NormaKit Guide

GDPR Consent Clauses: What to Put Under Your Forms

Practical guide · GDPR Art. 13 & Art. 7 · newsletter signups, contact forms, and checkout

A full Privacy Policy covers everything, but nobody reads it at the exact moment they're about to tick a box. GDPR's Art. 13 solves this with the "informativa breve": a short notice given right where data is collected, linking to the full policy for detail. If your forms have no notice at all, or just a vague "I agree to the terms," that's a real, fixable compliance gap, and a quick one to close.

The one rule that breaks the most forms

Never bundle marketing consent with anything else. Newsletter/marketing opt-in must be its own separate, specific, freely-given checkbox, unticked by default. Combining it with "accept Terms & Conditions" or hiding it inside a purchase flow is one of the most common reasons marketing consent gets thrown out as invalid (GDPR Art. 4(11), Art. 7(2)).

Newsletter / marketing opt-in

Use near the email signup field. Checkbox must be unticked by default:

☐ I would like to receive [Business Name]'s newsletter with news, offers, and updates by email. You can unsubscribe at any time using the link in every email. See our Privacy Policy for how we handle your data. We will not share your email with third parties for their own marketing.

Contact form

Use directly under the "Send" button. Unlike marketing, this one usually doesn't need a checkbox at all: replying to an enquiry someone initiated is a low-risk, expected activity, normally covered by legitimate interest (Art. 6(1)(f)) or pre-contractual steps (Art. 6(1)(b)). A plain notice satisfies Art. 13 transparency:

By submitting this form, you agree that [Business Name] will use the information provided (name, email, message) to respond to your enquiry, as described in our Privacy Policy. We will not use this information for marketing unless you separately opt in.

Checkout / account creation

Two separate checkboxes, never merge them:

Comments / reviews (if your site has them)

By submitting a comment, your name and comment text will be published on this page. Your email address will not be published. See our Privacy Policy for details.

Quick self-audit

  1. Is your newsletter checkbox unticked by default, and separate from any Terms/Privacy checkbox?
  2. Does every form that collects personal data have some short notice next to it, not just a link to a policy nobody will click?
  3. Does your checkout keep "accept terms" and "receive marketing" as two distinct checkboxes?
  4. If you sell instant digital downloads, is the withdrawal-right notice actually shown before purchase, not buried in the policy only?

Related reading

These short notices point back to your full policies, not replace them. See our Privacy Policy checklist for what the full policy itself must state, and our cookie consent banner guide if the form in question also sets cookies. For the full picture, legal bases, the DPO question, and a day-one checklist, see our plain-language GDPR guide.

Don't want to draft all of this from scratch?

NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: ready-to-paste consent clauses for every form on your site, plus a Privacy Policy, Cookie Policy, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist, €29 one-time, instant download, editable .docx and .pdf.

See what's included →

Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.