Free Tool: GDPR/DSAR Readiness Checklist
The GDPR/DSAR readiness checklist on the developer tools hub is a no-sign-up self-assessment that walks the five tenant-owned controls an EU-facing sender operates on Devotel Orbit: consent capture with a lawful basis, cheap withdrawal paths (Art. 7(3)), DSAR intake via operator or the public portal, the Art. 30 privacy register with its DPIA screen, and Data Processing Agreement acceptance. Mark the steps you have covered; the page scores your posture in plain language with a docs link per open item. This guide maps each step to the control that sets it and walks a go/no-go runbook for the checklist.Every step on this checklist is tenant-owned: Orbit supplies the
consent ledger, the DSAR pipeline, the privacy register, and the DPA
e-sign flow; which GDPR obligations actually apply is a legal
determination you make with counsel. Nothing on this page enforces or
verifies what you mark, and the self-assessment is exactly that —
advisory posture, never an enforced verdict.
1. What the tool walks
The checklist covers five steps in the order a controller typically stands them up before the first DSAR arrives:- Consent capture with a lawful basis — record consent per channel (email, SMS, voice) with a lawful basis before the first send to an EU recipient. The consent endpoint stamps a proof-of-record row per channel, basis, source, and timestamp — exportable when a supervisory authority asks.
- Cheap withdrawal paths (Art. 7(3)) — make withdrawing consent as easy as giving it: STOP keywords on SMS/WhatsApp, the preference center with signed per-contact links, and bulk-import of a legacy suppression list.
- DSAR intake — operator, portal, or both — file a DSAR with
jurisdiction: gdprto start the 30-day SLA clock. Operators file requests on behalf of a data subject; the public portal lets them self-serve, with a two-factor email + SMS OTP identity check before anything queues. - Art. 30 privacy register — document every processing activity (purpose, data categories, recipients, cross-border transfers, retention, and security measures). Each activity gets a human reference and an exportable inventory; activities hitting the Art. 35(3) DPIA triggers stay un-active until the DPIA is recorded.
- Data Processing Agreement (Art. 28) — preview the DPA template, accept with the typed e-signature, and archive the executed copy. Until accepted, your DPA status sits as an open item a buyer’s procurement review will find.
The checklist items and their descriptions are taken verbatim from the
same model that drives the tool page — the checklist you see at
/tools/gdpr-dsar-checklist is the exact set of steps and hints this
guide references, with no drift between the two.2. Each step mapped to the control that sets it
Marking a step covered on the tool page is a note to yourself; setting up the control in the dashboard is the real posture. Here is the mapping:
The checklist page links each step to its canonical docs page; the “deep-dive”
pages above are the full walkthrough you follow after the tool points you at
an open item.
3. How readiness scoring works
The page computes a posture tier from the steps you mark:- All five covered — the panel reads complete: a green state with a reminder that the register and SLA clocks are ongoing obligations.
- Some covered — the panel reads partial: the score names the gap count and links each open item to the docs page that walks the control.
- None covered — the panel reads open: each step names the docs page for the control it describes.
4. Step-by-step go/no-go runbook
Open the tool at/tools/gdpr-dsar-checklist and work the five steps in
order. For each open item, the page links directly to the docs; this
runbook names the acceptance check per step:
1
Consent capture with a lawful basis
Wire consent per channel before the first send to an EU recipient.
Acceptance: a consent record exists per channel with a lawful
basis field set — check under Consent management
that the consent ledger shows rows per channel you dispatch on.
2
Cheap withdrawal paths
Make opt-out as easy as opt-in. Acceptance: STOP keywords are
active on SMS/WhatsApp; the preference center is published and linked
from the contact list; and any legacy suppression list is imported
so the first send already respects existing revocations.
3
DSAR intake
Stand up at least one path: operator-filed or the public portal.
Acceptance: a DSAR filed with
jurisdiction: gdpr starts a
30-day SLA clock, and the portal’s sender email is configured so it
can accept self-service filings. See the DSAR
page for the full intake configuration.4
Art. 30 privacy register
Document every processing activity before the first DSAR arrives.
Acceptance: at least one processing activity is recorded with a
human reference, and any Art. 35(3) trigger is paired with a
recorded DPIA — the privacy register
walking the activity form.
5
DPA acceptance
Accept the Data Processing Agreement. Acceptance: the DPA status
on Data Processing Agreement
shows an executed, archived copy with a typed e-signature and a
timestamp.
5. Tenant-owned posture with a legal-advice warning
Every step on this checklist is a tenant-operated control: Orbit supplies the consent ledger, the DSAR pipeline, the privacy register, and the DPA e-sign flow; which GDPR obligations actually apply to your processing activities is a legal determination you make with counsel. The checklist advises and never enforces — the same contract as every other compliance self-assessment on the tools hub. The sole platform-owned compliance guard (the federal TCPA 8 AM–9 PM US voice window) does not apply here: GDPR is a controller-level regulation, and the platform does not gate GDPR posture. See Compliance FAQ for the full boundary between platform-owned and tenant-owned controls.See also
- TCPA compliance checklist — a graded self-check across all four sending gates.
- HIPAA/BAA readiness checklist — the same self-assessment pattern for healthcare senders.
- Quiet-hours checker tool — the timezone window checker for US recipients.
- Carrier & line-type lookup tool — detect mobile, fixed-line, toll-free, or VoIP.
- E.164 formatter tool — normalize any number into a dialable E.164.
- SMS calculator tool — estimate cost and segment count from message text.
- Compliance FAQ — common questions across the compliance surface.