Guides

Guide · Data protection

The contact form. GDPR-compliant, without Google CAPTCHA.

A contact form lowers the barrier for enquiries and collects personal data along the way. For a welfare association, that quickly includes diagnoses and official letters. This guide shows what a form needs under data protection law and how spam protection works without Google.

By Paul Czichos, consulting and project support at czichos.net GmbH · Updated

What a form needs

What a GDPR-compliant contact form needs. Six points every form should meet.

None of them is complicated.

01

Encrypted transmission

The page runs over HTTPS. This also applies to embedded forms and wherever they send their data.

02

Only the fields you need

Required is what you need to reply, usually an email address. Phone number, postal address or date of birth are optional or left out.

03

A privacy notice

A link to the privacy policy right next to the form, with the information required by Article 13 GDPR. A consent checkbox is usually not needed just to answer an enquiry.

04

A retention period

Decide when enquiries are deleted, and make sure it actually happens.

05

Spam protection without data leaks

A CAPTCHA that sends data to a third party is a data protection issue in itself. The next section covers alternatives.

06

A contract if a service is involved

If an external service receives the form data, it processes it on your behalf. Then you need a data processing agreement.

Spam protection without Google

CAPTCHA alternatives without Google. Spam protection without picture puzzles.

Google reCAPTCHA sends data about visitors to Google and analyses their behaviour. Many data protection authorities therefore consider consent necessary, which means a cookie banner. Many people also struggle with the picture puzzles, especially those with visual impairments.

For an association’s form, a combination of simple measures is almost always enough:

  • Honeypot field: a field people cannot see but bots fill in anyway.
  • Time check: whoever submits a form within one second is not a person.
  • Proof of work: the browser quietly solves a small calculation. It costs nothing for a single visit and becomes expensive for mass submissions. ALTCHA is an open-source example.
  • Rate limit: only a handful of submissions per address within a quarter of an hour.

A form without spam protection can even put your own mail server on a blocklist. The guide to checking your mail server against blocklists shows how to spot it.

Where the message goes

Delivering and storing form enquiries. What happens after you press send.

Many forms store every enquiry in the website’s database and send an email as well. Then the data exists twice, and everyone forgets the copy on the website. A better form delivers the enquiry and keeps only what is strictly necessary.

Deliver enquiries to a shared role mailbox instead of one person. Then nothing gets stuck when someone is on holiday or hands over the task. A confirmation with a reference number saves the sender asking whether the message arrived.

Set deletion periods for enquiries and add the form to your record of processing activities. The guide to the GDPR for associations explains both. If an enquiry turns into a conversation, see the guide to GDPR-compliant video consultations.

Do it yourself or have it done

A WordPress form or a service? For a single form, what you have is often enough.

If your website runs on a common site builder or WordPress, you probably have the tools already. It gets complicated with many forms and sensitive content.

Set it up yourself

If you have one or two forms

  • Your website system’s formSite builders and WordPress plugins come with forms. Add a honeypot field and switch off reCAPTCHA.
  • Embed ALTCHA yourselfOpen-source spam protection by proof of work, without cookies or third parties. Needs a little integration work.
  • Turn off storageMany form plugins also save every enquiry in the database. If you don’t need that, switch it off.

Have it done

If many offices receive enquiries

  • Several branches, several websitesEvery office should get its own enquiries, and all forms should be equally secure.
  • Sensitive contentWith official letters, diagnoses and attachments, it matters that nothing is stored unnecessarily and deletion periods apply.
  • Nobody maintains the pluginsOutdated form plugins are among the most common ways into association websites.

On our own behalf: we earn money from the second column. If your association has a single contact form, set it up with a honeypot and without reCAPTCHA. It costs nothing.

Common questions

Contact form FAQ. What associations ask.

Does a contact form need a consent checkbox?

Usually not. Someone sending an enquiry wants a reply, and processing for that purpose is lawful without separate consent. A clearly visible link to the privacy notice is enough. If you want to use the data for something else, such as a newsletter, you need consent.

Is Google reCAPTCHA GDPR-compliant?

That is disputed. Because reCAPTCHA sends data to Google and analyses visitor behaviour, many data protection authorities consider consent necessary. Honeypot fields or proof of work need no third party.

How long may I keep enquiries?

As long as you need them to deal with the matter, plus any statutory retention duties. A fixed period, such as one year after closing, is good practice. What matters is that deletion actually happens.

May the form accept attachments?

Yes, if the transfer is encrypted, files are not stored unnecessarily and the size is limited. With official letters or medical certificates, pay particular attention to where the files end up.

Contact forms with secContact

secContact is embedded in your website via an iframe. Spam is kept out by a combination of proof of work, a honeypot and a time check, without Google. The enquiry goes to the right office and is not kept in a database. We retain only a reference number and basic details and delete them after twelve months.

See secContact

Forms on several websites? Ask us.

Tell us how many forms you have and who receives the enquiries. We will tell you whether secContact fits or your website system can already do it with a few settings.

No obligation and no contract. We usually reply within one working day and are happy to show you the tool in a short call.

Prefer to reach us directly? Send an email · call 030 994048000

Address czichos.net GmbH
Königsweg 220
14129 Berlin