Now launchingAI Receptionist — free setup, first 3 months free with a package.Learn more →
← Guides

How does GDPR apply to a small business booking or enquiry form?

A booking or enquiry form is personal data processing under GDPR from the moment it collects a name, phone number or email — so you need a valid lawful basis, a clear statement of what happens to the data, and a plan for how long you keep it. Some sectors (health-adjacent services in particular) collect special category data and face a higher bar under Article 9.

This is general information, not legal or professional advice. Confirm current rules directly with the ASAI, your industry's own regulator (if it has one), or your own advisor before relying on it.

What a booking form actually collects

Even a short form processes personal data — name, phone, email, and often the nature of the enquiry. That's enough to bring GDPR into play regardless of business size.

Some sectors go further: a form that asks about symptoms, treatment, or anything revealing health information is processing special category data under Article 9, which needs an additional lawful condition on top of the ordinary one. If that's your sector, treat the form accordingly.

What this changes in practice

Ask for less. The strongest privacy position and the strongest conversion position agree here: a short form collects less data and completes more often — three-field forms convert around 25%.

Know where the submission goes. A form that emails a plain-text submission to a personal address, or posts into a third-party tool outside the EU, is a different risk profile from one writing to a controlled system.

Have a processing agreement with anyone handling it on your behalf — form provider, CRM, booking software.

Say what happens to the data at the point of collection, in language a customer understands, and retain it only as long as you need it.

The common failure

The most common problem we see is not a missing privacy policy — it is a form built by a general web agency with no thought given to what the data is, wired into whatever tool was convenient, with submissions sitting indefinitely in an inbox.

That is a compliance issue and an operational one: enquiries in a personal inbox get missed, which is the same reason it costs the business money.

Questions

Is consent enough on its own?

Explicit consent is one valid lawful basis, but it must be freely given, specific, informed and unambiguous, and withdrawable. Whether it is the right basis for your form is a question for your own advisor.

Who is responsible — the business or the web agency?

The business is normally the data controller and carries the obligation. An agency handling data on your behalf is typically a processor and should be covered by a written agreement.

Does GDPR apply to a very small business?

Yes — GDPR applies regardless of business size once you process personal data. There's no small-business exemption from the core obligations.

See your own site rebuilt.

Drop in your business URL. We rebuild your homepage and send it back in 48 hours — no call required.

No call required. No obligation. Yours to keep.

Chat to us