GDPR-Compliant Form APIs

A form API can help you meet GDPR duties - but it cannot make your business compliant on its own. I start with three checks: collect only needed fields, document a lawful basis for each use, and keep marketing consent separate from inquiry handling.
That applies to U.S. businesses targeting or monitoring people in the EU, too. Business contact details can still be personal data.
Here’s the checklist I use for the entire lead flow:
- Collection: Limit fields and API payloads, provide clear notices, and record consent when needed.
- Rights and retention: Set deletion rules across forms, CRMs, logs, and backups. Plan to respond to rights requests within 1 month.
- Vendors and transfers: Check recipient roles, processor agreements, and the legal basis for transfers outside the EEA.
- Security: Protect credentials, verify webhooks, restrict access, and plan for breach reporting within 72 hours when required.
- Testing and ownership: Assign owners and test withdrawals, failed deletions, retries, and backup restores.
My rule: <u>follow the data, not just the form</u>. Every connected system needs checks that keep privacy choices intact.
GDPR Form API Lead-Flow Control Map
Collect Lead Data Lawfully
Choose Lawful Bases and Record Consent
Assign one lawful basis to each purpose. Record that basis along with the recipients and retention period. Use pre-contract steps only when the processing is needed to take steps the person requested before a contract begins.
Keep inquiry handling, marketing choices, and terms acceptance separate. Acknowledging a notice isn't the same as giving consent. Marketing also needs a check against applicable ePrivacy rules.
For each consent purpose, use an optional, unticked control. In access-controlled records, store the exact consent text, notice version, user ID, form or campaign ID, timestamp with time zone, consent status, and withdrawal events. Make withdrawal easy, and ensure later syncs can't restore permission after someone withdraws it.
At collection, link to a notice that names the controller and states the purposes, lawful bases, required fields, recipients, retention periods, transfers, rights, and contact details. Use the purpose map to stop unapproved fields from passing downstream.
Limit Fields, API Payloads, and Enrichment
Apply controls to every field, including hidden fields and data added through enrichment. Enforce an API allowlist and schema, validate formats, limit free text, and block uploads you don't need.
Review the source, accuracy, disclosure, and lawful basis for enrichment separately. If you need special-category data, document both an Article 9 condition and an Article 6 basis. Otherwise, restrict or remove the collection path.
| Field | Purpose | Lawful basis | Required? | Destination | Retention | Deletion method |
|---|---|---|---|---|---|---|
| Work email | Respond to inquiry | Pre-contract steps or legitimate interest, as documented | Yes | CRM and support inbox | Active sales period plus defined follow-up window | Delete from CRM, inbox, and backups under the backup schedule |
| Marketing opt-in | Promotional email | Consent | No | Email platform | Until withdrawal or scheduled consent review | Mark unsubscribed and remove from marketing segments |
| Company size | Qualification | Documented legitimate interest or consent, depending on use | No | CRM | Short qualification period | Delete field or entire lead record |
| Free-text message | Understand inquiry | Same basis as inquiry handling | Yes, if needed | CRM and support system | Inquiry retention period | Delete message and attachments |
Apply these same field rules to retention and deletion.
Set Up Reform for Controlled Lead Collection
Use Reform to put the field map, separate consent choices, and payload limits into practice. Keep inquiry fields separate from optional marketing choices. Apply conditional routing and email validation, and send only approved fields to integrations.
Treat analytics, partial submissions, spam-prevention data, and enrichment as separate processing activities. Test the form workflow to confirm that consent choices remain separate and integrations receive only approved fields.
With collection controls in place, move on to rights handling, retention, and deletion.
sbb-itb-5f36581
Manage Data Rights and Retention
Respond to Data-Subject Requests
Assign a privacy owner to each request. Record the request ID, received timestamp, requested right, systems in scope, owner, status, deadline, and completion evidence. Match identity checks to the risk: use an existing account or email confirmation rather than asking for government ID by default.
Use the lead-flow map to locate every copy. Search live systems, queues, exports, logs, support tools, and relevant backups using stable IDs and known aliases. Respond within 1 month. For complex or numerous requests, you can extend the deadline by up to 2 months, but explain the reason within the first month.
Handle access, correction, erasure, restriction, portability, or objection requests as applicable. Keep restricted records out of ordinary use. Portability applies to user-provided data processed automatically based on consent or a contract. Stop direct marketing when someone objects, and stop consent-based processing when they withdraw consent.
Notify recipients of corrections, erasure, or restriction unless doing so is impossible or disproportionate. Explain what you retained, why you retained it, and how the person can challenge the decision. Use versioned, idempotent updates so retries or stale events cannot restore erased profiles or remove contact suppression. Keep only the minimum suppression data needed to enforce the request.
