Hosted in Germany • GDPR-ready

GDPR Checklist Before Launching an App

The moment you get your first paying customer from Europe, GDPR compliance becomes real. This checklist breaks down what you actually need to do—and what can wait.

CCRMAAnalyticsAAutomationBBlogFForms

When Compliance Becomes Non-Negotiable

You've built something people want. Now someone in Germany wants to pay you for it.

That's when GDPR stops being "something legal said I should think about" and becomes a real operational requirement. You cannot legally accept EU customers without it.

The good news: you don't need a lawyer. You need a checklist. You need infrastructure that makes compliance the default, not a retrofit.

Everything below is based on the official GDPR guidance from gdpr.eu and the practical steps founders actually take before their first EU launch.

The 4-Part Checklist

1. Data Audit and Mapping

You cannot comply with a rule you don't understand. Start here.

  • List every SDK in your app. Analytics, error tracking, crash logs, ads, feature flags, session recording. Write them down.
  • Document what each one collects. Read their privacy policy. Some collect IP address. Some collect device ID. Some collect browsing behavior. Write it down.
  • Pick a lawful basis for each dataset. Consent, legitimate interest, contract, or legal obligation. If you can't name it, you can't have it.
  • Keep a record of data flows. Where does the data go? Who accesses it? How long do you keep it? This is your "Records of Processing Activity" (Article 30).

Why this matters: GDPR audits always start with "what data are you actually collecting?" If you don't have a list, you're already non-compliant.

People need to know what you're doing with their data before you do it.

  • Pre-consent screen before any tracking. When the user opens your app, ask for permission before you fire up any analytics SDK.
  • Active opt-in (no pre-checked boxes). The user must take an action. Silence does not equal consent.
  • Granular consent (separate toggles per purpose). Not: "Allow all tracking." Instead: "Essential (required)", "Analytics (optional)", "Marketing (optional)".
  • Frictionless revocation. The user can turn any of these off in settings. Easy toggle, no forms, no email confirmation needed.
  • Transparent privacy policy. Name every SDK. Name every third party. Link to their privacy policies. Be specific: "We use Amplitude for analytics" not "We use tools to improve your experience".

Why this matters: GDPR specifically requires "clear and plain language." A privacy policy that uses marketing speak fails the first audit.

3. User Rights and Controls

People have legal rights to their data. You must build features for them.

  • Data download button. User clicks "export my data," they get a JSON/CSV file with everything you have on them. (Article 20: right to portability.)
  • Account and data deletion. User clicks "delete my account," everything goes. No backup archive. No "we'll delete it in 30 days." It's gone.
  • Fast data correction. If a user flags an error in their profile, you fix it within 30 days.

Why this matters: These are legal rights, not nice features. If an EU customer asks for their data and you cannot deliver it in 30 days, you're in breach.

4. Security and Process

Data is a liability. Protect it.

  • Encryption at rest and in transit. All data on your servers should be encrypted. All data in transit should use HTTPS (this is table stakes now).
  • Data Processing Agreement (DPA) with every vendor and cloud provider. You use Stripe? Stripe signs your DPA. You use AWS? AWS signs your DPA. No DPA, no vendor.
  • 72-hour breach notification plan. If you ever get hacked, you have 72 hours to notify affected EU customers. Write down the plan now, before it happens.

Why this matters: A breach is a crisis. A breach without a notification plan is a legal liability. A breach with a vendor that has no DPA? You're liable for their mistake.

430
Ship GitHub stars
📝
1,083
Active commits
💰
€7
Cheapest compliance tools start at
⏱️
3–5
Hours to set up basics
€0–€2,275

Compliance tool costs range wildly

Usercentrics starts at €7/month. OneTrust's GDPR bundle costs €2,275/month. Most early-stage startups spend €20–€50/month on compliance tooling. Add this to your infrastructure cost when you budget.

Why Geography Matters

Data Residency Is Not Optional

GDPR doesn't just regulate what you do with data. It regulates where your data lives.

People in Germany expect their data to stay in Germany. People in Ireland expect Irish storage. The rule is simple: data from EU residents must stay in the EU.

This matters because the US and Europe have different legal frameworks. EU data that flows to US servers is automatically in breach, even if you encrypt it and even if you didn't mean to.

So when you choose hosting, choose infrastructure that runs in the EU by default—not as an option you can get wrong.

Two camps:

The multi-choice camp (Northflank, AWS): You pick the region. Frankfurt, Paris, Stockholm available. Problem: you can pick wrong. If your team is in San Francisco and you forget to specify EU, data flows to us-east-1.

The default-EU camp (Opsily): All data stays in Frankfurt. No choice to get wrong. No US data flows. This is better if you're shipping fast and GDPR compliance is mandatory from day one.

Infrastructure Choices for EU Customers

Where your data lives shapes compliance. A comparison of hosting platforms and what they include by default.

FeatureNorthflankOpsily
Starting price
€2.70/mo (consumption-based)
€40/mo (flat-rate)
Data residency default
Multi-region (you choose)
Germany only
Compliance defaults
Infrastructure only
✓ GDPR built-in
Deployment friction
Requires DevOps knowledge
Connect GitHub, deploy once
Best for
Teams with engineers on staff
Founders shipping their own code
DPA included
✓ Yes
✓ Yes

Northflank pricing as of August 2026. Opsily flat fee includes all backups, SSL renewal, and updates.

Ship Hosting Plans

Pick the server size your app needs. All plans include GDPR-compliant German hosting, automatic SSL renewal, daily encrypted backups, and 7-day free trial.

Monthly
Annual

Loading pricing...

Security and Compliance Built In

GDPR Compliant

Data residency in Frankfurt, Germany. Zero US data flows. EU jurisdiction from day one.

Encrypted by Default

All data encrypted at rest and in transit. Automatic SSL renewal on every deployment.

Daily Backups

Encrypted, redundant backups with 30-day retention. One-click restore if anything goes wrong.

Data Processing Agreement

Signed DPA included with every plan. Comply with GDPR Article 28 from day one.

Questions About Compliance Before Launch

Only if you have even one EU user. GDPR applies to any company processing personal data of EU residents, regardless of where you're based or where your other users are. If you start North American and add an EU customer later, you must add GDPR compliance before they sign up. This is why founders usually handle it at launch to EU, not after. One European customer makes it mandatory.

Ready to launch compliant?

Start with a 7-day free trial of Ship. No credit card. No compliance surprises later.