The 5-point GDPR checklist for social apps
Treat any platform that fails one of these as not actually compliant — regardless of what their cookie banner says.
- Lawful basis for every processing activity (Art. 6)
- Data residency inside the EU/EEA, or adequate safeguards under Chapter V
- Transparent, granular consent — not dark patterns
- Right to data export and right to erasure, with a clear UI
- Privacy by design and by default (Art. 25), including encryption where appropriate