Websites7 min read
Business Contact Form: Which Fields Do You Actually Need?
Published By Ichii GmbH
Contents
For most business websites, three required fields are enough: name, email address and message. Everything else, such as phone number, company or timeframe, works better as optional. Fields you don't need for a first reply are best left out altogether.
No law lists which fields must be required. If you operate in Germany, though, the GDPR (DSGVO in German) sets a principle that shapes the answer: personal data must be limited to what is necessary for the purpose (data minimisation, Article 5(1)(c)). For a contact form, that means: make required only what you genuinely need to reply.
This guide covers the form itself. If your form works but nobody uses it, the diagnosis in website visitors but no enquiries is the better starting point.
In short
- Required: name, email, message. Optional: phone, company, topic, timeframe. Avoid: title or salutation, postal address, date of birth and anything you don't need for a first reply.
- No law prescribes required fields. The yardstick is data minimisation under Article 5(1)(c) GDPR.
- Next to the form, say briefly what you use the data for and link your privacy policy (Article 13 GDPR).
- A consent checkbox is often not the right legal basis for simply answering an enquiry. Check this with a data protection adviser.
- Visible labels, clearly marked required fields and helpful error messages make the form usable for everyone.
- Spam can often be stopped without picture puzzles, for example with a hidden field for bots and a limit on how often someone can submit.
Field by field: required, optional or avoid
The table assumes a typical contact form on a service business website. If you have a good reason to deviate, for example because you only advise by phone, write that reason down.
| Field | Status | Why | Technical note |
|---|---|---|---|
| Name | required | To address the person and match the enquiry | One single field, autocomplete name |
| Email address | required | No address, no reply | Input type email, autocomplete email |
| Message | required | The actual enquiry | A generous text box with a hint on what helps |
| Phone number | optional | Only for people who want a call back | Input type tel, autocomplete tel; accept international numbers |
| Company | optional | Useful for business clients, irrelevant for private ones | autocomplete organization |
| Topic or service | optional | Helps you route the enquiry | Drop-down with an "Other" option |
| Timeframe or budget range | optional | Helps both sides judge fit early | Rough ranges rather than free text |
| Preferred language | optional | If you reply in English and German | Two options are enough |
| Postcode | optional, only for on-site services | To check your service area | Only if you actually decide on it |
| Title or salutation (Herr/Frau) | avoid | Not needed to reply; forces a choice | – |
| Full postal address | avoid | Not needed for a first reply | Ask later, in the quote |
| Date of birth | avoid | Not needed for an enquiry | – |
| File upload | only if needed, optional | E.g. photos of damage, floor plans | State allowed file types and size |
Note: this is practical guidance based on data minimisation, not a legal list. A form that leaves name and email optional is not wrong if you are happy to answer anonymous questions.
Why one name field, and why the phone number is optional
A single name field works better than separate first and last name fields, especially if your clients come from many countries. MDN, the web developer reference, notes that a single full-name field "avoids dealing with the wide diversity of human names". Google's web.dev guide on forms likewise recommends letting people enter their name in one input.
The phone number is the classic debate. If you can answer by email, you don't need it. As a required field it would then be hard to square with the rule that data must be limited to what is necessary. As an optional field labelled "for a call back", you still get the number from everyone who actually wants a call.
web.dev puts the general rule plainly: don't ask for data you don't need. Every extra field makes the form longer, and stored data is a responsibility.
The privacy notice next to the form
Under Article 13 GDPR, you inform people at the time you collect their data, including who is responsible, the purpose, the legal basis, how long you keep the data and their rights. The full details belong in your privacy policy (Datenschutzerklärung). Next to the form, a short note with a link is usually enough in practice.
Template
Short notice below the form
- We only use your details to reply to your enquiry.
- Required fields are marked; everything else is voluntary.
- We delete your enquiry once it is dealt with, unless we have to keep it for legal reasons.
- Details, your rights and the legal basis are in our privacy policy [link].
Adapt the wording to what you actually do. The deletion point reflects the GDPR principle of storage limitation (Article 5(1)(e)): keep data only as long as needed for the purpose. How long that is for you can also depend on German tax and commercial record-keeping rules, so check with your tax adviser.
If your site is bilingual, the notice and the form labels should be in the same language as the page.
Do you need a consent checkbox?
Many forms show a required checkbox saying "I consent to the processing of my data". For simply answering an enquiry, that is often not the right construction. Besides consent (Article 6(1)(a)), the GDPR provides other legal bases:
- Article 6(1)(b): processing needed for steps taken at the person's request before entering into a contract, for example a request for a quote.
- Article 6(1)(f): legitimate interests, for example for general questions, unless the person's interests override them.
