Search for GDPR and forms and you will find either a thousand words of hedged generality or a consent banner vendor explaining that you need their consent banner. Neither tells a plumber with a contact form what to actually do.
The genuine answer, for the overwhelming majority of small business forms, is shorter than people expect and involves no cookie banner, no consent checkbox, and no data protection officer. It involves being honest about what you collect, using it for the reason you said, and deleting it when you no longer need it.
This is not legal advice and your situation may be unusual. But it is the shape of the obligation, and knowing the shape is what stops people either ignoring it entirely or bolting a consent checkbox onto everything as a talisman.
The checkbox you probably do not need
The most widespread misunderstanding is that collecting anybody's data requires their consent. It does not. Consent is one of several lawful bases, and for an enquiry form it is usually the wrong one.
When somebody fills in your contact form asking for a quote, you do not need their permission to reply. They asked you to. That is covered by legitimate interests, or by steps taken at their request prior to entering a contract, depending on how you look at it. Adding a tick box that says I consent to being contacted is redundant and it costs you submissions.
Worse, if you rely on consent you inherit its rules, including that it must be as easy to withdraw as to give. You have taken on an obligation you did not need in order to do something you were already allowed to do.
If somebody fills in your contact form asking for a quote, you do not need permission to reply to them.
Where consent genuinely is required
There is one common case where you do need it, and it is marketing. Adding somebody to a newsletter, or contacting them about something other than the thing they enquired about, is a separate activity requiring separate permission.
That permission has to be specific, unbundled and affirmative, which in practice means an unticked box with plain wording, separate from the submit action. Pre-ticked boxes have not been valid anywhere in the UK or EU for years and continue to appear on new forms constantly.
The narrow exception, sometimes called the soft opt-in, allows marketing to existing customers about similar products, provided you offered a way out when you collected the address and offer one every time. It applies to customers rather than enquirers, which is a distinction worth getting right.
Say what you collect and why, in two lines
The obligation that does apply to essentially every form is transparency. People are entitled to know who is collecting their information, what it will be used for, and how long it will be kept.
This does not require a wall of text. Two lines under the submit button, linking to a fuller policy for anybody who wants it, is a perfectly reasonable implementation for a small business. We use these details to reply to your enquiry and keep them for two years. We never share them.
The important part is that it is true. A notice that says one thing while your actual practice does another is worse than no notice at all, because it converts a technical shortfall into a written misstatement.
Only ask for what you will use
Data minimisation sounds like a principle for large organisations and it is the single most practical rule on this list, because it is also good form design.
Every field you collect is something you have to secure, something you have to disclose if asked, something you have to delete on request, and something that costs you completions. A date of birth on a form that does not need one is a liability with no upside.
Go through your main form and, for each field, ask what you do with the answer. The fields where the honest answer is nothing are the fields to remove, and most established forms have at least one. Removing it improves conversion and reduces obligation simultaneously, which is not a common combination.
Keeping it forever is a decision
Storage limitation is the requirement people ignore most, partly because doing nothing is the default and deleting takes effort.
There is no fixed period in the legislation. You keep personal data as long as you need it for the purpose, and then you do not. For enquiries that went nowhere, that is typically one to two years. For customers, it is usually longer, and tax rules may require six years for anything connected to a transaction.
The practical step is to pick a number, write it in your notice, and actually do it. A yearly calendar reminder to delete enquiries older than the stated period is a compliance programme that fits in one line and is more than most small businesses have.
Requests from individuals
People can ask what you hold about them, ask for it to be corrected, and in many cases ask for it to be deleted. For a small business these requests are rare and easy to handle, provided you know where the data is.
That proviso is the whole difficulty. If submissions live in a form tool, a CRM, two spreadsheets and an email thread, honouring a deletion request properly is genuinely hard, and most businesses that get one discover this at the worst moment.
Keeping the number of places down is the entire mitigation. One system of record, with other tools referencing it rather than copying it, turns an afternoon of archaeology into a two-minute job.
Where your form tool sits
Your form provider processes personal data on your behalf, which makes them a processor and you the controller. You are responsible for choosing them sensibly and for having an agreement in place, which reputable providers offer as standard.
