---

Before you serve EU users

If your app can be used by someone in the EU, GDPR applies to their personal data. This is a control inventory, not a pass/fail certificate — each unchecked item is a remediation task, and counsel should review the result.

The checklist

  • Lawful basis per purpose — consent, contract, or legitimate interest documented for each thing you do with personal data (Art. 6).
  • Transparent notice — a privacy policy stating what you collect, why, and the basis, in plain language (Art. 12–14).
  • User-rights handling — a working path for access, deletion, portability, and objection (Art. 15–22).
  • Processor agreements — written terms with each SDK/processor that touches personal data (Art. 28).
  • International transfer — a mechanism (e.g., SCCs) if you send EU data outside the EEA.
  • Breach path — a process to detect and report a personal-data breach within 72 hours (Art. 33).

How to use the output

Each unchecked item becomes a tracked fix with an owner. A generator like PolicyDeck drafts the notice from your answers; the agreements, transfer mechanism, and breach process stay with your team and counsel. The finished checklist is evidence you looked — not a claim of compliance.

What the checklist is not

It is a GDPR control inventory for an app, not a full legal assessment. It does not cover every obligation (e.g., DPIAs for high-risk processing) and a completed checklist is not a guarantee. Compliance depends on actual practices plus counsel review.

Authoritative references

  • GDPR Art. 6 (lawful basis): https://gdpr-info.eu/art-6-gdpr/
  • GDPR Art. 12–14 (transparency): https://gdpr-info.eu/art-12-gdpr/
  • GDPR Art. 33 (breach notification): https://gdpr-info.eu/art-33-gdpr/