Put two plain sentences next to the submit button saying who receives it, what you will use it for, and whether you will add them to anything. The policy link stays, and the notice does the work.

The link nobody opens

The standard arrangement is a privacy policy linked in the footer, several scrolls below the form somebody is completing.

Almost nobody opens it, which is not a failure of the reader. They are trying to get a quote, not to research your data practices.

So the document exists, is accurate, and communicates nothing at the moment it would matter.

The remedy is not a longer policy. It is a short notice where the person actually is.

This is a general description rather than legal advice, and what is required varies by jurisdiction and by what you collect.

What the notice has to answer

The third is the one people care about most and the one most often left unanswered, because businesses are reluctant to say plainly that a form signs somebody up to something.

Two sentences is usually enough

The length that works, and it is shorter than most people expect.

Something like: we use these details to reply to your enquiry and nothing else, and we will not add you to a mailing list. We keep enquiries for two years. Full details in our privacy policy.

That is specific, it answers the question somebody is actually holding, and it takes eight seconds to read.

Longer notices are read less, which inverts the intention: a paragraph of careful qualification communicates less than two direct sentences.

If the honest version needs more than three sentences, the form is probably collecting more than it should.

Put it beside the button

Position matters as much as wording.

Directly above or below the submit control, in normal readable text rather than in grey six-point type.

Not in a collapsed section, not behind a link, and not at the top of the form where it is read before anybody has decided to submit anything.

On a phone, that means it should be visible without scrolling once the form is filled in, which is the moment somebody hesitates.

Making it small and grey to reduce its visual weight is a common instinct and it defeats the entire purpose.

A worked example

A firm's contact form had no notice and a footer policy link.

They added one line above the button: we will use this to reply to you, we will not add you to any mailing list, and we delete enquiries after two years.

Submissions rose slightly rather than falling, which was the opposite of what the marketing lead had predicted.

The explanation, from two customers who mentioned it, was that people had assumed filling in a form meant being marketed to indefinitely, and saying otherwise removed a reason to hesitate.

The line also had an internal effect. It became true because it was published, so somebody set up a routine to actually delete old enquiries, which had not previously existed.

Forms that need more

Some collection genuinely warrants a fuller notice.

Anything gathering sensitive information, such as health details on an intake form or financial circumstances on an application.

Anything where the information goes to a third party the person would not expect, such as a lead being passed to a partner.

Anything creating an account, where the relationship is ongoing rather than a single exchange.

And anything involving children, where the standard is higher and worth taking advice on rather than drafting yourself.

In those cases the notice is longer because there is genuinely more to say, not because the language is more cautious.

The checkbox question

Whether to add a tickbox, and the answer differs by purpose.

For an enquiry form where you will only reply, a tickbox is unnecessary and adds friction. The person submitting has evidently agreed to be replied to.

For anything beyond that, particularly adding somebody to a mailing list, a separate unticked box with its own wording is the right approach, and the record of it is what you would rely on later.

What does not work is a single box covering both, worded so that agreeing to be contacted about the enquiry also agrees to marketing.

That is the pattern regulators have consistently disliked, and it produces a list that cannot be defended.

Keep it true

The maintenance point, and it is the reason to write conservatively.

A notice saying you will not add people to a mailing list is a commitment, and somebody will eventually suggest exporting enquiries into the mailing platform.

Write what you are willing to keep to rather than what sounds most reassuring, and tell whoever handles marketing what the forms say.

When something changes, change the notice, and note the date so you know what people saw when.

A published commitment nobody internally knows about is a worse position than a vaguer notice that is accurate.

The counter-case

There is a version of this that clutters a form and helps nobody.

A notice on every field, a paragraph of qualification, and three links produce a form that looks like a legal document, which reduces completion without improving anybody's understanding.

For a simple contact form, one short line is proportionate and more is not.

There is also a limit to what a notice fixes. If the underlying practice is that enquiries are added to a marketing list without any separate agreement, describing that clearly does not make it acceptable, and the notice is not the thing to change first.

Get the practice right, then describe it briefly. The description is the easy half.

Writing yours

  1. Say what you use it for, in one clause.
  2. Say whether you add people to anything ongoing.
  3. Give a retention period if it is short.
  4. Keep it to two sentences.
  5. Put it beside the button, at readable size.
  6. Use a separate unticked box for anything beyond replying.
  7. Tell whoever does marketing what it says.

Step seven is what stops the notice becoming untrue six months later.

The full document is covered in a privacy policy written for a real business.


Frequently asked questions

Is a footer privacy policy link enough?

It exists and communicates nothing at the moment it matters, because almost nobody opens it while filling in a form. A short notice beside the button does the actual work.

What should the notice say?

Who receives it, what you will use it for, whether you will add them to anything ongoing, a retention period if it is short, and a link to the full policy.

How long should it be?

Two sentences. Longer notices are read less, so a paragraph of qualification communicates less than two direct sentences. If you need more than three, the form may collect too much.

Where should it go?

Directly above or below the submit button, in normal readable text. Not collapsed, not behind a link, and not made small and grey to reduce its visual weight.

Do I need a tickbox?

Not for an enquiry form where you will only reply. For anything beyond that, a separate unticked box with its own wording, recorded separately.

Will a notice reduce form submissions?

Often the reverse. People assume a form means being marketed to indefinitely, and saying plainly that you will not removes a reason to hesitate.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Form with no notice?

Add one line above the button saying what you use it for and whether you add people to a list. Then make sure it stays true.

Start a Conversation