GDPR Contact Form Guide: Consent, Retention and Privacy
Build a GDPR contact form the practical way: pick a lawful basis, collect less data, word your privacy notice, set retention, and check your processor's DPA.
6 min read

A GDPR contact form collects only what you need to answer the inquiry, tells people clearly how their data is used, keeps it no longer than necessary, and runs on processors you have a data processing agreement with. You usually do not need a consent checkbox just to reply, but you do need separate, opt-in consent for marketing.
Contact forms are one of the most common ways a small site handles personal data, and one of the easiest to get roughly right. This guide walks through the decisions in order, with example wording and a checklist you can work through in an afternoon.
Start with the purpose and lawful basis
GDPR requires a lawful basis for processing personal data. For a contact form, the purpose is usually narrow: someone asks a question and you want to answer it. Two bases are commonly relied on here:
- Legitimate interests: you have a reasonable interest in responding to people who contact you, and they expect a reply.
- Steps prior to a contract: when someone requests a quote or asks about buying your service.
Consent is a third option, but it is the hardest to manage, because it must be freely given, specific and withdrawable. That is why many privacy professionals advise against using consent as the basis for simply replying to a message. Write down the basis you chose and why. That record is useful if a customer or regulator ever asks.
When you need GDPR form consent (and when you do not)
The common mistake is a single mandatory checkbox that says "I agree to the privacy policy." That checkbox usually does not help: agreeing to a policy is not meaningful consent, and making it mandatory means it is not freely given.
| Scenario | Consent checkbox needed? | Notes |
|---|---|---|
| Replying to a question | Usually no | Show a short privacy notice instead |
| Sending a quote someone requested | Usually no | Pre-contractual steps |
| Adding the person to a newsletter | Yes | Separate, optional, unticked |
| Sharing details with a partner company | Often yes | Name the partner and purpose |
| Collecting health or other special-category data | Needs extra care | Get specific advice first |
If you do want marketing consent, make it a separate optional checkbox:
<label>
<input type="checkbox" name="newsletter_opt_in" value="yes">
Send me occasional product updates by email. I can unsubscribe any time.
</label>It must be unticked by default, and the form must work whether or not it is checked. Store the value with the submission, so you have a record of what the person agreed to and when.
Data minimization: fewer fields, less risk
Every field you add is data you must protect, disclose and eventually delete. For most inquiries, this is enough:
- Name
- Email address
- Message
Ask yourself before adding a phone number, company, address or date of birth: will we actually use this to answer the inquiry? If not, leave it out. Shorter forms also tend to convert better, which our contact form best practices post covers in more detail.
Avoid free-text prompts that invite sensitive data, such as "Tell us about your medical history." If you genuinely need special-category data, that is a separate, more involved compliance project.
Write a short privacy notice at the point of collection
People should know, at the moment they submit, who receives their data and why. A short notice under the submit button, linking to your full privacy policy, works well:
We use your name, email and message only to reply to your inquiry. Submissions are processed by our form provider and kept for 12 months, then deleted. See our privacy policy for details and your rights.
Make sure the full policy covers the identity of the controller (you), the purpose and lawful basis, the processors involved (form backend, email provider, any integrations such as spreadsheets or CRMs), any international transfers, the retention period, and how to exercise rights such as access and deletion.
Set a data retention period
Data retention is where many contact forms quietly fail. Submissions pile up in inboxes, spreadsheets and dashboards for years with no reason to keep them.
Pick a period that matches the purpose. For general inquiries, many businesses choose somewhere between 90 days and a year. Then make deletion automatic rather than relying on someone remembering. In FormSubmit, for example, each form has a retention setting: Forever, 1 year, 90 days, 30 days, 7 days, or Don't store, which forwards submissions by email and integrations without saving them. Old submissions and their files are purged daily.
Remember that copies live elsewhere too. Email notifications, Google Sheets rows and CRM records each need their own cleanup plan.
Processors and the DPA
If a third-party service receives or stores submissions for you, it is generally acting as your processor. GDPR expects a written data processing agreement (DPA) with each processor, covering what they do with the data, security measures and sub-processors.
Before choosing a form backend, check:
- Does it publish a DPA you can accept? (FormSubmit's is at /legal/dpa.)
- How is data secured? Look for encrypted secrets, private file storage and minimized logging. For example, FormSubmit hashes submitter IP addresses rather than storing them in plain text, and serves uploaded files only through time-limited signed links. Details are in the security and privacy docs.
- Can you export and delete data yourself?
Do not assume a provider holds a particular certification unless it states so on its own site.
Handling access and deletion requests
People can ask what data you hold about them, ask you to correct it, or ask you to delete it. For a contact form, that usually means searching your submissions by email address, exporting what you find, and deleting it from every place it was copied.
- Confirm the request comes from the person concerned, for example by replying to the email address on file.
- Search your form dashboard, inbox and any connected tools for their email.
- Export the records (CSV or JSON) if they asked for a copy.
- Delete the submission and any uploaded files, plus copies in spreadsheets or CRMs.
- Reply to confirm, and note the date you completed the request.
Captcha and contact form privacy
Spam protection has its own privacy trade-offs. Captcha services typically process the visitor's IP address and browser signals, and some may set cookies. If you use one, name it in your privacy notice and check whether your cookie banner needs to account for it.
A lighter approach is to start with invisible, server-side checks such as a honeypot field, a timing check and content heuristics, and add a captcha only if spam persists. Our honeypot vs captcha comparison explains the trade-offs, and spam protection lists what runs automatically.
GDPR contact form checklist
- Purpose and lawful basis written down
- Only necessary fields collected
- No mandatory "I agree" checkbox for simple inquiries
- Separate, unticked opt-in for marketing, stored with the submission
- Short privacy notice next to the submit button, linking to the full policy
- Privacy policy lists every processor and integration
- DPA in place with your form backend and email provider
- Retention period set and deletion automated
- Process for access and deletion requests
- Captcha provider disclosed, or honeypot-first spam protection
Next steps
A privacy-friendly contact form is mostly about restraint: fewer fields, clear wording and automatic deletion. If you want a form backend with per-form retention, a published DPA and spam protection that does not rely on tracking, FormSubmit is free to start. Build your form with the form generator and review plans on the pricing page.
Last updated .


