Is Typeform GDPR compliant? What it covers and what you still own
Is Typeform GDPR compliant? Typeform publishes the documents a GDPR-conscious buyer expects, but a form tool can only ever cover its half of the arrangement. This guide walks through Typeform's data processing agreement, sub-processors, transfer mechanism and EU data hosting, notes which plan each item sits on, and lists what stays your job as the organization collecting the answers.
By Raj Kumar, Founder, Zunoform

Short answer
Typeform can be used in a GDPR-compliant way: it acts as your processor, offers a data processing agreement that applies without a separate signature, publishes its sub-processors, and uses Standard Contractual Clauses for transfers outside the EEA. But data is hosted in the US (Virginia) by default, and EU data hosting is only offered to new Enterprise and Growth Custom customers. Whether your use of Typeform is compliant depends on what you do as the controller.
- DPA: part of Typeform's legal terms for every plan; a custom signed DPA needs Enterprise or Growth Custom.
- Hosting: AWS in Virginia, USA by default; EU hosting on Enterprise and Growth Custom, new accounts only.
- Transfers: Standard Contractual Clauses plus supplementary measures, per Typeform's sub-processor page.
- Your side: lawful basis, privacy notice, consent wording, retention and answering respondents' requests.
What does "GDPR compliant" mean for a form builder?
No software product is GDPR compliant on its own, because the GDPR regulates what organizations do with personal data, not the tools they use. When you publish a form and collect names, emails or opinions, you are the controller: you decide why the data is collected and what happens to it. The form builder is a processor that stores and handles the answers on your instructions.
So the useful question is narrower: does the vendor give you what a processor must give a controller? Article 28 of the GDPR requires a contract (a data processing agreement, or DPA) that covers confidentiality, security, sub-processors, help with data subject requests, breach notification, deletion or return of data at the end, and audits. If personal data leaves the EEA, Chapter V requires a transfer mechanism such as an adequacy decision or Standard Contractual Clauses (SCCs).
Everything else, including telling respondents what you do with their answers, choosing a lawful basis and deciding how long to keep responses, stays with you whichever tool you pick.
What Typeform provides for GDPR, and on which plans
Read from Typeform's own legal pages and help centre on 28 September 2026. Typeform notes in its help centre that it experiments with pricing, so check your account's plan page too.
| GDPR item | What Typeform provides | Plans | Where it is documented |
|---|---|---|---|
| Processor role | Typeform processes respondent data on the form creator's behalf; respondents are told to contact the creator to exercise their rights | All | Help: GDPR rights for respondents |
| Data processing agreement | Online DPA with Typeform S.L. (Barcelona) that applies without a separate signature; last updated 20 July 2026 | All | typeform.com/legal/data-processing-agreement |
| Custom, signed DPA | Available on request through sales | Enterprise, Growth Custom | Help: Do I have to sign a DPA? |
| Sub-processor list | Public list with purpose, location and transfer tool; email list for change notices; 15 days to object | All | Help: What other companies do we share data with? |
| Transfer mechanism | SCCs (module 3 for onward transfers, module 4 for non-EEA customers) plus UK addendum | All | DPA section 9 and Annex IV |
| Default hosting | AWS, main servers in Virginia, USA | All self-serve plans | Help: What happens to my data? |
| EU data hosting | EU servers for new accounts only; not available to move existing accounts | Enterprise, Growth Custom | Help: Enterprise plan; pricing page |
| Consent field | Legal question type (accept or decline terms) usable with logic | All, including Free | Help: Free plan; What happens to my data? |
| Deletion | Deleted responses, forms and accounts cannot be restored; inactive free accounts deleted after 24 months | All | Help: deleted responses; DPA section 7 |
| Certifications | SOC 2 Type II, ISO/IEC 27001:2022, 27017, 27018 | Company-wide | Help: Security at Typeform |
| HIPAA / BAA | Offered | Enterprise only | Pricing page; Help: BAA |
Sources: Typeform Data Processing Agreement · Typeform Help: Do I have to sign a DPA? · Typeform Help: What other companies do we share data with? · Typeform Help: What happens to my data? · Typeform Help: Enterprise plan · Typeform pricing
Does Typeform have a data processing agreement?
Yes. Typeform's help centre says the GDPR processor obligations are part of its published legal terms, so you do not need to sign a separate DPA. The DPA itself sits at typeform.com/legal/data-processing-agreement and names Typeform S.L., a Spanish company registered in Barcelona, as the other party. It covers processing only on your documented instructions (which include settings you choose in the product), confidentiality, security measures listed in an annex, sub-processors, help with data subject requests, breach notification "without undue delay", deletion or return at the end, and audits.
Two details are worth reading before you rely on it. First, audits: Typeform can satisfy audit requests by sharing its ISO 27001 and SOC 2 reports, and on-site audits are limited to one a year at your cost unless a material breach is found. Second, if you want a countersigned or negotiated DPA, which some procurement and legal teams insist on, Typeform offers that only on Enterprise and Growth Custom plans.
