GDPR has a scary reputation, and an industry happy to keep it that way. For a small business running a contact, quote or order form, the actual duties are modest — mostly common decency written down: say what you're doing with people's details, don't collect more than you need, and don't keep them forever. Here's the whole picture in plain language.
If people in the EU can submit your form — and on the open web they can — then effectively yes, wherever your business sits. And "personal data" is anything about an identifiable person: name, email address, phone number, the message text itself, an IP address. A contact form is personal data by definition; that's its job.
Don't let that alarm you. GDPR doesn't say you may not collect it — it says you must be able to answer three honest questions: why do you have it, where is it, and when does it go away?
GDPR gives the two parties names. You are the controller: you decide what the form asks and what the answers are used for. The service that receives and stores submissions (hform, or any form backend) is your processor: it handles the data only on your instructions.
The rule that follows: controller and processor need a written agreement — a data processing agreement (DPA) — saying exactly that. This sounds heavier than it is; with most services it's a standard document. hform's DPA is published and applies to every account automatically, so this box is ticked the moment you claim your form.
Every use of personal data needs one of six lawful bases. For a form, two cover almost everything:
Honestly: no form service makes you "GDPR compliant" — compliance lives in what you ask, promise and do. What a tool can do is make the defaults right, so keeping your promises takes no effort: EU storage, automatic deletion on a schedule, export and delete buttons, a published DPA. That's the part we've built — the one-sentence privacy note is still yours to mean.
No. Consent is one of six lawful bases, and the wrong one for replying to a message someone sent you — that rests on legitimate interest or steps toward a contract. Save checkboxes for genuinely optional extras like a newsletter.
Not for the form. A plain HTML form sets no cookies, and hform’s hosted form pages set none either. Cookie banners are about tracking cookies elsewhere on a site — a different topic from forms.
If you offer goods or services to people in the EU, or monitor their behavior, GDPR applies to that processing regardless of where your business is based. A public form that EU customers use falls in scope.
A data processing agreement is the contract between you (controller) and any service that stores personal data for you (processor). You need one with your form service; hform’s is published at hform.com/legal/dpa/ and applies to every account.
Build a form in two minutes: EU-hosted (Sweden), automatic retention limits, CSV export, published DPA. The honest part stays yours; the plumbing is done. Free plan included, plain pricing beyond it.
More on forms and privacy: Consent checkboxes · Data retention · The privacy note · EU hosting — or see all guides.
This guide is plain-language orientation, not legal advice. For edge cases — special-category data, children's data, large-scale processing — talk to someone who does this for a living.