Whether your contact form needs a consent checkbox depends entirely on what you plan to do with the details. Replying to an enquiry usually relies on legitimate interests, so no checkbox is needed there. Marketing is different: if you want to add someone to a newsletter or follow up with offers, you need explicit consent through a separate, unticked checkbox, plus a short privacy notice visible near the form.
TL;DR:
- A consent checkbox is only necessary if you plan to add contacts to marketing lists, not for replying to inquiries which use legitimate interests.
- The marketing opt-in checkbox must be unticked by default, separate from the submission button, and clearly specify the purpose and channel.
- Contact form notices should be short and visible, including your identity, purpose, legal basis, data recipients, individual rights, and a link to the privacy policy.
- Record keeping of consent requires storing the exact wording, method, timestamp, purpose, and withdrawal option, with re-permissioning old contacts if needed.
- Privacy policies must detail processing lawful bases, retention periods, processors, international transfers, and individuals’ rights, structured under clear headings.
Table of Contents
- GDPR contact forms: quick compliance checklist (what to do now)
- When do you actually need a GDPR consent checkbox?
- What Article 13 requires you to show on the form
- How do you write a valid marketing opt-in checkbox?
- How should you record and manage consent once it's given?
- How long can you keep contact form data?
- What belongs in your privacy policy for contact form data?
- Copyable Article 13 lines and consent templates
- Why aceSites builds compliance into the form, not as an afterthought
- Get a compliant contact form live today with aceSites
- Sources
GDPR contact forms: quick compliance checklist (what to do now)
If you run a UK business website, here's what to sort out today rather than next month:
- Decide your legal basis first. Is this form for enquiries only, or will you also market to people who submit it?
- Add a short Article 13 notice near the form, not buried three clicks away in your footer.
- Add a separate, unticked marketing checkbox if you intend to send promotional emails or newsletters.
- Declare your processors. If you use a form plugin or CRM, note who processes the data and check you have a data processing agreement in place.
- Set a retention period and actually delete data when it expires, rather than leaving it in a database indefinitely.
- Check your existing privacy policy covers contact-form data specifically, not just cookies or general website use.
None of this takes long once you know the shape of it. Most of the friction comes from not knowing which basis applies to which type of form, which is where a lot of small business sites fall down.
When do you actually need a GDPR consent checkbox?
UK GDPR gives you several lawful bases for processing personal data, and consent is only one of them. Most contact form replies don't need it at all.
Legitimate interests covers the ordinary business of replying to someone who has contacted you. If a customer fills in a form asking about your plumbing rates or your wedding photography packages, you have a legitimate interest in replying, and they clearly expect a response. No checkbox required.
Precontractual measures apply when someone is asking about a service with a view to buying it, such as requesting a quote. This is still processing "necessary for the performance of a contract" the person is trying to enter into.
Consent only becomes necessary when you want to do something beyond the reply itself, such as adding the person to a marketing list.
The decision flow is simple: enquiry only, no checkbox needed; marketing intended, checkbox required. According to the ICO's guidance on consent, consent must be a clear, affirmative action, never assumed or bundled into other terms.
Three mistakes come up repeatedly on small business sites:
- Pre-ticked marketing boxes (not valid consent under UK GDPR or PECR)
- Bundling marketing consent together with terms and conditions or the enquiry itself
- Making form submission conditional on ticking a marketing box that has nothing to do with the enquiry
Pro Tip: If you're not sure whether a use counts as "marketing", ask yourself whether the person would be surprised to receive it. If yes, get consent.
What Article 13 requires you to show on the form
Article 13 of UK GDPR sets out what people must be told at the point you collect their data, not somewhere they'll never read. For a contact form, that means a visible short notice, not a wall of legal text, sitting near the submit button or checkbox.
According to TrustYourWebsite's guide to Article 13 compliance, this first layer should cover:
- Who you are (the controller, usually just your business name)
- Why you're collecting the data (to respond to the enquiry, and separately, for marketing if applicable)
- The legal basis you're relying on
- Who else sees the data, such as a CRM provider or email marketing platform
- What rights the person has, including access, deletion, and objection
- A link to your full privacy policy for anyone who wants the detail
The practical approach is layered disclosure: a single sentence by the form, something like "We'll use your details to respond to your enquiry. See our [privacy policy] for more." Anyone who wants the full picture clicks through. Anyone who doesn't still got the essentials. This keeps the form uncluttered while satisfying the transparency requirement, which auditors treat as the practical standard for compliance.
How do you write a valid marketing opt-in checkbox?
A marketing checkbox only counts as valid consent if it meets a few specific conditions. It must be separate from the enquiry submission, unticked by default, and worded specifically enough that the person knows exactly what they're agreeing to.
According to Duport's guidance on contact form checkboxes, bundling marketing consent with general terms, or ticking the box for the user, invalidates it entirely.
