Answer access and erasure requests across all your forms
Sooner or later someone writes: “What data do you have about me?” or “Please delete everything.” For form data the request itself is simple. The work is in finding every submission that mentions the person, across every form you run, and being able to show afterwards what you did.
A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.
What people can ask for
Chapter III of the GDPR gives the people who fill in your forms a set of rights. The two you will see most often:
- Access (Article 15). Confirmation of whether you hold their data, a copy of it, and information such as the purposes, the recipients and how long you keep it.
- Erasure (Article 17). Deletion when, among other grounds, the data is no longer needed, consent is withdrawn, or they object and there is no overriding reason to keep it. Article 17(3) lists exceptions, such as data you must keep to comply with a legal obligation.
People can also ask for correction (Article 16), restriction (Article 18) or a portable copy (Article 20), and object to processing based on legitimate interests (Article 21).
Deadlines and identity checks
Article 12(3) sets the clock: respond without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests if you tell the person within the first month. The answer is normally free (Article 12(5)).
If you have reasonable doubts about who is asking, you may ask for information to confirm their identity (Article 12(6)). For form data a proportionate check is often a reply from the email address that appears in the submissions. Avoid asking for more data, such as an ID scan, than the request justifies. The European Data Protection Board's Guidelines 01/2022 on the right of access cover identity checks and the scope of a copy in detail.
Who does what
You are the controller, so the request is yours to answer. Formward is your processor and, under Article 28(3)(e) and section 8 of the DPA, assists you with tools rather than by answering on your behalf. A request that reaches Formward directly is referred to you.
How the Formward DSAR console works
The DSAR console is in the dashboard under Data subject requests, available from the Personal plan. It works on email addresses.
- Search. Enter the person's email address. The console looks through every form in the workspaces you belong to and finds submissions where the address appears anywhere in the content, including free-text fields and earlier versions of edited answers. Results are grouped per form with the date, a preview and the names of attached files. Notification-recipient verifications and DPA acceptances tied to that address are listed too.
- Export. Download the result as JSON. It lists each matching submission with its form, date and a preview of the content. For long submissions or attached files, open the submission in the dashboard to give the person a complete copy.
- Erase. After a confirmation, Formward deletes every matching submission across your forms, with its attached files, answer history and webhook delivery records, plus matching recipient verifications. You get an erasure certificate as a JSON file: a hash of the email address, the number of records erased, the forms affected and the time.
- History. Every search and erasure is logged in the request history, and erasures also in the workspace audit log. The person is identified there by a one-way hash, never by their email address.
One thing to check before erasing: the search matches the address as text, so anna@example.com also matches joanna@example.com. Read the per-form results first. And if a form never asked for an email address, search the submissions for the name or phone number instead.
A short checklist
- Log the date the request arrived; the month starts then.
- Confirm identity proportionately, usually by replying to the address on file.
- Search the DSAR console, then the places it cannot see: notification inboxes, spreadsheets, CRMs fed by webhooks, exported files.
- For access, send the copy together with the Article 15 information: purposes, recipients, retention period and the person's other rights.
- For erasure, check whether an Article 17(3) exception applies, erase, and keep the certificate.
- Reply within the month, or explain the extension within it.
A short retention period makes every one of these steps smaller. The contact us template and the contact form guide both collect an email address, which is what the console searches on.
Questions
- How long do I have to answer a data subject request?
- Without undue delay and at the latest within one month of receiving it (Article 12(3)). For complex or numerous requests you can extend by two further months, but you must tell the person within the first month and explain why.
- Can I charge for answering?
- Normally not. Article 12(5) makes the response free of charge. Only for requests that are manifestly unfounded or excessive can you charge a reasonable fee or refuse, and you carry the burden of showing that.
- Will Formward answer requests from people who filled in my forms?
- No. You are the controller and the person's request is addressed to you. If someone contacts Formward about data in your forms, we refer them to you, as set out in section 8 of the DPA. Our part is to give you the tools to answer.
- Which plans include the DSAR console?
- The Personal plan and above. A member of a workspace whose owner is on one of those plans can use it for that workspace even with a Free personal account.
One search across every form
The DSAR console is included from the Personal plan. Search by email, export the result, erase with a certificate.