FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. FormAssembly

FormAssembly

MarketingWebsite

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does FormAssembly do?

FormAssembly is a powerful form builder and data collection platform used by enterprises, nonprofits, and healthcare organisations to create complex forms with conditional logic, Salesforce integration, and HIPAA-compliant configurations. Form submission data is processed in the US by default, with EU data residency available on Enterprise plans. Each form deployment requires careful consideration of the GDPR legal basis applicable to the data being collected.

What is FormAssembly?

FormAssembly is an enterprise data collection platform specialising in complex form creation with conditional logic, multi-step workflows, Salesforce native integration, and HIPAA-compliant configurations. It is used by healthcare organisations, financial services firms, nonprofits, and higher education institutions to collect sensitive data through secure online forms. Forms can be embedded on websites or accessed via hosted URLs. The platform processes form submission data including all personally identifiable information entered by respondents.

What data does FormAssembly collect?

FormAssembly collects all data entered by form respondents, which varies by form configuration but may include names, email addresses, phone numbers, addresses, dates of birth, health information, financial data, and any other fields defined by the form designer. It also collects IP addresses and browser information when the form loads. Submitted data is stored in FormAssembly''s database and may be synced to Salesforce or other connected systems depending on integration configuration.

GDPR and ePrivacy implications

FormAssembly''s GDPR compliance depends heavily on what data is collected in each specific form. For contact or inquiry forms, the legal basis is often legitimate interest or contract performance. For forms collecting consent to marketing, the form itself is the consent mechanism. For healthcare forms collecting health data, explicit consent under Article 9(2)(a) is required. Each form deployment should be assessed individually for its applicable legal basis, data minimisation compliance, and retention period.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

ePrivacy consent is required before the FormAssembly embed script loads for any non-essential cookies it sets. For the form data itself, the consent requirement depends on the purpose: contact forms may rely on legitimate interest or contract performance; lead generation forms require marketing consent captured in the form; forms collecting special category data require explicit consent under Article 9. Every form must include a privacy notice linking to your privacy policy before respondents submit their data.

Data transfers and EU residency

FormAssembly processes data on US infrastructure by default. EU data residency is available for Enterprise customers. For organisations collecting sensitive data from European users, evaluating EU data residency is strongly recommended. Standard Contractual Clauses apply for non-Enterprise customers. The Salesforce integration may create additional transfer obligations if Salesforce data is also processed in the US.

Practical compliance steps

To use FormAssembly compliantly: assess each form individually for its applicable legal basis; include a privacy notice on every form before submission; obtain ePrivacy consent before the embed script loads; for special category data forms, obtain explicit Article 9 consent; sign a DPA with FormAssembly; evaluate EU data residency for sensitive data forms; configure data retention and auto-deletion in the FormAssembly admin; document all form processing in your RoPA with the specific legal basis for each form type.

GDPR consent category

Marketing

Websites using FormAssembly must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) or contract performance (Art. 6(1)(b)) depending on the purpose of the form. Non-essential tracking cookies require ePrivacy consent. Legal obligation (Art. 6(1)(c)) may apply where form data collection is legally required.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, UK GDPR, CCPA, HIPAA (healthcare forms)

DPIA considerations

A DPIA is advisable when FormAssembly forms collect sensitive personal data at scale, particularly health data (HIPAA-applicable forms), financial information, or special category data under GDPR Article 9. The US data transfer and the breadth of Salesforce integration data flows also warrant assessment.

Sample consent text

This form is powered by FormAssembly. The data you submit will be processed by FormAssembly and may be transferred to servers in the United States. Please review our privacy policy to understand how your data will be used before submitting this form.

Technical details

Tracking methodHosted form iframe or embedded JavaScript, first-party cookies, server-side form submission and data storage
Server locationUnited States (FormAssembly infrastructure, AWS) with EU data residency available on Enterprise plans
Data transferred outside the EUFormAssembly is a US-based form builder and data collection platform. Form submission data is processed on US infrastructure by default. EU data residency is available for Enterprise customers. Transfers rely on Standard Contractual Clauses under GDPR Article 46.

Third-party domains contacted

formassembly.comapp.formassembly.comcdn.formassembly.com

Cookies placed

NameTypeDurationPurpose
FASM_SESSIONsessionSessionSession management cookie required for secure form submission and CSRF protection
fa_trackpersistent1 yearForm interaction tracking cookie used to measure form completion rates and funnel analytics

FormAssembly places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does FormAssembly set?

When FormAssembly forms are embedded on a website, the form script may set functional cookies for session management and CSRF protection. For forms served from formassembly.com, cookies are set on the FormAssembly domain. Embedded forms on your own domain require ePrivacy consent for any non-essential cookies.

Does FormAssembly require a GDPR consent banner?

For form submission data, no separate cookie consent is needed if the form uses a contract performance basis. However, embedded form scripts that set non-essential cookies require ePrivacy consent. Every form must include a privacy notice informing submitters of the data controller, legal basis, and US transfer.

What is the legal basis for using FormAssembly?

The basis depends on the form purpose. Contact and service request forms: contract performance (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)). Marketing and newsletter sign-up forms: consent (Art. 6(1)(a)). Healthcare and sensitive data forms: explicit consent (Art. 9(2)(a)).

Does FormAssembly transfer data outside the EU?

Yes by default. FormAssembly processes data in the US. EU data residency is available on Enterprise plans. Standard Contractual Clauses apply for standard plans. Sign FormAssembly's DPA and document the transfer in your RoPA.

Do I need a DPIA for FormAssembly?

A DPIA is advisable when FormAssembly is used to collect sensitive personal data at scale, particularly in healthcare contexts where HIPAA configuration is used, or when form data is used for automated decision-making or profiling.

How do I make FormAssembly forms GDPR-compliant?

Include a privacy notice on every form with the data controller identity, legal basis, data recipients (including FormAssembly), US transfer and SCC safeguard, and data subject rights. For sensitive data, use EU data residency if possible. Sign FormAssembly's DPA. Document the processing in your RoPA.

Are there EU-hosted alternatives to FormAssembly?

Typeform and Tally offer EU data residency. For Salesforce-integrated forms with EU data, Formstack (with EU hosting) is an alternative. For self-hosted form solutions with full data sovereignty, open-source tools like Formio or LimeSurvey can be deployed on EU infrastructure.

How do I handle healthcare data collected via FormAssembly?

Use FormAssembly's HIPAA-compliant configuration and sign a BAA (Business Associate Agreement). Under GDPR, health data collected via forms is special category data under Article 9, requiring explicit consent (not just implied consent). Include a specific statement that health information is being collected and will be processed for the stated medical purpose. Evaluate EU data residency for maximum compliance.