Three examples you can adapt directly:
- "Yes, I'd like to receive occasional emails about new services and offers. You can unsubscribe at any time." (general marketing, one channel)
- "Tick here if you'd like a text reminder before your appointment." (specific, functional, low friction)
- "I'd like to hear about seasonal promotions by email. See our privacy policy for how we handle your data." (specific purpose plus a policy link)
Each works because it names the purpose, the channel, and gives an easy way out. Keep your submit button independent of the checkbox, so declining marketing never blocks the enquiry itself, and keep the label visible rather than shrunk into grey text nobody notices.
How should you record and manage consent once it's given?
Getting consent is only half the job. You also need to keep a record of it and make it just as easy to withdraw as it was to give.
At minimum, your consent log should capture:
- The exact wording shown to the person at the time
- The method used (checkbox, email confirmation, phone opt-in)
- A timestamp
- The specific purpose they agreed to
This level of detail matters if the ICO ever asks you to demonstrate compliance, since the regulator's own guidance treats consent withdrawal as needing to be "as easy as it was to give" consent. That means a one-click unsubscribe link in every marketing email, not a request to phone up or send a letter.
If you're sitting on an older list collected before these standards tightened, it's worth re-permissioning it: send a fresh, clear opt-in request rather than assuming old consent still holds, particularly across mixed channels like paper forms, phone enquiries, and email sign-ups collected at different times.
Pro Tip: Store consent records in the same system as your customer data, not a separate spreadsheet nobody updates. Orphaned records are the first thing an audit finds.
How long can you keep contact form data?
Storage limitation means keeping data only as long as you actually need it, and being able to justify the timeframe if asked.
Reasonable retention periods for most small businesses typically include:
- Simple enquiries that don't convert: a defined duration followed by deletion
- Converted leads or contracts: retention aligning with contract duration and applicable record-keeping requirements
- Server and form-submission logs: a limited period sufficient for security and abuse prevention
Build the deletion schedule into your form handler and database rather than relying on someone remembering to clear it manually. If you use a third-party form plugin, CRM, or email platform, you need a data processing agreement (a DPA) under Article 28, and your privacy notice should name that processor and disclose any transfer outside the UK. Recent regulatory tightening has raised the stakes on getting this documented properly, not just assumed.
What belongs in your privacy policy for contact form data?
Your privacy policy is the second layer, the fuller explanation that sits behind the short notice on the form itself. It needs to cover everything Article 13 requires in full:
- Your lawful bases for each type of processing (enquiry handling versus marketing)
- Retention periods for each data category
- Named processors and any international transfers
- The individual's rights, including access, correction, and deletion
- How to complain to the ICO if they're unhappy with your response
Structure it with clear headings such as "How we use enquiry data," "Marketing communications," and "Your rights," rather than one dense paragraph. Ace-sites has a detailed guide to publishing a UK privacy policy if you want a working structure to adapt, and it's worth reviewing your cookie banner setup at the same time, since cookie consent and form consent often get conflated by mistake.
Copyable Article 13 lines and consent templates
Here are ready-to-adapt snippets rather than abstract principles.
Article 13 short lines, by sector:
- Trades: "We use your details to respond to your enquiry. See our privacy policy for more."
- Salons/beauty: "Your information helps us book and manage your appointment. Full details in our privacy policy."
- Professional services: "We'll process your enquiry to provide the requested information. See our privacy notice."
Marketing checkbox templates (as detailed earlier): specific purpose, named channel, unticked by default, easy withdrawal.
Consent record fields: name, email, wording shown, method, timestamp, purpose, withdrawal date if applicable. A standard template like the TMCP data consent form shows the structure clearly if you want a reference point.
Retention schedule example: enquiries 12 months, contracts for the contract term, logs 30 to 90 days.
Why aceSites builds compliance into the form, not as an afterthought
Most small business owners aren't lawyers, and they shouldn't have to become one just to publish a contact form. Ace-sites builds privacy-notice snippets, DPA-ready third-party integrations, and structured form fields directly into the platform, so the compliance groundwork is already there when you start typing.
Use the built-in templates rather than writing checkbox wording from scratch under deadline pressure. It cuts both the legal risk and the time it takes to get a form live.
— Gabbi
Get a compliant contact form live today with aceSites
Ace-sites gets you a working, GDPR-aware contact form without the hours of research this article just walked you through. The platform's built-in features include privacy-policy snippets, SSL as standard, and form integrations designed to make DPA paperwork straightforward rather than a mystery.
You don't need to brief a developer or chase a template online. Whether you're comfortable building it yourself or want it handled for you, Ace-sites gives you both routes: the AI website builder gets a site with compliant forms live fast, or the free website build service means someone else sets it up properly while you get on with running your business. Start a build today and see your compliant contact form before you pay a penny.
Sources
For the primary rules and ongoing detail beyond this guide:
- How should we obtain, record and manage consent? | ICO
- Do I Need a Checkbox on My Contact Form? UK GDPR
- Contact Form GDPR Requirements: Article 13 Compliance
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
