3 ms·
On a technical level: have a process for gathering and sending responses to requests from EU users for their data. Have a process for being able to hard delete
by throwaway40324 7y ago
On a technical level: have a process for gathering and sending responses to requests from EU users for their data. Have a process for being able to hard delete that data, and a user's account. Dont store anything you dont need, not even in logs (IP addresses), and dont send that data to third party providers. Don't use third party monitoring, and analytics services that aren't GDPR compliant. Keep a constantly up to date document of cookies your site uses, and whether they're essential or non-essential for your product/service to operate. Lastly, learn exactly what is considered PII and not. This is a non-exhaustive list of things you should start with, and then go with common sense, and legal counsel as you can begin to afford it.
Edit: Following up, I say on a technical level, because much of this you can do yourself via having some scripts and report generation in place.