Blog

GDPR-Compliant Form APIs

By
The Reform Team
Use AI to summarize text or ask questions

A form API can help you meet GDPR duties - but it cannot make your business compliant on its own. I start with three checks: collect only needed fields, document a lawful basis for each use, and keep marketing consent separate from inquiry handling.

That applies to U.S. businesses targeting or monitoring people in the EU, too. Business contact details can still be personal data.

Here’s the checklist I use for the entire lead flow:

  • Collection: Limit fields and API payloads, provide clear notices, and record consent when needed.
  • Rights and retention: Set deletion rules across forms, CRMs, logs, and backups. Plan to respond to rights requests within 1 month.
  • Vendors and transfers: Check recipient roles, processor agreements, and the legal basis for transfers outside the EEA.
  • Security: Protect credentials, verify webhooks, restrict access, and plan for breach reporting within 72 hours when required.
  • Testing and ownership: Assign owners and test withdrawals, failed deletions, retries, and backup restores.

My rule: <u>follow the data, not just the form</u>. Every connected system needs checks that keep privacy choices intact.

GDPR Form API Lead-Flow Control Map

GDPR Form API Lead-Flow Control Map

Collect Lead Data Lawfully

Assign one lawful basis to each purpose. Record that basis along with the recipients and retention period. Use pre-contract steps only when the processing is needed to take steps the person requested before a contract begins.

Keep inquiry handling, marketing choices, and terms acceptance separate. Acknowledging a notice isn't the same as giving consent. Marketing also needs a check against applicable ePrivacy rules.

For each consent purpose, use an optional, unticked control. In access-controlled records, store the exact consent text, notice version, user ID, form or campaign ID, timestamp with time zone, consent status, and withdrawal events. Make withdrawal easy, and ensure later syncs can't restore permission after someone withdraws it.

At collection, link to a notice that names the controller and states the purposes, lawful bases, required fields, recipients, retention periods, transfers, rights, and contact details. Use the purpose map to stop unapproved fields from passing downstream.

Limit Fields, API Payloads, and Enrichment

Apply controls to every field, including hidden fields and data added through enrichment. Enforce an API allowlist and schema, validate formats, limit free text, and block uploads you don't need.

Review the source, accuracy, disclosure, and lawful basis for enrichment separately. If you need special-category data, document both an Article 9 condition and an Article 6 basis. Otherwise, restrict or remove the collection path.

Field Purpose Lawful basis Required? Destination Retention Deletion method
Work email Respond to inquiry Pre-contract steps or legitimate interest, as documented Yes CRM and support inbox Active sales period plus defined follow-up window Delete from CRM, inbox, and backups under the backup schedule
Marketing opt-in Promotional email Consent No Email platform Until withdrawal or scheduled consent review Mark unsubscribed and remove from marketing segments
Company size Qualification Documented legitimate interest or consent, depending on use No CRM Short qualification period Delete field or entire lead record
Free-text message Understand inquiry Same basis as inquiry handling Yes, if needed CRM and support system Inquiry retention period Delete message and attachments

Apply these same field rules to retention and deletion.

Set Up Reform for Controlled Lead Collection

Use Reform to put the field map, separate consent choices, and payload limits into practice. Keep inquiry fields separate from optional marketing choices. Apply conditional routing and email validation, and send only approved fields to integrations.

Treat analytics, partial submissions, spam-prevention data, and enrichment as separate processing activities. Test the form workflow to confirm that consent choices remain separate and integrations receive only approved fields.

With collection controls in place, move on to rights handling, retention, and deletion.

Manage Data Rights and Retention

Respond to Data-Subject Requests

Assign a privacy owner to each request. Record the request ID, received timestamp, requested right, systems in scope, owner, status, deadline, and completion evidence. Match identity checks to the risk: use an existing account or email confirmation rather than asking for government ID by default.

Use the lead-flow map to locate every copy. Search live systems, queues, exports, logs, support tools, and relevant backups using stable IDs and known aliases. Respond within 1 month. For complex or numerous requests, you can extend the deadline by up to 2 months, but explain the reason within the first month.

Handle access, correction, erasure, restriction, portability, or objection requests as applicable. Keep restricted records out of ordinary use. Portability applies to user-provided data processed automatically based on consent or a contract. Stop direct marketing when someone objects, and stop consent-based processing when they withdraw consent.

