Contact forms and GDPR: retention, purpose and who sees the data
How to run a contact form lawfully: what you may ask, on what basis, where the submissions go, how long you keep them and what to tell people.
The short answer
A contact form collects personal data, so it needs the same four things as any other processing: a clear purpose, a legal basis, only the data that purpose requires, and a retention period that is written down and applied. For handling an enquiry, the basis is normally pre-contractual steps or legitimate interest rather than consent, because the person contacted you and expects an answer; a consent checkbox for that purpose is unnecessary and confuses the picture. Consent does apply to the separate purpose of marketing, which requires its own unticked box, clear wording and a record of what was agreed. Beyond the legal framing, most of the practical risk is in where the submissions land and how long they stay: a shared inbox that everyone can read and nobody ever clears is the most common quiet breach on small business websites, and it turns any account compromise into a much larger incident.
Getting a form right
| Element | What good looks like |
|---|---|
| Fields | Only what you need to answer: name, contact method, message. Phone optional unless you need it |
| Purpose | Stated on the page in one line: to answer your enquiry |
| Legal basis | Pre-contractual steps or legitimate interest for the reply; consent only for marketing |
| Marketing opt-in | A separate, unticked checkbox with plain wording; never required to submit |
| Information | A short notice beside the button linking to the privacy statement |
| Destination | A CRM or ticketing system with access control, not an open shared inbox |
| Retention | A stated period, applied by a routine; customer correspondence moved to the customer record |
| Security | HTTPS, server-side validation, anti-spam, rate limits, no data in third-party trackers |
| Form provider | Check whether it stores copies, where, and for how long; processing agreement on file |
| Special categories | Avoid asking for health, financial or other sensitive details in a general form |
Making retention real
- Decide the period for enquiries that do not become customers, and write it down.
- Choose the destination with access control and the ability to delete.
- Move real customers into the customer record with its own retention.
- Set a recurring task to apply deletion, with an owner.
- Check the form provider’s own storage and turn off or shorten retention there.
- Clear the historical backlog once, which is usually the largest exposure.
- State the period in the privacy statement and beside the form.
- Record it in your record of processing.
The special category trap
General contact forms invite people to explain their situation, and some will volunteer health, financial or other sensitive information. You cannot prevent it entirely, but you can avoid inviting it: do not ask open questions that require it, warn briefly where relevant, and make sure such messages are handled by people who should see them and are not archived indefinitely. For sectors where sensitive details are inherent, a general web form is the wrong channel and a secure intake process is the right one.
What this means for you
Run your contact form on a clear purpose with the right basis, minimal fields, a separate unticked marketing opt-in, an accurate notice, a destination with access control, and a retention period that is stated and actually applied. Check what the form provider stores, clear the historical backlog once, and keep sensitive details out of a general form. The legal framing takes an hour; the retention routine is what protects you. This is general information rather than legal advice.
Frequently asked questions
Do we need a consent checkbox on our contact form?
Not for answering the enquiry. Someone who fills in a form asking you to contact them has initiated the processing, and the basis is normally pre-contractual steps or legitimate interest, not consent. You do need a separate, unticked, clearly worded checkbox if you also want to add them to a newsletter or send marketing later, because that is a different purpose. Bundling the two, or requiring marketing consent to submit the form, is not valid.
How long may we keep form submissions?
As long as the purpose requires, and no longer, which you decide and state. A common approach is to keep enquiries that did not become customers for a defined period such as six or twelve months, and to move customer correspondence into the customer record under its own retention. The essential part is that a period exists, is written down, is stated to the person and is actually applied rather than aspirational.
Where should submissions be stored?
Somewhere with access control and a retention mechanism: a CRM or a ticketing system rather than a shared inbox that everyone can read and nobody clears. If email is the destination, restrict who receives it, avoid forwarding to personal accounts, and apply a deletion routine. Also check where the form service itself stores submissions and for how long, because many keep a copy by default.
Sources
- EUR-Lex: Regulation (EU) 2016/679, Articles 5, 6 and 13 (accessed 2026-09-14)
- Autoriteit Persoonsgegevens: Grondslagen AVG uitgelegd (accessed 2026-09-12)