Running your IT

Collecting Data With Microsoft Forms: A UK GDPR Checklist

Microsoft Forms makes it easy to send a questionnaire to clients, staff or event guests and have the answers land in one place. That ease is also the risk: anyone in the company can create a form that collects personal data, and nobody else may know it exists.

If you’re new to Forms, start with our introduction to Microsoft Forms. This post is about doing it properly once names, contact details or anything about a person are involved.

Where your Forms data lives

Two copies of your data usually exist:

  • In Forms itself. Microsoft’s data location guidance says Forms data for tenants in European countries outside the EU and EFTA, which covers UK businesses, is stored in its Europe region rather than the United States.
  • In Excel. When you select Open in Excel, the responses are saved to a workbook in OneDrive or SharePoint, alongside your other Microsoft 365 files.

Both count when you think about security, retention and subject access requests.

A checklist for every form that collects personal data

1. Decide who can respond

In Settings, choose between Anyone can respond and Only people in my organisation can respond (or specific people). Internal surveys should always be limited to your organisation, so the link is useless if it’s forwarded outside.

2. Only ask for what you need

UK GDPR’s data minimisation principle says personal data must be adequate, relevant and limited to what’s necessary for your purpose. Before publishing, go through each question and ask what you’ll do with the answer. Date of birth, home address and phone number are common questions that often aren’t needed.

Be especially careful with special category data, such as health information, ethnicity or religion. The ICO stresses that it’s particularly important to keep this to a minimum. If you really need it, talk to whoever handles data protection in your company first.

3. Tell people how you’ll use it

The ICO’s guidance on the right to be informed says you must give people privacy information when you collect their data, including why you’re collecting it, how long you’ll keep it and who you’ll share it with. Put two or three plain sentences at the top of the form and link to your full privacy notice.

4. Turn off names when you don’t need them

For internal staff surveys, untick Record name if you want honest, anonymous answers. Bear in mind that free-text answers and small teams can still make people identifiable.

5. Don’t use Forms for documents or passwords

File upload questions only work when a form is limited to people in your organisation, and uploads go to the form owner’s OneDrive. For clients sending ID or financial documents, use a secure client portal or a OneDrive file request, which lets people upload without seeing anything else in the folder.

And never ask for passwords or bank login details. Staff and clients should treat any form that does as phishing.

6. Keep forms in a group, not one person’s account

A form belongs to whoever created it. If that person leaves, the form and its responses can be lost or hard to find. Move the form to a Microsoft 365 group so the whole team owns it.

This matters for subject access requests. The Data (Use and Access) Act 2025 confirmed that organisations must make reasonable and proportionate searches when someone asks for their data. That’s much easier when forms live in known, shared places.

7. Set a retention period and stick to it

The ICO’s storage limitation principle says you mustn’t keep personal data longer than you need it, and you should be able to justify how long you keep it. Decide when each form’s responses will be deleted, for example three months after an event.

When the time comes, delete the responses in Forms and delete the linked Excel workbook (or its rows) as well, because deleting in Forms doesn’t touch Excel.

Good uses for solicitors and accountants

With those controls in place, Forms is useful for:

  • Client feedback after a matter, a year-end or a tax return
  • Event and webinar registrations
  • Staff training quizzes and policy sign-offs, giving you a record for audits and insurers
  • Internal incident reporting, so staff can quickly flag a lost laptop or an email sent to the wrong person

That last one is worth setting up now. The ICO expects reportable personal data breaches to be reported within 72 hours of you becoming aware of them, so a quick way for staff to raise the alarm helps.

From our work

We suggested Microsoft Forms to one client who was using SurveyMonkey, for collecting information from their own clients, gathering feedback and running staff surveys. It’s already in their Microsoft 365 plan, and the responses stay inside their Microsoft 365 rather than with another supplier.

David Gilbey, Just Gilbey IT Solutions

Getting it right

Forms is a good tool, but it’s one of many places personal data can end up in Microsoft 365. If you need to show clients, insurers or regulators that you handle data properly, our IT for regulated businesses page explains how we help with the controls and policies behind UK GDPR. Our cyber security service covers the technical side.

Questions people ask

Where is Microsoft Forms data stored for UK businesses?

Microsoft’s data location guidance says Forms data for tenants in European countries outside the EU and EFTA, which includes the UK, is stored in its Europe region rather than the US. Responses you open in Excel are also stored in OneDrive or SharePoint.

Can clients upload ID documents through Microsoft Forms?

Not usually. File upload questions only work when the form is limited to people in your organisation. For clients, use a secure portal or a OneDrive file request instead.

Do I need a privacy notice on a Microsoft Form?

If the form collects personal data, the ICO says you must give people privacy information at the time you collect it. A short statement at the top of the form with a link to your full privacy notice usually does the job.

Does deleting responses in Forms delete them everywhere?

No. Deleting responses in Forms doesn’t remove rows already in the linked Excel workbook, so delete those too.

Sources

More on running your IT

All running your IT articles