Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Formidable Forms is a self hosted WordPress form builder by Strategy11 that collects personal data through forms; optional integrations such as reCAPTCHA, Stripe, Akismet and Mailchimp can add third party calls and cookies.
Formidable Forms is a WordPress form builder plugin developed by Strategy11, a company based in the United States. It lets site owners create contact forms, surveys, registrations and advanced data driven forms that run on their own WordPress installation. Because the plugin is self hosted, the form submissions are stored in the operator own database rather than on a vendor cloud. The privacy profile therefore depends mostly on what data the forms collect and which optional integrations are switched on.
Forms typically collect names, email addresses, messages and any other fields the operator defines, and the plugin can also log the submitter IP address and user agent. The core plugin does not need advertising cookies to function. Cookies and external calls appear mainly through optional integrations, for example Google reCAPTCHA for spam protection, Stripe for payments, Akismet for spam filtering and Mailchimp for email marketing. Each enabled integration broadens the data that leaves the operator server.
Processing the personal data submitted through a form is governed by the GDPR, so the operator acts as controller and must identify a legal basis. Storing or reading any non essential cookie set by an integration falls under Art. 5(3) of the ePrivacy Directive and requires prior consent. A service like reCAPTCHA, which loads Google scripts and can set cookies, is therefore not strictly necessary in the legal sense. The operator should map each integration to a lawful basis and a cookie classification.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The form submission itself can usually rely on contract or on consent, depending on the purpose, and a clear privacy notice must be shown at the point of collection. Optional integrations that set cookies need prior consent before they load, which means reCAPTCHA and similar scripts should be gated behind your consent management platform. If a form processes special categories of data, explicit consent is required. Always make participation possible without forcing acceptance of non essential features.
The core plugin keeps data within your own hosting, but the common integrations send data to providers in the United States. Google, Stripe, Automattic and Intuit each receive personal data when their integration is active, which constitutes a transfer to a third country. You must rely on a valid mechanism such as Standard Contractual Clauses or Data Privacy Framework certification, supported by a transfer impact assessment. Disabling unnecessary integrations is the simplest way to reduce transfer risk.
Show a privacy notice next to each form and record the legal basis for the data you collect. Enable only the integrations you truly need, and gate any cookie setting integration behind consent so it loads after opt in. Keep a register of the providers, the data they receive and the transfer safeguards, and set retention limits for stored submissions. Review forms regularly and delete data that is no longer needed.
Websites using Formidable Forms must obtain user consent under GDPR regulations.
DPIA considerations
The core plugin keeps form data on your own server, which limits exposure, but a screening for a data protection impact assessment is sensible when forms collect sensitive categories of data or operate at scale. The need for a full assessment rises sharply once United States based integrations such as reCAPTCHA, Stripe, Akismet or Mailchimp are activated, because they add cookies, external calls and third country transfers. Document which integrations are enabled, the data each receives, and the transfer safeguards in place.
Sample consent text
This form is protected by additional services. With your consent we use reCAPTCHA and other integrations that may set cookies and send data, including your IP address, to providers in the United States. You can submit the form without optional features, and you can withdraw your consent at any time.
Third-party domains contacted
formidableforms.comgoogle.comgstatic.comstripe.comakismet.comlist-manage.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| frm_form | first party | session | Functional cookie set by the plugin to track form state and protect against duplicate submissions |
| _GRECAPTCHA | third party | 6 months | Set by the optional Google reCAPTCHA integration to provide spam and bot protection |
| __stripe_mid | third party | 1 year | Set by the optional Stripe integration for payment fraud prevention |
| __stripe_sid | third party | 30 minutes | Set by the optional Stripe integration to associate a payment session with the device |
Formidable Forms collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The core plugin does not set advertising or tracking cookies, and at most it may use a functional cookie to remember partial form progress. Cookies typically appear through optional integrations, such as Google reCAPTCHA, which can place its own cookies. You should audit each enabled integration to know exactly which cookies are written.
Using the core form does not by itself require cookie consent, but a privacy notice at the point of collection is mandatory. Consent becomes necessary when an integration that sets non essential cookies, such as reCAPTCHA, is enabled, because it must load only after the visitor opts in. Special category data also requires explicit consent.
For the form data itself the basis is usually contract under Art. 6(1)(b) GDPR when the form is needed to provide a service, or consent under Art. 6(1)(a) for purposes like marketing. Integrations that set cookies rely on consent under Art. 5(3) ePrivacy and Art. 6(1)(a) GDPR. Each purpose should be documented separately.
The plugin alone keeps data on your own server, so no transfer happens by default. Transfers occur when you enable United States based integrations such as reCAPTCHA, Stripe, Akismet or Mailchimp, each of which receives personal data. Those transfers need Standard Contractual Clauses or Data Privacy Framework certification plus a transfer impact assessment.
A full assessment is often unnecessary for a simple self hosted contact form, but you should run a screening to confirm. The threshold for a DPIA rises when forms collect sensitive data, operate at large scale, or feed United States based integrations that introduce cookies and transfers.
Collect only the fields you need, show a privacy notice beside each form, and set a retention period for stored submissions. Enable only essential integrations and gate any cookie setting integration behind a consent banner. Keep records of the legal basis, the providers used and the transfer safeguards.
You can reduce risk within Formidable Forms itself by disabling reCAPTCHA in favour of a cookieless honeypot or a European captcha such as Friendly Captcha or hCaptcha configured for EU hosting. EU based form tools or self hosted spam filters also lower the transfer footprint. Choosing fewer external integrations is the most effective change.
Only list cookies that are actually set, which usually means the cookies introduced by the integrations you enabled rather than the core plugin. Name each integration provider, its cookies, their purpose and duration, and note any United States transfer and its safeguard. Review the policy whenever you add or remove an integration.