Back to Blog
forms

GDPR-Compliant Forms: What You Actually Have to Do

A practical guide to GDPR for web forms — lawful basis, consent wording, retention, and the four changes that matter most. Written for people who build forms, not lawyers.

Instaform Team
August 9, 20265 min read

Most GDPR advice aimed at form builders is either a legal disclaimer or a checklist that tells you to "obtain consent" without saying what that means in a form field. This is the practical version: what changes on the form itself, and what changes behind it.

None of this is legal advice. If you process health data, children's data, or operate at scale, talk to someone qualified. For an ordinary contact or lead form, the following covers most of it.

The most common mistake is assuming every form needs a consent checkbox. GDPR gives six lawful bases, and consent is only one — often the weakest, because it can be withdrawn at any time.

If someone fills in a contact form asking you to quote for work, you are processing their data to take steps at their request before entering a contract. That is a different lawful basis, and it does not need a tick box. Adding one implies the processing depends on consent they can later withdraw, which is not what you want for a record of an enquiry.

Where you do need explicit consent is anything beyond the immediate purpose — adding them to a newsletter, sharing with a partner, using their data for profiling. That consent must be separate, specific and unticked by default.

Practically: one checkbox, only for marketing, never pre-ticked, and worded as an action rather than a permission. "Email me occasionally about new features" beats "I consent to the processing of my personal data for marketing purposes."

Say what happens next, on the form

The transparency requirement is usually satisfied by a single line near the submit button saying who you are, what you will do with the data, and where the full policy lives. Not a modal, not a wall of text — one sentence.

The test is whether someone could answer "what is this company going to do with my email address?" without leaving the page. If the honest answer involves a third party they would not expect, that belongs in the sentence rather than in paragraph nine of your privacy policy.

Collect less

The strongest compliance position is not collecting the data in the first place. Every field you remove is one you do not have to justify, secure, retain or delete.

This aligns neatly with conversion: shorter forms convert better and carry less obligation. If you cannot name what a field is for, it should not be there. Phone numbers "in case we need to call" and company size "for our records" are the two that most often fail this test.

Our contact form template ships with three fields for exactly this reason.

Retention is where most people are non-compliant

Data must not be kept longer than necessary for the purpose. Almost every business gets the form right and then keeps every submission forever in a spreadsheet or an inbox.

Decide a period per form type. Enquiries that went nowhere might be twelve months; customer records follow your accounting obligations; job applications are commonly six to twelve months unless the candidate agrees to longer. Write it down, then actually delete.

This is considerably easier when submissions live in a system with structured records rather than scattered across email. In Instaform each submission becomes a Contact you can filter by date and remove in bulk — which is the difference between a retention policy you can execute and one that exists only in a document.

The four things worth fixing first

If you do nothing else:

  1. Separate marketing consent from the form's primary purpose, unticked.
  2. Put one transparency sentence near the submit button.
  3. Delete fields you cannot justify.
  4. Set a retention period per form and enforce it.

Those four cover the majority of what a small business gets asked about, and each one also makes the form better independently of compliance.

Form pages frequently load analytics that set cookies before consent. That is a separate obligation from the form itself and a common source of complaints, because it happens on page load rather than on submit.

If you embed forms across several sites, check what loads alongside them. A compliant form on a page with a non-compliant tracker is still a problem — and it is usually the tracker, not the form, that draws attention.

The record you will be glad to have

If someone asks what data you hold on them, you need to answer within a month. The practical difficulty is rarely refusal; it is that the data is in four places and nobody is sure which.

Keeping submissions as structured records, tied to a person, with a timestamp and a source, turns that request into a search rather than an archaeology project. That is worth doing before someone asks — and it is the same structure that makes form analytics and follow-up work at all.

Ready to try Instaform?

Join the waitlist and be the first to build forms that actually work for your business.

Related Posts