Source: Typeform Data Processing Agreement
Source: Typeform Help: What is GDPR?
Who are Typeform's sub-processors?
Typeform's sub-processor page splits the list into two groups. For response data, the core sub-processor is Amazon Web Services, located in the US, or the EU for EU data hosting customers. A second group only touches response data if you use optional features, for example Alloy for some integrations (Klaviyo, Zendesk, Freshdesk, Asana, Aircall, Shopify) and AWS AI services for AI form building and analysis.
A separate page lists the companies Typeform uses for its own business, such as billing, analytics and monitoring, which mostly concern your account data rather than your respondents' answers. Under the DPA, you are expected to subscribe to Typeform's email list for sub-processor changes, and you have 15 calendar days to object to a new one; if you do, Typeform may end the contract.
Source: Typeform Help: What other companies do we share data with?
Source: Typeform Help: Which companies have access to customers' personal information?
How does Typeform handle transfers outside the EU?
Typeform is an EU company, but on self-serve plans your responses are stored on AWS servers in Virginia. That is an international transfer, so the mechanism matters. Typeform's DPA relies on the European Commission's 2021 Standard Contractual Clauses: module 3 (processor to processor) for onward transfers to sub-processors, module 4 when the customer is outside the EEA, and the UK addendum for UK customers. Its sub-processor page adds that where SCCs alone cannot give equivalent protection, Typeform applies supplementary security measures.
The EU-US Data Privacy Framework, adopted by the Commission in July 2023, is a separate route that certified US companies can use. Typeform's sub-processor page lists "Adequacy decision and SCCs" as the transfer tool for AWS; its own DPA is built on SCCs. If your data protection officer wants a transfer impact assessment, Typeform's Enterprise plan includes security team support for vendor assessments.
Source: Typeform Help: Standard Contractual Clauses 2021
Source: European Commission: Data transfers between the EU and the US
Where is Typeform data stored, and which plans get the EU data center?
Typeform's help centre says all data is hosted on AWS, with main servers in Virginia, USA. Data is encrypted in transit with TLS 1.2 and at rest with AES-256, including backups. The pricing page lists "Choose your preferred data center (US or EU)" as Enterprise only, and the help centre adds Growth Custom as a second plan with EU hosting.
The catch that trips up existing customers: EU data hosting is available to new customers, and the Enterprise help article says it is not currently available for existing accounts. If you already have years of forms on a Basic or Plus account and later need EU residency, expect a new account and a migration rather than a switch. EU-hosted accounts also have their own list of supported integrations, so check that the tools you connect are on it before you sign.
None of this makes US hosting unlawful under the GDPR. With SCCs in place, many EU organizations use US-hosted tools. But some public bodies, health providers and works councils require EU residency as internal policy, and for them Typeform's self-serve plans (Free, Basic, Plus, Business and Growth Flow) are off the table.
Source: Typeform Help: What happens to my data?
Source: Typeform Help: Enterprise plan
Source: Typeform Help: Growth Custom plan
Source: Typeform Help: Integrations available on the EU Data Center
Is Typeform DSGVO and RGPD compliant?
DSGVO (German) and RGPD (French, Spanish) are the same regulation as the GDPR under local names, so the answer does not change: Typeform provides the processor terms, and compliance depends on your setup. In German practice the DPA is usually called an AVV (Auftragsverarbeitungsvertrag). Typeform's position is that its online DPA applies without a signature; if your data protection officer requires a signed AVV, that is an Enterprise or Growth Custom conversation.
For UK organizations, the DPA includes the UK addendum to the SCCs and treats transfers between the UK and Spain as covered by adequacy decisions.
How do consent, retention and deletion work in Typeform?
Typeform's help centre puts consent on the form owner: you are responsible for getting respondents' consent where needed and for telling them how the data will be used. It suggests a welcome screen or statement explaining the purpose, and a Legal question, which asks respondents to accept or decline terms. With logic, a decline can send someone straight to the end. The Legal question type is on the free plan's list of question types.
On deletion, Typeform is blunt: deleted responses, forms and accounts cannot be restored, and deleting a form also deletes its file uploads. Deleted responses still count toward the month's response limit. There is a bulk delete through the Responses API if you need to purge on a schedule. The DPA also says inactive free accounts are deleted after 24 months.
When a respondent asks you for access or erasure, Typeform expects the request to go to you; if it receives one directly, it forwards it to the form creator. Keep a note of which form a person answered so you can find and export or delete their response quickly.
Source: Typeform Help: What happens to my data? (owner responsibilities)
Source: Typeform Help: What happens to deleted responses, forms, and accounts
Your GDPR checklist before publishing a typeform
These are the controller's jobs. They apply to Typeform, Google Forms, Zunoform or any other tool.
- Write down the purpose of the form and the lawful basis (consent, contract, legitimate interest) before you add questions.
- Remove every question you do not need. Data minimization is a principle, not a nice-to-have.
