hform/guides

GDPR and Web Forms in Plain Language

GDPR has a scary reputation, and an industry happy to keep it that way. For a small business running a contact, quote or order form, the actual duties are modest — mostly common decency written down: say what you're doing with people's details, don't collect more than you need, and don't keep them forever. Here's the whole picture in plain language.

Does GDPR apply to your form?

If people in the EU can submit your form — and on the open web they can — then effectively yes, wherever your business sits. And "personal data" is anything about an identifiable person: name, email address, phone number, the message text itself, an IP address. A contact form is personal data by definition; that's its job.

Don't let that alarm you. GDPR doesn't say you may not collect it — it says you must be able to answer three honest questions: why do you have it, where is it, and when does it go away?

Two roles: you, and your form service

GDPR gives the two parties names. You are the controller: you decide what the form asks and what the answers are used for. The service that receives and stores submissions (hform, or any form backend) is your processor: it handles the data only on your instructions.

The rule that follows: controller and processor need a written agreement — a data processing agreement (DPA) — saying exactly that. This sounds heavier than it is; with most services it's a standard document. hform's DPA is published and applies to every account automatically, so this box is ticked the moment you claim your form.

Your lawful basis (and why it’s usually not consent)

Every use of personal data needs one of six lawful bases. For a form, two cover almost everything:

The five duties, in practice

  1. Tell people. A short, honest note near the form saying what you use the details for — one sentence covers the common case. See the privacy note under your form, with copy-paste examples.
  2. Ask only what you need. Every field should earn its place. A contact form rarely needs a birth date.
  3. Don't keep it forever. Decide how long submissions live and delete them after — sensible retention periods here.
  4. Honor people's rights. If someone asks what you have on them, or asks you to delete it, do it and reply. With your submissions in one inbox with CSV export and delete buttons, this is minutes, not projects.
  5. Know where the data lives. Data stored inside the EU keeps this simple. hform stores submissions in Sweden; if you use another service, check whether your data crosses to the US and under what safeguards — the full story is in why EU hosting matters.

What a tool can and can’t do for you

Honestly: no form service makes you "GDPR compliant" — compliance lives in what you ask, promise and do. What a tool can do is make the defaults right, so keeping your promises takes no effort: EU storage, automatic deletion on a schedule, export and delete buttons, a published DPA. That's the part we've built — the one-sentence privacy note is still yours to mean.

Quick answers

Do I need a consent checkbox on my contact form?

No. Consent is one of six lawful bases, and the wrong one for replying to a message someone sent you — that rests on legitimate interest or steps toward a contract. Save checkboxes for genuinely optional extras like a newsletter.

Do I need a cookie banner for my form?

Not for the form. A plain HTML form sets no cookies, and hform’s hosted form pages set none either. Cookie banners are about tracking cookies elsewhere on a site — a different topic from forms.

My business is outside the EU — does GDPR still apply?

If you offer goods or services to people in the EU, or monitor their behavior, GDPR applies to that processing regardless of where your business is based. A public form that EU customers use falls in scope.

What is a DPA and do I really need one?

A data processing agreement is the contract between you (controller) and any service that stores personal data for you (processor). You need one with your form service; hform’s is published at hform.com/legal/dpa/ and applies to every account.

Free — no signup

Forms with the right defaults

Build a form in two minutes: EU-hosted (Sweden), automatic retention limits, CSV export, published DPA. The honest part stays yours; the plumbing is done. Free plan included, plain pricing beyond it.

More on forms and privacy: Consent checkboxes · Data retention · The privacy note · EU hosting — or see all guides.

This guide is plain-language orientation, not legal advice. For edge cases — special-category data, children's data, large-scale processing — talk to someone who does this for a living.