Help center
Go to home
Go to templates
Go to settings
Go to help center

How to create a GDPR compliant form

Collect consent the way GDPR expects: an unticked checkbox, a plain explanation with a link to your policy, and the retention and deletion controls behind it.

If a form collects a name, an email address or anything else that identifies a person, the person filling it in has rights over that data, and you have duties. This guide shows how to build a form in Tinyform that asks for consent properly, and which controls cover the rest.

What GDPR is

The General Data Protection Regulation is the European law on handling personal data. It covers anyone who collects, stores, uses or passes on data about people in the European Economic Area, and the UK keeps a near-identical law of its own. If your respondents are there, the rules reach you wherever your forms are served from.

A form built for personal use may fall outside it, and some small organisations are exempt from parts of it. The official GDPR site is the place to check, together with your adviser.

Building the form

The GDPR page describes how this product handles data on your behalf. The points below are about the form itself, and they matter whenever a question asks for a name, an email address, a phone number or anything similar.

Collecting consent

Consent has to be freely given, specific, informed and unambiguous. The respondent must know what they are agreeing to, why you want the data, what you will do with it and whether anyone else will get it, and they cannot be forced into agreeing.

In Tinyform that comes down to two blocks:

  • A Checkboxes question for the consent itself. Leave the box unticked; a pre-ticked box is not consent. Mark the question Required if the form cannot proceed without agreement. If you will use the data for more than one purpose, add one checkbox per purpose, each with its own wording.
  • A text block above it explaining what you collect and why, with a link to your privacy policy. The text toolbar's Add link puts the link in, and the checkbox's own label takes bold, italic and links too, so the policy can be linked from the consent line itself.

Control and deletion

Respondents have the right to see the data you hold on them and to have it removed. Tell them how to ask, which can be as simple as an email address in the form's explanatory text.

Your install gives you the controls to act on such a request:

  • In the form's Submissions tab, any response can be deleted from its row or in a batch. Deleting a response removes its uploaded files and any drawn signature with it, in the same operation. See How do I delete responses?.
  • A single response can be downloaded as a PDF from its row, and the tab exports every response as a CSV, which is how you answer a request to see the data.
  • Submissions data retention in Settings deletes responses automatically after a period you set, from minutes to years, so a form collects nothing it keeps for longer than it needs. See Control submissions data retention.
  • Deleting a form moves it to Trash, where it waits 30 days before it and its responses are purged; restoring it before then brings everything back.
  • A respondent's uploads and signatures have no public address. They can be read only by a signed-in member of the workspace that owns the form, or through a short-lived signed link the app itself mints.

Answers are not handed to any third party for the product's own purposes. Where the data rests and how long a backup of it is kept are stated in the privacy notice and the data processing agreement, which are where those facts belong.