Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Data Protection and Security

Your contact form may be the most open door on your site

Forms are the points where your site accepts data from outside, which is why they are the first place spam bots and attackers try. Here are the layers that make a form secure and KVKK-compliant.

Web form security is the full set of measures that keep the contact, quote, application and sign-up forms on your site from being abused and protect the personal data they collect. A form is the door through which your site accepts data from outside. Spam bots knock on that door hundreds of times a day, and sometimes someone tries to force the lock. The picture we see most often in the field: an inbox full of fake messages with real customer requests lost among them, and form data piling up in a table for years without ever being deleted. In this article we explain how to secure a form layer by layer.

Spam and bot protection without wearing out visitors

The first reflex against spam bots is usually to add a visual challenge (CAPTCHA). It works, but it also wears out real visitors, and some solutions bring third-party cookies and cross-border data transfers with them. A more balanced approach combines several invisible layers:

  • Honeypot field: A hidden field that humans don't see but bots fill in. If it is filled, the submission is rejected.
  • Timing check: A form submitted two seconds after the page loaded is very likely not a human.
  • Rate limit: Large numbers of submissions from the same address in a short time are stopped.
  • Content rules: Messages stuffed with links or matching certain patterns are moved to a separate box.
  • Invisible verification, if needed: If the layers above aren't enough, add a verification layer that works without asking the visitor anything. If a third-party service is used, this must be reflected in your cookie and privacy notices.

Injection and malicious input

Every piece of data coming from a form should be treated as untrusted. Injection is when an attacker types a command into a form field instead of data, so that the system executes that command. The main types and their countermeasures:

RiskWhat happensCountermeasure
SQL injectionData is read from or deleted in the databaseParameterized queries; never paste input into the query text
XSS (cross-site scripting)A message opened in the admin panel runs code in the admin's browserEscape output when rendering it, content security policy
Email header injectionThe form is used to send spam to othersReject line-break characters in name and email fields
CSRF (cross-site request forgery)Another site submits the form on the user's behalfA single-use validation token per form

Validation should happen both in the browser and on the server. Browser checks are a convenience for the user; server checks are what provide security.

File uploads: the riskiest part

File upload fields, such as those for job applications or for sending drawings or photos with a quote request, are the riskiest part of a form. Our recommendations:

  1. Allow only the file types you really need, and check the type from the file's content, not its extension.
  2. Set a maximum file size.
  3. Store uploaded files with random names in a folder that can't be accessed directly over the web.
  4. Disable script execution in the upload folder.
  5. If possible, run files through a malware scan.
  6. Instead of attaching files to emails, show them to the authorized person in the admin panel.

Files such as CVs and identity documents contain a lot of personal data; making them reachable through a public link carries a serious risk of a breach.

Data minimization: the safest data is data you never collect

One of the core principles of KVKK (Türkiye's Personal Data Protection Law) is that data must be relevant, limited and proportionate to the purpose for which it is processed. When designing a form, ask of every field: "Could we respond to the request without this information?" Asking for a national ID number, date of birth or home address on a contact form is usually unnecessary. Removing unnecessary fields reduces both the risk of a breach and the number of visitors who abandon the form halfway.

Retention periods are part of minimization, too. Contact requests that have been answered should be deleted or anonymized once the defined period ends. We explained how to write the information shown on the form in our article on the website privacy notice, and how to route requests into the sales process without losing them in from web form to CRM.

Form security checklist

  • The form runs only over HTTPS
  • Invisible bot layers (honeypot, timing, rate limit) are active
  • All input is validated on the server; queries are parameterized
  • Each form has a validation token
  • File upload type, size and storage location are restricted
  • Every field has a defined purpose; there are no unnecessary fields
  • The privacy notice link is visible before the submit button
  • A retention period is defined and enforced for form data
  • Notification emails don't carry sensitive data or attachments

How we do it at Globya

On the corporate websites we build, we deliver forms with invisible bot layers, server-side validation and protected file storage. Incoming requests are collected in the admin panel; the notification email carries only a summary, and attachments stay in the panel. We set the retention period with you and build it into the software as a rule. As part of our KVKK compliance approach, these requirements are never left out, and there is no extra charge for them.

Frequently asked questions

Does spam really go down without a CAPTCHA?

On most sites, invisible layers stop the bulk of spam. If that isn't enough, an additional verification layer is added; we recommend trying the methods that don't burden visitors first.

How long should we keep form data?

It depends on the purpose. An answered information request and a job application have different retention periods. Set your periods in line with your retention and destruction policy, and confirm the legal periods with your legal advisor.

Is it a problem for form notifications to arrive by email?

A summary notification is fine. But having sensitive content such as identity details, CVs or health information, along with attachments, circulating by email increases the risk; keeping them in the panel is safer.

Can you test our existing forms?

Yes. Reach us at +90 850 432 55 13 or through our contact page; we will review your forms against this list and send you our findings in writing.

Anything on your mind about this article?

The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.

Ask the assistant

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.