Explorer
KNOW-REF-051

GDPR Compliance for Web Apps (2026) — Checklist conformité RGPD

Domaine
cybersecu
Type
reference
Priorité
P1

GDPR Compliance for Web Apps (2026)

Description

Checklist de conformité RGPD pour applications web, couvrant les articles clés du RGPD.

Articles clés

Article 25 — Privacy by Design and by Default

  • DPIA pour processing novel, large-scale, ou special-category data
  • Defaults privacy-friendly (marketing off, profiles privés par défaut)
  • Pseudonymisation partout où possible (analytics, logging, internal tooling)
  • Chiffrement colonne-level pour champs sensibles (adresses, payment, health)

Article 32 — Security and Breach Response

  • Chiffrer personal data at rest (column-level ou transparent disk encryption)
  • TLS 1.2+ sur tous les endpoints, HSTS, redirect HTTP→HTTPS
  • Role-based access control (RBAC)
  • Audit logs pour accès staff/admin
  • Pen testing régulier
  • Incident response runbook documenté

6 principes RGPD pour l'architecture

  1. Lawfulness, Fairness, Transparency — Base légale pour chaque donnée
  2. Purpose Limitation — Une finalité = un consentement
  3. Data Minimization — Collecter le minimum nécessaire
  4. Accuracy — Permettre correction
  5. Storage Limitation — Retention periods + automated deletion
  6. Integrity & Confidentiality — Encryption, access controls, audit logs

Références

  • GDPR Compliance Checklist
  • [[KNOW-REF-050]] — Privacy by Design Checklist
  • [[KNOW-PAT-221]] — Privacy by Design Architecture