Website & Development
Is Your Contact Form GDPR Compliant? Consent and Retention Periods
Copy for AI
A contact form is GDPR compliant if you only ask for the data you genuinely need, have a valid legal basis to process it, are transparent about what you do with it and do not keep it longer than necessary. That sounds simple, but in practice many B2B forms collect too many fields, lack a clear privacy reference, and nobody ever cleans up the leads. This article explains how to handle consent, data minimisation and retention periods in practical terms, without wrecking your conversion. This is general guidance, not legal advice: if in doubt, consult a privacy lawyer.
What does GDPR compliant mean for your contact form?
GDPR compliant means that every piece of personal data that reaches you through your form has a clear purpose, a legal basis and a retention period, and that the visitor knows what happens to their data. The GDPR (AVG in Dutch) is the European privacy law that applies to anyone processing personal data of EU citizens. A name, email address or phone number in your form simply falls under it.
At its core it comes down to a few principles from the law: you process no more than necessary (data minimisation), you are fair and transparent, you have a valid legal basis, and you secure the data properly. So a form is not “compliant” because of a single checkbox, but because of the combination of what you ask, how you explain it, where the data goes and how long you keep it.
Which legal basis applies to a contact form?
For simply answering a request, you generally rely on legitimate interest or on the steps towards a possible contract, not necessarily on separate consent. Someone who fills in a form to reach you logically expects you to email or call back. The GDPR sets out six possible legal bases, and consent is only one of them. Which one fits depends on what you do with the data.
The distinction that often goes wrong in B2B: answering a question is not the same as adding someone to your newsletter or calling them for sales. If you also want to use the data for marketing, you usually need separate, explicit consent for that, collected through a checkbox that is not pre-ticked. Do not squeeze the two together into one generic “I agree”. A common, clean approach: process the request on the basis of your legitimate interest, and add a separate, optional checkbox for those who also want commercial follow-up. That keeps your legal basis defensible and respects the visitor’s choice.
Note: whether you rely on consent or on legitimate interest, you must be able to justify and document that choice. With legitimate interest you explicitly weigh your interest against the visitor’s privacy.
What data are you allowed to ask for?
Only the fields you genuinely need to handle the request, and not a single field more. That is the data minimisation principle, and it is exactly where most B2B forms go wrong. Job title, company size, budget, phone number, postal address: every extra mandatory field you do not directly need in order to respond is harder to justify under the GDPR and costs you conversion at the same time.
A good test per field: can you answer the request without this data point? If so, make it optional or drop it. For a first contact, a name, an email address and the message often suffice. You can offer a phone number as an option for those who prefer to be called. If you do collect enriching data (for lead qualification, for instance), make clear why and do not make it mandatory. Short forms are not only more privacy friendly, they usually convert better too. You can read more about this in our guide on form conversion optimisation.
How long may you keep the data?
No longer than necessary for the purpose you collected it for: the GDPR deliberately sets no fixed retention period. You determine a reasonable period per data category yourself, document it and stick to it. The alternative, leaving everything in your inbox or CRM indefinitely, is exactly what the law wants to prevent.
In practice that means: for a request that leads nowhere, you do not need to keep the data for years. If it does become a customer or an active opportunity, you have a legitimate reason to keep it longer, and statutory retention obligations sometimes come into play as well (for invoicing, for example). So work with simple logic: set a standard period for unanswered or rejected leads, and a separate period for data that moves into a customer relationship. Write down somewhere, for example in your record of processing activities, which period applies to which purpose and who is responsible for the clean-up. A period you do not enforce does not count in practice.
What else needs to be next to your form?
A visible, honest explanation of what happens to the data, with a link to your privacy statement right next to the submit button. Transparency is a core GDPR obligation: before submitting, the visitor must be able to see who processes the data, for what purpose, and on which legal basis. One line with a click-through to your full privacy statement usually suffices, provided that statement is accurate and up to date.
On top of that, a few technical and organisational points come into play:
- Security. Your site should run over HTTPS and the submitted data must arrive safely where it needs to go, not in an unsecured inbox or some random plugin.
- Processors. If you use a form tool, CRM or email marketing service, those are processors. That requires a data processing agreement, and you check where they store the data.
- No unnecessary trackers. Do not load marketing cookies or scripts before consent on your contact page; that is a separate obligation alongside the form itself.
- Data subject rights. People may request access to their data or have it erased. Make sure you can actually carry out a deletion request.
How you work all of this neatly into the page without raising the barrier ties in with your broader contact page optimisation.
How do you combine GDPR compliance with conversion?
By treating privacy as a trust signal instead of an obstacle. In B2B, the request through your form is often the start of a sales process, and that is exactly where trust counts. A form that only asks what is needed, clearly explains what happens and shows a tidy privacy reference feels more professional and usually brings in more completed requests, not fewer.
The flawed assumption is that you have to choose between compliance and leads. In practice they point in the same direction: fewer fields, clear language and visible care lower the barrier and raise trust. That fits our broader approach to turning a B2B website into a reliable lead engine. If you want to get it right from the ground up, you build the forms into the design of the site, not as a bolted-on plugin afterwards. That is how we work on website development and in our broader B2B website guide.
The short summary
A GDPR compliant contact form asks only for what is needed, has a defensible legal basis, separates answering a request from marketing consent, refers visibly to your privacy statement and keeps data no longer than necessary according to a period you actually enforce. No single checkbox solves that in one go: it is the combination of what you ask, how you explain it and what happens to the data afterwards. The good news is that those same choices also make your form convert better.
Want to set up your contact forms and your entire lead flow in a way that is both privacy friendly and conversion focused? Book your free intake.
Free website scan
Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.
We only use your details for your scan. No spam, unsubscribe anytime.