All articles

Privacy by design

Better Privacy Starts with a Shorter Form

September 8, 2026 · Web Privacy Consulting

How to ask for less information, explain what you need, and make website forms more respectful of the people using them.

Minimal glass form with three fields beside a stack of unused field panels
Original AI-generated editorial illustration.

A simple request can turn into a surprisingly personal questionnaire. Someone wants a product update, a quote, or a response to a question, yet the form asks for a phone number, job title, home address, and date of birth. Before adding another field, a website owner can ask a more useful question: what does this person need us to do, and what information makes that possible?

That question puts privacy into an ordinary design decision. A shorter form is not automatically a compliant form, and some services genuinely need detailed information. The goal is to make each request intentional and understandable, rather than allowing a template to decide what everyone must disclose.

Give every field a job

The Federal Trade Commission’s business guide recommends limiting sensitive personal information to what a business has a legitimate need to collect and retain. That principle offers a useful starting point for reviewing a website form.

Imagine a newsletter signup. An email address has an obvious role in delivery. A mailing address may not. For each field, finish this sentence: “We use this information to…” If the answer is vague, such as “it might be useful someday,” pause the collection and identify a concrete purpose before keeping the field.

Make this a conversation with the people who actually handle submissions. A field may have been added for a campaign that ended months ago, or for an internal report nobody uses. Asking how a value changes the next step can reveal whether it is useful in practice.

Ask for the least detailed useful answer

NIST’s definition of minimization connects personal information processing with what is relevant and necessary for its purpose. As a design exercise, consider whether a broad answer could accomplish the same task as a precise one.

For example, an initial service inquiry might need a general service area before it needs a street address. A request for an estimate might start with a project category rather than an unrestricted description of someone’s circumstances. These are illustrative choices, not universal rules; the appropriate level of detail depends on the service.

Timing matters too. Information needed to complete an order may not be needed when someone is only asking whether a service is available. Consider gathering additional details at the stage when they become relevant, with an explanation beside the request.

Make optional mean optional

If a phone number is optional, label it that way and test the form without one. A field that looks optional but blocks submission creates an avoidable mismatch between the interface and the actual process. Do the same check on a phone screen, where explanatory text can be easy to miss.

Keep a request for updates distinct from a request for help. A person asking a question should be able to understand whether they are also choosing a separate communication. Design those choices clearly, and check any applicable consent requirements rather than treating a general submit button as a complete answer.

Put explanations where decisions happen

A privacy notice remains useful, but short, accurate explanations beside a field can answer the immediate question: why are you asking? Explain the intended use in ordinary language. Avoid reassuring statements that your actual tools or internal practices cannot support.

Free-text boxes deserve particular care. Consider a brief instruction asking people to leave out sensitive details that are unnecessary for the request. If sensitive information is required, choose a collection process appropriate to that information rather than encouraging it in a general inquiry box.

Follow the submission beyond the screen

Review what happens after someone presses submit. Does the entry arrive in a shared inbox, populate another service, or appear in automated notifications? A form review should include those destinations and the people who can access them. Removing a visible field will not resolve unnecessary collection elsewhere in the workflow.

Once you know the route, connect it to a retention and deletion plan. A focused collection process and a clear end point work together: one limits what arrives, while the other addresses what happens when its purpose is finished.

Start with one form

Choose your most common form and review it field by field. Remove one unnecessary request, clarify one confusing explanation, and test the completed experience with ordinary sample data. Repeat the review when the form or its connected services change. Privacy becomes more practical when it is part of these everyday maintenance decisions.

General educational information, not legal advice. Requirements depend on the service, information, and applicable rules.