Compliance

GDPR Compliance

How Cookify helps you stay compliant with the General Data Protection Regulation.

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into force on 25 May 2018. It applies to all organisations that process personal data of EU residents, regardless of where the organisation is based. Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher.

Does GDPR Apply to Me?

GDPR applies to you if your website or app:

  • Is accessible to users in the European Union
  • Collects personal data (e.g., names, emails, IP addresses, cookie identifiers)
  • Uses analytics, advertising, or functional cookies

If you use any third-party tools (Google Analytics, Facebook Pixel, HubSpot, etc.), you almost certainly need a GDPR-compliant cookie consent solution.

Cookify's GDPR Features

Consent Management
Collect, record, and manage user consent in full compliance with GDPR Articles 6 and 7.
Audit Logs
Timestamped, tamper-proof records of every consent event — ready for regulatory audits.
Breach Notification
Real-time alerts help you meet the 72-hour breach notification requirement under Article 33.
Data Processing Agreements
We sign a DPA with every customer, fulfilling processor requirements under Article 28.
Data Subject Requests
Tools to handle access, deletion, and portability requests within the 30-day GDPR window.
Cross-border Transfers
Standard Contractual Clauses (SCCs) in place for all data transfers outside the EEA.

Lawful Basis for Consent

Under GDPR, consent must be:

  • Freely given — no pre-ticked boxes or consent bundled with other agreements
  • Specific — separate consent for each purpose (analytics, marketing, etc.)
  • Informed — users must know what they're consenting to
  • Unambiguous — a clear affirmative action (e.g., clicking "Accept")
  • Withdrawable — users can change their mind at any time

Cookify's consent banners are built to satisfy all five requirements out of the box.

Our Certifications

Cookify maintains the following certifications and standards:

  • SOC 2 Type II certified
  • ISO 27001 in progress
  • GDPR Data Processing Agreement available for all customers
  • EU Standard Contractual Clauses (SCCs) in place
  • Hosted on AWS EU-WEST-1 (Dublin, Ireland)

Questions?

Our compliance team is here to help. Email us at gdpr@cookify.io or visit support.

Become GDPR-compliant today

Start your 7-day free trial. No credit card required.