Skip to content

Privacy guide

How to design GDPR-compliant forms

Collect only useful personal data and make the respondent experience clear.

Build this form free

Privacy-conscious form design starts before implementation: decide what data is genuinely needed, why it is needed, and who can access it. A long form that gathers data “just in case” creates risk and weakens completion rates.

This guide is a product-design checklist, not legal advice. Apply it together with your organization’s approved privacy language and retention rules.

Collect only the data you need

Every field should support a stated operational purpose. Remove optional personal details that do not affect the service, decision, or follow-up.

Explain the purpose in plain language

Put the most important context near the relevant field. A respondent should understand what will happen after they submit the form without reading a separate policy first.

Control access and review retention

Share response access only with people who need it, and pair the form with a documented retention and deletion process.

Frequently asked questions

Does adding a consent checkbox make a form GDPR compliant?
No. Consent is only one possible part of a broader lawful, transparent, and proportionate data-handling process.
What is the simplest privacy improvement?
Remove fields that do not have a clear purpose and explain the purpose of the remaining data near the form.

Continue learning