GDPR compliance for websites and SaaS is not only a privacy policy link — it is lawful processing, transparent notices, processor contracts, and rights fulfillment. This hub orients SMB publishers; enterprise GRC platforms (OneTrust-class) serve different scale.
Core GDPR obligations for publishers
- Lawful basis for each processing activity (Art. 6)
- Transparent privacy notice (Art. 13–14) — see requirements guide
- Data minimization and purpose limitation
- Processor DPAs with vendors (Art. 28)
- Security measures appropriate to risk (Art. 32)
- Records of processing (ROPA) for many controllers (Art. 30)
- Breach notification to authority and individuals when required (Art. 33–34)
- Rights request handling — access, deletion, portability, etc.
Privacy policy vs full compliance
A GDPR-aligned privacy policy is necessary but not sufficient. You must actually operate as described — subprocessors, retention, consent records, and deletion workflows.
Clerica helps with notice clarity and verify proof — not ROPA, DSAR portals, or DPO services.
Cookie consent
EU cookie/ePrivacy rules often require consent before non-essential cookies. Cookie consent/CMP is not Clerica's focus today — pair readable notices with a CMP vendor if needed.
SMB roadmap
| Phase | Action |
|---|---|
| 1 | Data inventory and legal basis mapping |
| 2 | Publish GDPR notice on your domain |
| 3 | Execute DPAs with major processors |
| 4 | Document rights request process |
| 5 | Review international transfers |
| 6 | Optional: Certified verify for customer trust |
Related: What is GDPR? · GDPR checklist · GDPR template · Compare Clerica vs OneTrust
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.