The GDPR requires websites and apps to have:
- A privacy policy that includes specific information about what data you process and your legal basis for doing so,
- A consent management platform that tracks and logs active opt-in agreements from users,
- A DSAR form or other method so users can submit requests to follow through on their right to access, correct, or delete their personal data,
- Security measures keep personal data safe from unauthorized access or breaches.
There are also requirements around how long you can retain personal data and when it’s legal to transfer data internationally.