Home Blog Is Typeform GDPR Compliant? What You Still Have to Do

GDPR

Is Typeform GDPR Compliant? What You Still Have to Do

Posted by Kevin Yun|August 17, 2026

Typeform provides the processor-side contract GDPR asks for. Its data processing terms sit in Section 4 of its privacy policy rather than in a separate document, and Typeform's own help centre confirms there is no need to sign anything separately. The contracting entity is Typeform S.L., a Spanish company. None of that settles whether your form is lawful, because a form is a data collection instrument and almost every decision that makes one compliant is made by whoever built it.

This article covers where Typeform's DPA actually is, when you would want a signed one instead, what the contract says about subprocessors and objections, the questions about storage location you should put to Typeform directly, and the controller obligations that sit with you the moment you publish a form.

The DPA Is In The Privacy Policy, Not Beside It

This is the single most common point of confusion, and it is worth stating precisely. Typeform's help centre states that Section 4 of its privacy policy contains its obligations for handling personal data under GDPR, and that as a result there is no need for customers to sign a separate data processing agreement. We checked Typeform's privacy policy and help centre on 7 August 2026; terms move, so confirm the version that applies to you before relying on it.

That is a legitimate structure. Article 28(9) permits a processing contract to be concluded in writing including in electronic form, and terms accepted electronically satisfy it. But it produces the same evidentiary awkwardness as any click-through arrangement: your DPA is a section of a document that can be revised, and what you agreed to is the version live on the day you agreed. Record the date, keep a copy of the section as it stood, and note it in your processor inventory. If you are unsure what a DPA is supposed to contain in the first place, start with our guide to data processing agreements.

Typeform's help centre also states that a custom, separately executed DPA is available on Enterprise or Growth Custom plans, arranged through its sales team. If your customers' procurement teams demand a countersigned document with your company name on it — and enterprise buyers routinely do — that plan requirement is a real cost input, not a footnote.

Who Is The Controller, And Why It Is Obviously You

Typeform's Master Enterprise Agreement is unambiguous on the point: the client is the data controller, and warrants that it will inform data subjects and obtain their consent where appropriate. That allocation is also the default position under GDPR for anyone who builds and publishes a form, so it holds regardless of which version of the agreement you are on.

Restated without the legal register: Typeform provides the machinery, you decide what to ask, who to ask, why, and on what basis. If your form asks for a phone number you do not need, that is your data minimisation failure. If it asks about dietary requirements or accessibility needs, you may be collecting special category data and you need a condition under Article 9, not merely a lawful basis under Article 6. If your form has a pre-ticked marketing checkbox, that is your invalid consent. The vendor is not in the room for any of those decisions.

The agreement also names Typeform S.L. as the contracting entity and contemplates assistance from its US affiliate, Typeform US LLC. A Spanish company is not automatically an EEA-only processing operation, and the presence of a US affiliate in the contract is the clue that transfers are in scope.

Subprocessors, Objections And The Fifteen-Day Window

Typeform provides subprocessor information through a subscription mechanism rather than an openly browsable table — you sign up and are notified when the list changes. Sign up for it. An unmonitored subprocessor list is the most common gap in an otherwise tidy vendor file.

The objection mechanics deserve a close read, and they cut in a direction most people do not expect. A published version of Typeform's Master Enterprise Agreement gives the client a non-extendable fifteen calendar days to reasonably oppose a new or replacement subprocessor — and provides that if the client exercises that right, Typeform becomes entitled to terminate the contractual relationship early on fifteen days' notice. The same clause defines "reasonably oppose" narrowly: a challenge grounded in the subprocessor's potential or actual failure to meet GDPR requirements, not a general preference.

Read together, that is a meaningful commercial fact. Objecting is not a free action. It is a right that, once exercised, hands the vendor an exit — so the decision to object belongs with someone who understands what losing the service would cost you, not only with whoever reviews the privacy paperwork.

One caution on sourcing. The clause above appears on a Typeform-hosted page that is presented as an archived version of the agreement, and enterprise terms are versioned and often negotiated. Treat it as indicative of how Typeform approaches subprocessor objections, then check the wording in the agreement you actually executed. Our guide to subprocessor management covers how to run that review without it becoming a full-time job.

