GDPR (General Data Protection Regulation)
Definition
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law enacted by the European Union in May 2018. It governs how organizations collect, process, store, and share personal data of individuals within the EU/EEA. Non-compliance can result in fines up to 4% of global annual revenue or 20 million euros, whichever is greater.
Seven Key Principles
1. Lawfulness
Data processing must have a legal basis (consent, contract, legitimate interest, etc.).
2. Purpose limitation
Data must be collected for specified, explicit, and legitimate purposes.
3. Data minimization
Only collect data that is necessary for the stated purpose.
4. Accuracy
Personal data must be accurate and kept up to date.
5. Storage limitation
Data should not be kept longer than necessary.
6. Integrity & confidentiality
Appropriate security measures must protect personal data.
7. Accountability
The data controller must demonstrate compliance.
Why It Matters for Forms and Surveys
Every online form that collects personal data from EU residents must comply with GDPR:
- Explicit consent: use clear, affirmative checkboxes (no pre-checked boxes).
- Privacy notice: link to your privacy policy and explain how data will be used.
- Data minimization: only collect fields that are strictly necessary.
- Right to deletion: provide a way for users to request data erasure.
- Data portability: allow users to export their submitted data.
GDPR Form Compliance Checklist
- ✓Add an explicit consent checkbox with clear language.
- ✓Link to your privacy policy near the submit button.
- ✓Remove any pre-checked consent boxes.
- ✓Only collect fields you actually need.
- ✓Encrypt data in transit (HTTPS) and at rest.
- ✓Set up data retention policies and auto-deletion.
- ✓Provide a mechanism for data access and deletion requests.
- ✓Keep records of consent (who, when, what they agreed to).
Related Terms