Home Blog GDPR-compliant form processing: What businesses need to know
Compliance 6 min read

GDPR-compliant form processing: What businesses need to know

Forms almost always contain personal data. As soon as an external service provider is involved, specific GDPR obligations arise – and they're more manageable than many assume.

Whether it's an insurance application, patient questionnaire or event registration – almost every business form contains personal data. And as soon as those forms are sent to an external provider for digitization, a question arises: what GDPR requirements apply?

The good news: the requirements are clearly defined and manageable in practice. The key framework is Article 28 GDPR, which governs data processing on behalf of a controller.

Medical form containing personal data
Medical forms contain some of the most sensitive personal data – processing them triggers the strictest GDPR requirements.

What is data processing on behalf of a controller?

When formalogix processes your form data, we act as a data processor – we process data on your behalf, according to your instructions, exclusively for the agreed purpose. We do not use the data for our own purposes, do not share it, and delete it after project completion.

This requires a Data Processing Agreement (DPA), which we provide for every project. It covers, among other things:

  • Technical and organisational measures (TOMs) for data protection
  • Which sub-processors may be used
  • Deletion periods for original documents and intermediate data
  • Your rights to audit and inspect

EU hosting: Why server location matters

formalogix processes and stores all data exclusively on servers in Germany. There is no transfer to third countries. This is especially relevant if your documents contain special categories of personal data – such as health data (Art. 9 GDPR) or biometric information.

Providers using US infrastructure or cloud services outside the EU face stricter requirements (Standard Contractual Clauses, Transfer Impact Assessment). This significantly increases compliance overhead.

Comparing providers by hosting location

Your choice of service provider has a direct impact on your GDPR workload. The table below shows what additional steps are required depending on where data is hosted:

CriterionProvider in GermanyEU provider (non-DE)US / global provider
Core GDPR requirements✓ met✓ met⚠️ extra effort
Standard Contractual Clauses neededNoNoYes
Transfer Impact AssessmentNot requiredRarely requiredRequired
Data sovereigntyHighMediumLow
Recommended for health data⚠️ review

Deletion periods and data minimisation

After project completion, all original documents and intermediate data are securely deleted within a contractually defined period (default: 30 days). You receive only the structured output data in the format you need – CSV, JSON, XML or directly via API.

How the onboarding process works

From initial enquiry to compliant delivery of your structured data, we follow a clearly defined process:

1

Initial meeting & form analysis

We discuss your forms, volume and any special requirements. You receive an assessment of the GDPR relevance of the data involved.

2

DPA & TOMs

We provide the Data Processing Agreement including TOMs for review. On request, we can walk through individual clauses together with your Data Protection Officer.

3

Secure handover

Documents are transferred via encrypted channels – no email, no unencrypted FTP.

4

Processing & deletion

After project completion you receive the structured data. Original documents are securely deleted within the agreed period and deletion is logged.

Checklist before commissioning

  1. 1 Sign a Data Processing Agreement with formalogix
  2. 2 Review and document TOMs internally
  3. 3 Define deletion periods for original documents
  4. 4 Update your Record of Processing Activities (RoPA)
  5. 5 Inform your Data Protection Officer (if applicable)

What happens when a GDPR violation occurs?

Data protection authorities can impose fines of up to 4% of global annual turnover or €20 million – whichever is higher. On top of that, violations can lead to reputational damage, cease-and-desist letters from competitors and civil claims from affected individuals. Controllers who choose unreliable processors share the liability.

Our recommendation: for every external provider handling personal data, check not just the DPA on paper, but also the actual technical implementation. Our processing log provides a complete audit trail of which documents were handled, when, and by whom – available for data protection audits at any time.

We provide all necessary documentation and support you with your RoPA records. If you have specific requirements from your sector – healthcare, financial services or others – contact us directly.

Next step

Have specific forms to digitize?

Send us a sample – we'll have a quote ready within 24 hours.

More articles