Notify recipients of corrections, erasure, or restriction unless doing so is impossible or disproportionate. Explain what you retained, why you retained it, and how the person can challenge the decision. Use versioned, idempotent updates so retries or stale events cannot restore erased profiles or remove contact suppression. Keep only the minimum suppression data needed to enforce the request.

Use that same system map to determine what must stay, what must expire, and what to delete next.

Set Retention Periods by Record Type

GDPR sets no universal retention period. Define the purpose, trigger, period, action, and owner for each record category. Give each row one owner and one system of record. Check periods against legal duties and actual business needs - not whether the data might be useful someday.

The table below is a planning template, not a set of GDPR-required deadlines. Replace each policy window with an approved duration, and review it whenever purposes or integrations change.

Record type Purpose System of record Retention trigger Policy period Action Owner
Submissions Inquiry handling Form database Last sales activity Approved inquiry window Delete or retain only approved business records Form operations
CRM leads Sales follow-up CRM Last meaningful interaction Approved retention window Delete or anonymize unnecessary profile data Sales operations
Engagement data Campaign measurement Marketing system Last campaign interaction Approved measurement window Aggregate or delete events Marketing operations
Enriched attributes Qualification CRM or enrichment service Qualification ends Until purpose ends Remove unnecessary attributes Sales operations
Consent evidence Accountability Consent ledger Relevant processing ends Justified accountability or legal window Retain necessary evidence, then delete Privacy owner
Suppression records Prevent unwanted marketing Suppression store Withdrawal or objection While necessary to enforce the request Retain minimum identifier and status Privacy owner
API logs Security and troubleshooting Log store Log creation Short security-log window Redact payloads; expire logs Security owner
Backups Disaster recovery Backup platform Backup creation Fixed rotation window Expire; reconcile restored data Infrastructure owner

Automate and Verify Deletion

Run scheduled deletion jobs and time-to-live limits (TTLs) for temporary submissions, webhooks, queue messages, debug traces, and exports. Track acknowledgments from every integration. Retry temporary failures and escalate any that remain unresolved.

Restrict access to archives retained for a specific legal need, and prohibit ordinary business use. If deleting individual records from backups is impractical, keep erased data inaccessible until those backups expire. Before processing resumes after any restore, reconcile the restored data against deletion and suppression records.

Keep personal data in logs to a minimum. Log the request ID, type, timestamps, systems contacted, outcome, retry status, owner, and lawful reason for retaining any data - not full submissions.

Pseudonymization is not deletion. Tokens and hashes remain personal data when they can be linked back to a person. Use anonymization only when identification is no longer reasonably possible.

Test the full workflow with synthetic leads. Include correction, restriction, withdrawal, deletion, failed deliveries, and backup restoration. Check deadline compliance, propagation time, and whether old events reactivate records.

Once deletion works, check which third-party systems still receive data and which transfers leave the EEA.

Secure Integrations and Manage Data Transfers

Use the lead-flow map to check every downstream recipient, access point, and transfer path.

Check Recipient Roles and Processor Agreements

Classify recipients by what they actually do, not what the contract calls them: processor, independent controller, or joint controller. Check whether they reuse, profile, or enrich the data, then choose the agreement that matches their role.

An Article 28 processor agreement must cover instructions, confidentiality, security, subprocessor authorization, help with rights requests and breaches, audit information, and deletion or return. Before granting access, verify the purpose, retention period, data categories, and current subprocessors.

Keep an integration register like the one below. Replace each instruction with verified details for that recipient. Unresolved agreement or transfer checks must block approval.

Recipient Data received Role Processing location Transfer mechanism Agreement status Retention Rights support
CRM Name, business email, company, source, consent record Processor United States and approved subprocessors EU-U.S. Data Privacy Framework or SCCs, as applicable DPA signed 24 months after last activity Export, correction, deletion
Email platform Email, campaign status, unsubscribe record Processor EEA and United States Adequacy decision or SCCs DPA under review Until suppression or deletion policy applies Suppression and deletion workflow
Analytics provider Event data, IDs, and form metadata Verify role Hosting and access countries Verify mechanism Contract and notice reviewed Short, purpose-specific period Route DSARs
Automation service Workflow fields and routing data Processor Execution and support locations Verify mechanism DPA and subprocessors confirmed Purpose-specific period Route DSARs
Enrichment provider Business email, domain, account data Verify role Vendor-disclosed locations Verify mechanism Approval required 90 days Route DSARs

Check Transfers Outside the EEA

After checking roles, confirm where each recipient stores, accesses, and forwards lead data. EU hosting does not remove transfer requirements. Map overseas access, backups, subprocessors, and onward transfers.

