Typeform (typeform.com, Typeform S.L. with a corporate link to the USA) is a popular form and survey tool. The embedded form loads scripts from typeform.com and, depending on the embed type, can establish connections even before it is filled in.
Typeform has several embed types: the fullscreen embed, the popup, the slider panel and the inline container. All of them load the Typeform embed script on page load. The plain link to a hosted Typeform (typeform.com/to/...) is the most data-frugal variant — nothing happens here until the click, and the visitor then calls the service themselves.
For the entered responses, Typeform is a processor. The storage location is decisive: depending on the plan, Typeform offers an EU data region in which the responses are stored in Europe. If it is not active, the data is in the USA, and the transfer needs a basis (EU-US Data Privacy Framework) and an entry in the privacy policy. A DPA with Typeform is mandatory in any case.
Forms that collect personal data additionally need their own privacy information directly at the form or linked: which fields are processed, for what purpose, on what legal basis and how long the responses are stored. This applies regardless of the form tool.
An embedded Typeform loads JavaScript on page load and establishes a connection to Typeform servers. As long as no one uses the form, this access to the device is not “strictly necessary” — it therefore requires consent under Section 25(1) TDDDG if the form is loaded globally. In addition: the data entered into the form is stored at Typeform, and without an activated EU data region it can end up in the USA.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.