GDPR and online forms: a practical checklist
Most writing about GDPR and forms stops at “get consent”. That is both inaccurate and not enough. This is a checklist you can run over one form in ten minutes to see what is missing — and, more usefully, what does not need to be there at all.
Work top to bottom
- 1
1. Write down what the data is for
One sentence per purpose. “Fulfil the order.” “Send the event programme.” Nothing else can be decided without it.
- 2
2. Assign a legal basis to each purpose
Orders and paid sign-ups = performance of a contract. Replying to an enquiry = legitimate interests. Marketing emails = consent. Consent is not the default; it is one basis of six.
- 3
3. Drop fields the purpose does not need
A date of birth on a contact form, a national ID on a workshop sign-up. What you never collect, you never have to protect, export or delete.
- 4
4. Separate marketing from everything else
A newsletter opt-in belongs in its own checkbox — not pre-ticked, and not required to submit.
- 5
5. Say who you are and what you do with the data
Link your privacy policy next to the submit button. The duty to inform applies even when you do not need consent.
- 6
6. Decide how long you keep the data
No fixed number exists — it follows from the purpose. Once the purpose is met, delete or anonymise.
- 7
7. Check who can see the responses
Set team roles so that personal data is visible only to people whose work needs it.
Common mistakes
“I agree to the processing of my data” on an order form makes no sense — the order cannot be fulfilled without the data, so the consent would not be freely given. A pre-ticked box is not consent. And linking a privacy policy satisfies the duty to inform, but it does not supply a legal basis.
Where Gatherino helps
Data sits on EU servers, is encrypted in transit and at rest, and is backed up daily. Access to responses can be limited by role and per form, so a temp on the collection desk does not see the whole database.
You can add a consent field whose wording you write yourself, linking to your own policy. Responses can be deleted individually or in bulk.
What Gatherino will not do: decide your legal basis for you, or delete data by itself once a retention period ends. That stays with you.
FAQ
Do I need a processing consent on every form?
No. Orders and sign-ups usually rely on performance of a contract. Consent is typically for marketing emails.
Can the consent box be pre-ticked?
No. A pre-ticked box is not valid consent.
How long may I keep responses?
Until the purpose is met, plus any period other rules require (accounting, for example). The exact figures depend on the data.
Where should responses be stored?
Somewhere you can account for. EU servers sidestep the whole third-country transfer problem.
Related
Try Gatherino for free
Free plan: 3 forms and 100 responses a month. No credit card, EU-hosted data.
Get started free →