English
consentglass · GDPR scanner for websites

HomeGuides › Service

Embedding Jotform in a GDPR-compliant way

Jotform (jotform.com, Jotform Inc., USA) is a widely used form builder. By default, forms and the submitted data are processed on US servers; an EU server can optionally be selected.

Jotform offers three server regions: US, EU and Canada. The choice is made per account and determines where forms are hosted and responses are stored. For the German market, the EU server is the obvious choice — it moves storage to Frankfurt and eases the third-country question. Important: the switch is not retroactive; existing forms and data have to be actively migrated.

With Jotform, embedding is usually done via an iframe plus a feeder script that adjusts the height. Both load on page load. Anyone who wants to avoid this links the hosted form (form.jotform.com/...) or loads the iframe only after a user interaction. Jotform also sets cookies depending on the form functions (e.g. save progress), which belong in the cookie statement.

An often overlooked point is the add-on functions: payment integrations, reCAPTCHA against spam, email autoresponders and integrations to Google Sheets or CRM systems each bring their own recipients and data flows. Every active integration belongs in the privacy policy.

Is this a risk?

An embedded Jotform form loads scripts from jotform.com or the associated CDN domains on page load and establishes a connection to Jotform servers. This access to the device is not necessary without active use and therefore requires consent under Section 25(1) TDDDG if the form is integrated globally. Without an EU server, the form data is stored in the USA.

What you can do

Häufige Fragen

Can Jotform be used in a GDPR-compliant way with the EU server?
The EU server moves hosting and data storage to the EU and thus eases the third-country transfer. The consent question for a globally embedded form script and the DPA are unaffected by this.
Do I have to choose the EU server before creating the forms?
Ideally yes. The server region applies per account and is not retroactive. When switching, existing forms and responses have to be actively migrated to the EU server.
Which cookies does Jotform set?
Several, depending on the form functions (session management, save progress, spam protection). The specific cookies set should be checked in the network tab and documented in the cookie statement.
What about reCAPTCHA in Jotform forms?
If you enable the reCAPTCHA spam protection, Google reCAPTCHA loads in the form — with the same data protection questions as any reCAPTCHA integration. Alternatives are Jotform's own honeypot or a time filter.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.