Whether you’re a small business collecting enquiries through a contact form, a landlord managing online rental applications or a charity handling referral requests – as long as you are operating in the UK, GDPR applies to you and your organisation. If your forms aren’t compliant, you risk complaints, enforcement action and even fines from the Information Commissioner’s Office.
In this article, we’ll look at:
- Why GDPR applies to website contact forms
- The role of the ICO (Information Commissioner’s Office)
- What you need to do to make sure your forms are compliant
Why GDPR Applies to Contact Forms
Any time you collect personal data - whether it’s a name, email, phone number or more sensitive information such as financial details or medical history, you are a “data controller” under UK data protection legislation.
That means you’re responsible for:
- Collecting the data lawfully, fairly and transparently
- Making sure you only ask for data you really need (also referred to as ‘data minimisation’)
- Keeping all data secure
- Informing people about how you’ll use their data
Examples:
- A landlord using an online form for tenancy applications is processing personal data like addresses, income details and references.
- A charity’s referral form may involve special category data (such as health or safeguarding concerns).
- A small business contact form may only ask for a name and email - but it still counts as personal data.
In all these cases, GDPR applies.
The Role of the ICO
The Information Commissioner’s Office (ICO) is the UK’s regulator for data protection. Their role includes:
- Issuing guidance: They publish clear advice on how organisations should obtain, record and manage consent.
- Investigating complaints: If someone believes their data was misused or mishandled, they can report it to the ICO.
- Taking enforcement action: In serious cases, the ICO can issue fines, enforcement notices or even order organisations to stop processing data.
- Education: The ICO offers resources tailored for small businesses and charities who may not have in-house legal teams.
It’s worth noting that the ICO is generally supportive, not punitive - especially with smaller businesses. Their focus is often on helping you comply, not immediately handing out penalties. But repeated or serious failings can, and do, result in enforcement.
Key GDPR Requirements for forms on your website
Here are five practical steps to keep your contact or application forms compliant:
1. Be clear about the purpose
Tell people why you’re collecting their data and what you’ll do with it.
- For a landlord: “We will use this information to assess your tenancy application.”
- For a charity: “We’ll use these details to process your referral request and provide support services.”
- For a business: “We’ll use your contact details to respond to your enquiry.”
This helps you meet the GDPR principle of lawfulness, fairness and transparency.
2. Link to your privacy policy
Every form should include a clear link to your privacy policy, ideally near the submit button.
This policy should set out:
- Who you are (data controller details)
- What data you collect and why
- How long you’ll keep it
- Who you may share it with
- How people can exercise their rights (including withdrawing consent)
3. Handle consent correctly
The ICO is clear: consent requests must be specific, informed and freely given.
- Do not pre-tick boxes.
- Keep consent requests separate from general terms and conditions.
- Use plain language, not legal jargon.
Examples:
- If you’re only collecting data to respond to an enquiry, you don’t need a checkbox - legitimate interest may apply.
- If you want to also send marketing emails, you need a separate opt-in box such as:
“Tick this box if you’d like to receive our monthly email newsletter. You can unsubscribe at any time.”
4. Collect only what you need
Asking for more information than necessary is a data protection red flag.
- Landlords should avoid asking for documents like passports or bank statements at the first stage - keep it proportionate.
- Charities should only collect sensitive information if it’s essential for delivering services.
- Businesses should stick to basics like name, email, phone number and enquiry message.
5. Respect withdrawal of consent
If you rely on consent (e.g. for marketing), you must make it easy to withdraw.
This might be:
- An unsubscribe link in every email
- A simple request process (such as “reply ‘STOP’ to opt out”)
- A clear privacy contact email on your site
Summary
The ICO expects all organisations -no matter how small -to treat personal data responsibly.
To stay compliant with GDPR when using online forms:
- Be transparent about why you’re collecting data
- Always link to your privacy policy
- Use consent only when appropriate, and ask for it properly
- Limit data collection to what’s necessary
- Give people easy ways to withdraw consent
By following these principles, charities and small businesses can avoid complaints, build trust and stay on the right side of the law.
If in doubt, check the ICO guidance on consent or speak with a GDPR consultant.