August 17, 2026 · 6 min read
GDPR and HubSpot forms: proving what your consent text said
Auditors ask what your consent checkbox said on a specific date. HubSpot keeps no history of it. Where consent lives in the form definition and how to build an evidence trail.
GDPR audits rarely ask “do you collect consent?” — they ask something sharper: “show us the exact consent text a visitor saw when this contact submitted your form on March 3rd.” If your consent checkbox has been reworded since — by legal, by a marketer tidying copy, by anyone — HubSpot has no record of what it used to say. Form edits overwrite in place, and there is no version history for forms.
A community Ideas thread has been asking for revision history as a GDPR requirement for years; it hasn’t shipped.
Where consent actually lives
Every HubSpot form definition contains a legalConsentOptions object — the consent-to-communicate text, the consent-to-process text (or legitimate-interest basis), and each subscription checkbox with its label. Pull any form via the API and you can see it:
curl "https://api.hubapi.com/marketing/v3/forms/FORM_GUID" \
-H "Authorization: Bearer YOUR_TOKEN" | jq .legalConsentOptionsThat object is your compliance surface. What HubSpot does store per submission is the consent captured at that moment (visible on the contact’s timeline) — but the form-side history of how the text evolved, when it changed and what it said between edits does not exist anywhere in the product.
A manual evidence pipeline
- Export on a schedule. Fetch every form’s
legalConsentOptionsdaily (the changelog pipeline works verbatim here). - Store immutably with timestamps. A git repository or an S3 bucket with object versioning — the point is that records can’t be quietly edited after the fact.
- Retain to match your policy. Consent evidence should live at least as long as the personal data it justifies — for most teams that means years, not a 30-day log window.
- Document the process itself. Auditors weigh a described, running process much higher than a folder of ad-hoc screenshots.
The gap to close honestly
Neither HubSpot’s API nor any external tool can tell you which user edited a form — the actor isn’t exposed. What can be reconstructed externally, completely, is the what and the when: every version of the consent text with timestamps. For a GDPR evidence trail, that’s the part auditors actually request.
Or automate it
FormRecall snapshots every form — including the full consent configuration — up to every minute, flags any consent-text change as a highlighted event, alerts you by email, and (on Agency) exports timestamped audit reports as PDF/CSV per form: every version of what your consent said, ready to hand over.
Get beta access — first month freethen 50% off any plan for 3 months · lifetime priority support