GDPR Checklist Before Launching an App
The moment you get your first paying customer from Europe, GDPR compliance becomes real. This checklist breaks down what you actually need to do—and what can wait.
When Compliance Becomes Non-Negotiable
You've built something people want. Now someone in Germany wants to pay you for it.
That's when GDPR stops being "something legal said I should think about" and becomes a real operational requirement. You cannot legally accept EU customers without it.
The good news: you don't need a lawyer. You need a checklist. You need infrastructure that makes compliance the default, not a retrofit.
Everything below is based on the official GDPR guidance from gdpr.eu and the practical steps founders actually take before their first EU launch.
1. Data Audit and Mapping
You cannot comply with a rule you don't understand. Start here.
- List every SDK in your app. Analytics, error tracking, crash logs, ads, feature flags, session recording. Write them down.
- Document what each one collects. Read their privacy policy. Some collect IP address. Some collect device ID. Some collect browsing behavior. Write it down.
- Pick a lawful basis for each dataset. Consent, legitimate interest, contract, or legal obligation. If you can't name it, you can't have it.
- Keep a record of data flows. Where does the data go? Who accesses it? How long do you keep it? This is your "Records of Processing Activity" (Article 30).
Why this matters: GDPR audits always start with "what data are you actually collecting?" If you don't have a list, you're already non-compliant.
2. Consent and Transparency
People need to know what you're doing with their data before you do it.
- Pre-consent screen before any tracking. When the user opens your app, ask for permission before you fire up any analytics SDK.
- Active opt-in (no pre-checked boxes). The user must take an action. Silence does not equal consent.
- Granular consent (separate toggles per purpose). Not: "Allow all tracking." Instead: "Essential (required)", "Analytics (optional)", "Marketing (optional)".
- Frictionless revocation. The user can turn any of these off in settings. Easy toggle, no forms, no email confirmation needed.
- Transparent privacy policy. Name every SDK. Name every third party. Link to their privacy policies. Be specific: "We use Amplitude for analytics" not "We use tools to improve your experience".
Why this matters: GDPR specifically requires "clear and plain language." A privacy policy that uses marketing speak fails the first audit.
3. User Rights and Controls
People have legal rights to their data. You must build features for them.
- Data download button. User clicks "export my data," they get a JSON/CSV file with everything you have on them. (Article 20: right to portability.)
- Account and data deletion. User clicks "delete my account," everything goes. No backup archive. No "we'll delete it in 30 days." It's gone.
- Fast data correction. If a user flags an error in their profile, you fix it within 30 days.
Why this matters: These are legal rights, not nice features. If an EU customer asks for their data and you cannot deliver it in 30 days, you're in breach.
4. Security and Process
Data is a liability. Protect it.
- Encryption at rest and in transit. All data on your servers should be encrypted. All data in transit should use HTTPS (this is table stakes now).
- Data Processing Agreement (DPA) with every vendor and cloud provider. You use Stripe? Stripe signs your DPA. You use AWS? AWS signs your DPA. No DPA, no vendor.
- 72-hour breach notification plan. If you ever get hacked, you have 72 hours to notify affected EU customers. Write down the plan now, before it happens.
Why this matters: A breach is a crisis. A breach without a notification plan is a legal liability. A breach with a vendor that has no DPA? You're liable for their mistake.
Compliance tool costs range wildly
Usercentrics starts at €7/month. OneTrust's GDPR bundle costs €2,275/month. Most early-stage startups spend €20–€50/month on compliance tooling. Add this to your infrastructure cost when you budget.
Data Residency Is Not Optional
GDPR doesn't just regulate what you do with data. It regulates where your data lives.
People in Germany expect their data to stay in Germany. People in Ireland expect Irish storage. The rule is simple: data from EU residents must stay in the EU.
This matters because the US and Europe have different legal frameworks. EU data that flows to US servers is automatically in breach, even if you encrypt it and even if you didn't mean to.
So when you choose hosting, choose infrastructure that runs in the EU by default—not as an option you can get wrong.
Two camps:
The multi-choice camp (Northflank, AWS): You pick the region. Frankfurt, Paris, Stockholm available. Problem: you can pick wrong. If your team is in San Francisco and you forget to specify EU, data flows to us-east-1.
The default-EU camp (Opsily): All data stays in Frankfurt. No choice to get wrong. No US data flows. This is better if you're shipping fast and GDPR compliance is mandatory from day one.
Infrastructure Choices for EU Customers
Where your data lives shapes compliance. A comparison of hosting platforms and what they include by default.
Northflank pricing as of August 2026. Opsily flat fee includes all backups, SSL renewal, and updates.
Ship Hosting Plans
Pick the server size your app needs. All plans include GDPR-compliant German hosting, automatic SSL renewal, daily encrypted backups, and 7-day free trial.
Loading pricing...
Security and Compliance Built In
GDPR Compliant
Data residency in Frankfurt, Germany. Zero US data flows. EU jurisdiction from day one.
Encrypted by Default
All data encrypted at rest and in transit. Automatic SSL renewal on every deployment.
Daily Backups
Encrypted, redundant backups with 30-day retention. One-click restore if anything goes wrong.
Data Processing Agreement
Signed DPA included with every plan. Comply with GDPR Article 28 from day one.
Questions About Compliance Before Launch
Only if you have even one EU user. GDPR applies to any company processing personal data of EU residents, regardless of where you're based or where your other users are. If you start North American and add an EU customer later, you must add GDPR compliance before they sign up. This is why founders usually handle it at launch to EU, not after. One European customer makes it mandatory.
Ready to launch compliant?
Start with a 7-day free trial of Ship. No credit card. No compliance surprises later.