Skip to content
IssuePilot

Free tool

Is your toolchain GDPR-proof?

Ten questions that come up first in any review. At the end there is no grade, just a list of open points you can work through.

No credit card · 30 days of Pro free · up and running in 15 minutes

  • Servers in Germany
  • GDPR-compliant
  • Built in Germany
  1. 1Do you have a data processing agreement (DPA) with every tool vendor?

    As soon as a provider processes personal data on your behalf – customer names inside tasks are enough – Article 28 GDPR requires a contract covering it. Without one, the legal basis for the entire processing is missing.

    Do you have a data processing agreement (DPA) with every tool vendor?
  2. 2Do you know which country the data actually sits in?

    Where a company is registered says nothing about where its servers are. What matters is where data is processed and backed up – backups included.

    Do you know which country the data actually sits in?
  3. 3Is it clear whether data is transferred to third countries such as the US?

    With US vendors, the transfer needs a solid legal basis. This isn't a formality — it's the first thing supervisory authorities look at.

    Is it clear whether data is transferred to third countries such as the US?
  4. 4Do you have an up-to-date list of sub-processors?

    Almost every SaaS tool relies on further services for hosting, email delivery or error logging. That chain belongs in your documentation, and you have to be told when it changes.

    Do you have an up-to-date list of sub-processors?
  5. 5Is every tool you use listed in your record of processing activities?

    Article 30 GDPR requires a record of processing activities. In practice, the tools missing from it are exactly the ones individual teams picked up on the side.

    Is every tool you use listed in your record of processing activities?
  6. 6Is it defined how long data is kept and when it gets deleted?

    Without a deletion policy, customer data from finished projects piles up indefinitely. That contradicts the storage limitation principle and makes any breach worse.

    Is it defined how long data is kept and when it gets deleted?
  7. 7Can you actually fulfil access and deletion requests for a single person?

    Data subject rights apply whether or not your tool has a matching feature. If you can't locate data reliably, every request becomes manual work — against a deadline.

    Can you actually fulfil access and deletion requests for a single person?
  8. 8Is it defined who may access what — and is access logged?

    Freelancers, former staff, interns: accounts often outlive the collaboration. Roles and an audit log are the difference between an incident and a provable incident.

    Is it defined who may access what — and is access logged?
  9. 9Are client credentials stored encrypted — and not in a spreadsheet or chat?

    For agencies this is the most delicate point: whoever manages access to client systems is also liable for keeping it safe. A spreadsheet in a shared folder meets none of the requirements.

    Are client credentials stored encrypted — and not in a spreadsheet or chat?
  10. 10Is the channel your customers use to report issues legally sound?

    A widget, portal or form on your website collects personal data. It needs a mention in your privacy policy — and the data collected is subject to the same rules as everything else.

    Is the channel your customers use to report issues legally sound?

Answer the questions above. There's no grade at the end — just a list of the points worth clarifying, ready to take into your next vendor conversation.

This self-check is orientation, not legal advice. Whether your processing is lawful depends on the individual case — when in doubt, clarify it with a specialist lawyer or your data protection officer. Your answers stay in your browser and are not transmitted.

Context

The most common misconception: “it's only tasks in there”

Personal data starts earlier than most people assume.

The moment a customer's name appears in a task, an email address shows up in a comment or a screenshot shows a customer account, you are processing personal data. The same rules apply as for a CRM – except that nobody thinks of a project tool that way.

The second misconception is about the chain behind it. A tool operated in Europe can still use sub-processors outside the EU – for sending email, error logging or support. That chain belongs in your documentation, and you have to be told when it changes.

What we do ourselves, and what we don't, is written out on security – including the points that are still manual work on our side.

Common questions

Questions about the check

No, and it does not try to. It asks the questions that most often go unanswered in practice and explains why each one is asked. Whether your specific processing is lawful is for a specialist lawyer or your data protection officer to judge.

One tool less, one contract less.

Tasks, customer reports and credentials in one place – hosted in Germany, data processing agreement on request.

No credit card required · Up and running in 15 minutes · Cancel anytime

  • Servers in Germany
  • GDPR-compliant
  • Built in Germany

Prefer to talk first? Request a demo