Files
birthday_messaging/docs/compliance/gdpr-audit.md

984 B

# GDPR Adequacy Checklist

## Governance & Breach Protocols

- DPO appointed and documented

- 72-hour breach notification process defined

## Consent & Data Collection

- No pre-ticked marketing consent boxes

- Explicit consent required for birthday listings

## Sensitive Data Handling

- Medical data restricted to "unwell" status

- Dietary data shared only with explicit consent

## International Data Transfers

- Photo/video sharing audited for adequacy mechanisms

Data Protection Officer (DPO)

Name: [Your Name Here] Role: [Your Role Here] Contact: [email@example.com] Date Appointed: [YYYY-MM-DD]

Data Protection Officer (DPO)

Name: Role: Contact: Date Appointed:

Regulatory Feature Specifications

Right of Access (Article 15)

Users can request a downloadable summary of stored personal data.

Right of Erasure (Article 17)

Users can trigger full deletion across all systems and subprocessors.