The useful question is not what the survey is called. It is who, if anyone, can connect an answer to a person.
Identifiable information can exist while access to it is restricted.
The reporting design is intended to prevent the recipient from identifying the respondent.
A wider set of questions: what information exists, who possesses it, whether datasets can be joined, what is disclosed, and whether small groups can expose a person even after obvious identifiers are removed.
Many survey systems can be configured to restrict access to respondent-level information. That is a legitimate confidentiality model. It is different from designing the information flow so that the organization never receives the individual response in the first place.
How SafePorter keeps identity and answer apart → Why small groups still need protection →