Skip to content
FormSubmit
Privacy & Compliance

GDPR Contact Form Guide: Consent, Retention and Privacy

Build a GDPR contact form the practical way: pick a lawful basis, collect less data, word your privacy notice, set retention, and check your processor's DPA.

FormSubmit Team

6 min read

Website contact form with a privacy notice and consent checkbox illustrating GDPR contact form practices

A GDPR contact form collects only what you need to answer the inquiry, tells people clearly how their data is used, keeps it no longer than necessary, and runs on processors you have a data processing agreement with. You usually do not need a consent checkbox just to reply, but you do need separate, opt-in consent for marketing.

Contact forms are one of the most common ways a small site handles personal data, and one of the easiest to get roughly right. This guide walks through the decisions in order, with example wording and a checklist you can work through in an afternoon.

Start with the purpose and lawful basis

GDPR requires a lawful basis for processing personal data. For a contact form, the purpose is usually narrow: someone asks a question and you want to answer it. Two bases are commonly relied on here:

  • Legitimate interests: you have a reasonable interest in responding to people who contact you, and they expect a reply.
  • Steps prior to a contract: when someone requests a quote or asks about buying your service.

Consent is a third option, but it is the hardest to manage, because it must be freely given, specific and withdrawable. That is why many privacy professionals advise against using consent as the basis for simply replying to a message. Write down the basis you chose and why. That record is useful if a customer or regulator ever asks.

The common mistake is a single mandatory checkbox that says "I agree to the privacy policy." That checkbox usually does not help: agreeing to a policy is not meaningful consent, and making it mandatory means it is not freely given.

ScenarioConsent checkbox needed?Notes
Replying to a questionUsually noShow a short privacy notice instead
Sending a quote someone requestedUsually noPre-contractual steps
Adding the person to a newsletterYesSeparate, optional, unticked
Sharing details with a partner companyOften yesName the partner and purpose
Collecting health or other special-category dataNeeds extra careGet specific advice first

If you do want marketing consent, make it a separate optional checkbox:

html
<label>
  <input type="checkbox" name="newsletter_opt_in" value="yes">
  Send me occasional product updates by email. I can unsubscribe any time.
</label>

It must be unticked by default, and the form must work whether or not it is checked. Store the value with the submission, so you have a record of what the person agreed to and when.

Data minimization: fewer fields, less risk

Every field you add is data you must protect, disclose and eventually delete. For most inquiries, this is enough:

  • Name
  • Email address
  • Message

Ask yourself before adding a phone number, company, address or date of birth: will we actually use this to answer the inquiry? If not, leave it out. Shorter forms also tend to convert better, which our contact form best practices post covers in more detail.

Avoid free-text prompts that invite sensitive data, such as "Tell us about your medical history." If you genuinely need special-category data, that is a separate, more involved compliance project.

Write a short privacy notice at the point of collection

People should know, at the moment they submit, who receives their data and why. A short notice under the submit button, linking to your full privacy policy, works well:

We use your name, email and message only to reply to your inquiry. Submissions are processed by our form provider and kept for 12 months, then deleted. See our privacy policy for details and your rights.

Make sure the full policy covers the identity of the controller (you), the purpose and lawful basis, the processors involved (form backend, email provider, any integrations such as spreadsheets or CRMs), any international transfers, the retention period, and how to exercise rights such as access and deletion.

Set a data retention period

Data retention is where many contact forms quietly fail. Submissions pile up in inboxes, spreadsheets and dashboards for years with no reason to keep them.

Pick a period that matches the purpose. For general inquiries, many businesses choose somewhere between 90 days and a year. Then make deletion automatic rather than relying on someone remembering. In FormSubmit, for example, each form has a retention setting: Forever, 1 year, 90 days, 30 days, 7 days, or Don't store, which forwards submissions by email and integrations without saving them. Old submissions and their files are purged daily.

Remember that copies live elsewhere too. Email notifications, Google Sheets rows and CRM records each need their own cleanup plan.

Processors and the DPA

If a third-party service receives or stores submissions for you, it is generally acting as your processor. GDPR expects a written data processing agreement (DPA) with each processor, covering what they do with the data, security measures and sub-processors.

Before choosing a form backend, check:

  • Does it publish a DPA you can accept? (FormSubmit's is at /legal/dpa.)
  • How is data secured? Look for encrypted secrets, private file storage and minimized logging. For example, FormSubmit hashes submitter IP addresses rather than storing them in plain text, and serves uploaded files only through time-limited signed links. Details are in the security and privacy docs.
  • Can you export and delete data yourself?

Do not assume a provider holds a particular certification unless it states so on its own site.

Handling access and deletion requests

People can ask what data you hold about them, ask you to correct it, or ask you to delete it. For a contact form, that usually means searching your submissions by email address, exporting what you find, and deleting it from every place it was copied.

  1. Confirm the request comes from the person concerned, for example by replying to the email address on file.
  2. Search your form dashboard, inbox and any connected tools for their email.
  3. Export the records (CSV or JSON) if they asked for a copy.
  4. Delete the submission and any uploaded files, plus copies in spreadsheets or CRMs.
  5. Reply to confirm, and note the date you completed the request.

Captcha and contact form privacy

Spam protection has its own privacy trade-offs. Captcha services typically process the visitor's IP address and browser signals, and some may set cookies. If you use one, name it in your privacy notice and check whether your cookie banner needs to account for it.

A lighter approach is to start with invisible, server-side checks such as a honeypot field, a timing check and content heuristics, and add a captcha only if spam persists. Our honeypot vs captcha comparison explains the trade-offs, and spam protection lists what runs automatically.

GDPR contact form checklist

  • Purpose and lawful basis written down
  • Only necessary fields collected
  • No mandatory "I agree" checkbox for simple inquiries
  • Separate, unticked opt-in for marketing, stored with the submission
  • Short privacy notice next to the submit button, linking to the full policy
  • Privacy policy lists every processor and integration
  • DPA in place with your form backend and email provider
  • Retention period set and deletion automated
  • Process for access and deletion requests
  • Captcha provider disclosed, or honeypot-first spam protection

Next steps

A privacy-friendly contact form is mostly about restraint: fewer fields, clear wording and automatic deletion. If you want a form backend with per-form retention, a published DPA and spam protection that does not rely on tracking, FormSubmit is free to start. Build your form with the form generator and review plans on the pricing page.

Last updated .

Frequently asked questions

Does a contact form need a GDPR consent checkbox?

Usually not for simply replying to an inquiry, where legitimate interests or pre-contractual steps are commonly relied on. You typically need separate, unticked consent if you also want to send marketing emails.

How long should I keep contact form submissions?

Only as long as you need them for the purpose you collected them. Many small businesses choose a fixed period, such as 90 days or a year, and delete older entries automatically.

Do I need a DPA with my form backend?

If a service stores or processes submissions on your behalf, it is generally acting as a processor, and GDPR expects a data processing agreement with it. Check the provider's DPA before you go live.

Is reCAPTCHA a GDPR concern?

Captcha services may process visitor data such as IP addresses and browser signals. Mention the provider in your privacy notice and consider lighter options like a honeypot first.

Related resources

Keep reading

Your form backend is 60 seconds away

Sign up with Google or email, create a form, paste the endpoint. Free forever for small sites — no credit card.