Verify applicable adequacy coverage or safeguards such as Standard Contractual Clauses (SCCs). When using SCCs, assess destination-country laws and practices, the risk of public-authority access, and any supplementary measures needed. For U.S. recipients, check the organization’s current EU-U.S. Data Privacy Framework certification and service coverage before relying on it.

Record processing locations, subprocessors, transfer checks, assessments, and relevant privacy-notice disclosures. Certification does not replace a processor agreement, and encryption alone does not authorize a transfer.

With transfer requirements in place, secure credentials, webhooks, and logs.

Secure API Access, Webhooks, and Logs

Use HTTPS/TLS with certificate validation. Encrypt stored lead data and backups, and give service accounts only the permissions they need.

Keep secrets out of browsers and source code. Use managed secret storage, set rotation schedules, and rotate credentials immediately after suspected exposure. Keep development, staging, and production credentials, endpoints, data, and access permissions separate.

Verify webhook signatures before processing events. Reject stale or duplicate events, validate schemas, and apply rate limits and spam controls. Log event IDs, status codes, and retries - not submitted answers or auth headers.

Create an incident runbook with named security, privacy, and processor contacts. Include credential revocation, webhook isolation, evidence preservation, impact assessment, and records of notification decisions and the reasons behind them.

Processors must notify the controller without undue delay after becoming aware of a personal-data breach. The controller must assess the risk and, when required, notify the competent authority within 72 hours of becoming aware of it.

Security controls do not replace lawful collection, recipient agreements, or transfer rules.

Conclusion: Keep a GDPR Lead-Flow Control Map

Once collection, rights handling, retention, and transfers are in place, keep one control map. Link each control to its form setting, API step, connected system, evidence, and owner so you can show that every step works.

Assign Control Owners

Before launch, assign owners for form logic, API security, CRM sync, access control, and privacy review:

  • Marketing: Form purpose and notices.
  • Engineering: API security and webhook behavior.
  • Sales operations: CRM sync.
  • IT/security: Access controls.
  • Privacy/legal: Higher-risk decisions.

Each owner should keep evidence and a review date. Make clear which controls meet legal requirements, which act as safeguards, and which reflect business choices.

Get qualified privacy or legal review when lawful bases are uncertain, data is sensitive or high risk, recipient roles are unclear, or transfers are complex.

Once owners are assigned, test failure paths to find gaps in the map.

Test Failures and Review Changes

Test consent withdrawal, queued deletion, retry loops, and transfer-location changes. Recovery must not restart blocked processing. Record expected results, timestamps, failures, evidence, and a remediation owner.

Review the map after any material process change and on a fixed schedule. Check form fields, lawful bases, consent, permissions, keys, webhooks, processors, transfers, retention jobs, failed deletions, DSAR timing, and audit-log access.

Close each review with evidence and remediation deadlines. Keep diagnostic records to a minimum.

FAQs

How do I choose a lawful basis for lead collection?

Document why you collect each data field, whether it’s to fulfill a contract, meet a legal obligation, or act on a documented user preference. Map each field to its destination and intended use.

For consent, use clear opt-in checkboxes tied to specific processing activities. Keep consent records for audits, and collect only the personal data your defined workflows need.

How can I verify deletion across integrations?

Keep an inventory of every system, backup, and log that receives or stores lead data. Deleting a record in your form builder doesn’t automatically delete synced copies in CRMs, email sequencers, or error logs. Document and run a separate deletion workflow for each destination.

Test these workflows regularly with synthetic records to check that deletion works across your stack. Keep detailed deletion audit logs as proof of compliance.

What if a vendor changes where it processes data?

Assess the compliance impact right away. Under GDPR, you must ensure the new location maintains the agreed level of data protection.

Check whether transfer mechanisms, such as Standard Contractual Clauses (SCCs) or Data Privacy Framework documentation, need updates. Review your Data Processing Agreement (DPA) for requirements to give advance notice of subprocessor or hosting-region changes.

Update your data inventory and audit logs, and keep retention and security policies consistent across systems.

Related Blog Posts

Use AI to summarize text or ask questions

Discover proven form optimizations that drive real results for B2B, Lead/Demand Generation, and SaaS companies.

Lead Conversion Playbook

Get new content delivered straight to your inbox

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The Playbook

Drive real results with form optimizations

Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.