Contact forms on websites: Data privacy & GDPR

Last updated:
03.02.2023
Data protection often ends where online contact forms begin. The principle of data minimization, in particular, is frequently nowhere to be found. For website operators, this can quickly become expensive, as it carries the risk of significant fines.
Contact forms on websites: Data privacy & GDPR
Key Takeaways
  • Contact forms must be designed to be GDPR-compliant, otherwise you risk fines.
  • Data minimization: Only collect data that is necessary for inquiries (Art. 5 GDPR).
  • Purpose limitation principle: Only use data for the specified purpose and delete it afterwards.
  • Clearly mark mandatory fields; allow additional data to be provided voluntarily.
  • Data transmission must be encrypted to ensure integrity and confidentiality.

When filling out contact forms, users are often asked to provide a wealth of information. This frequently reaches absurd proportions, leading many to wonder—especially with minor inquiries—whether providing just an email address would have sufficed. Those who feel this way are not entirely wrong: a website's contact form must also be designed in compliance with data protection regulations.

Contact forms: Data protection is often overlooked

When requesting any data via a contact form, the principle of data minimization (Art. 5 GDPR) is paramount. Only data that is necessary to respond to an inquiry may be collected. For an online shop order, for example, a delivery address is necessary, but a mobile phone number is not.

Closely linked to this is the so-called purpose limitation principle (Art. 5 GDPR). The collected data may only be used for the specific purpose—e.g., responding to an inquiry—and must be deleted once that purpose has been fulfilled. It may not, for example, be used for advertising purposes. Finally, the person making the inquiry must also be informed about the nature and scope of the data being collected. So, how can you meet these GDPR requirements as comprehensively as possible?

Smartly integrating data protection into contact forms

Responding to a contact inquiry usually requires a name—though in many cases, a pseudonym can suffice—and a valid email address. Anyone taking data protection seriously regarding their contact form should be satisfied with just this information. However, some forms demand much more from users and potential customers. The motive is clear: data is digital gold and therefore highly valuable.

To comply with data protection, you can use clear labeling for mandatory fields to distinguish them from optional data. Typically, a name and email address are mandatory fields in a contact form, while other data requests, such as a phone number, are marked with an asterisk (*) and a justification for the request. This allows users to decide for themselves whether they want to follow that justification and provide more than just the required information.

Which fields are marked as mandatory on a specific website depends on the nature and purpose of the inquiries handled by that contact form. In case of doubt, you as the user must be able to justify why, for example, a phone number is a mandatory field on your website. If you are unsure, you should either contact your data protection officer or, for the sake of data minimization, stick to just a name and email address.

Contact forms and encryption

Finally, your contact forms must meet the Principle of integrity and confidentiality (Art. 5 GDPR). This means that the data transmission process encrypted must be carried out. This ensures that appropriate security of personal data is maintained and that the data is protected against unauthorized or unlawful processing.

Furthermore, under Art. 5 GDPR, you as the site operator—and therefore the party responsible—are accountable for compliance with these principles and must be able to demonstrate this compliance upon request (accountability). You should take this responsibility seriously, as failure to do so can be costly: negligent or incomplete compliance with data protection regulations regarding contact forms can not only lead to fines but also make you liable to legal warnings under competition law.

By the way: You can include a link to your site's privacy policy below your contact form. However, the belief that users must check a box to acknowledge the privacy policy is a misconception.

Is your privacy policy incorrect? Use the Proliance privacy policy template as a guide or seek professional advice.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in