To use this feature on individual forms, your organization's super admin must first enable Form Encryption at the organization level — similar to HIPAA compliance. This is a one-time setup that allows all forms in your organization to be encrypted.
Here are some key things to keep in mind:
Access Code: Each encrypted form is protected by a unique access code you set. You and your collaborators must enter this code to view or manage the data.
Org-level Control: Your organization's super admin must enable this feature for the organization first, before it can be used on individual forms.
Data Access Control: To keep your form data secure, some features like notifications or data exports, that use form data, are restricted by default when a form is encrypted.
Permanent Protection: Once a form's data is encrypted, it stays that way forever. It cannot be converted back to normal text within Zoho Forms.
To enable Form Encryption for your organization:
On the forms listing page, under Setup, click Control Panel.
Click Form Encryption under Data Administration.
Click Enable Form Encryption to set it up for your organization.
In the pop-up, click Enable.
Form encryption is now enabled for your organization. You can view and edit the Data Access Permissions for your organization.
Enabling form encryption restricts data access for features like notifications, data export/download, integrations, and webhooks. You can modify these permissions later if needed. Learn more
With Org-level Form Encryption enabled, form admins can now configure encryption for individual forms. Learn more
You also have the option to disable Org-level Form Encryption later if needed. Learn more

To enable Form Encryption for your form:
In your form builder, navigate to Settings > Compliance & Audit > Form Encryption.
Click Configure Form Encryption to proceed.
A configuration screen will appear. Read the instructions in the Encryption Details section and click Next.
Set a 6-character alphanumeric access code and confirm it to secure your form data in the Access Code Setup section. All users, including the form admin will need this code to view the encrypted data later. Learn more

In the Data Access Permissions section, you can choose to restrict or allow form data access for the listed features. Learn more

Click Enable Form Encryption to complete the encryption setup for your form.
Your form is now encrypted. This will secure your All Entries, Reports, Approvals and Tasks with an Access Code.
Note:
If Org-level Form Encryption is enabled, the organization admin has the option to disable it anytime.
To disable Form Encryption for your organization:
On the forms listing page, navigate to Control Panel > Data Administration, then click Form Encryption.
Click Disable.
In the pop-up, click Disable again to confirm.

Click Enable.
In the pop-up, click Enable again to confirm.
Now, you can go ahead and configure form encryption for individual forms within the organization.
Notifications – Email, SMS, WhatsApp, Mobile App: Send notifications via email, SMS, Whatsapp or in Mobile app involving form data.
Data Export/Download: Export the form data as PDF/CSV, use form data for scheduled reports and download the uploaded attachments.
Integrations/Webhooks: Share form data via Integrations and Webhooks to other Zoho products or third parties.
If data access is allowed at org-level for a feature, it will continue to work normally for encrypted forms in the organization. If it's restricted, the feature will be either limited or disabled:
Notifications will still be sent, but they will not contain any form data.
Data Export/Download will be disabled. This means PDF/CSV export cannot be done, uploaded attachments can't be downloaded, and form data cannot be used for scheduled reports.
Integrations/Webhooks cannot be configured for encrypted forms in the organization.
Organization admins can view and modify data access permissions. To modify these permissions for your organization:
Under Data Access Permissions, view the current permissions (either Allow or Restrict) for each feature.
In the pop-up, enable or disable the checkboxes to Allow or Restrict data access for each feature, then click Save.
A list of encrypted forms impacted by this change will appear. Click Yes, Proceed to finish editing the settings.
Restrictions on Active Integrations/Webhooks
You cannot restrict data access for Integrations/Webhooks at the organization level if they are already enabled on one or more forms. A list of these forms will be shown for your reference.
For a form with Integrations or Webhooks configured, you cannot configure form encryption if the data access for Integrations/Webhooks is restricted at the org-level. You must allow data access at org-level and then proceed for configuring encryption for the form.
If Integrations/Webhooks are already configured in a form, their data access cannot be restricted later within both the org-level and form-level encryption settings.

Note: If data access for a feature is restricted at the org-level, it will be restricted across all encrypted forms, even if allowed at the form-level.
Form admins can modify the data access permissions for their specific forms. To manage these permissions:
Under Data Access Permissions, view the current permissions (either Allow or Restrict) for the listed features.

Click Edit to modify the data access permissions.

In the pop-up, enable or disable the checkboxes to Allow or Restrict form data access for each feature, then click Save.

Let's quickly summarize the data access permissions for the features in the table below:
Features | Data Access Permissions | |
If Allowed at Org-level | If Restricted at Org-level | |
Notifications (Email,SMS, WhatsApp,Mobile App) | 1. For notification-configured forms, the feature continues to work normally, and form data is included in notifications. | 1. For notification-configured forms, feature will still work, but notifications will be sent without form data. |
Data Export/Download | 1. Data export as PDF/CSV, downloading attachments, sending attachments in report mailers all continue to work normally. | 1. Data export as PDF/CSV, downloading attachments, sending attachments in report mailers will all be disabled. |
Integrations/Webhooks | 1. For forms with integrations/webhooks configured, feature continues to work normally. | 1. For forms with integrations/webhooks configured, restricting org-level form data access is not possible and error will be thrown. |
Note:
Once a form is encrypted, its data (All Entries, Reports, Approvals and Tasks) is secured and requires an Access Code for viewing. This code is unique to each form, so even if you have multiple encrypted forms, each is independently protected. You should keep the code secure to protect your data from unauthorized access.
When you attempt to view an encrypted form's entries, reports, or approval sections, a popup will appear and you'll be prompted to enter the Access Code.
Enter the correct access code and click Access Form Data to view.

If you're the form owner or a collaborator and forget the access code, you can have it sent to your registered email address.
To receive the access code:
In your form builder, navigate to Settings > Compliance & Audit > Form Encryption.
Click on the horizontal ellipsis.
Click Forgot Access Code.
In the pop-up, click Send Access Code.
You can now retreive the access code from your mailbox and use it to view your encrypted form data.
Form admins can securely share the access code with collaborators, such as approvers or form users, via email.
For Shared Users: For users with access to the form, you can send them the access code via a notification mail from Form Settings > Share.
For users with Modify Form or higher permissions, hover over their name and click Send Access Code.
For users with the Submit Form role, the access code cannot be sent.
For Approvers: When adding an approver in an encrypted form, you have an additional option named Notify Approvers with Access Code. This includes the code in the email notification they receive, allowing them to access the approvals section.
When a user enters the access code incorrectly for 5 times, their access to the form data will be locked to prevent unauthorized attempts. The locked user must contact the form owner or collaborator to regain access.
You can access the Locked Users list from the Form Encryption Settings. This shows all users whose access to form data is locked due to failed attempts, and you can unlock them individually or in bulk.
To unlock users, a form owner or collaborator can follow these steps:
In your form builder, navigate to Settings > Compliance & Audit > Form Encryption.
Click Locked users.
In the pop-up, locked users will be listed under the Users section.
To unlock a single user: Hover over the user's name, click Unlock, click Yes in the confirmation pop-up.
To unlock all users: Click Unlock All and click Yes in the pop-up.

Form Encryption in Zoho Forms provides top-notch security for your submissions, ensuring the stored data is readable only by authorized parties with the secret Access Code. It is specifically designed to help you meet strict data privacy standards when dealing with information like confidential records or personal identifiers.
By understanding and following the steps above, you can confidently use Form Encryption to secure your forms. Always remember to keep the Access Code safe and limited to the right people and make use of one of the strongest security features Zoho Forms has to offer in the right way.
Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.
If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.
All-in-one knowledge management and training platform for your employees and customers.
You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.