Section 37 · Operations & Incident Management

GDPR & Privacy Compliance

User rights, consent management, and privacy documentation for regulatory compliance

11 items 10 critical 1 recommended

This guide walks you through auditing a project's GDPR and privacy compliance - user rights, consent management, and required documentation.

The Goal: Privacy by Design

User data should be handled with intentionality. Rights are exercisable, consent is meaningful, and data flows are documented and controlled.

  • Exercisable — Users can delete, export, and manage their data through clear mechanisms
  • Enforceable — No tracking before consent; withdrawal as easy as granting
  • Documented — Privacy policy current, ROPA maintained, all processors known and contracted
  • Complete — Deletion and export cover all services, not just the main database

Before You Start

  1. Identify target markets (EU users trigger GDPR, California triggers CCPA, etc.)
  2. Understand data collected (what personal data, how sensitive)
  3. Check for existing privacy documentation (privacy policy, ROPA, DPAs)
  4. Review user-facing flows (signup, consent banners, account settings)