Skip to content
GDPR · Guide

GDPR for web forms

A contact form looks like a small thing, yet every message that comes through it is personal data, and the GDPR asks the site owner to make a handful of decisions about it. This guide walks through those decisions in the order a submission lives: before it is collected, where it goes, how long it stays, and what happens when the person asks about it.

Each step links to a longer page. Where Formward has a setting for the step, we say what it does and what it does not do.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

Before you collect: lawful basis and notice

Every processing of personal data needs one of the six lawful bases in Article 6(1) of the GDPR. For a contact form the basis is often not consent: answering someone who asked you a question can rest on steps taken at their request or on legitimate interests. Consent comes in when you want to do something the person did not ask for, such as adding them to a newsletter. When a consent checkbox is needed, and what it should say.

Article 13 requires a short notice at the point of collection: who you are, why you collect the data, the lawful basis, who receives it and how long you keep it. A link to your privacy policy beside the submit button usually does the job (what the notice should say, with example wording). Ask only for the fields you need to reply (data minimisation, Article 5(1)(c)): a phone number field you never use is a liability, not a convenience.

Where the data goes: processors and transfers

The service that receives your form POST is a processor. Article 28 requires a contract with it, a Data Processing Agreement, and you are responsible for knowing which sub-processors it uses and where they are. If any of them stores the data outside the EU/EEA, Chapter V transfer rules apply as well. Using a US form provider under the GDPR covers Schrems II, the Data Privacy Framework and what to ask a provider.

Formward stores submissions in Sweden, and its sub-processor register lists every third party with its location and purpose. The DPA is published in full and can be accepted in the dashboard. For the transfer side, see where each part of the data lives and the Schrems II explainer.

Notifications and copies

The stored submission is rarely the only copy. A notification email lands in an inbox, a webhook pushes the data into a CRM, a sync fills a spreadsheet. Each of those is a copy with its own location and its own lifetime, and the retention you set on the form does not reach them.

If your notification address is a mailbox hosted outside the EU, the email can carry submission content out of the EU. Formward's link-only notification mode sends an email with no field values, subject or attachment names, so you read the submission in the EU-hosted dashboard instead. More on notification setup in form to email.

How long you keep it

The storage limitation principle (Article 5(1)(e)) says personal data should be kept no longer than the purpose needs. The GDPR does not set a number for you; you choose one, write it down and stick to it. Formward deletes submissions automatically after the period you set per form, and the Free plan is fixed at 30 days. How to choose a retention period.

When people ask about their data

Anyone who filled in your form can ask for a copy of their data (Article 15) or for it to be erased (Article 17), and you normally have one month to respond (Article 12(3)). The hard part is finding every submission that mentions the person. Formward's DSAR console searches all forms in your workspaces by email address, exports what it finds and erases it with a certificate. How to handle a data subject request.

Writing it down

Many organisations keep a record of processing activities under Article 30. For a form that is one entry: purpose, fields, lawful basis, retention, recipients and processors. If your form posts to Formward, the processor details you need are in our Article 30 record and the sub-processor register. Formward's honeypot field _gotcha and keyed IP hashing are documented on the security page if you need to describe the technical measures.

More topics

  • IP addresses: whether they are personal data, why a plain hash is not anonymous, and how long to keep them.
  • File uploads: CVs, photos and documents, with minimisation, retention and access control.
  • US form providers: transfers, Schrems II, the Data Privacy Framework and standard contractual clauses.
  • Privacy notice for a contact form: the Article 13 points and wording you can adapt.

Questions

Does a simple contact form fall under the GDPR?
Usually yes. A name and an email address identify a person, so the form collects personal data and you, as the site owner, are the controller for it. The obligations are proportionate though: for a small contact form they mostly come down to a short privacy notice, a sensible retention period and a way to find and delete a person's messages.
Is Formward the controller or the processor?
Formward processes form submissions on your behalf, as your processor under Article 28. You decide why the form exists and what happens to the data, so you remain the controller. The terms are in the Data Processing Agreement published at formward.eu/dpa.
Does using an EU-hosted form backend make my form GDPR compliant?
No tool can do that on its own. Hosting in the EU removes one question (transfers of the stored data outside the EU), but the lawful basis, the privacy notice, the retention period and how you answer requests are decisions you make as the controller. Formward provides settings for several of them; the choices stay yours.

Start with the defaults in place

Consent capture is on every plan, Free included. Retention, the DSAR console and the DPA are ready when you need them.

GDPR for web forms: a practical guide | Formward