GDPR / DPA compliance checklist
8 questions covering the objections your legal team actually raises about transactional email.
1.Is your email data (send logs, backups, database) hosted in the EU?
2.Do you have a signed Data Processing Agreement (DPA) with your email provider?
3.Do you know exactly how long your provider retains delivery logs?
4.Do your own application logs avoid storing full recipient email addresses in plaintext?
5.Do you have a documented, current list of subprocessors for your email sending?
6.Do your retention/deletion jobs actually delete data on schedule, not just mark it as deleted?
7.If any subprocessor operates outside the EEA, are they covered by Standard Contractual Clauses (SCCs)?
8.Could you produce a data-flow diagram (where a message goes, what's stored where) if a customer's security team asked?
0 of 8 answered
Want more detail on any of this? See Envello's own GDPR & data residency page or read DPA vs. this checklist.