> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Free Tool: GDPR/DSAR Readiness Checklist

> Work the free, no-sign-up GDPR/DSAR self-assessment on orbit.devotel.io from first visit to a scored posture — the five tenant-owned steps (consent capture, withdrawal paths, DSAR intake, Art. 30 register, and DPA acceptance) and the docs pages that set each one up.

# Free Tool: GDPR/DSAR Readiness Checklist

The [GDPR/DSAR readiness checklist](https://orbit.devotel.io/en/tools/gdpr-dsar-checklist)
on the [developer tools hub](https://orbit.devotel.io/en/tools) is a
no-sign-up self-assessment that walks the five tenant-owned controls an
EU-facing sender operates on Devotel Orbit: **consent capture with a lawful
basis, cheap withdrawal paths (Art. 7(3)), DSAR intake via operator or the
public portal, the Art. 30 privacy register with its DPIA screen, and
Data Processing Agreement acceptance**. Mark the steps you have covered;
the page scores your posture in plain language with a docs link per open
item. This guide maps each step to the control that sets it and walks a
go/no-go runbook for the checklist.

<Note>
  Every step on this checklist is **tenant-owned**: Orbit supplies the
  consent ledger, the DSAR pipeline, the privacy register, and the DPA
  e-sign flow; which GDPR obligations actually apply is a legal
  determination you make with counsel. Nothing on this page enforces or
  verifies what you mark, and the self-assessment is exactly that —
  advisory posture, never an enforced verdict.
</Note>

## 1. What the tool walks

The checklist covers five steps in the order a controller typically stands
them up before the first DSAR arrives:

1. **Consent capture with a lawful basis** — record consent per channel
   (email, SMS, voice) with a lawful basis before the first send to an EU
   recipient. The consent endpoint stamps a proof-of-record row per
   channel, basis, source, and timestamp — exportable when a supervisory
   authority asks.
2. **Cheap withdrawal paths (Art. 7(3))** — make withdrawing consent as
   easy as giving it: STOP keywords on SMS/WhatsApp, the preference
   center with signed per-contact links, and bulk-import of a legacy
   suppression list.
3. **DSAR intake — operator, portal, or both** — file a DSAR with
   `jurisdiction: gdpr` to start the 30-day SLA clock. Operators file
   requests on behalf of a data subject; the public portal lets them
   self-serve, with a two-factor email + SMS OTP identity check before
   anything queues.
4. **Art. 30 privacy register** — document every processing activity
   (purpose, data categories, recipients, cross-border transfers,
   retention, and security measures). Each activity gets a human
   reference and an exportable inventory; activities hitting the
   Art. 35(3) DPIA triggers stay un-active until the DPIA is recorded.
5. **Data Processing Agreement (Art. 28)** — preview the DPA template,
   accept with the typed e-signature, and archive the executed copy.
   Until accepted, your DPA status sits as an open item a buyer's
   procurement review will find.

<Note>
  The checklist items and their descriptions are taken verbatim from the
  same model that drives the tool page — the checklist you see at
  `/tools/gdpr-dsar-checklist` is the exact set of steps and hints this
  guide references, with no drift between the two.
</Note>

## 2. Each step mapped to the control that sets it

Marking a step covered on the tool page is a note to yourself; setting up
the control in the dashboard is the real posture. Here is the mapping:

| Checklist step | Control surface | Deep-dive page |
| - | - | - |
| Consent capture with a lawful basis | Record consent per channel through the consent endpoint | [Consent management](/compliance/consent-management) |
| Cheap withdrawal paths (Art. 7(3)) | STOP keywords, preference center, and suppression import | [Opt-out & suppression lists](/compliance/opt-out-suppression), [Preference center opt-out page](/guides/preference-center-opt-out-page) |
| DSAR intake | File requests as `gdpr` jurisdiction; publish the public portal | [DSAR](/compliance/dsar), [Self-service DSAR portal](/guides/self-service-dsar-portal) |
| Art. 30 register + DPIA screen | Document activities; record DPIAs for Art. 35(3) triggers | [Privacy register (Art. 30)](/compliance/privacy-register), [Compliance privacy register](/guides/compliance-privacy-register) |
| DPA acceptance | Preview, e-sign, and archive the DPA | [Data Processing Agreement](/compliance/data-processing-agreement), [DPA/BAA acceptance & consent recording](/guides/compliance-dpa-baa-recording-consent) |

The checklist page links each step to its canonical docs page; the "deep-dive"
pages above are the full walkthrough you follow after the tool points you at
an open item.

