Legal and accounting support for UK businesses and individuals
office@yudey.uk
Data protection and digital business guides · 6 min read

Collecting information through website forms

Design business website forms that collect necessary information, explain its use and support secure handling and appropriate marketing choices.

Jurisdiction: United Kingdom.

A website form should collect the information needed for its stated task. Start with the action the visitor wants to complete and remove fields that have no justified purpose. Provide relevant privacy information at the point of collection and route submissions to a controlled destination.

Separate an enquiry from optional marketing and avoid asking for sensitive documents in an unrestricted first-contact field. Review embedded services, anti-spam tools and analytics as part of the data flow. Check the actual form delivery, access and retention settings rather than only the visible labels.

Begin with the visitor's immediate task

Decide what is needed to respond to the enquiry before selecting fields. A first-contact form may need a name, suitable reply method and a short description, while detailed identification documents may belong to a later controlled stage. Explain which fields are required and why. Do not collect a date of birth, home address or complete case history merely because the form builder makes those fields easy to add.

Write prompts that discourage unnecessary sensitive detail. For professional services, a concise description can often establish the service category without asking visitors to disclose confidential evidence immediately. If attachments are genuinely needed, consider a separate upload process with appropriate access and retention controls. A disclaimer beside an unrestricted upload button is less effective than a design that limits unnecessary collection from the outset.

Explain the use where the person submits

Place a short, relevant explanation beside the submission action and link to the full notice. The ICO's design guidance supports considering privacy within the actual service design. [1] Do not force visitors to agree that they have consented to every use merely to send a question. Establish the proper lawful basis for responding and present any optional marketing choice separately.

Use Privacy notices for UK small businesses to align the privacy explanation and Marketing consent and customer preferences for marketing preferences. Check that the wording matches the automation: a form described as contact us should not silently subscribe every enquirer to promotional email. Keep the version of the wording associated with the submission where evidence of a choice is needed, rather than storing only an unexplained true value in a database.

Trace delivery beyond the visible form

Identify whether submissions go to a database, email service, CRM or several destinations. Check the recipients of notifications and whether the full message is included in an email subject or push notification. Restrict access to the people handling enquiries. Avoid sending sensitive attachments to a broad distribution list merely because that was the default notification address when the site was first created.

Review anti-spam tools, embedded scheduling services and analytics as part of the data flow. These providers may receive information even if the business never reads it itself. Assess their role and relevant settings. Do not assume a successful form submission proves that the intended team received it; test acknowledgement, internal delivery and the process for failed notifications using harmless sample information.

Plan error handling and enquiry retention

Make error messages specific and accessible without exposing submitted information in public URLs or logs. If a visitor resubmits after an apparent failure, avoid creating multiple uncontrolled copies. A confirmation should explain what happens next without promising an unverified response time. Provide an alternative contact route that the business can actually support when the form is unavailable.

Define how abandoned, duplicate and completed enquiries are handled. Assign an owner for unanswered submissions and set a retention decision appropriate to the purpose. Where an enquiry becomes a client matter, transfer the relevant information through a controlled process instead of leaving permanent parallel copies in the website database and every staff inbox. Retain only the evidence needed for the applicable ongoing purpose.

For Website terms and cookie review, bring screenshots, field definitions, sample notifications and a diagram of destinations. Ask the developer to confirm actual storage and third-party behaviour, not just the visible layout. The review should produce a field-by-field decision and a delivery, access and deletion specification. Revisit it when adding a new form type or integration because small interface changes can create substantial differences in how information is used.

Test attachments and confirmation messages

Submit a sample enquiry containing an attachment, then follow it through the confirmation email, staff notification and customer management system. Check whether the attachment is copied unnecessarily, whether a notification exposes its contents on a shared device and whether staff can open it without granting broad folder access.

Review the confirmation message as part of the same journey. It should accurately describe what happens next and provide a useful correction route if the person supplied the wrong details. Avoid reflecting sensitive free-text content into an email subject line. These checks often reveal avoidable copies that are not apparent when the designer looks only at the visible fields on the website.

Illustrative scenario

A professional services form asks visitors to upload passports before the business has assessed their enquiry. The team replaces that request with a brief matter summary and contact details. If identity evidence becomes necessary later, it is collected through an agreed process appropriate to the purpose and sensitivity.

Preparation checklist

  • Justify each field and identify required versus optional input.
  • Provide relevant privacy information beside the form.
  • Separate marketing choices from the requested service.
  • Check delivery, access, retention and third party integrations.

Frequently asked questions

Do we need a mandatory privacy consent box?

Not every enquiry process relies on consent. Identify the proper basis and give clear information. Keep optional marketing choices separate from the action needed to request a response.

Should we request passports on first contact?

Only collect identity evidence when justified for the actual stage and purpose. A brief enquiry often does not need it; use an appropriate controlled process when detailed verification becomes necessary.

Is email delivery alone a complete form workflow?

No. Check receipt, access, failure handling and retention across every destination. A success message can appear even when an internal notification is lost or sent to an unsuitable mailbox.

What should we use for testing?

Use harmless synthetic details to test submission, errors, notifications and deletion. Do not create real client records or expose confidential documents merely to check that the form works.

Official sources

Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.

  1. ICO: Data protection by design and default

General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.

Report a correction