This is general orientation, not legal advice - consult your own counsel for anything you're relying on for compliance. A few practical habits worth adopting regardless of jurisdiction:
Every extra personal-data field you collect is extra risk and extra scope for a data-subject request later. If you don't have a clear use for a piece of information, don't ask for it.
A short line in your survey description ("responses are used to improve our support process and are reviewed by the CX team") sets honest expectations and tends to improve response quality too.
If a survey collects anything sensitive, add a signature or explicit single-choice consent question near the top rather than assuming implied consent from participation.
For any survey collecting sensitive information, mark it Private with an access password rather than relying on an unguessable link alone.
You can export all responses to a survey at any time; deleting a response removes its answers permanently. Build a retention habit - export what you need for the record, then delete responses you no longer have a reason to keep.
See the Security page for what protections are and aren't in place today, including the note that we hold no formal compliance certifications.