Compliance-Ready online forms for every business

From the instant someone clicks Submit until every response is securely stored, Zoho Forms safeguards your data with enterprise-grade security and global compliance standards.

Alt text for image

Certifications, not claims.

Each one represents a standard that Zoho's infrastructure and Zoho Forms are assessed against.

  • Alt text for image

    GDPR

    Full compliance with the EU's General Data Protection Regulation for collecting and processing respondent data.

    Learn more
  • Alt text for image

    HIPAA

    Built-in ePHI handling, encryption, and audit trails so covered entities can collect health data responsibly.

    Learn more
  • CCPA

    CCPA

    Respects the access, deletion, and opt-out rights of California residents whose data passes through your forms.

  • wcag

    WCAG 2.2 AA

    Forms can be built to meet accessibility guidelines, so no respondent is discriminated based on their disabilities.

  • ISO

    ISO/IEC standards

    Zoho Forms adheres to globally recognized standards to ensure the highest levels of data security, privacy, and quality. 

  • Audit-logs

    SSL certification

    All data transferred between users and Zoho Forms is encrypted using secure sockets layer (SSL) certification.

  • enc

    AES-256 encryption

    Zoho Forms encrypts data at rest using the AES-256 standard. This is the baseline for high-security environments.

  • transit

    TLS 1.2/1.3

    Every form is protected by TLS 1.2/1.3 (Transport Layer Security). This ensures that data moving from the respondent’s device to Zoho Forms' servers is unreadable to anyone trying to intercept it.

The controls behind every certification

These are the actual settings inside Zoho Forms that make the certifications above more than a logo on a page.

  • Double Opt-In

    Double Opt-In sends a confirmation email to the respondents after they submit the form. The submission is only recorded once they click the confirmation link in that email to reduce spam entries.

    Learn more
  • OTP Verification

    Verify respondents before their submission counts with One-time password (OTP) confirmation. Users receive a unique code via WhatsApp, SMS, or email, and the form becomes accessible only after the OTP verification.

    Learn more
  • CAPTCHA

    Protect your forms from spam and abuse with CAPTCHA. Make use of Zoho Forms CAPTCHA, Google reCAPTCHA and Cloudflare Turnstile to ensure that your form submissions are from real users and not automated bots.

    Learn more
  • Field encryption

    Encrypting field data protects your data from any possible data leak or unauthorized access. It is the process of encoding field information to make it accessible only to authorized parties.

    Learn more
  • Full-scale audit logs

    Maintain accountability, ensure compliance, and foster transparency with Zoho Forms' built-in auditing features - Org Audit, Form Audit, Record Audit, Email Audit. Every submission, edit, and event is logged.

    Learn more
  • Form Encryption

    Form Encryption is an advanced security feature in Zoho Forms that protects your form data with a secret Access Code. This makes your data unreadable to anyone without the code, even if they gain unauthorized access.

    Learn more
  • Consent & Legal Fields

    Purpose-built field types make lawful data collection easy. Terms & Conditions field with a rich-text agreement and required checkbox.Consent field for granular opt-ins.Zoho Sign field for legally binding signatures.

    Learn More
  • Inline OTP Verification

    Send a time-sensitive code to respondents email address or phone number. Unlike pre-access OTP, the respondent fills in their contact detail inside the form, receives the OTP to that address, and must verify it before the submission is recorded.

    Learn More
  • Layered defence

    Combining multiple security features to get the right combination that helps keep bots and human spammers out of your form. CAPTCHA + Inline OTPCAPTCHA + Double Opt-InOTP Verification + Double Opt-In are some combinations to try out.

    Learn More

Best practices to build secure online forms

Collecting data securely is only half of the battle. How you handle, transmit, and store that data after submission is equally important.

  • Secure file uploads

    Restrict allowed file types to what is necessary. Enable field-level encryption for sensitive files like proof of ID.

  • Data retention

    Only collect what is essential. Removing unnecessary fields reduces your security liability. Periodically delete old entries that are no longer needed.

  • Enable HIPAA before collecting PHI

    If your forms will collect Protected Health Information (PHI), activate HIPAA mode before a single response comes in

  • Include a Consent field

    This gives respondents meaningful transparency about how their data will be used.

Image alt text

Frequently Asked Questions

The forms created or the data collected would still be accessible and will not be lost or deleted unless the same is deleted manually on your end when the account is downgraded to the Free plan. We do not have a time boundary for our Free plan. However, if you do not access Zoho Forms for a year, you would receive three email notifications from our end and your free Zoho Forms account would be eligible for cleanup. To avoid deletion of your free Zoho Forms account, we recommend that you log in to Zoho Forms at least once a year.

All Zoho products are secure by design. Our framework ensures that each customer's data is logically separated from other customers' data. Individual sensitive fields can be independently encrypted via field-level encryption. Our data centers (DCs) are physically secure with strict access control.

There is no universal rule. Retention periods depend on the purpose of the form. As a general rule, delete entries that are no longer needed, especially for forms collecting personal or sensitive information.

Field-level encryption lets you apply a dedicated layer of encryption to individual form fields (separate from the database-level AES-256 encryption that already covers all stored data). It is recommended for fields that capture particularly sensitive information, such as national ID numbers, financial account details, or health-related data, where you want that field's contents encrypted independently even within the same database.

Zoho Forms retains record audit logs for 90 days, after which they are automatically deleted.

When you delete data, it enters a Trash state. Once purged from the trash, it is removed from active databases immediately.

What better day to start building compliant forms?