Here is your contact form
Name.
Email.
Phone number.
A message.
A typical contact form may contain as few as four fields, but the moment a visitor submits them, the company is processing personal data.
So what exactly should be written on the form?
And should the customer check the box:
“I accept the privacy policy”?
As a general rule: no.
A privacy policy is information—not something the customer has to accept
It is a common misconception that a checkbox must be included, where the visitor agrees to the company’s privacy policy, before a contact form can be submitted.
The Danish Data Protection Agency states explicitly that the customer is not required to consent to the company’s privacy policy.
Instead, the privacy policy should explain to the individual how the company processes personal information.
That’s an important difference.
You must inform the visitor.
That does not mean that the visitor must “approve” the information.
A link in the footer isn’t always enough
Many websites already have a link to their privacy policy at the very bottom of the page.
It’s nice to have that there.
However, if a company collects personal data through a form, the Danish Data Protection Agency recommends that the information also be made actively available at the point where the data is submitted.
For example, this could be a short piece of text below the form with a direct link to the privacy policy.
It could be as simple as:
When you submit the form, we will process your information in order to respond to your inquiry. Read more in our privacy policy.
This way, the user knows that the information is being processed, why it is being collected, and where to find more information.
Ask only for what you actually need
Another good rule of thumb is to look at the form itself.
Do you really need a date of birth?
Address?
Company name?
Phone number?
The more information you collect, the more personal data you must have a legitimate purpose for processing.
The Danish Data Protection Agency’s guidelines are based on the principle that companies should not collect more personal data than they actually need.
A standard contact form can therefore often be very simple.
A contact form and a newsletter are not the same thing
Here, it is important to distinguish between different purposes.
If someone gives you their email address because they want an answer to a question, that does not automatically mean that the address may also be used for newsletters or other marketing purposes.
This is a different purpose and may require separate consent.
So a checkbox may well be relevant on a form—but not necessarily to “accept the privacy policy.”
For example, this may be relevant if the user actively chooses to subscribe to a newsletter as well.
So what should the privacy policy include?
The Danish Data Protection Agency emphasizes, among other things, that the data subject must be informed about who is processing the data, why it is being processed, what data is being processed, and how long it will be retained.
Exactly what should be included depends on how the company specifically processes personal data.
That is why you should not simply copy a privacy policy from another website.
Keep the form simple
For most standard business websites, GDPR requirements regarding contact forms do not have to make the form cumbersome or difficult to use.
The most important thing is that you know what information you are collecting, why you are collecting it, and that visitors can easily find information about how it is processed.
And before you add yet another mandatory checkbox, it’s worth asking:
What exactly is the customer being asked to agree to?


