A full Privacy Policy covers everything, but nobody reads it at the exact moment
they're about to tick a box. GDPR's Art. 13 solves this with the "informativa
breve": a short notice given right where data is collected, linking to the
full policy for detail. If your forms have no notice at all, or just a vague
"I agree to the terms," that's a real, fixable compliance gap, and a quick one
to close.
The one rule that breaks the most forms
Never bundle marketing consent with anything else. Newsletter/marketing
opt-in must be its own separate, specific, freely-given checkbox, unticked by
default. Combining it with "accept Terms & Conditions" or hiding it inside a
purchase flow is one of the most common reasons marketing consent gets thrown
out as invalid (GDPR Art. 4(11), Art. 7(2)).
Newsletter / marketing opt-in
Use near the email signup field. Checkbox must be unticked by default:
☐ I would like to receive [Business Name]'s newsletter with news, offers, and
updates by email. You can unsubscribe at any time using the link in every email.
See our Privacy Policy for how we handle your data. We will not share your email
with third parties for their own marketing.
Contact form
Use directly under the "Send" button. Unlike marketing, this one usually
doesn't need a checkbox at all: replying to an enquiry someone initiated is
a low-risk, expected activity, normally covered by legitimate interest (Art.
6(1)(f)) or pre-contractual steps (Art. 6(1)(b)). A plain notice satisfies Art. 13
transparency:
By submitting this form, you agree that [Business Name] will use the information
provided (name, email, message) to respond to your enquiry, as described in our
Privacy Policy. We will not use this information for marketing unless you
separately opt in.
If you sell instant digital downloads: a separate acknowledgement that
immediate delivery means giving up the 14-day right of withdrawal, this is its
own disclosure under EU consumer law, not a GDPR clause, but it belongs in the
same checkout step and is just as often missing.
Comments / reviews (if your site has them)
By submitting a comment, your name and comment text will be published on this
page. Your email address will not be published. See our Privacy Policy for
details.
Quick self-audit
Is your newsletter checkbox unticked by default, and separate from any
Terms/Privacy checkbox?
Does every form that collects personal data have some short notice
next to it, not just a link to a policy nobody will click?
Does your checkout keep "accept terms" and "receive marketing" as two
distinct checkboxes?
If you sell instant digital downloads, is the withdrawal-right notice
actually shown before purchase, not buried in the policy only?
Related reading
These short notices point back to your full policies, not replace them. See our
Privacy Policy checklist
for what the full policy itself must state, and our
cookie consent banner guide if
the form in question also sets cookies. For the full picture, legal bases, the
DPO question, and a day-one checklist, see our
plain-language GDPR guide.
Don't want to draft all of this from scratch?
NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this
situation: ready-to-paste consent clauses for every form on your site, plus a
Privacy Policy, Cookie Policy, a full Art. 28 DPA, a mini Records-of-Processing
(ROPA) template, and a breach-notification checklist, €29 one-time, instant
download, editable .docx and .pdf.
Not legal advice. This guide is general information,
not a substitute for advice from a qualified lawyer or data protection professional
about your specific situation. NormaKit's templates are likewise informational
starting points, not legal advice, and should be reviewed and adapted before use.