people answered. That shortens the arithmetic, and it can expose a single respondent with no hierarchy involved at all.

“One of thirty chose this” clears a floor set at any of the usual figures: the group is thirty. It also names one person to anyone who knows who is in the group. So does the far end — an option twenty-nine of thirty picked identifies the one who did not, just as precisely. Both tails have to go.

And withholding the tail on its own achieves nothing, because the rest still adds up:

30 − (12 + 9 + 8) = 1 the withheld option is recovered by anyone who can add.

A second option has to go with it, and which one matters: withholding an option nobody picked moves no residue at all, so the sacrifice has to start at the smallest non-zero count and work up until what is left unaccounted for is either nothing or big enough to hide in. Then the same rule has to run across groups, because a unit’s distribution and its parent’s are two equations in the same people.

One more trap, for a “pick your top three” question: the counts no longer sum to the number of respondents, because each person casts three. Any rule that assumes they do will under-withhold — and the gap between the assumed total and the real one is itself solvable. The honest answer, where the total cannot be established, is to publish none of that group’s distribution rather than a version that looks careful.

Written comments are the weak point

Numbers can be averaged; sentences cannot. A single verbatim comment — even with the name removed — is often identifiable by content (“since the Denver move”), by style, or by the fact that only one person on the team would say it. Thresholds do not protect free text. The defensible options are: do not show comments to anyone at the organization; show only themes that several different people raised, paraphrased; or show comments only at a very large aggregation. Anything else is a promise the design cannot keep.

What to tell employees

Say the true thing, in advance, in plain words. A defensible participant notice covers:

  • Whether answers are linked to you (in a confidential design: yes, so you can finish later and nobody can answer twice).
  • Who can read individual answers (in a good design: no one at your organization, and no signed-in account).
  • The reporting floor and the fact that a second group may also be withheld to protect a small one.
  • What happens to written comments — shown to nobody, or themes only.
  • The honest caveat: privacy is an effort the system makes on purpose and can explain, not something that is impossible by accident.

A notice like this costs a little in response rate against a vaguer promise — and it is the only version that survives the first employee who asks how the tool actually works.

How Facets applies all of this

The rules our own instruments run under are published on the instrument page, and they are these:

The thresholds each Facets instrument applies
InstrumentFloor for anything to be shownFloor for question-level detailWritten commentsSubtraction rule
Team survey (3–12 people)3 raters; a team of 3 gets no individual peer scores at all5 ratersTwo short written items per teammate; never quoted verbatim in any pack — a six-word overlap with a written answer is rejected before releaseNot needed — one team, one report
Leadership 3603 raters, or the leader sees nothing5 ratersNever quoted verbatim; themes onlyNot needed — one subject
Engagement cycle5 respondents by default; raisable to 50, not lowerableInstrument: group numbers only. Your own questions: counts per option, withheld when either the option or the rest of the group is under the floorShown to nobody at the organization; themes that at least three different people raised, in our wordsApplied to means across groups and to counts within a question: a sibling group, or a second option, is withheld so the hidden one cannot be added back

Individual answers in all three have no read path for any signed-in account — not a manager, not an administrator, not the workspace owner. The participant notice says so in those words before anyone starts. Who can see what, role by role · How an engagement cycle reports · Which of the three instruments answers which question.

Frequently asked questions

What is the minimum number of responses for an anonymous survey?
There is no legal number. Groups under three to five respondents are commonly hidden; five is usual when results are broken down by manager. The floor stops an average reading as one person's answer — if the surrounding groups cannot be subtracted from the total.
Are employee engagement surveys really anonymous?
Usually they are confidential rather than anonymous: answers are linked to a person so reminders and roster-based reporting work, and policy plus access controls keep them private. Ask who can read an individual answer, and whether written comments are ever shown.
Why is a group of five hidden when a group of four is shown elsewhere?
Because publishing it would let someone recover a hidden group by subtraction. If a division's total and all but one of its teams are visible, the missing team's number is arithmetic. A second group has to be withheld to close that gap.
Can someone be identified from a percentage?
Yes, and a group-size floor does not stop it. In a group of thirty, an option three percent picked is one person; one ninety-seven percent picked names the one who did not. Both ends go, plus a second option, or the rest adds back.
Does a threshold protect written comments?
No. A single comment can identify its author by content or style even with the name removed. The defensible options are showing comments to nobody at the organization, or reporting only themes several different people raised, paraphrased.
What does Facets use as its threshold?
Team survey: 3 raters for anything, 5 for question-level detail. Leadership 360: 3, and comments are never quoted. Engagement cycle: 5 by default, raisable, with sibling groups withheld when they would reveal a hidden one.

Sources and notes

Threshold conventions are described from vendor documentation reviewed in 2026 and are an observation, not a measurement. The regulatory framing (“identifiable by means reasonably likely to be used”) paraphrases the GDPR’s Recital 26; consult counsel for any specific obligation. The Facets rules are read from the published instrument specification.

See how an engagement cycle reports.

Group numbers with error bars for every unit and manager, a floor of 5 you can raise, and the sibling rule applied so a hidden group stays hidden.

All guides