GDPR and online forms: a practical checklist

Most writing about GDPR and forms stops at “get consent”. That is both inaccurate and not enough. This is a checklist you can run over one form in ten minutes to see what is missing — and, more usefully, what does not need to be there at all.

Work top to bottom

  1. 1

    1. Write down what the data is for

    One sentence per purpose. “Fulfil the order.” “Send the event programme.” Nothing else can be decided without it.

  2. 2

    2. Assign a legal basis to each purpose

    Orders and paid sign-ups = performance of a contract. Replying to an enquiry = legitimate interests. Marketing emails = consent. Consent is not the default; it is one basis of six.

  3. 3

    3. Drop fields the purpose does not need

    A date of birth on a contact form, a national ID on a workshop sign-up. What you never collect, you never have to protect, export or delete.

  4. 4

    4. Separate marketing from everything else

    A newsletter opt-in belongs in its own checkbox — not pre-ticked, and not required to submit.

  5. 5

    5. Say who you are and what you do with the data

    Link your privacy policy next to the submit button. The duty to inform applies even when you do not need consent.

  6. 6

    6. Decide how long you keep the data

    No fixed number exists — it follows from the purpose. Once the purpose is met, delete or anonymise.

  7. 7

    7. Check who can see the responses

    Set team roles so that personal data is visible only to people whose work needs it.

Common mistakes

“I agree to the processing of my data” on an order form makes no sense — the order cannot be fulfilled without the data, so the consent would not be freely given. A pre-ticked box is not consent. And linking a privacy policy satisfies the duty to inform, but it does not supply a legal basis.

Where Gatherino helps

Data sits on EU servers, is encrypted in transit and at rest, and is backed up daily. Access to responses can be limited by role and per form, so a temp on the collection desk does not see the whole database.

You can add a consent field whose wording you write yourself, linking to your own policy. Responses can be deleted individually or in bulk.

What Gatherino will not do: decide your legal basis for you, or delete data by itself once a retention period ends. That stays with you.

FAQ

Do I need a processing consent on every form?

No. Orders and sign-ups usually rely on performance of a contract. Consent is typically for marketing emails.

Can the consent box be pre-ticked?

No. A pre-ticked box is not valid consent.

How long may I keep responses?

Until the purpose is met, plus any period other rules require (accounting, for example). The exact figures depend on the data.

Where should responses be stored?

Somewhere you can account for. EU servers sidestep the whole third-country transfer problem.

Related

Try Gatherino for free

Free plan: 3 forms and 100 responses a month. No credit card, EU-hosted data.

Get started free →