By Donata Kalnenaite on Saturday, 20 June 2020
Category: June

Contact forms and GDPR

A contact form is key to any website that brings in new business - it’s how customers can inquire about your products or services, ask you questions, engage with your brand, and more. Individuals usually input some personal data into contact forms such as their name, email, phone number or address to allow you to contact them.

This provision of data may trigger the application of the General Data Protection Regulation (GDPR). If GDPR applies to you, it will place some restrictions on how you can collect, use and disclose personal data. In this article, we will discuss the requirements that GDPR places on websites that use contact forms, including: 

Obtaining consent

GDPR is unique in the sense that it prohibits the collection, use and disclosure of personal data by default. However, GDPR allows for the processing of personal data if certain exceptions, otherwise called legal bases, apply. One of these legal bases is consent, or the data subject voluntarily agreeing to you collecting, using or disclosing their data. Usually, contact form submissions are processed under the consent legal basis as the individual is agreeing to giving you their data. While consent may seem like an easy requirement to meet, that is unfortunately not the case as GDPR has certain requirements for what it means for consent to be valid.

GDPR defines consent as “any freely given, specific, informed and unambiguous indication of the individual’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data.” You may find the following tips helpful when deciding how you will obtain consent for the submission of personal data through your contact form: 

If you have determined that you will use consent as the legal basis for processing personal data, you are responsible for ensuring that you meet all of the requirements outlined above and that your contact form adequately captures consent. If you fail to meet the requirements, your processing of data would be considered and lawful and you could lose access to the data or even be fined for violating GDPR. 

Privacy Policy requirements

GDPR provides individuals with the right to transparency regarding the collection, use and disclosure of their personal data online. This means that your website needs to have a Privacy Policy that makes specific disclosures to meet the transparency and informed consent requirements. For consent to be informed, your Privacy Policy must make the following disclosures: 

While the above information needs to be disclosed in your Privacy Policy to obtain informed consent, GDPR also requires your Privacy Policy to make the following disclosures to meet the transparency requirement

It is imperative that the information outlined above is included in your Privacy Policy and that your Privacy Policy is easily accessible and understandable to individuals prior to them filling out your contact form. 

Rights provided to individuals 

GDPR protects the personal data of residents of the European Union by providing them with a set of privacy rights that give individuals more control over their data. The following is a list of privacy rights that are the most relevant to those using contact forms: 

If you have a contact form on your website, it is imperative that you obtain proper consent for the collection of that data, have a Privacy Policy that makes all of the required disclosures and respect the rights that are provided to individuals under GDPR. 

Leave Comments