DEV Community

[Comment from a deleted post]
Collapse
 
preciselyalyss profile image
Alyss 💜

Preface: I am NOT a lawyer. This is not a substitute for legal advice.

Some questions you need to answer:

  • Does your system use any third-party tools (review apps, payment gateways), and do they collect and process data in accordance with GDPR? Check the privacy policies provided by these companies or call/email them. Do not leave it to chance.
  • Do you have a list of all the types of personal data that you collect and all the ways you use this data? Article 30 of GDPR requires you to have a map of current data practices.
  • Do you have a privacy policy with information about how to contact you with privacy questions? You need one.

Some things you should not do:

  • Do NOT send anything other than the card ordered. The receiver did not consent to receiving marketing material.