Skip to content
← GDPR for web forms
GDPR · Consent

Consent checkboxes that hold up as proof

Many forms carry a box that says something like “I agree to the privacy policy”. It feels safe, but it often does nothing useful: agreeing to a policy is not consent to a specific purpose, and for a plain enquiry you may not need consent at all. This page covers when a consent checkbox is the right tool, how to word it, and how to keep a record that shows what each person agreed to.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

When a form needs a consent checkbox

Article 6(1) of the GDPR lists six lawful bases, and consent is only one of them. Which one fits depends on what you do with the data, not on the form itself.

  • Replying to an enquiry. The person asked you something and expects an answer. This is commonly handled under Article 6(1)(b), steps at the person's request before a contract, or 6(1)(f), legitimate interests. A consent box adds little here, and it has a cost: consent can be withdrawn at any time (Article 7(3)), after which you would have to stop processing on that basis.
  • Marketing email or a newsletter. Adding someone to a mailing list goes beyond what they asked for. This is the classic case for a separate, optional consent box. Email marketing is also governed by national rules implementing the ePrivacy Directive, which in most cases require prior consent as well.
  • Keeping data for later. Holding a job applicant's CV for future openings, or sharing details with a partner for their own use, are separate purposes. Each needs its own basis, and consent is often the one that fits.
  • Special category data. Health information and the other categories in Article 9 need an Article 9(2) condition on top of a lawful basis; explicit consent is one of them.

What makes consent valid

Article 4(11) defines consent as freely given, specific, informed and unambiguous. Article 7 adds the conditions. In form terms:

  • The box starts unticked. Silence, pre-ticked boxes and inactivity are not consent (Recital 32).
  • One box per purpose, separate from accepting your terms (Article 7(2)).
  • The service does not depend on ticking it when the data is not needed for the service (Article 7(4)).
  • The person can withdraw as easily as they gave it, and is told so before agreeing (Article 7(3)).
  • You can show that the person consented, and to which wording (Article 7(1)).

The European Data Protection Board covers each condition in detail, with examples, in its Guidelines 05/2020 on consent.

What the checkbox text should say

Good consent text names who you are, the specific purpose, and how to withdraw. It reads like a sentence a person would agree to, not a legal clause. For example:

Email me Acme Studio's monthly newsletter about new courses. I can unsubscribe at any time with the link in every email. Read the privacy policy.

Wording to avoid: “I agree to the terms and privacy policy” (bundled, and no specific purpose), “I consent to the processing of my data” (which processing, for what?), or anything that makes sending the enquiry conditional on joining a mailing list.

Consent capture in Formward

Each form has a GDPR consent setting in its privacy settings, available on every plan including Free. You switch on consent capture, write the consent text (up to 2,000 characters), and choose whether consent is required.

  • Hosted forms show the checkbox automatically, unticked, with your text beside it.
  • Required consent. When required, a submission without a ticked box is rejected with 422 consent_required before it is stored or counted against your quota.
  • Proof. When the person ticks the box, Formward stores the consent text configured on the form and the time of the submission alongside it. Both show in the submission view. The text is a snapshot: if you change the wording later, earlier submissions keep the wording their senders saw.
  • Optional consent. If consent is not required and the box is left unticked, the submission is accepted and no consent is recorded for it.

Formward records consent; it does not manage withdrawal for you. If a person withdraws, stop the processing that relied on it (for a newsletter, unsubscribe them in your mailing tool) and, if they ask, erase their submissions.

Markup for your own HTML form

On a form you host yourself, add a checkbox named _consent. Formward treats on, true, 1 and yes as consent given; a browser sends on for a ticked box and nothing for an unticked one.

<form action="https://forms.formward.eu/f/<FORM_ID>" method="POST">
  <label>Email <input type="email" name="email" required /></label>
  <label>Message <textarea name="message" required></textarea></label>

  <!-- Optional and unticked. Same wording as the form's consent text. -->
  <label>
    <input type="checkbox" name="_consent" />
    Email me Acme Studio's monthly newsletter about new courses.
    I can unsubscribe at any time with the link in every email.
  </label>

  <input type="text" name="_gotcha" style="display:none" tabindex="-1" autocomplete="off" />
  <button type="submit">Send</button>
</form>

Keep the label identical to the consent text in the form's settings. Formward stores the configured text, never text sent by the browser, so the two must match for the record to describe what the person actually saw. The _consent value itself is not stored with the answers.

Questions

Does every contact form need a consent checkbox?
No. Consent is one of six lawful bases in Article 6(1). If someone writes to you and expects a reply, answering them can usually rest on another basis, such as steps taken at their request or legitimate interests. A checkbox becomes necessary when you want to use the data for something the person did not ask for, such as marketing email.
Can the consent box be ticked by default?
No. Consent has to be an unambiguous, active choice. Recital 32 of the GDPR says pre-ticked boxes do not count, and the Court of Justice of the EU confirmed this in the Planet49 case (C-673/17). Formward's hosted forms render the box unticked.
Can I combine consent with accepting my terms?
Not in one box. Article 7(2) requires a consent request to be clearly distinguishable from other matters. Keep a separate checkbox for each purpose that needs consent.
Is consent capture a paid feature in Formward?
No. Consent capture is available on every plan, including Free.

Capture consent with proof, on any plan

Turn on consent capture in a form's privacy settings. The text and time are stored with every submission that agrees.

GDPR consent checkbox for forms, with proof | Formward