Free HTML GDPR Data Request Form Generator

UK organisations must offer an easy way to exercise access, erasure, and related rights. Use an HTML request form that starts the clock as a ticket, then verify identity through a process that does not involve uploading passports to a marketing backend.

Form Builder

#3b82f6

How to Use This Form Generator

1

Create a Form ID for the DPO / privacy queue

Not the marketing newsletter list.

2

Relabel request types

Access, erasure, rectification, objection, US delete, US opt-out of sale/share.

3

Publish identity-check steps

Tell people you will follow up by email, not that they must upload a passport here.

4

Fulfil from source systems

The form is the ticket. Exports of ‘all data’ still come from your databases.

What is a GDPR data request (DSAR) form?

Under UK GDPR, a data subject can request access to their personal data (a SAR/DSAR), correction, erasure, restriction, objection, and portability in defined cases. The ICO expects you not to put up unnecessary hurdles. You may reasonably verify identity, but demanding NI numbers or passport scans on a public HTML form is a disproportionate hurdle and a new breach risk. You typically have one month, with limited extensions for complex cases.

US visitors may be exercising CCPA/CPRA, VCDPA, or other state rights (access, delete, opt-out of sale/share). Those statutes are not GDPR. Use this form as a single intake labelled for both, then route UK DSARs to the DPO and US requests to your privacy ops playbook. HIPAA medical-record requests in the US are a different regime—use the HIPAA release generator for authorizations to send PHI to third parties.

Intake fields that start the statutory clock

You need to know who they claim to be and what they want. You do not need a colour scan of their driving licence in your form dashboard.

  • Name and email they believe you hold
  • Request type (access, delete, correct, opt-out—customise the select options after copy)
  • Context in details (product, approximate dates, other emails they used)
  • Preferred date only if you use it internally; statutory deadlines still apply

Never require Social Security, National Insurance, or passport/driving-licence scans on this public form. If you must verify, use a staged process: email challenge, account login, or a secure portal with staff review.

How privacy requests arrive

ICO and state AGs still see email to a buried address. A visible form is both UX and evidence you did not hide the door.

1. Privacy-centre HTML

A form on /privacy-requests.

2. Privacy-ops SaaS

DataGrail-class tools help at volume; they still need a public entry point.

3. Email to dpo@ or privacy@

Valid under UK GDPR. A form reduces missing subject lines.

4. Account settings delete button

Best for simple consumer apps; this form covers people without a login.

Static privacy pages

Your privacy notice and this form should live on the same static origin. Say which legal entity is the controller.

Log the submission time. That timestamp matters for the one-month UK GDPR clock and for US statutory windows.

Frequently Asked Questions

Does submitting this meet the ICO’s ‘easy’ test?

It helps. You still need a working inbox, a process, and no punishment of the requester.

Can I refuse until I get a passport?

You may reasonably verify, but a blanket passport-on-HTML-form policy is hard to justify and dangerous.

Is this a HIPAA records request?

No. US PHI disclosures to third parties often need an authorization. Patient access to their own designated record set follows HIPAA access rules, not this DSAR copy.

CCPA vs GDPR on one form?

One intake is fine if your privacy notice explains both and your team routes correctly. Do not tell Californians they must use UK wording.