Skip to content

GDPR and contact form spam filtering: what you are allowed to do

Filtering contact form spam means reading personal data. What GDPR asks of you: a lawful basis, short retention, a line in your privacy notice, and care with providers and AI models.

Humainbox 12 min read
In this piece
  1. Contact form messages are personal data
  2. Your lawful basis: legitimate interests
  3. Keep less, secure it, and say so
  4. Using a provider, including one that uses an AI model
  5. Automated decisions: why Article 22 is usually not the issue
  6. Access and erasure requests
  7. A practical checklist
  8. A note for the UK
  9. Further reading

A spam filter on a contact form works by reading what people send you. Those messages contain names, email addresses, phone numbers and whatever the sender chose to write, so filtering them is processing personal data. GDPR does not forbid it. It asks you to have a reason, keep no more than you need for no longer than you need, tell people, and choose any provider with care.

This article explains what the law says and links the text. It is not legal advice; where the answer matters to your business, confirm it with your own adviser or data protection officer.

Contact form messages are personal data

Article 4(1) of the GDPR defines personal data as "any information relating to an identified or identifiable natural person". A form submission with a name and an email address meets that easily, and so does the message body if it mentions the sender's job, address or situation. Article 4(2) defines processing as "any operation or set of operations" performed on personal data, "whether or not by automated means". Scanning a message and deciding whether to deliver it is processing.

This applies to both sides of the filter. The genuine enquirer's message is personal data. So, often, is the spam: outreach campaigns send real names and real work addresses, and some junk uses the details of a person who has nothing to do with it. You do not get to treat held mail as outside the rules because you did not want it.

Your lawful basis: legitimate interests

Most businesses will rely on Article 6(1)(f), which allows processing that "is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject".

The UK regulator breaks this into what it calls the three-part test: a purpose test (is there a legitimate interest?), a necessity test (is the processing necessary for it?) and a balancing test (do the person's interests override it?). The EDPB's draft Guidelines 1/2024, published for consultation in October 2024, describes the same "three cumulative conditions" and says controllers "should carefully assess and document" them before the processing starts.

Two recitals are worth reading alongside it.

Recital 49 says processing "to the extent strictly necessary and proportionate for the purposes of ensuring network and information security" is a legitimate interest, and gives examples: "preventing unauthorised access to electronic communications networks and malicious code distribution and stopping 'denial of service' attacks". It does not mention spam by name. A contact form filter that also stops malicious links and form floods sits close to those examples; one that only removes sales pitches is an argument by analogy, and you still owe the necessity and balancing tests.

Recital 47 puts weight on "the reasonable expectations of data subjects". Someone sending a genuine enquiry is unlikely to be surprised that it passes a spam check. They may well be surprised if the content is kept for a year, read by people who have nothing to do with their enquiry, or used for something else.

One caution from the EDPB draft is directly relevant. It recalls earlier warnings that security tools such as firewalls, anti-virus and anti-spam can lead to "intrusive analysis of communication content and meta data, which may have a significant impact on the outcome of the balancing test". A filter that reads message content is exactly that. It does not rule the practice out; it means the safeguards below are part of what makes the balance come out in your favour.

In practice, write a short legitimate interests assessment: what you filter and why, why a lighter method would not do the job, what you keep, and who can see it.

Keep less, secure it, and say so

Two principles in Article 5(1) do most of the practical work.

  • Data minimisation, Article 5(1)(c): personal data must be "adequate, relevant and limited to what is necessary". A filter must read the message to judge it; it need not keep every held message indefinitely.
  • Storage limitation, Article 5(1)(e): data must be kept "for no longer than is necessary for the purposes for which the personal data are processed". Decide how long the filter keeps message content, write the period down, and make sure deletion actually happens. Remember that the copies in your mailbox and CRM have their own retention question.

Security, Article 32, requires "appropriate technical and organisational measures to ensure a level of security appropriate to the risk". For a filter, the obvious measures are limiting who can open held mail, requiring proper logins, and knowing where the data is stored.

Transparency, Article 13, applies because the data comes directly from the person filling in your form. At the time of collection you must tell them, among other things, the purposes and legal basis, the legitimate interests pursued where you rely on Article 6(1)(f), the recipients or categories of recipients, any intention to transfer data outside the EU, and how long the data will be stored.

A typical addition to a privacy notice looks like this:

Messages sent through our contact forms are screened automatically to detect spam and abuse, on the basis of our legitimate interest in keeping our systems secure and our mailbox usable. Screening is carried out by a service provider acting on our behalf. Screened messages are kept for 30 days and then deleted.

Adjust the wording to what actually happens, and link the notice from the form.

Using a provider, including one that uses an AI model

If a service filters mail for you, it is almost certainly your processor, and Article 28 applies.

