gdpr-mobile
Installation
SKILL.md
GDPR on Mobile
Instructions
GDPR is mostly a product / process problem, but the mobile app is where most user-facing obligations land (notice, consent, export, deletion).
1. Lawful Basis, Per Purpose
Never treat "consent" as the default. Map each processing purpose to one of:
| Basis | Example on mobile |
|---|---|
| Contract | Order processing, account management, the thing the user actually signed up for. |
| Legitimate interest | Fraud prevention, security logging, basic aggregate usage analytics (documented LIA required). |
| Legal obligation | Tax record retention, lawful intercept requirements. |
| Consent | Personalized ads, cross-device tracking, optional marketing comms. |
| Vital interest | Rare; emergency contact features, some health apps. |
| Public task | Rare outside government / public services. |