Two things are worth checking rather than assuming. Where the data is stored geographically, because transfers outside the UK or EEA need a lawful mechanism and it is easier to pick a provider that stores locally than to manage one that does not. And who they pass it on to, which should be a published list rather than a question you have to email about.
A provider that cannot answer either question quickly is telling you something useful about how seriously they take the rest of it.
Cookies are a separate thing
Cookie consent and data protection get conflated constantly and they come from different rules. The cookie banner requirement concerns storing or reading information on somebody's device, which is why it applies to analytics and advertising scripts.
A form that collects a name and an email and sets no tracking cookies does not need a banner for that. If you have embedded an analytics tool that profiles visitors, the banner is about the analytics tool rather than the form.
This matters because banners cost conversions and many sites have one they do not need, or have one that appears before a form and blocks it on mobile. If your analytics does not track individuals across sites, you may be able to remove the banner entirely, which is worth an hour of somebody's time to establish.
The short checklist
For an ordinary small business form collecting contact details and enquiry information, this is more or less the whole of it.
- Remove any field you do not actually use.
- Two lines under the form saying what you collect it for and how long you keep it.
- No consent checkbox for replying to an enquiry. An unticked, separate one for marketing.
- A retention period you have chosen and a reminder in the calendar to honour it.
- Know every place a submission ends up, and keep that list short.
- Check where your form provider stores data and who they share it with.
When to get actual advice
There are situations where the short version is not enough and paying somebody is the right call, and they are reasonably easy to recognise.
Anything involving health information, anything about children, anything involving criminal records, financial services, or large-scale profiling of individuals. Also anything where you are the one being asked to sign a data processing agreement by a larger client, because those are negotiable and the defaults are rarely in your favour.
Outside those, a small business form is a well-trodden path and the obligations are proportionate by design. The regulators have been consistent that a two-person company is not expected to operate like a bank.
Uploads and the things people attach
A file upload field raises the stakes on everything above, because people attach whatever seems relevant and that is frequently more than you asked for. Photographs of a property including the neighbours, a scan of a document with a signature on it, a medical letter attached to explain a cancellation.
The practical consequences are that uploaded files should not be publicly reachable by anybody who guesses a URL, should be covered by the same retention period as the rest of the submission, and should be included when somebody asks you to delete their data. All three are commonly missed, and the first is a genuine risk rather than a technicality.
It is worth saying on the form what to attach and what not to. A line asking for photographs of the affected area only does more to prevent oversharing than any amount of policy text afterwards.
What a breach would look like
Nobody enjoys this part and it is short. If personal data you hold is exposed or lost, and there is a risk to the people involved, you may be required to notify the regulator within seventy-two hours and sometimes the individuals too.
For a small business the realistic scenarios are mundane rather than cinematic. A spreadsheet of submissions emailed to the wrong person. A shared document left publicly accessible. A former employee's account still active. An export sitting in a downloads folder on a stolen laptop.
Most of the prevention is the same advice as everything else here. Hold less, keep it in fewer places, and know where those places are. The businesses that handle an incident badly are almost always the ones that could not say what was in the file.
Writing the notice so somebody reads it
Privacy notices are written to be legally complete and are therefore mostly unread, which means the transparency obligation is technically met and practically failed.
A short version at the point of collection, in the words you would use out loud, does more real work than a long one behind a link. We will use this to reply to your enquiry and nothing else. We keep it for two years. Your details are not shared or sold. That is three sentences and it answers what people actually want to know.
Keep the full notice for the people who want detail and for the obligations the short version cannot carry. The two are complementary, and a business with only the long one has a document rather than a communication.
The honest summary
Most of what makes a form compliant also makes it better. Fewer fields convert more. A clear statement about what happens to somebody's details reduces the hesitation at the contact question. Not adding an unnecessary consent checkbox removes a step.
The exceptions are marketing consent, which does cost you sign-ups and is not optional, and retention, which is pure admin with no upside other than not being in breach and not holding data you would rather not hold if something went wrong.
If you do nothing else after reading this, delete the fields you do not use and write the two lines. That is most of the distance, and it takes half an hour.