GDPR requirements checklist
Last updated: July 1, 2026
This checklist maps core GDPR expectations to Verify.ge today. Each card shows whether the requirement is met, partially met, or still missing, plus a short proof note. It is a transparency and readiness view — not a certification.
Met
14
Partial
10
Missing
1
1. Principles & transparency (Art. 5, 12–14)
Current proof
Published Privacy Policy at /privacy covering account data, OTP processing, cookies (with consent), and contact channels.
Current proof
Published Terms of Service at /terms.
Current proof
Privacy Policy and Cookie Policy describe purposes, partners, and optional analytics/marketing/chat tools gated by consent.
2. Lawful basis & roles (Art. 6)
Current proof
Compliance and Privacy pages describe contractual necessity, legitimate interests, and consent where relevant.
Current proof
Compliance page documents controller/processor split for Georgian law and GDPR contexts.
3. Consent & cookies (Art. 7 + ePrivacy)
Current proof
Cookie banner with Accept all / Reject non-essential / Manage. GA, Plausible, Vercel Analytics, LinkedIn Insight, and Tawk load only after the matching consent category is granted. Essential cookies always on.
Current proof
Published /cookies page with categories and a Manage preferences control.
Current proof
Registration requires a Terms/Privacy checkbox; backend stores termsAcceptedAt and privacyAcceptedAt on account create.
Current proof
Partial: Account stores termsAcceptedAt and privacyAcceptedAt. Optional cookie categories (analytics/marketing/chat) are stored in the browser only; payment auto-charge consent is on SavedPaymentMethod.
Current proof
Partial: checkout includes consent for subscription/save-card; limited to billing flows only.
4. Data subject rights (Art. 15–22)
Current proof
Dashboard settings plus Download my data (JSON export of profile, key metadata, OTP summaries, transactions, webhooks).
Current proof
Partial: company, email, phone, and password can be updated in settings; some fields remain constrained by product rules.
Current proof
Settings → Close account anonymizes PII, revokes API keys, sets status INACTIVE, and keeps billing rows for legal/tax integrity. Soft-close only (no hard delete).
Current proof
GET /auth/me/export (and Settings download) returns a JSON package without OTP secrets or API key secrets.
Current proof
Partial: cookie preferences withdraw analytics/marketing/chat; saved cards can be removed; no full Art. 18 restriction or general objection workflow.
5. Security of processing (Art. 32)
Current proof
OTP encryption at rest, hashed verification attempts, rate limits, and IP blocking are in place.
Current proof
Public Security page at /security describes controls and disclosure.
6. Retention & minimization (Art. 5(1)(e))
Current proof
Partial: Privacy Policy describes retention themes; operational schedules are not fully user-facing.
Current proof
Partial: Redis OTP and IP-block keys expire; database OTP/verification rows and logs are kept indefinitely without a purge job.
7. Processors & DPA (Art. 28)
Current proof
Partial: DPA available on request via [email protected]; no self-serve download or e-sign flow.
Current proof
Partial: key partners are named in Privacy Policy prose; no dedicated living register page.
8. International transfers (Chapter V)
Current proof
Partial: Privacy Policy covers processing partners; no standalone transfer-impact or SCC summary page.
9. Breach notification (Art. 33–34)
Current proof
Partial: Security page describes incident response; no customer breach-notification portal.
10. Accountability & records (Art. 5(2), 30)
Current proof
Missing as a product artifact: no in-app Art. 30 register for operators. The public /gdpr checklist documents readiness but is not a records-of-processing activity (RoPA).
Current proof
Published Compliance page at /compliance plus this structured /gdpr checklist with regulatory contacts and DPA request path.