A contact form open on a laptop screen on a desk with a plant

Building a contact form that meets the GDPR

A contact form on a company website works cleanly when it asks for name, email address and a message, and anything beyond that minimum needs its own justification for why exactly that field is necessary to answer the enquiry.

The legal basis for processing form data usually comes from Article 6(1) of the GDPR, because answering the enquiry is simply not possible without a name and an email address, and that basis needs no consent checkbox next to the submit button.

Next to the submit button there should be a short link to the privacy policy describing what happens to the data after submission, who receives it and how long it is kept. That link is enough, a separate consent checkbox here is redundant as long as the form relies on necessity to answer the request.

A consent checkbox only becomes required once the form data is meant to be used for more than a single reply, for instance adding the address to a newsletter list. In that case a separate line with its own consent is needed, not one combined statement covering everything at once.

The message from the form usually lands in the company's ordinary inbox, and that too counts as processing personal data, so the email service the message passes through also has to meet GDPR requirements, including extra safeguards if it sits outside the European Union.

Enquiries from the form are kept only as long as handling them requires, not indefinitely. Once an enquiry is closed and there is no reason to keep the correspondence, such as tax retention rules or a legal dispute, the data is deleted.

Google reCAPTCHA remains the most common spam protection for forms and at the same time the most problematic, because it transmits data to Google servers in the US the same way externally loaded fonts do. A simpler defence, a trap field invisible to people but filled in by bots, or a plain question like the sum of two numbers, solves the same problem without sending data outside.

Testing the form yourself is worth doing from an outsider's perspective. Send a test message, check whether a notification arrives, what the confirmation email says, and whether a technical copy of the submitted data sits somewhere that the privacy policy never mentions.

Share
Portrait of Illia Belichenko, technical specialist at Illia BizTech
Illia Belichenko

Illia is responsible for the technical side of Illia BizTech: website development, website updates, forms, integrations, automation and technical support. He works on connecting websites, content, advertising and internal workflows so they work together without creating unnecessary manual work.

A contact form is often the only place on a site where a company actually collects personal data, which is exactly why it is worth checking separately from the rest of the site. Illia BizTech sets up form fields to ask for only what is genuinely needed, and puts the consent line and a link to the privacy page right next to the submit button, instead of losing them somewhere in the footer.

Illia BizTech builds and maintains websites for small and medium businesses in Russian, German and English, from the first version through ongoing maintenance and SEO work. A team carries the project from idea to launch without long internal approval chains, so the client speaks directly with the people writing the code and managing the content, not through a chain of account managers. That fits businesses moving to Germany or expanding into the German-speaking market who want to explain their task once, not repeat it on every call.