Status: Compliance inspection pending. The checklist below reflects what we've implemented ourselves as of the date below. It has not yet been reviewed or certified by a qualified data protection representative or outside legal counsel — treat this as a good-faith progress report, not a legal attestation of compliance.
Last updated: October 4, 2026
| # | Requirement | GDPR Article | Priority | Status |
|---|---|---|---|---|
| 1 | Data mapping and records of processing | Art. 30 | Foundation | Not yet documented |
| 2 | Lawful basis identification | Art. 6 | Critical | Documented in our Privacy Policy for our primary processing activities |
| 3 | Privacy notices and transparency | Art. 12, 13, 14 | Critical | In place — see our Privacy Policy |
| 4 | Consent management | Art. 7, 8 | Required where consent is the lawful basis | In place — cookie consent banner, and parental/guardian consent is required for signups under 16 |
| 5 | Data subject rights procedures | Art. 15–22 | Critical | Partially in place — self-service data export (Art. 20) and account deletion (Art. 17) are live today; rectification is available by editing your profile; formal written procedures for restriction and objection requests are not yet documented |
| 6 | DPO appointment | Art. 37–39 | Required where applicable | Not yet appointed — reviewing whether our scale/type of processing triggers this requirement |
| 7 | Data Protection Impact Assessments | Art. 35 | Required before high-risk processing | Not yet conducted |
| 8 | Processor contracts (DPAs) | Art. 28 | Critical | Pending — confirming Data Processing Agreements with our hosting providers (Vercel, Neon) and email delivery provider |
| 9 | Security measures | Art. 32 | Critical | In place — rate limiting, a full HTTP security header set, upload file-type verification, and sanitization of admin-authored content; dependency updates are ongoing |
| 10 | Breach response plan | Art. 33, 34 | Critical | Not yet documented |
| 11 | International transfer safeguards | Chapter V | Required when data leaves the EU/EEA | Applicable — our database is hosted in the United States (AWS us-east-1 region); reviewing Standard Contractual Clauses with our providers |
| 12 | Data protection by design and default | Art. 25 | Ongoing | Reflected in platform design — per-body visibility controls, scoped admin permissions, and minimal data collection at signup |
| 13 | Staff training and accountability | Art. 39(1)(b) | Ongoing | Not yet formalized |
| 14 | Vendor management and ongoing review | Art. 24, 28 | Ongoing | Not yet formalized |
What this means for you right now
Whether or not every item above is checked off, you already have full rights under the GDPR if you're an EU, UK, or EEA resident: access, rectification, erasure, portability, restriction, objection, and the right to lodge a complaint with your local supervisory authority. These are described in full in our Privacy Policy. Use "Download your data" on the Help page to exercise your access/portability rights right now, or email us below for anything else — you don't need to wait on this checklist.
Questions
Email legal@trestleboard.club (also listed on our Contact page) with any GDPR-related question, or to request a copy, correction, or deletion of your data.