- Link a privacy notice from the welcome screen or first question: who you are, why you collect the data, how long you keep it, and who you share it with.
- If consent is your lawful basis, use an unticked, separate consent question, and never make it a condition for something unrelated.
- Read the vendor's DPA and save a dated copy (Typeform's was last updated 20 July 2026).
- Check where the data is hosted and record the transfer mechanism in your records of processing.
- Review the sub-processor list and sign up for change notices.
- List every integration the form feeds (Sheets, CRM, email tool). Each one is another place the data lives.
- Set a retention period and put a calendar reminder to export and delete old responses.
- Decide who on your team can see responses, and turn on two-factor authentication for those accounts.
- Keep a process for access and erasure requests, with a named owner.
Is Typeform secure, and is it HIPAA compliant?
Typeform lists SOC 2 Type II, ISO/IEC 27001:2022, ISO 27017 and ISO 27018 certifications in its help centre, with reports in its trust center, and also lists ISO/IEC 42001, the standard for AI management systems. That is a strong set for a form tool and it answers most vendor security questionnaires.
HIPAA is a US health-data law, separate from the GDPR. Typeform signs a Business Associate Agreement only on Enterprise, according to its pricing page. If you collect health information from EU residents, the GDPR treats it as special category data, which needs an Article 9 condition and usually a data protection impact assessment, whatever tool you use.
Where Zunoform fits (and where it doesn't)
Zunoform publishes a short-form processor DPA at /dpa, incorporated into its terms. It names the customer as controller and Zunoform as processor, lists sub-processors (a hosting provider, Cloudflare, Resend for email, and the billing providers), incorporates the SCCs (module 2) for transfers from the EU and UK, and commits to deleting remaining copies within 30 days of termination. A countersigned copy is available by email on any plan.
Every plan, including Free, has an anonymous mode that stores no IP address, user agent, referrer, location, language or screen size for that form, which helps with data minimization on surveys that do not need identity. The contact question also has an optional privacy-consent checkbox you can switch on.
Where it does not fit: Zunoform does not offer guaranteed EU-only hosting, SOC 2, HIPAA or a BAA, or SSO. If your procurement checklist requires EU residency or third-party security certifications, Typeform Enterprise meets requirements that Zunoform does not today.
Not legal advice
This article summarizes what Typeform and Zunoform publish as of 28 September 2026. It is not legal advice. Vendor terms change; read the current DPA and check your use case with your data protection officer or a lawyer before relying on any of this.
Questions people ask
Is Typeform GDPR compliant?
Typeform provides what a GDPR processor should: a data processing agreement that applies to every plan, a public sub-processor list, Standard Contractual Clauses for transfers and help with data subject requests. Your use is compliant only if you, as controller, have a lawful basis, a privacy notice, sensible retention and a process for requests. Self-serve plans store data in the US.
Does Typeform store data in the EU?
Only on Enterprise and Growth Custom plans, and only for new accounts. Typeform's help centre says EU data hosting is not currently available for existing accounts. All other plans are hosted on AWS with main servers in Virginia, USA, and rely on Standard Contractual Clauses for the transfer.
Do I need to sign a DPA with Typeform?
No. Typeform says its published legal terms already include the GDPR processor obligations, so no separate signature is needed. The DPA is at typeform.com/legal/data-processing-agreement. If your organization requires a custom or countersigned DPA, Typeform offers that on Enterprise and Growth Custom plans through its sales team.
Where can I find Typeform's privacy policy and sub-processors?
The privacy policy, DPA, CCPA notice and cookie policy are linked from typeform.com/legal. Sub-processors are listed in the help centre article "What other companies do we share data with?", which shows each company's purpose, location and transfer tool, and links to an email list for change notices.
Is Typeform safe to use for personal data?
Typeform encrypts data in transit (TLS 1.2) and at rest (AES-256) and holds SOC 2 Type II and ISO 27001, 27017 and 27018 certifications. That covers the vendor side. Safety also depends on your settings: who has account access, which integrations receive the data, and how long you keep responses.
Who handles a respondent's GDPR request on a typeform?
You do. Typeform tells respondents that the form creator is responsible for their data and that they should contact the creator directly. If Typeform receives a request, it passes it to the creator. You can find, export or delete an individual response from the Results area or through the API.
Is Typeform HIPAA compliant?
Typeform offers HIPAA compliance and a Business Associate Agreement only on its Enterprise plan, according to its pricing page. HIPAA is a US law and separate from the GDPR; EU health data additionally needs an Article 9 condition under the GDPR.
Raj Kumar · Founder, Zunoform
Raj Kumar is the founder of Zunoform, the form builder made by Symphonic Grow. He builds the product and writes these guides, checking every competitor price and feature claim against the vendor's own pages before publishing.
Raj Kumar on LinkedInKeep reading

Ready when you are
Better forms.
Better data.
Start with a conversation, a document or a single page.
Unlimited forms and 500 responses per month on Free.
No card required.
- No credit card
- Unlimited forms
- 500 responses / month