Use that same system map to determine what must stay, what must expire, and what to delete next.
Set Retention Periods by Record Type
GDPR sets no universal retention period. Define the purpose, trigger, period, action, and owner for each record category. Give each row one owner and one system of record. Check periods against legal duties and actual business needs - not whether the data might be useful someday.
The table below is a planning template, not a set of GDPR-required deadlines. Replace each policy window with an approved duration, and review it whenever purposes or integrations change.
| Record type | Purpose | System of record | Retention trigger | Policy period | Action | Owner |
|---|---|---|---|---|---|---|
| Submissions | Inquiry handling | Form database | Last sales activity | Approved inquiry window | Delete or retain only approved business records | Form operations |
| CRM leads | Sales follow-up | CRM | Last meaningful interaction | Approved retention window | Delete or anonymize unnecessary profile data | Sales operations |
| Engagement data | Campaign measurement | Marketing system | Last campaign interaction | Approved measurement window | Aggregate or delete events | Marketing operations |
| Enriched attributes | Qualification | CRM or enrichment service | Qualification ends | Until purpose ends | Remove unnecessary attributes | Sales operations |
| Consent evidence | Accountability | Consent ledger | Relevant processing ends | Justified accountability or legal window | Retain necessary evidence, then delete | Privacy owner |
| Suppression records | Prevent unwanted marketing | Suppression store | Withdrawal or objection | While necessary to enforce the request | Retain minimum identifier and status | Privacy owner |
| API logs | Security and troubleshooting | Log store | Log creation | Short security-log window | Redact payloads; expire logs | Security owner |
| Backups | Disaster recovery | Backup platform | Backup creation | Fixed rotation window | Expire; reconcile restored data | Infrastructure owner |
Automate and Verify Deletion
Run scheduled deletion jobs and time-to-live limits (TTLs) for temporary submissions, webhooks, queue messages, debug traces, and exports. Track acknowledgments from every integration. Retry temporary failures and escalate any that remain unresolved.
Restrict access to archives retained for a specific legal need, and prohibit ordinary business use. If deleting individual records from backups is impractical, keep erased data inaccessible until those backups expire. Before processing resumes after any restore, reconcile the restored data against deletion and suppression records.
Keep personal data in logs to a minimum. Log the request ID, type, timestamps, systems contacted, outcome, retry status, owner, and lawful reason for retaining any data - not full submissions.
Pseudonymization is not deletion. Tokens and hashes remain personal data when they can be linked back to a person. Use anonymization only when identification is no longer reasonably possible.
Test the full workflow with synthetic leads. Include correction, restriction, withdrawal, deletion, failed deliveries, and backup restoration. Check deadline compliance, propagation time, and whether old events reactivate records.
Once deletion works, check which third-party systems still receive data and which transfers leave the EEA.
Getting started with GDPR compliance: Consent
Secure Integrations and Manage Data Transfers
Use the lead-flow map to check every downstream recipient, access point, and transfer path.
Check Recipient Roles and Processor Agreements
Classify recipients by what they actually do, not what the contract calls them: processor, independent controller, or joint controller. Check whether they reuse, profile, or enrich the data, then choose the agreement that matches their role.
An Article 28 processor agreement must cover instructions, confidentiality, security, subprocessor authorization, help with rights requests and breaches, audit information, and deletion or return. Before granting access, verify the purpose, retention period, data categories, and current subprocessors.
Keep an integration register like the one below. Replace each instruction with verified details for that recipient. Unresolved agreement or transfer checks must block approval.
| Recipient | Data received | Role | Processing location | Transfer mechanism | Agreement status | Retention | Rights support |
|---|---|---|---|---|---|---|---|
| CRM | Name, business email, company, source, consent record | Processor | United States and approved subprocessors | EU-U.S. Data Privacy Framework or SCCs, as applicable | DPA signed | 24 months after last activity | Export, correction, deletion |
| Email platform | Email, campaign status, unsubscribe record | Processor | EEA and United States | Adequacy decision or SCCs | DPA under review | Until suppression or deletion policy applies | Suppression and deletion workflow |
| Analytics provider | Event data, IDs, and form metadata | Verify role | Hosting and access countries | Verify mechanism | Contract and notice reviewed | Short, purpose-specific period | Route DSARs |
| Automation service | Workflow fields and routing data | Processor | Execution and support locations | Verify mechanism | DPA and subprocessors confirmed | Purpose-specific period | Route DSARs |
| Enrichment provider | Business email, domain, account data | Verify role | Vendor-disclosed locations | Verify mechanism | Approval required | 90 days | Route DSARs |
Check Transfers Outside the EEA
After checking roles, confirm where each recipient stores, accesses, and forwards lead data. EU hosting does not remove transfer requirements. Map overseas access, backups, subprocessors, and onward transfers.