  • A contract. Article 28(3) requires a contract setting out the subject matter, duration, nature and purpose of the processing, and requiring the processor to act "only on documented instructions from the controller". Ask for the data processing agreement and read it rather than assuming.
  • Sub-processors. Under Article 28(2) the processor "shall not engage another processor without prior specific or general written authorisation" and must tell you about changes so you can object. If the filter sends content to a language model provider, that provider is normally a sub-processor and should be on the list.
  • Transfers outside the EU. Chapter V applies to any transfer to a third country (Article 44). A transfer can rest on an adequacy decision (Article 45) or on appropriate safeguards such as standard contractual clauses (Article 46). For the United States, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework on 10 July 2023; it covers US companies that participate in the Framework. On 3 September 2025 the General Court dismissed an action to annul that decision (Case T-553/23, Latombe v Commission), and the applicant lodged an appeal with the Court of Justice (Case C-703/25 P). Check the current position before relying on it.
  • Model training. Ask whether your messages are used to train or improve anyone's models, and get the answer in the contract. Model providers publish their own terms here: OpenAI's data controls documentation, for instance, says data sent to its API "is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)" and that abuse monitoring logs are "retained for up to 30 days". What matters for you is the commitment in your own provider's agreement and sub-processor list.

Automated decisions: why Article 22 is usually not the issue

Article 22(1) gives people "the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her".

The EDPB-endorsed guidelines on automated decision-making (WP251rev.01) say the wording "makes it clear that only serious impactful effects will be covered", with examples such as decisions affecting someone's eligibility for credit, access to health services or an employment opportunity. Holding a sales pitch in a review folder, where a person can look at it and release it, is hard to fit into that category. So for most contact forms Article 22 is unlikely to apply. That is a reasoned reading, not a guarantee.

Two cases deserve more care.

Careers and application forms. Recital 71 names "e-recruiting practices without any human intervention" as a typical example of a significant automated decision. A filter that silently discards job applications is much closer to that line than one screening sales enquiries.

Token review. The same guidelines say human involvement must be "meaningful, rather than just a token gesture", carried out by "someone who has the authority and competence to change the decision". Having a held folder nobody opens does not count as review.

Either way, keeping held messages visible, explained and releasable is good practice. It supports the accuracy principle, and it lets you answer the person who says they contacted you and heard nothing. The business case for that is covered in false positives: what a held enquiry really costs.

Access and erasure requests

Access, Article 15. A person can ask whether you process their data and for access to it, including the purposes, recipients and retention period. Form messages, including held ones, are in scope. Your provider must help: Article 28(3)(e) requires processors to assist with data subject requests.

Erasure, Article 17. The right applies where one of the listed grounds does, for example where the data is "no longer necessary" or the person has objected under Article 21(1) and there are no overriding legitimate grounds. It is not absolute, but for old enquiries and held spam there is rarely a reason to refuse.

To handle both, you need to be able to search by email address across the filter, the mailbox the messages were delivered to, and anywhere they were forwarded. If enquiries are routed to several people or teams, as described in routing website enquiries, each of those copies counts.

A practical checklist

Question Why it matters Where
What is our lawful basis for filtering? Processing needs one; most businesses use legitimate interests Art. 6(1)(f); ICO three-part test
Have we written down the balancing test? Content-reading filters weigh on the balance EDPB draft Guidelines 1/2024; Recitals 47, 49
How long is message content kept, and is deletion automatic? Storage limitation Art. 5(1)(e); Art. 13(2)(a)
Do we keep only what the filter needs? Data minimisation Art. 5(1)(c)
Who can open held messages? Security of processing Art. 32
Does our privacy notice mention screening? Transparency at collection Art. 13
Do we have processor terms and a sub-processor list? Controller must use a contract Art. 28(2), 28(3)
Does data leave the EU, and on what basis? Transfer rules Art. 44–46; EU-US Data Privacy Framework
Are our messages used to train models? Processor acts on documented instructions only Art. 28(3)(a); provider terms
Can a person review and release held mail? Significant automated decisions; accuracy Art. 22; Recital 71; WP251rev.01
Can we find and delete one sender's messages? Access and erasure rights Art. 15, 17

A note for the UK

The UK GDPR contains the same core articles, and the Data (Use and Access) Act 2025 amends it rather than replacing it. The ICO updated its guidance on 19 June 2026 to say that "all data protection provisions" in the Act are now in force. Points worth knowing for form filtering: the UK GDPR lists processing "necessary for the purposes of ensuring the security of network and information systems" as an example of a legitimate interest (Article 6(11)(c)), with the three-part test still applying; for a subject access request you only have to make "reasonable and proportionate" searches; and complaints about your use of personal data must be acknowledged within 30 days. The rules on automated decisions have also changed, so UK readers should use the ICO's current guidance rather than the EU text for that part.

Humainbox, for its part, keeps message content for 30 days by default (adjustable up to 90), can erase a sender's messages on request, and lets you switch off classification by an outside model for your account. Where data is processed, its sub-processors and its retention are set out in the privacy policy.

Further reading

Stop contact form spam

Change one setting in your contact form. Spam stops arriving, and real enquiries go to whoever should answer them. Try it for a week with nothing switched on.

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.