GDPR and forms

GDPR compliant forms, and what the regulation actually asks of yours.

Your contact form asks for a name and an email address. That makes it a collection of personal data, and a short list of obligations attaches the moment somebody presses submit. None of them are difficult. All of them are easier to build in than to retrofit.

Collect fewer fields, not more One record to find, one record to delete Protected in transit and at rest

Integrates with the tools you already use.

Salesforce
HubSpot
Pipedrive
Gmail
Twilio
Google Ads
Gravity Forms
Jotform
Webflow
Wix
Calendly
Typeform
Start here

What counts as personal data on a form

Personal data is anything that identifies a living person, directly or in combination with something else you hold. On a form that set is wider than it looks.

A name qualifies. So does an email address, a phone number, a job title next to a company name, and free text where somebody describes their own situation. A message box is personal data by default, because you have no control over what goes into it.

Once a form collects personal data, five things attach to it. They arrive in this order, which is not the order the regulation numbers them.

A lawful basis

You need a reason to hold it that the regulation recognises. For an enquiry form the usual candidates are consent and legitimate interests. Which one applies is a decision you make and record, and it changes what you can do with the data afterwards.

Notice at the point of collection

The person filling in the form is told who is collecting, why, and where to read the detail. A line under the submit button with a link to your privacy notice does this work.

Data minimisation

Collect what you need for the stated purpose and no more. This is the obligation that slips by accident, because form fields get added and never removed.

Security appropriate to the risk

The submission is protected on the way in and once it is stored, and only the people who need it can open it.

The individual rights

Somebody can ask what you hold about them, ask for a copy, and ask you to delete it. You have to be able to do all three within a month, which means you have to be able to find them first.

The last one is where setups fall over, and the cause is never the form. It is that the submission was copied into four places and nobody kept a list.

Feature to requirement

Which Lead Source features serve which requirement

Compliance is a property of how you operate, not of a form tool. What a form tool can do is make each obligation cheap instead of expensive. These are the parts that map directly.

Minimisation

Switch a field off and its value is dropped on the way in, before anything writes it down. Password values are dropped on every form regardless. Turning a field off is the fastest way to stop holding something you never read.

Security

Submissions are protected from the moment they are sent, in transit and at rest, with access controlled at the database rather than in application code.

Nothing in the visitor’s browser

Lead Source uses no cookies and no client-side storage, so the tracking layer sits outside cookie-consent scope. Your other tags are a separate question. Analytics and advertising pixels do set client-side identifiers, so they stay in your consent flow exactly as before.

Access and deletion

One submission is one record. Search it, export it, delete it. The source and journey sit on the same record, so a deletion request takes the whole thing rather than leaving an orphan behind in a reporting table.

The processor side

When a form tool holds personal data for you, you are the controller and it is the processor, and the regulation wants the arrangement written down. Ours is published. The data processing terms set out the roles, the sub-processors, the security measures, how data subject requests are handled, and what happens on deletion.

Notice

That one is yours. The link under your submit button has to point at a privacy notice you wrote, and no tool can write it for you.

The stored copy is covered in more detail on encrypted forms, and the wider set of stages is on secure forms.

Still choosing a form tool?

The obligations above are cheaper to build in than to retrofit. Starting from a blank page? Free form templates cover most industries.

See lead capture forms →
Fewer fields, not more

Attribution that shortens the form instead of lengthening it

There is a field on a great many enquiry forms that reads “how did you hear about us?”. It exists because somebody in marketing needed an answer and the form was the only place to ask.

It is a field you are collecting, storing, exporting and deleting on request, in exchange for an answer you cannot rely on. People are reliable about referrals. They are unreliable about channels, and somebody who clicked an ad will tell you in good faith that they found you on Google.

You can delete that field. The source is collected from the page rather than from the person, so nothing has to be asked for and nothing extra has to be typed.

That is minimisation doing something useful for once. One fewer field on the form, one fewer thing on the record, and better information than the field was producing.

It also keeps the deletion story simple. The campaign, the referrer and the pages somebody read sit on the same lead record as the submission. Removing that person removes all of it in one action. There is no separate analytics profile to hunt down afterwards and no reporting table quietly holding a copy.

Concretely. Somebody clicks a Google Ads listing for a managed services firm, lands on /managed-it, reads /pricing, and fills in the form on /contact. You know all of that without a single extra question on the form. If they later ask to be removed, one record goes and the whole trail goes with it.

The mechanics of how the source gets captured are on form tracking, and you can check what your own form records right now.

Who asks for this

Who this lands on hardest

Managed service providers

You hold personal data for your own prospects and you process it for your clients as well. Two hats, two sets of obligations, and the enquiry form is the one place both apply at once. An MSP enquiry form asks more questions than most, which makes minimisation the quickest win available.

Law firms

The contact form collects a description of somebody’s matter before there is a retainer. A description of an injury or a health problem is special category data, and it arrives before any file has been opened.

Insurance agencies

An insurance quote form collects date of birth, licence number and prior claims. Every one of those is a field somebody can ask you to produce and then delete, so every one of them needs to be findable.

The pattern across all three is the same. The obligation is easy while the data lives in one place, and it gets expensive the moment it does not.

If you are building the form rather than fixing one, lead capture software is the place to start. Secure lead capture covers the run from submission to CRM record.

Common questions

GDPR and forms, answered.

What makes a form GDPR compliant?

A form meets the regulation on five counts. It has a recorded lawful basis for collecting. It tells people at the point of collection who is collecting and why. It asks only for what the stated purpose needs. It protects the submission in transit and at rest. And it lets you find, produce and delete an individual record on request. That is the whole list for an ordinary enquiry form.

Do I need a consent checkbox on my contact form?

Only if consent is the lawful basis you are relying on. Somebody who has filled in an enquiry form is asking to be contacted back, and legitimate interests covers that. A tick box there adds friction without adding protection. Consent is the right basis when you intend to send marketing afterwards. Then the box has to be unticked by default and separate from the submit action.

What counts as personal data on a form?

Anything that identifies a living person on its own or alongside something else you hold. A name, an email address, a phone number, a job title next to a company name. A free text message box counts by default, because you have no control over what somebody writes in it.

What happens if someone asks me to delete their data?

You find every copy you hold and remove it, within a month. Finding it is the hard part, not deleting it. Where one submission is one record, a deletion request is one action, and the source and journey attached to that record go with it.

Does GDPR apply if my business is not in the EU?

It applies to the people whose data you collect, not to where you are based. The test is who you offer goods or services to. Collect details from people in the EU or the UK and the obligations follow the data, not your postcode.

How long can I keep form submissions?

The regulation sets no number. It asks you to decide a period that fits the purpose you collected for, write it down, and then actually apply it. A retention period nobody enforces is the same as no retention period.

Does tracking where a lead came from add to my obligations?

It removes a field rather than adding one. The source is collected from the page instead of from the person, so the “how did you hear about us” question comes off the form. The campaign and journey sit on the same lead record as the submission, not in a separate profile somewhere else.

Collect less. Know more.

One record per enquiry, protected in transit and at rest, with the source attached and no extra field to ask for it.

Start free

Free to start · no card