What a booking form actually collects
Even a short form processes personal data — name, phone, email, and often the nature of the enquiry. That's enough to bring GDPR into play regardless of business size.
Some sectors go further: a form that asks about symptoms, treatment, or anything revealing health information is processing special category data under Article 9, which needs an additional lawful condition on top of the ordinary one. If that's your sector, treat the form accordingly.
What this changes in practice
Ask for less. The strongest privacy position and the strongest conversion position agree here: a short form collects less data and completes more often — three-field forms convert around 25%.
Know where the submission goes. A form that emails a plain-text submission to a personal address, or posts into a third-party tool outside the EU, is a different risk profile from one writing to a controlled system.
Have a processing agreement with anyone handling it on your behalf — form provider, CRM, booking software.
Say what happens to the data at the point of collection, in language a customer understands, and retain it only as long as you need it.
The common failure
The most common problem we see is not a missing privacy policy — it is a form built by a general web agency with no thought given to what the data is, wired into whatever tool was convenient, with submissions sitting indefinitely in an inbox.
That is a compliance issue and an operational one: enquiries in a personal inbox get missed, which is the same reason it costs the business money.
Questions
Is consent enough on its own?
Explicit consent is one valid lawful basis, but it must be freely given, specific, informed and unambiguous, and withdrawable. Whether it is the right basis for your form is a question for your own advisor.
Who is responsible — the business or the web agency?
The business is normally the data controller and carries the obligation. An agency handling data on your behalf is typically a processor and should be covered by a written agreement.
Does GDPR apply to a very small business?
Yes — GDPR applies regardless of business size once you process personal data. There's no small-business exemption from the core obligations.
