Коротко
- The controller decides «why and how»; the processor acts on instructions — a DPA is required.
- Rights: informed, access, rectification, erasure, restriction, portability, object, automated decisions.
- Request response time — a 1-month guideline (+ up to 2 if complex, with notification).
- Practice: data map → lawful basis → banner → policy → DSAR process → vendors/DPA → security/breach.
Not legal advice
An operational checklist. Appointing a DPO, DPIA and adequacy are point legal decisions.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → GDPR. Not legal advice and not a verbatim translation.
Controller and processor
Controller defines purposes and means. Bears primary responsibility for compliance, notices, choosing legal bases, and responding to data subjects.
Processor processes only under a contract/instructions, implements TOMs, helps with DSARs, does not use the data «for itself» against the mandate.
There can be joint controllers — if they jointly determine purposes; that is a separate regime with a transparent split of roles.
- The ClikBy account client for clickers of their link is the controller;
- ClikBy is the processor (authorized person) for these clicks;
- Pixel ad vendors are often separate recipients / controllers or processors under their models — describe in the notice.
Without a DPA/contractual clauses with the processor you leave a hole in accountability.
Data subject rights
- Right to be informed — a transparent privacy notice before/at the moment of collection.
- Access — confirmation of processing + a copy/information on purposes, periods, recipients, transfers.
- Rectification — correction of inaccurate data.
- Erasure — the «right to be forgotten» under conditions (consent withdrawal, purpose exhausted, etc.).
- Restriction — temporary restriction of processing.
- Portability — a structured machine-readable copy; transfer to another controller if feasible.
- Object — including to direct marketing (the right is stronger here) and to LI in a number of cases.
- Automated decision-making — the right not to be subject to solely automated decision with legal/significant effects without safeguards (human review, contest).
How to respond to a DSAR
- Intake: form / email / cabinet — convenient and found in the policy;
- Identity verification before releasing data;
- Deadline: without undue delay, guideline 1 month; +2 months if complex — with notification and reason;
- Usually free (except clearly excessive/repetitive);
- Log requests and responses — part of accountability;
- Escalation to processors: you request ClikBy/vendors under your instructions.
The clicker writes to the link sender (you). The account client, for account data — to ClikBy using the Policy contacts.
Key business duties
- Follow Art. 5 principles and have a lawful basis;
- Privacy by design / by default;
- TOMs and readiness for breach notification;
- Manage processors through contracts;
- Children's data: parental consent (16, or lower by country, not below 13);
- DPIA at high risk (profiling, special categories at scale);
- DPO — if public authority / large-scale systematic monitoring / large-scale special categories;
- Transparent notices; control of international transfers.
Checklist: 10 practical steps
- 1. Data mapping — forms, CRM, cookies, pixels, accounts, backups; cookie scan regularly.
- 2. Lawful basis — a «processing → basis» table before campaign launch.
- 3. Consent management — opt-in banner, equal Reject, tag blocking, consent logs.
- 4. Privacy & cookie notices — clear language, current vendors and retention periods.
- 5. DSAR process — process owner, templates, SLA.
- 6. Privacy by design — minimum fields, access, DPIA before high-risk features.
- 7. Security + breach plan — encryption, MFA, 72h playbook, breach register.
- 8. Vendors & DPA — ClikBy, hosting, ads, analytics; SCCs/adequacy for transfers.
- 9. Regular review — policies, banner, vendors, retention, team training.
- 10. Accountability owner — DPO or an appointed privacy lead.
Expanded best practices: CookieYes — GDPR Best Practices · checklist for websites.
Cross-border transfers
Before transferring personal data from the EEA to «third countries» a mechanism is required: an adequacy decision of the European Commission, Standard Contractual Clauses (SCCs), binding corporate rules, or other permitted tools. Assess vendors (US ads/analytics, clouds) and reflect transfers in the notice.
The EU-US Data Privacy Framework and equivalents — check the current status; do not rely on the outdated Privacy Shield. The CookieYes KB has a card on the Framework — GDPR section.
Personal data breach
If there is a risk to the rights and freedoms of data subjects — notify the supervisory authority without undue delay, a 72-hour reference from the moment of awareness. Content: nature, categories/volume, consequences, measures. Sometimes subjects must be notified too. Keep an internal incident register even if you «did not report outward».
An ad-account «leak» or unauthorized access to a visits export are also candidates for a breach assessment.
Request and settings routes in ClikBy
| Situation | Куда |
|---|---|
| A clicker asks to delete click data | You as controller → ClikBy support/DPA |
| Account client / account | Contacts from the ClikBy privacy-policy |
| Withdrawal of marketing cookies on the site | /cookies + tags wait for consent |
| Refusal on a redirect with pixels | pixel_notification → Reject |
| Policy and roles | privacy-policy.html + privacy-cookies-guide |
In ClikBy for clicks on the client's links: Customer = controller, ClikBy = processor (privacy-policy §1.9). The EU representative in the Policy is Barcelona. Levers: Cookie Consent, pixel_notification on the redirect, a DPA if needed.
FAQ
Is a GDPR audit mandatory?
Clearly not always a «must», but regular audits are best practice for accountability (see CookieYes materials on a compliance audit).
Is GDPR enough for California?
No. You also need CCPA/CPRA disclosures and opt-out if there is sale/share. Comparison.
Link to 99-3
For a Belarusian operator and a local audience also see Law No. 99-3 and the BY section — GDPR does not replace it.