Which basis fits your form depends on the case and should be stated in your privacy policy. Have this reviewed by your data protection adviser or a lawyer familiar with German and EU data protection law. Additional purposes are different: a newsletter, for example, needs its own voluntary consent, such as a checkbox that is not pre-ticked.
Watch out
No compliance guarantee
This article gives practical orientation and is not legal advice. The right notices and legal bases for your form depend on your business, your processes and the services you use.
Accessibility: labels, required fields, errors
A form that some people can't use loses enquiries. The key points from the web standards:
- A visible label for every field. WCAG 2.2 requires labels or instructions where input is expected (Success Criterion 3.3.2, Level A). A placeholder inside the field is not enough, because it disappears as soon as someone types.
- Mark required fields in the label, for example "(required)", or mark the optional ones with "(optional)". If you use an asterisk, explain it at the top of the form.
- Error messages that explain what went wrong and how to fix it, such as "Please enter an email address including @".
- The right input types and autocomplete values, so phones show the right keyboard and browsers can fill in name, email and phone.
- A success message after sending, so people know the enquiry arrived.
Spam protection without picture puzzles
Picture puzzles (CAPTCHAs) are a barrier for many people. W3C's accessibility working group writes that CAPTCHAs often prevent people with disabilities from completing a task, and describes alternatives. For a small contact form, these are often enough:
- Honeypot: a field hidden from humans that only bots fill in. The W3C note says this approach is easy to implement and should be considered.
- Rate limiting: one sender can only submit a certain number of times in a short period.
- Server-side checks: for example a minimum time between loading and sending the form, and plausibility checks on the input.
- Your mailbox's spam filter for whatever gets through.
If you use a third-party CAPTCHA service, also check whether it sends data to others or stores information on the visitor's device. That can affect your privacy policy and whether you need consent under § 25 TDDDG, the German rule on cookies and similar technologies.
Before and after
Example
Hypothetical example: a small language school's form
Before: title, first name, last name, nationality, street, postcode, city, phone, email and message, all required, plus a required consent checkbox and a picture puzzle.
After: name, email and message required. Phone optional, labelled "for a call back". Preferred language (English or German) optional. Nationality removed, because the first reply doesn't depend on it. Below the form, a short privacy note with a link, and a hidden honeypot field instead of the puzzle. Eleven required entries become three.
Which questions help you without overloading the form also depends on what your pages already answer. For structure and content, see the pages a small business website needs.
At Ichii, a contact option is part of the business website with up to 10 pages (€790 net plus VAT, one-time). We decide together which fields your form asks for. You supply the text for your privacy policy and Impressum; the legal review is a job for your adviser.
Your next step
Go through your current form with the table above and remove every required field you don't need for a first reply. If you are planning a new website, note the fields you want in your brief straight away. Our website brief template has room for that, and our business website page shows what's included and the price.
Sources
- Art. 5 GDPR – Principles relating to processing of personal data — dsgvo-gesetz.de (unofficial consolidated text, German), accessed 2026-10-09
- Art. 6 GDPR – Lawfulness of processing — dsgvo-gesetz.de (unofficial consolidated text, German), accessed 2026-10-09
- Art. 13 GDPR – Information to be provided where personal data are collected — dsgvo-gesetz.de (unofficial consolidated text, German), accessed 2026-10-09
- § 25 TDDDG – Schutz der Privatsphäre bei Endeinrichtungen — Federal Ministry of Justice, gesetze-im-internet.de, accessed 2026-10-09
- Understanding SC 3.3.2: Labels or Instructions — W3C WAI, accessed 2026-10-09
- Forms Tutorial — W3C WAI, accessed 2026-10-09
- Inaccessibility of CAPTCHA (Group Draft Note, 16 December 2021) — W3C, accessed 2026-10-09
- Payment and address form best practices — web.dev (Google), last updated 2020, accessed 2026-10-09
- HTML attribute: autocomplete — MDN Web Docs, accessed 2026-10-09
Read next
Websites
Website Visitors but No Enquiries? How to Find the Cause
A diagnostic checklist for small business sites in Germany: quick technical checks first, then audience, message, language, contact path and trust. No invented benchmarks.
7 min read
Websites
Which Pages Does a Small Business Website Need?
The core pages, the two legal pages every business site in Germany needs, and when one page is enough, with a page planner and two example site structures.
6 min read
Project planning
Website Brief Template: What to Send Before You Ask for a Quote
A copyable brief for a small business website, sized for up to 10 pages and adapted to Germany, with notes on each section and a filled-in example.
8 min read
A business website with up to 10 pages
A one-time €790 net – built on a proven design system with your text and images. The offer page lists everything that is included.