Verify applicable adequacy coverage or safeguards such as Standard Contractual Clauses (SCCs). When using SCCs, assess destination-country laws and practices, the risk of public-authority access, and any supplementary measures needed. For U.S. recipients, check the organization’s current EU-U.S. Data Privacy Framework certification and service coverage before relying on it.
Record processing locations, subprocessors, transfer checks, assessments, and relevant privacy-notice disclosures. Certification does not replace a processor agreement, and encryption alone does not authorize a transfer.
With transfer requirements in place, secure credentials, webhooks, and logs.
Secure API Access, Webhooks, and Logs
Use HTTPS/TLS with certificate validation. Encrypt stored lead data and backups, and give service accounts only the permissions they need.
Keep secrets out of browsers and source code. Use managed secret storage, set rotation schedules, and rotate credentials immediately after suspected exposure. Keep development, staging, and production credentials, endpoints, data, and access permissions separate.
Verify webhook signatures before processing events. Reject stale or duplicate events, validate schemas, and apply rate limits and spam controls. Log event IDs, status codes, and retries - not submitted answers or auth headers.
Create an incident runbook with named security, privacy, and processor contacts. Include credential revocation, webhook isolation, evidence preservation, impact assessment, and records of notification decisions and the reasons behind them.
Processors must notify the controller without undue delay after becoming aware of a personal-data breach. The controller must assess the risk and, when required, notify the competent authority within 72 hours of becoming aware of it.
Security controls do not replace lawful collection, recipient agreements, or transfer rules.
Conclusion: Keep a GDPR Lead-Flow Control Map
Once collection, rights handling, retention, and transfers are in place, keep one control map. Link each control to its form setting, API step, connected system, evidence, and owner so you can show that every step works.
Assign Control Owners
Before launch, assign owners for form logic, API security, CRM sync, access control, and privacy review:
- Marketing: Form purpose and notices.
- Engineering: API security and webhook behavior.
- Sales operations: CRM sync.
- IT/security: Access controls.
- Privacy/legal: Higher-risk decisions.
Each owner should keep evidence and a review date. Make clear which controls meet legal requirements, which act as safeguards, and which reflect business choices.
Get qualified privacy or legal review when lawful bases are uncertain, data is sensitive or high risk, recipient roles are unclear, or transfers are complex.
Once owners are assigned, test failure paths to find gaps in the map.
Test Failures and Review Changes
Test consent withdrawal, queued deletion, retry loops, and transfer-location changes. Recovery must not restart blocked processing. Record expected results, timestamps, failures, evidence, and a remediation owner.
Review the map after any material process change and on a fixed schedule. Check form fields, lawful bases, consent, permissions, keys, webhooks, processors, transfers, retention jobs, failed deletions, DSAR timing, and audit-log access.
Close each review with evidence and remediation deadlines. Keep diagnostic records to a minimum.
FAQs
How do I choose a lawful basis for lead collection?
Document why you collect each data field, whether it’s to fulfill a contract, meet a legal obligation, or act on a documented user preference. Map each field to its destination and intended use.
For consent, use clear opt-in checkboxes tied to specific processing activities. Keep consent records for audits, and collect only the personal data your defined workflows need.
How can I verify deletion across integrations?
Keep an inventory of every system, backup, and log that receives or stores lead data. Deleting a record in your form builder doesn’t automatically delete synced copies in CRMs, email sequencers, or error logs. Document and run a separate deletion workflow for each destination.
Test these workflows regularly with synthetic records to check that deletion works across your stack. Keep detailed deletion audit logs as proof of compliance.
What if a vendor changes where it processes data?
Assess the compliance impact right away. Under GDPR, you must ensure the new location maintains the agreed level of data protection.
Check whether transfer mechanisms, such as Standard Contractual Clauses (SCCs) or Data Privacy Framework documentation, need updates. Review your Data Processing Agreement (DPA) for requirements to give advance notice of subprocessor or hosting-region changes.
Update your data inventory and audit logs, and keep retention and security policies consistent across systems.
Related Blog Posts
Get new content delivered straight to your inbox
The Response
Updates on the Reform platform, insights on optimizing conversion rates, and tips to craft forms that convert.
Drive real results with form optimizations
Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.

.webp)


