Skip to content
← GDPR for web forms
GDPR · Privacy notice

What your privacy notice should say about a contact form

Article 13 of the GDPR asks you to tell people certain things at the moment you collect their data. For a contact form that moment is the form itself, so the information has to be there or one click away. The good news is that a contact form needs only a short section, and most of it you can write once and reuse.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

What Article 13 requires for a contact form

Not every point applies to every form, but these are the ones a contact form normally touches:

Who you are
Your name or company and contact details, and your data protection officer if you have one. Article 13(1)(a) and (b).
Why you collect it, and on what basis
To answer the message, and the lawful basis for that. Usually legitimate interests or steps before a contract. Article 13(1)(c). If you rely on legitimate interests, say what they are, Article 13(1)(d).
Who receives it
Your form service and email provider, and anyone you forward submissions to, such as a CRM. Article 13(1)(e).
Transfers outside the EU
Whether any recipient is outside the EU and EEA, and the safeguard used. Article 13(1)(f).
How long you keep it
A period, or the criteria that decide it. Article 13(2)(a).
The person's rights
Access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where you rely on it, and the right to complain to a supervisory authority. Article 13(2)(b) to (d).
Whether they must provide it
Which fields are required and what happens if they are left out. Article 13(2)(e).

If the form feeds automated decisions with significant effects, Article 13(2)(f) adds a duty to explain them. A plain contact form rarely does.

Example wording you can adapt

This example is for a small business using Formward. Replace the bracketed parts, the periods and the contact address with your own, and remove anything that does not match what you actually do.

Contact form. When you send us a message through the contact form on this site, we use your name, email address and message to reply to you. If you ask for a quote, we also use the details to prepare it. Our legal basis is our legitimate interest in answering enquiries (Article 6(1)(f) GDPR), and for quote requests, steps you ask us to take before a contract (Article 6(1)(b) GDPR).

The form is run for us by Formward (EGF Fastighetsservice AB, Sweden), which receives and stores the messages on our behalf as our processor, on servers in Sweden. We receive each message by email at our mailbox hosted by [your email provider, location]. We do not use your message for marketing.

We keep messages for 12 months after our last reply and then delete them, unless the message leads to a contract, in which case we keep it with the contract records. Name, email and message are required, since we cannot reply without them.

You can ask us for a copy of your message, ask us to correct or delete it, or object to our use of it, by writing to privacy@example.com. You can also complain to your data protection authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).

If you add a newsletter checkbox, describe that purpose separately, with consent as its basis and how to unsubscribe. If you switch on Cloudflare Turnstile, add a sentence that Cloudflare, Inc. (United States) runs the bot check and receives technical data such as the IP address.

Mentioning your form service as a processor

The service that receives your form is your processor under Article 28, and you need a contract with it. In the notice it is a recipient. The Article 29 Working Party's guidelines on transparency (WP260 rev.01), endorsed by the EDPB, say the default should be to name recipients, and that if you only give categories they should be as specific as possible.

Keep the notice in step with your setup. If submissions go on to a CRM by webhook, or your notification inbox is hosted outside the EU, those are recipients and possibly transfers too, and they belong in the notice as well. Formward's sub-processor register and DPA give you the details to fill in.

Where to put it

A link to the notice right next to the submit button meets the “at the time of collection” requirement for most forms. One line is enough, for example: “We use your details to reply to you. Read how we handle your data.” The transparency guidelines recommend this layered approach: the key facts at the form, the full detail one click away.

On a hosted Formward page, put the same link in the form description, so visitors see it before they submit.

Questions

Does a contact form need its own privacy policy?
No. It needs to be covered by your privacy notice, and the notice should be easy to reach from the form. A short section about the contact form inside your main privacy policy, linked next to the submit button, is the usual approach.
Do I have to name my form provider?
Article 13 asks for the recipients or categories of recipients. Naming the provider is the clearest option, and guidance from the Article 29 Working Party, endorsed by the EDPB, treats naming as the default. If you use categories, make them specific, such as a form processing service in Sweden.
Should visitors tick a box to accept the privacy policy?
No. A privacy notice informs, it is not something people agree to. A tick box that says I accept the privacy policy adds nothing and can be confused with consent. Link the notice instead, and keep consent checkboxes for purposes that actually need consent.
What if my form uses a CAPTCHA?
Mention it. Say which service runs the check, that it receives technical data such as the IP address, and where it is based. With Formward that only applies if you switch on Cloudflare Turnstile.

A contact form your notice can describe in one line

Formward stores messages in Sweden as your processor, with a published DPA and sub-processor list.

Privacy notice for a contact form: what to say | Formward