## 3. How readiness scoring works

The page computes a posture tier from the steps you mark:

* **All five covered** — the panel reads **complete**: a green state with
  a reminder that the register and SLA clocks are ongoing obligations.
* **Some covered** — the panel reads **partial**: the score names the gap
  count and links each open item to the docs page that walks the control.
* **None covered** — the panel reads **open**: each step names the docs
  page for the control it describes.

The scoring is a **self-attested, advisory label** — the same honesty
contract as the HIPAA/BAA readiness checklist and the TCPA compliance
checklist. Nothing leaves your browser; nothing on the page enforces or
verifies what you mark. Use it as a launch-day check and re-run it when
your compliance posture changes. The scoring is not legal advice.

## 4. Step-by-step go/no-go runbook

Open the tool at `/tools/gdpr-dsar-checklist` and work the five steps in
order. For each open item, the page links directly to the docs; this
runbook names the acceptance check per step:

<Steps>
  <Step title="Consent capture with a lawful basis">
    Wire consent per channel before the first send to an EU recipient.
    **Acceptance:** a consent record exists per channel with a lawful
    basis field set — check under [Consent management](/compliance/consent-management)
    that the consent ledger shows rows per channel you dispatch on.
  </Step>

  <Step title="Cheap withdrawal paths">
    Make opt-out as easy as opt-in. **Acceptance:** STOP keywords are
    active on SMS/WhatsApp; the preference center is published and linked
    from the contact list; and any legacy suppression list is imported
    so the first send already respects existing revocations.
  </Step>

  <Step title="DSAR intake">
    Stand up at least one path: operator-filed or the public portal.
    **Acceptance:** a DSAR filed with `jurisdiction: gdpr` starts a
    30-day SLA clock, and the portal's sender email is configured so it
    can accept self-service filings. See the [DSAR](/compliance/dsar)
    page for the full intake configuration.
  </Step>

  <Step title="Art. 30 privacy register">
    Document every processing activity before the first DSAR arrives.
    **Acceptance:** at least one processing activity is recorded with a
    human reference, and any Art. 35(3) trigger is paired with a
    recorded DPIA — the [privacy register](/compliance/privacy-register)
    walking the activity form.
  </Step>

  <Step title="DPA acceptance">
    Accept the Data Processing Agreement. **Acceptance:** the DPA status
    on [Data Processing Agreement](/compliance/data-processing-agreement)
    shows an executed, archived copy with a typed e-signature and a
    timestamp.
  </Step>
</Steps>

Until each acceptance criterion holds, the mark on the tool is an open
item. The scoring in Section 3 reads it that way.

## 5. Tenant-owned posture with a legal-advice warning

Every step on this checklist is a tenant-operated control: Orbit supplies
the consent ledger, the DSAR pipeline, the privacy register, and the DPA
e-sign flow; which GDPR obligations actually apply to your processing
activities is a legal determination you make with counsel. The checklist
advises and never enforces — the same contract as every other compliance
self-assessment on the tools hub.

The sole platform-owned compliance guard (the federal TCPA 8 AM–9 PM US
voice window) does not apply here: GDPR is a controller-level regulation,
and the platform does not gate GDPR posture. See [Compliance FAQ](/compliance/faq) for the full boundary between
platform-owned and tenant-owned controls.

<Warning>
  This checklist is not legal advice. Confirm your GDPR obligations with
  qualified counsel before relying on the self-assessment for a
  supervisory-authority showing.
</Warning>

## See also

* [TCPA compliance checklist](/guides/tcpa-compliance-checklist-tool) — a graded self-check across all four sending gates.
* [HIPAA/BAA readiness checklist](/compliance/hipaa-checklist-runbook) — the same self-assessment pattern for healthcare senders.
* [Quiet-hours checker tool](/guides/quiet-hours-checker-tool) — the timezone window checker for US recipients.
* [Carrier & line-type lookup tool](/guides/carrier-line-type-lookup-tool) — detect mobile, fixed-line, toll-free, or VoIP.
* [E.164 formatter tool](/guides/e164-formatter-tool) — normalize any number into a dialable E.164.
* [SMS calculator tool](/guides/sms-calculator-tool) — estimate cost and segment count from message text.
* [Compliance FAQ](/compliance/faq) — common questions across the compliance surface.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.