The free checklist

The GDPR checklist
for agencies that build client apps

Find every copy of your users' data before your client asks you to delete it

Free, straight to your inbox. No call, no pitch

The video, without the music

The short answer

What GDPR means for the app you built

If your client has users in Europe, GDPR applies to the app you built for them, even if you work from the US. You process their users' data, so you sign a data processing agreement (DPA) with your client, every outside tool that gets the data needs your client's approval, and if anything leaks you tell your client right away so they can report it within 72 hours.

Does GDPR apply to a US agency?

Yes, when the app serves people in the EU. The law follows the users, not where you sit

Is an IP address personal data?

It can be, when it can point back to a person. Treat it as personal data

Can I host in the US?

Yes, when the provider's DPA includes the EU transfer terms (Standard Contractual Clauses or the EU-US Data Privacy Framework)

Who reports a breach?

Your client reports it to their regulator within 72 hours. Your job is to tell your client without delay

The Blinkz team · Updated

GDPR in plain English

What it is, and why it lands on you

What GDPR is

The EU law for personal data, meaning anything that points back to a person, even an IP address. It follows the users, not the company, so it applies to anyone serving people in the EU

Why it lands on you

The data belongs to your client, and you are the one holding it. That makes you a processor: you need a signed DPA, you can only use outside services your client approves, and you can be fined directly

What Claude can check

Every place personal data is stored, logged or sent to an outside company, with the file and line, and which copies a delete request would miss

What Claude can't check

Whether your client approved those companies, and whether the DPAs are signed. That part is paperwork

In the full checklist

What the checklist gives you

The full audit prompt

Ready to copy into Claude. It reads your code and changes nothing

Five things to look for

The copies in Claude's answer that get agencies in trouble

What you can ignore

So you don't chase data the law lets you keep

The paperwork after the scan

The DPA, the approvals and the breach plan the code can't do for you

Free, no call

Get the full GDPR checklist

The prompt to give Claude, what to look for in its answer, what you can ignore, and the paperwork you still have to sort out with your client

Free, straight to your inbox. No call, no pitch

Fine print

What this page is, and isn't

  • This is a technical checklist, not legal advice. For your situation, talk to a lawyer or your client's compliance lead.
  • The Claude prompts only read your code and report back. They don't change anything.
  • The page explains the rules in plain English. The law and the auditor's criteria are the final word, linked below.

Building an app that has to pass a check like this

An engineer checks it, fixes it, tests it and puts their name on it

  • 30 minutes
  • Free
  • No slides, no sales team