Skip to content
← GDPR for web forms
GDPR · Transfers

Using a US form provider under the GDPR

Many form tools are run by US companies, and plenty of European sites use them. That is allowed, but it is a transfer of personal data to a third country, and Chapter V of the GDPR sets conditions for it. This page explains the rules as they stand, the court cases behind them, and the questions worth putting to any provider, wherever it is based.

A practical guide, not legal advice. For a decision about your own processing, check with your data protection officer or a lawyer.

When a form creates a transfer

Articles 44 to 49 of the GDPR govern transfers of personal data to countries outside the EU and EEA. A transfer needs one of three things: an adequacy decision for the destination (Article 45), appropriate safeguards such as standard contractual clauses (Article 46), or, for occasional cases, one of the derogations in Article 49.

For a form, the provider that receives and stores submissions is the obvious place to look. It is not the only one. The notification email can land in a mailbox hosted abroad, and a webhook or automation tool can send the same data on. Each of those is a separate question.

Schrems II and what it changed

On 16 July 2020 the Court of Justice decided Data Protection Commissioner v Facebook Ireland and Schrems (C-311/18). It struck down the EU-US Privacy Shield, finding that US surveillance law and the remedies available to Europeans did not meet the EU standard.

The Court kept standard contractual clauses valid, with a condition: the exporter has to check, case by case, whether the law of the destination lets the importer keep its promises, and add supplementary measures where it does not. The European Data Protection Board described how to do that in its Recommendations 01/2020 on supplementary measures, adopted in final form on 18 June 2021.

The EU-US Data Privacy Framework

On 10 July 2023 the Commission adopted Implementing Decision (EU) 2023/1795, finding that the United States ensures an adequate level of protection for data sent to companies certified under the EU-US Data Privacy Framework. It rests on US Executive Order 14086, which added limits on signals intelligence and a redress route through a Data Protection Review Court.

For a form owner this means: if the US provider is certified, and its certification covers the kind of data you send, the transfer needs no further tool. You can check a company on the official Data Privacy Framework list. A provider that is not on the list needs another basis, usually standard contractual clauses.

The framework has been challenged. The General Court dismissed the action in Latombe v Commission (T-553/23) on 3 September 2025, and the applicant appealed to the Court of Justice as Case C-703/25 P. Two earlier arrangements, Safe Harbor and Privacy Shield, were struck down by that court, so many organisations keep a fallback in their contracts in case the framework falls too.

Standard contractual clauses

The current clauses were adopted in Commission Implementing Decision (EU) 2021/914 of 4 June 2021. They come in modules for different relationships; for a form service acting on your behalf the usual one is controller to processor. Using them means doing a transfer impact assessment and recording the outcome, which is real work for a small site. That is one reason the Data Privacy Framework is popular with US vendors that have certified.

What to ask any form provider

These questions work the same for US and European providers, and a good provider answers them in public documents:

  1. Where are submissions, file uploads and backups stored?
  2. Which sub-processors touch submission data, and in which countries?
  3. For each transfer outside the EU, which tool applies: adequacy, DPF certification or SCCs?
  4. Is the DPA published or available before you sign up, and does it list the sub-processors?
  5. Can staff outside the EU reach the data for support, and under what controls?
  6. Does the notification email carry the full submission, and can you turn that off?
  7. How does the provider handle a request for data from a foreign authority?

Our comparison pages collect what several providers say publicly about data location. Check their current documents too, since policies change.

Where Formward stands

Formward is run by a Swedish company. The app, the database and file uploads are hosted in Sweden. Notification email is sent by an EU provider, and the optional AI features on Professional and Business run on Mistral in the EU. Billing goes through Stripe Payments Europe, Limited, in Ireland, and concerns only the paying customer's own billing details.

The one US touchpoint is Cloudflare Turnstile, an anti-bot check that is off unless you switch it on for a form. When on, Cloudflare sees challenge data from the visitor's browser, not the form's answers. Destinations you add yourself, such as a webhook, a Slack channel or a mailbox hosted elsewhere, go wherever you point them.

Questions

Can I use a US-based form provider under the GDPR?
Yes, if the transfer rests on a valid tool from Chapter V. Today that is usually the EU-US Data Privacy Framework for a certified provider, or standard contractual clauses with a transfer impact assessment. You also need the usual DPA under Article 28.
Is the EU-US Data Privacy Framework still valid?
The Commission adopted it on 10 July 2023 and it applies. The General Court dismissed a challenge in Latombe v Commission (T-553/23) on 3 September 2025, and an appeal to the Court of Justice (C-703/25 P) was lodged on 31 October 2025. Check its current status before relying on it for the long term.
Does EU hosting by a US company avoid transfers?
It removes the transfer of the stored data, which helps. It does not settle everything: support staff abroad, sub-processors, backups and requests under US law can still be relevant. Ask the provider how each of those is handled.
Is using an EU provider enough to be GDPR compliant?
No. It answers the transfer question for the data that provider holds. Your lawful basis, privacy notice, retention and handling of requests remain your job, whichever provider you pick.

Keep the transfer question short

Formward stores submissions in Sweden. The optional US touchpoint is off unless you switch it on.

Using a US form provider under the GDPR | Formward