Status: Compliance inspection pending. The checklist below reflects what we've implemented ourselves as of the date below. It has not yet been reviewed or certified by a qualified data protection representative or outside legal counsel — treat this as a good-faith progress report, not a legal attestation of compliance.

Last updated: October 4, 2026

# Requirement GDPR Article Priority Status
1 Data mapping and records of processing Art. 30 Foundation Not yet documented
2 Lawful basis identification Art. 6 Critical Documented in our Privacy Policy for our primary processing activities
3 Privacy notices and transparency Art. 12, 13, 14 Critical In place — see our Privacy Policy
4 Consent management Art. 7, 8 Required where consent is the lawful basis In place — cookie consent banner, and parental/guardian consent is required for signups under 16
5 Data subject rights procedures Art. 15–22 Critical Partially in place — self-service data export (Art. 20) and account deletion (Art. 17) are live today; rectification is available by editing your profile; formal written procedures for restriction and objection requests are not yet documented
6 DPO appointment Art. 37–39 Required where applicable Not yet appointed — reviewing whether our scale/type of processing triggers this requirement
7 Data Protection Impact Assessments Art. 35 Required before high-risk processing Not yet conducted
8 Processor contracts (DPAs) Art. 28 Critical Pending — confirming Data Processing Agreements with our hosting providers (Vercel, Neon) and email delivery provider
9 Security measures Art. 32 Critical In place — rate limiting, a full HTTP security header set, upload file-type verification, and sanitization of admin-authored content; dependency updates are ongoing
10 Breach response plan Art. 33, 34 Critical Not yet documented
11 International transfer safeguards Chapter V Required when data leaves the EU/EEA Applicable — our database is hosted in the United States (AWS us-east-1 region); reviewing Standard Contractual Clauses with our providers
12 Data protection by design and default Art. 25 Ongoing Reflected in platform design — per-body visibility controls, scoped admin permissions, and minimal data collection at signup
13 Staff training and accountability Art. 39(1)(b) Ongoing Not yet formalized
14 Vendor management and ongoing review Art. 24, 28 Ongoing Not yet formalized

What this means for you right now

Whether or not every item above is checked off, you already have full rights under the GDPR if you're an EU, UK, or EEA resident: access, rectification, erasure, portability, restriction, objection, and the right to lodge a complaint with your local supervisory authority. These are described in full in our Privacy Policy. Use "Download your data" on the Help page to exercise your access/portability rights right now, or email us below for anything else — you don't need to wait on this checklist.

Questions

Email legal@trestleboard.club (also listed on our Contact page) with any GDPR-related question, or to request a copy, correction, or deletion of your data.