---
Before you serve EU users
If your app can be used by someone in the EU, GDPR applies to their personal data. This is a control inventory, not a pass/fail certificate — each unchecked item is a remediation task, and counsel should review the result.
The checklist
- Lawful basis per purpose — consent, contract, or legitimate interest documented for each thing you do with personal data (Art. 6).
- Transparent notice — a privacy policy stating what you collect, why, and the basis, in plain language (Art. 12–14).
- User-rights handling — a working path for access, deletion, portability, and objection (Art. 15–22).
- Processor agreements — written terms with each SDK/processor that touches personal data (Art. 28).
- International transfer — a mechanism (e.g., SCCs) if you send EU data outside the EEA.
- Breach path — a process to detect and report a personal-data breach within 72 hours (Art. 33).
How to use the output
Each unchecked item becomes a tracked fix with an owner. A generator like PolicyDeck drafts the notice from your answers; the agreements, transfer mechanism, and breach process stay with your team and counsel. The finished checklist is evidence you looked — not a claim of compliance.
What the checklist is not
It is a GDPR control inventory for an app, not a full legal assessment. It does not cover every obligation (e.g., DPIAs for high-risk processing) and a completed checklist is not a guarantee. Compliance depends on actual practices plus counsel review.
Authoritative references
- GDPR Art. 6 (lawful basis): https://gdpr-info.eu/art-6-gdpr/
- GDPR Art. 12–14 (transparency): https://gdpr-info.eu/art-12-gdpr/
- GDPR Art. 33 (breach notification): https://gdpr-info.eu/art-33-gdpr/