Guide · Surveys
Survey anonymity thresholds: what the minimum-n rule protects, and the limits of anonymity
Most employee survey tools promise that results for small groups are hidden. Fewer explain what “small” means, why, and how a hidden number can still be recovered — from the groups around it, or from the options published beside it. This guide is the explanation — including the part that is usually left out.
About a 11-minute read · Not legal advice · Last reviewed
What a threshold is
An anonymity threshold (also minimum n, minimum group size, reporting floor) is the smallest number of respondents a group must have before its results are shown. The name is a term of art — the answers behind it are usually confidential, not anonymous, as the next section explains. If a team of four answers and the floor is five, the team’s numbers are not reported — they roll up into the unit above, or are dropped.
The threshold exists because a group average with very few people in it is close to an individual answer. With one respondent the average is their answer. With two, anyone who knows their own answer can subtract it and read the other person’s. The floor is the point at which that arithmetic stops being useful.
A threshold is a statistical protection. It is not the same as anonymity — which is an effort, never a guarantee — and it is not a legal number.
Anonymous, confidential, and the difference that matters
The words are used interchangeably in marketing and mean different things in practice.
| Row | Anonymous | Confidential |
|---|---|---|
| Is the answer linked to a person anywhere? | No — not even in the database | Yes, so someone can finish later and nobody answers twice |
| Can the vendor identify a respondent? | Not by design | Technically, yes; policy and access controls prevent it |
| Can the employer? | No | Only if the vendor lets them — the honest question to ask |
| Can you send reminders to non-responders? | Not without a separate tracking mechanism | Yes |
| Can results be tied to a manager or unit? | Only if the respondent self-reports it | Yes, from the roster |
Almost every modern employee survey is confidential, not anonymous — the roster-based reporting that makes results useful requires it. The honest claim is therefore “we keep your answers private on purpose, and here is how”, not “nobody can know”. A vendor that promises anonymity outright while emailing you a personal link is describing a policy, not a property — confidential, not anonymous.
Why five, and why not three
Thresholds in the industry cluster between three and five — an observation from vendor documentation, not a measurement. The reasoning behind the two ends:
- Three is the smallest group where no single respondent can recover another’s answer by subtracting their own — with three, you know your answer and the average, which leaves two unknowns.
- Five adds margin against two things three does not cover: a group where two people compare notes, and a group with a known outlier (“everyone knows who was unhappy”) where the average moves visibly with one answer.
Five is the more common floor for engagement surveys where results are broken down by manager, because the manager often knows their people well enough to guess. Three is common in team-level peer instruments, where the raters are peers and the subject is one person.
Is there a legal minimum? Not that we have been able to find, in any jurisdiction we have looked at. Data-protection regulators ask whether a person is identifiable by means reasonably likely to be used, which is a question about the whole reporting design, not a count. A threshold helps you answer that question; it does not answer it for you. Nothing here is legal advice.
The subtraction problem
This is the part most reporting gets wrong, and it is the reason a threshold on its own is not enough.
Suppose a division of 30 people publishes a mean of 3.8. It has four teams: A (10), B (9), C (7) and D (4). D is under the floor of five, so it is hidden. But A, B and C are published, and a division mean is just a weighted average of its teams. Anyone with the four numbers and the four headcounts can solve for D:
30 × 3.8 = (10 × A) + (9 × B) + (7 × C) + (4 × D) → D is recoverable to two decimal places.
Hiding the small team while publishing everything around it protects nobody. The fix is to withhold one more group — a sibling large enough that D can no longer be isolated — or to withhold the parent’s total. Done properly, this rule has to be applied recursively up the hierarchy, and it has to consider every published slice (by unit, by manager, by tenure band) that shares the same people, because two different breakdowns of the same group are two equations in the same unknowns.
The same problem, in a distribution
Averages are not the only thing that subtracts. A question answered by picking from a list reports a count per option, and those counts sum to a number the reader already has — how many people answered. That shortens the arithmetic, and it can expose a single respondent with no hierarchy involved at all.
