GDPRComplianceVendor selection
GDPR-Compliant Marketing Automation: A Buyer's Checklist
By DBautopost Team · 5 March 2026 · 7 min read
Procuring a marketing automation tool in the EU is no longer just a feature comparison. Legal exposure scales with the wrong vendor.
The 12 questions
- Where exactly is customer data stored — region and country?
- Do you offer a GDPR-compliant DPA out of the box?
- List your subprocessors and their regions.
- Do you train any AI models on customer content?
- Encryption standards in transit and at rest?
- How do you handle data subject access requests (timeline)?
- Are auth tokens for connected social accounts isolated?
- What is your incident notification SLA?
- Can I export all data on demand?
- Retention policy after account deletion?
- SOC 2 / ISO 27001 status?
- EU-based support and legal entity?
If a vendor cannot answer all twelve clearly, walk away. The cheap stack becomes very expensive when a regulator calls.