Skip to content
← GDPR for web forms
GDPR · File uploads

File uploads on forms and the GDPR

A file field turns a short form into a document store. CVs list employment history and home addresses, photos show faces, scanned documents carry numbers you would never ask for in a text field. The GDPR rules are the same as for any other field, but the stakes are higher, so each decision deserves a second look.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

Ask for less

Data minimisation (Article 5(1)(c) of the GDPR) applies to files as much as to fields. Before adding an upload, check whether the form needs the file at all:

  • A link often does the job. Candidates can share a CV or portfolio link, which leaves the file with them.
  • Limit the types with the accept attribute so people are not tempted to send a phone photo of a document when a PDF will do.
  • Say what the file is for and what not to include, for example “no photo needed” next to a CV upload.
  • Remember the metadata. Photos can carry location data and documents can carry author names. Removing it is up to the sender or to you after download.

When a file contains sensitive data

Some uploads fall into the special categories of Article 9: a doctor's note on a leave request, a medical certificate for a sports club, a document that shows religious belief or trade union membership. Processing those needs a condition from Article 9(2) on top of a lawful basis, such as explicit consent or an employment law duty.

A photo of a person is not automatically special category data. Recital 51 says photographs count as biometric data only when processed with specific technical means to identify someone. Even so, a photo is personal data, so ask for one only when you have a use for it.

How long files should stay

The storage limitation principle (Article 5(1)(e)) applies to every copy. Pick a retention period that matches the purpose, such as a few months after a role is filled for job applications, and write it on the form. Then make sure the deletion actually happens: in the form backend, in the mailbox that received notifications, and in any folder where someone saved the files.

Who can open the files

Article 32 asks for security appropriate to the risk. For uploads that usually means:

  • Files are opened only by people signed in to an account, not through public links.
  • Files are not attached to notification emails, where they get forwarded and archived.
  • Only the file types you need are accepted, and executables are refused.
  • Access is limited to the people who handle the form, not the whole company.

How uploads work in Formward

  • Plans. Uploads start on Professional, with up to 5 files and 10 MB per file on that plan. Business allows more.
  • Location. Files are stored with the submission on servers in Sweden, run by Hostup AB.
  • Access. Members of the workspace that owns the form download files through a signed-in dashboard link. Downloads are always served as attachments, so an uploaded HTML or SVG file cannot run as a page.
  • Notifications. The email lists file names and sizes with a link, never the files. With link-only notifications switched on, the names are left out too.
  • Types. Only common image, document, spreadsheet and presentation formats are accepted. Archives, scripts and executables are refused.
  • Deletion. Files are deleted with their submission, manually or by the form's retention period. From Business, a file field can also be marked sensitive so its files are removed after 7, 30 or 90 days while the rest of the submission stays.

Questions

Are uploaded files personal data?
Usually. A CV, a photo of a person or a scanned ID identifies someone directly, and even an ordinary document can carry a name in its text or its metadata. Treat uploads with the same care as the rest of the submission, and often more.
Should I accept copies of ID documents on a form?
Only if you have a clear need, such as a legal duty to verify identity. ID scans are attractive to attackers, and in some countries national identity numbers have extra rules under Article 87. If you only need to know the person exists, ask for something less sensitive.
Do uploaded files follow the form's retention period?
In Formward, yes. When a submission is deleted, by you or by the retention schedule, its files are deleted with it. Copies you downloaded or forwarded are outside that schedule.
Which Formward plans support uploads?
Uploads start on Professional. A submission carrying files to a form on a lower plan is refused, and the rest of the form keeps working.

Uploads stored in Sweden, deleted on schedule

Uploads come with Professional and above. Files live with the submission and go when it goes.

File uploads on forms: a GDPR checklist | Formward