Retention periods for form submissions
The GDPR sets no fixed retention period for form submissions: Article 5(1)(e) requires keeping personal data no longer than necessary, so the period is yours to choose and justify. Formward deletes submissions and their files automatically after the period you set per form, and Free forms always delete after 30 days.
A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.
The storage limitation principle
Article 5(1)(e) of the GDPR requires personal data to be kept in a form that identifies people for no longer than the purpose needs. Article 13(2)(a) asks you to tell people, when you collect their data, how long you will keep it or how you decide. Article 17(1)(a) adds that a person can ask for erasure once the data is no longer needed.
In practice that means three things for each form: a period you can explain, a privacy notice that states it, and a mechanism that actually deletes the data when the period ends.
How to choose a period
Start from the purpose of the form and ask how long after the last useful action you could still need the submission. Some starting points to adapt to your own situation:
| Form | Questions to ask |
|---|---|
| Contact or support enquiry | How long after a reply do follow-up questions still arrive? A few months is often enough; if the enquiry becomes a customer relationship, the data moves into your CRM or accounts and their periods apply there. |
| Job application | How long after the decision could a candidate challenge it under your national employment law? Keeping CVs for future roles is a separate purpose and usually needs consent. |
| Event registration | Do you need the list after the event, for example for a follow-up or a certificate? Dietary and accessibility details rarely need to outlive the event. |
| Quote or order request | If it leads to a sale, bookkeeping rules may require keeping the resulting records for years, but in your accounting system rather than in the form inbox. |
| Feedback or survey | Do you need to know who answered, or only what was answered? If only the answers, export the figures and delete the submissions. |
Whatever you choose, write it down in your record of processing and your privacy notice, and use the shortest period you can defend.
What Formward does
- Per-form retention. Each form has a data retention setting in its privacy settings. On paid plans you choose 7, 30, 90, 180 or 365 days, or keep submissions until you delete them, and the dashboard flags forms with no limit.
- Free plan: 30 days, fixed. Free forms delete submissions after 30 days. The setting cannot be switched off, and a paid account that moves back to Free has longer settings brought down to 30 days.
- Automatic, permanent deletion. A nightly job deletes every submission older than its form's period, together with its attached files and webhook delivery records. Deletion cannot be undone.
- Applies to stored data. Shortening the period also applies to submissions already stored, so the next run removes anything older than the new limit.
- Backups. Encrypted backups rotate on a 14-day cycle, as described on the security page.
IP hashes
Formward never writes a submitter's raw IP address to disk. It stores a keyed hash (HMAC-SHA-256 with a secret server-side salt), used for rate limiting and abuse detection. By default the hash lives as long as the submission. In the dashboard's privacy center you can instead remove it once a submission is 24 hours old, which drops the link between submissions from the same connection after that point. Anonymous hosted forms do not keep this link at all.
Copies outside Formward
A retention setting only reaches data Formward holds. Review the other places a submission lands: the notification inbox, a spreadsheet sync, webhook targets, exported CSV files on a laptop. If the notification inbox is the problem, Formward's link-only mode sends notifications without any submission content, so the inbox holds nothing to delete. For one person's data, the DSAR console erases it ahead of schedule. The contact us template keeps the field list short, which leaves less to retain in the first place.
Questions
- Does the GDPR say how long I can keep form submissions?
- No. Article 5(1)(e) says personal data must be kept no longer than necessary for the purpose, and Article 13 asks you to tell people the period or the criteria for it. The number itself is yours to set and justify. Other laws, such as bookkeeping or employment rules in your country, can require a minimum for some records.
- What happens on the Formward Free plan?
- Free forms delete submissions after 30 days, and that setting cannot be changed or switched off. If a paid account moves back to Free, longer settings are brought down to 30 days at the next nightly run.
- Are deleted submissions gone from backups too?
- Not immediately. Formward's encrypted database backups rotate on a 14-day cycle, so a deleted submission can remain in a backup until that backup is replaced.
- Does the retention setting delete my notification emails?
- No. Retention applies to what Formward stores. Copies that already left, such as notification emails in your inbox, rows synced to a spreadsheet or records pushed to a CRM by webhook, follow the retention of those tools.
Set a retention period once, per form
Free forms delete after 30 days. Paid plans choose a period per form or keep submissions until you delete them.