On Storage Location, Get It In Writing

Here is where we stop and say what we do not know.

Typeform's transfer position is documented: the company points to the 2021 Standard Contractual Clauses for transfers, and its legal and compliance help centre section covers the DPA, the Standard Contractual Clauses and the availability of a business associate agreement. What is not settled by any single public page we could verify is where response data sits at rest for a given plan, or which plans — if any — offer an EEA-only storage option.

As of 7 August 2026, published third-party summaries disagree with each other on this point, confidently and in opposite directions. That is a good reason to trust none of them, including any summary you read of this article. If data residency matters to your customers or your risk assessment, ask Typeform's sales or support team directly, name your plan when you ask, and get the answer in writing. Then put that answer, with its date, in your records. A residency claim you cannot evidence is worse than no claim, because you will eventually repeat it to a customer.

The Embed Is Your Problem, Not Typeform's

If you embed a form in your own site rather than linking to a hosted one, the embed is a third-party resource loading inside your page, and everything it does on load happens under your cookie banner and your privacy notice.

That means the test is yours to run. Load the page in a clean browser, refuse all non-essential cookies, and look at what network requests fire and what gets written to storage before consent is given. If anything non-essential loads before the visitor has agreed, the correct fix is to gate the embed behind consent rather than to describe it in your policy afterwards. This is a configuration question about your site, and no vendor contract resolves it for you.

Common Mistakes With Typeform And GDPR

Looking for a DPA that does not exist as a separate file. It is Section 4 of the privacy policy. Teams waste a week asking support for a document, then conclude none exists.

Assuming a Spanish entity means EEA-only storage. The contracting entity is Spanish and a US affiliate appears in the agreement. Where response data rests is a question to ask, not to infer from an address.

Treating a subprocessor objection as a low-stakes tick-box. The published enterprise wording makes the window non-extendable at fifteen days and lets Typeform terminate early if you object. That is a commercial decision wearing a compliance costume — check your own executed agreement and route it to someone who can weigh it.

Collecting special category data without noticing. Health conditions, dietary needs, accessibility requirements and religious observance all appear in ordinary event and onboarding forms. Article 9 needs a condition of its own, and "the respondent typed it in" is not one.

Leaving responses in the account indefinitely. Retention is a decision you make and enforce. Nothing deletes a three-year-old response set for you, and every one of those responses is still your liability at the point somebody asks.

FAQ

Do I need to sign a DPA with Typeform?

Not on standard plans. Typeform's help centre states that Section 4 of its privacy policy contains its GDPR obligations for handling personal data and that no separate signature is required. A custom, separately executed DPA is available on Enterprise or Growth Custom plans through its sales team, which matters if a buyer insists on a countersigned document.

Is Typeform a controller or a processor?

A processor, for the responses you collect. Typeform's enterprise agreement identifies the client as the data controller and requires the client to inform data subjects and obtain consent where appropriate. It will also be a controller of its own account and billing data about you, which is a separate relationship.

Can respondents ask for their data to be deleted?

Yes, and the request is yours to handle. Responses can be deleted from the responses view of the relevant form, but the obligation to identify, verify and act on the request within the statutory deadline sits with you as controller, along with removing the same data from anywhere you exported it.

Where is my Typeform data stored?

Ask Typeform directly and name your plan. Public third-party summaries contradict each other on whether an EEA-only option exists and on which plans, so the only answer worth relying on is one you obtain from Typeform in writing and file with a date against it.

Closing Thought

Forms are where privacy programmes quietly fail, and the reason is that a form is trivially easy to make. Nobody convenes a review to add a field. Someone in marketing needs a phone number for follow-up, adds it in ninety seconds, and the organisation is now collecting a new category of personal data with no lawful basis recorded, no retention period set, and no entry in any register. The vendor's contract is immaculate throughout.

That gap is not a Typeform problem, and it is not solved by choosing a different form builder. It is solved by having somewhere that records what you collect, why, for how long and who else touches it. ComplyDog gives you a compliance portal on your own domain covering your DPA, your subprocessor list, your data subject request intake and your security page. It will not audit your forms. It will mean that when someone finally asks what you collect and on what basis, the question has an address.