← All guides

August 17, 2026 · 6 min read

GDPR and HubSpot forms: proving what your consent text said

Auditors ask what your consent checkbox said on a specific date. HubSpot keeps no history of it. Where consent lives in the form definition and how to build an evidence trail.


GDPR audits rarely ask “do you collect consent?” — they ask something sharper: “show us the exact consent text a visitor saw when this contact submitted your form on March 3rd.” If your consent checkbox has been reworded since — by legal, by a marketer tidying copy, by anyone — HubSpot has no record of what it used to say. Form edits overwrite in place, and there is no version history for forms.

A community Ideas thread has been asking for revision history as a GDPR requirement for years; it hasn’t shipped.

Where consent actually lives

Every HubSpot form definition contains a legalConsentOptions object — the consent-to-communicate text, the consent-to-process text (or legitimate-interest basis), and each subscription checkbox with its label. Pull any form via the API and you can see it:

curl "https://api.hubapi.com/marketing/v3/forms/FORM_GUID" \
  -H "Authorization: Bearer YOUR_TOKEN" | jq .legalConsentOptions

That object is your compliance surface. What HubSpot does store per submission is the consent captured at that moment (visible on the contact’s timeline) — but the form-side history of how the text evolved, when it changed and what it said between edits does not exist anywhere in the product.

A manual evidence pipeline

  1. Export on a schedule. Fetch every form’s legalConsentOptions daily (the changelog pipeline works verbatim here).
  2. Store immutably with timestamps. A git repository or an S3 bucket with object versioning — the point is that records can’t be quietly edited after the fact.
  3. Retain to match your policy. Consent evidence should live at least as long as the personal data it justifies — for most teams that means years, not a 30-day log window.
  4. Document the process itself. Auditors weigh a described, running process much higher than a folder of ad-hoc screenshots.
Timestamped records produced by an independent system read stronger in an audit than internal spreadsheets edited by the same team that edits the forms. (This is general information, not legal advice — run your retention and evidence approach past your counsel.)

The gap to close honestly

Neither HubSpot’s API nor any external tool can tell you which user edited a form — the actor isn’t exposed. What can be reconstructed externally, completely, is the what and the when: every version of the consent text with timestamps. For a GDPR evidence trail, that’s the part auditors actually request.

Or automate it

FormRecall snapshots every form — including the full consent configuration — up to every minute, flags any consent-text change as a highlighted event, alerts you by email, and (on Agency) exports timestamped audit reports as PDF/CSV per form: every version of what your consent said, ready to hand over.

Get beta access — first month freethen 50% off any plan for 3 months · lifetime priority support