English
consentglass · GDPR scanner for websites

HomeGuides › Service

Embedding Typeform in a GDPR-compliant way

Typeform (typeform.com, Typeform S.L. with a corporate link to the USA) is a popular form and survey tool. The embedded form loads scripts from typeform.com and, depending on the embed type, can establish connections even before it is filled in.

Typeform has several embed types: the fullscreen embed, the popup, the slider panel and the inline container. All of them load the Typeform embed script on page load. The plain link to a hosted Typeform (typeform.com/to/...) is the most data-frugal variant — nothing happens here until the click, and the visitor then calls the service themselves.

For the entered responses, Typeform is a processor. The storage location is decisive: depending on the plan, Typeform offers an EU data region in which the responses are stored in Europe. If it is not active, the data is in the USA, and the transfer needs a basis (EU-US Data Privacy Framework) and an entry in the privacy policy. A DPA with Typeform is mandatory in any case.

Forms that collect personal data additionally need their own privacy information directly at the form or linked: which fields are processed, for what purpose, on what legal basis and how long the responses are stored. This applies regardless of the form tool.

Is this a risk?

An embedded Typeform loads JavaScript on page load and establishes a connection to Typeform servers. As long as no one uses the form, this access to the device is not “strictly necessary” — it therefore requires consent under Section 25(1) TDDDG if the form is loaded globally. In addition: the data entered into the form is stored at Typeform, and without an activated EU data region it can end up in the USA.

What you can do

Häufige Fragen

Does an embedded Typeform need a consent banner?
If the embed script loads on page load: yes. If the form only loads after an active click or is merely linked, the use can be based on Section 25(2) TDDDG.
Where does Typeform store the form responses?
By default in the USA. Depending on the plan, an EU data region can be activated that keeps the responses in Europe. The actual storage location belongs in the privacy policy.
Is a link to the Typeform enough instead of an embed?
Yes, and it is the most data-frugal solution. A text link or button that opens the hosted form in a new tab transmits no data to Typeform until the click.
What has to be stated at the form itself?
A short privacy notice: which data is collected, for what purpose, on what basis and how long it is stored — plus a link to the full privacy policy.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.