“One of thirty chose this” clears a floor set at any of the usual figures: the group is thirty. It also names one person to anyone who knows who is in the group. So does the far end — an option twenty-nine of thirty picked identifies the one who did not, just as precisely. Both tails have to go.
And withholding the tail on its own achieves nothing, because the rest still adds up:
30 − (12 + 9 + 8) = 1 → the withheld option is recovered by anyone who can add.
A second option has to go with it, and which one matters: withholding an option nobody picked moves no residue at all, so the sacrifice has to start at the smallest non-zero count and work up until what is left unaccounted for is either nothing or big enough to hide in. Then the same rule has to run across groups, because a unit’s distribution and its parent’s are two equations in the same people.
One more trap, for a “pick your top three” question: the counts no longer sum to the number of respondents, because each person casts three. Any rule that assumes they do will under-withhold — and the gap between the assumed total and the real one is itself solvable. The honest answer, where the total cannot be established, is to publish none of that group’s distribution rather than a version that looks careful.
Written comments are the weak point
Numbers can be averaged; sentences cannot. A single verbatim comment — even with the name removed — is often identifiable by content (“since the Denver move”), by style, or by the fact that only one person on the team would say it. Thresholds do not protect free text. The defensible options are: do not show comments to anyone at the organization; show only themes that several different people raised, paraphrased; or show comments only at a very large aggregation. Anything else is a promise the design cannot keep.
What to tell employees
Say the true thing, in advance, in plain words. A defensible participant notice covers:
- Whether answers are linked to you (in a confidential design: yes, so you can finish later and nobody can answer twice).
- Who can read individual answers (in a good design: no one at your organization, and no signed-in account).
- The reporting floor and the fact that a second group may also be withheld to protect a small one.
- What happens to written comments — shown to nobody, or themes only.
- The honest caveat: privacy is an effort the system makes on purpose and can explain, not something that is impossible by accident.
A notice like this costs a little in response rate against a vaguer promise — and it is the only version that survives the first employee who asks how the tool actually works.
How Facets applies all of this
The rules our own instruments run under are published on the instrument page, and they are these:
| Instrument | Floor for anything to be shown | Floor for question-level detail | Written comments | Subtraction rule |
|---|---|---|---|---|
| Team survey (3–12 people) | 3 raters; a team of 3 gets no individual peer scores at all | 5 raters | Two short written items per teammate; never quoted verbatim in any pack — a six-word overlap with a written answer is rejected before release | Not needed — one team, one report |
| Leadership 360 | 3 raters, or the leader sees nothing | 5 raters | Never quoted verbatim; themes only | Not needed — one subject |
| Engagement cycle | 5 respondents by default; raisable to 50, not lowerable | Instrument: group numbers only. Your own questions: counts per option, withheld when either the option or the rest of the group is under the floor | Shown to nobody at the organization; themes that at least three different people raised, in our words | Applied to means across groups and to counts within a question: a sibling group, or a second option, is withheld so the hidden one cannot be added back |
Individual answers in all three have no read path for any signed-in account — not a manager, not an administrator, not the workspace owner. The participant notice says so in those words before anyone starts. Who can see what, role by role · How an engagement cycle reports · Which of the three instruments answers which question.
Frequently asked questions
What is the minimum number of responses for an anonymous survey?
Are employee engagement surveys really anonymous?
Why is a group of five hidden when a group of four is shown elsewhere?
Can someone be identified from a percentage?
Does a threshold protect written comments?
What does Facets use as its threshold?
Sources and notes
Threshold conventions are described from vendor documentation reviewed in 2026 and are an observation, not a measurement. The regulatory framing (“identifiable by means reasonably likely to be used”) paraphrases the GDPR’s Recital 26; consult counsel for any specific obligation. The Facets rules are read from the published instrument specification.
See how an engagement cycle reports.
Group numbers with error bars for every unit and manager, a floor of 5 you can raise, and the sibling rule applied so a hidden group stays hidden.