Legal

GDPR requirements checklist

Last updated: July 1, 2026

This checklist maps core GDPR expectations to Verify.ge today. Each card shows whether the requirement is met, partially met, or still missing, plus a short proof note. It is a transparency and readiness view — not a certification.

Met

14

Partial

10

Missing

1

1. Principles & transparency (Art. 5, 12–14)

Privacy notice
Met
Provide clear information about what personal data is collected, why, and how it is used.

Current proof

Published Privacy Policy at /privacy covering account data, OTP processing, cookies (with consent), and contact channels.

Related page
Terms of service
Met
Publish contractual terms that govern use of the service alongside privacy information.

Current proof

Published Terms of Service at /terms.

Related page
Transparent processing purposes
Met
Explain processing purposes, categories of data, and recipients in plain language.

Current proof

Privacy Policy and Cookie Policy describe purposes, partners, and optional analytics/marketing/chat tools gated by consent.

Related page

2. Lawful basis & roles (Art. 6)

Lawful basis documented
Met
Identify and communicate the lawful basis for each main processing activity.

Current proof

Compliance and Privacy pages describe contractual necessity, legitimate interests, and consent where relevant.

Related page
Controller vs processor roles
Met
Clarify when Verify.ge acts as controller (account data) vs processor (customer OTP traffic).

Current proof

Compliance page documents controller/processor split for Georgian law and GDPR contexts.

Related page

3. Consent & cookies (Art. 7 + ePrivacy)

Cookie / analytics consent (CMP)
Met
Obtain prior consent before non-essential cookies or third-party tracking scripts.

Current proof

Cookie banner with Accept all / Reject non-essential / Manage. GA, Plausible, Vercel Analytics, LinkedIn Insight, and Tawk load only after the matching consent category is granted. Essential cookies always on.

Related page
Cookie policy page
Met
Publish a dedicated cookies notice listing essential vs optional cookies and controls.

Current proof

Published /cookies page with categories and a Manage preferences control.

Related page
Registration acceptance of legal terms
Met
Capture affirmative acceptance of Terms and Privacy when creating an account.

Current proof

Registration requires a Terms/Privacy checkbox; backend stores termsAcceptedAt and privacyAcceptedAt on account create.

Stored privacy / marketing consent flags
Partial
Record consent choices on the account for auditability and withdrawal.

Current proof

Partial: Account stores termsAcceptedAt and privacyAcceptedAt. Optional cookie categories (analytics/marketing/chat) are stored in the browser only; payment auto-charge consent is on SavedPaymentMethod.

Payment auto-charge consent
Partial
Record clear consent when saving a card or enabling automatic renewal charges.

Current proof

Partial: checkout includes consent for subscription/save-card; limited to billing flows only.

4. Data subject rights (Art. 15–22)

Right of access (Art. 15)
Met
Let individuals obtain confirmation of processing and a copy of their personal data.

Current proof

Dashboard settings plus Download my data (JSON export of profile, key metadata, OTP summaries, transactions, webhooks).

Related page
Right to rectification (Art. 16)
Partial
Allow correction of inaccurate personal data without undue delay.

Current proof

Partial: company, email, phone, and password can be updated in settings; some fields remain constrained by product rules.

Right to erasure (Art. 17)
Met
Provide a way to delete or anonymize personal data when grounds apply.

Current proof

Settings → Close account anonymizes PII, revokes API keys, sets status INACTIVE, and keeps billing rows for legal/tax integrity. Soft-close only (no hard delete).

Related page
Right to data portability (Art. 20)
Met
Provide personal data in a structured, commonly used, machine-readable format.

Current proof

GET /auth/me/export (and Settings download) returns a JSON package without OTP secrets or API key secrets.

Related page
Restriction / objection (Art. 18, 21)
Partial
Support restriction of processing and objection where applicable, including consent withdrawal.

Current proof

Partial: cookie preferences withdraw analytics/marketing/chat; saved cards can be removed; no full Art. 18 restriction or general objection workflow.

5. Security of processing (Art. 32)

Technical & organizational security
Met
Implement appropriate security measures for confidentiality, integrity, and availability.

Current proof

OTP encryption at rest, hashed verification attempts, rate limits, and IP blocking are in place.

Related page
Security documentation
Met
Publish how security controls protect accounts, APIs, and payments.

Current proof

Public Security page at /security describes controls and disclosure.

Related page

6. Retention & minimization (Art. 5(1)(e))

Retention periods disclosed
Partial
Tell people how long categories of personal data are kept.

Current proof

Partial: Privacy Policy describes retention themes; operational schedules are not fully user-facing.

Related page
Automated retention / purge
Partial
Delete or anonymize data when retention periods expire.

Current proof

Partial: Redis OTP and IP-block keys expire; database OTP/verification rows and logs are kept indefinitely without a purge job.

7. Processors & DPA (Art. 28)

Data Processing Agreement (Art. 28)
Partial
Offer a DPA to customers who use Verify.ge as a processor for OTP delivery.

Current proof

Partial: DPA available on request via [email protected]; no self-serve download or e-sign flow.

Related page
Sub-processor transparency
Partial
Identify sub-processors and keep the list reasonably current.

Current proof

Partial: key partners are named in Privacy Policy prose; no dedicated living register page.

Related page

8. International transfers (Chapter V)

International transfer safeguards
Partial
Document transfers outside Georgia/EEA and applicable safeguards.

Current proof

Partial: Privacy Policy covers processing partners; no standalone transfer-impact or SCC summary page.

Related page

9. Breach notification (Art. 33–34)

Personal data breach process
Partial
Detect, assess, notify authorities, and inform affected individuals when required.

Current proof

Partial: Security page describes incident response; no customer breach-notification portal.

Related page

10. Accountability & records (Art. 5(2), 30)

Records of processing (Art. 30)
Missing
Maintain internal records of processing activities for accountability.

Current proof

Missing as a product artifact: no in-app Art. 30 register for operators. The public /gdpr checklist documents readiness but is not a records-of-processing activity (RoPA).

Public compliance overview
Met
Provide a high-level compliance statement covering GDPR, local law, and payments.

Current proof

Published Compliance page at /compliance plus this structured /gdpr checklist with regulatory contacts and DPA request path.

Related page