Compliance checklist
Use this checklist to track your progress. It covers the obligations that fall on you as data controller, as well as the actions recommended to consolidate your compliance.
Mandatory
- Privacy policy updated: mention of the two purposes (§3.2 deliverability, §3.1 performance measurement), of the optional nature of the consent, of the ability to withdraw it, of the retention periods and of Ediware’s qualification (processor / joint controller). The detailed wording is in the documentation for your DPO.
- §7 transitional information sent to the eligible lists (prior B2C opt-ins, B2B with an established relationship), before 14 July 2026 (3 months after the publication of the recommendation). Beyond the deadline, a documented voluntary approach remains recommended.
- Consent register initialized with your existing consents. CSV import or “Import from a campaign”, depending on your flows (API and tracked collection link coming soon).
- Documented analysis of the applied regimes list by list and campaign by campaign (cold B2B on raw aggregated measurement §3.2, lists under §7 opt-out, explicit §3.1 consents, campaigns with hygiene measurement enabled §3.2, campaigns declared out of scope), to be kept in your record of processing activities.
Recommended
- Consent collection built into your new forms: download pages, demo requests, newsletter sign-ups, with a dedicated checkbox for the pixel.
- Consent collection campaigns launched on your engaged B2B prospects (who have interacted, clicked, replied).
- Review of transactional campaigns: pixel disabled if no open measurement is relevant (order confirmations, notifications).
- “Campaign not subject to pixel consent (recipients outside the scope of the applicable regulations)” setting reviewed: enabled by default on campaigns created until 14 July 2026 (then disabled by default). Check that it actually matches the reality of your recipients, and document the qualification (validated by your DPO) for the campaigns where you leave it enabled.
- “Identify inactive addresses (hygiene measurement)” setting reviewed: to be enabled only on campaigns for which you consider you can rely on the §3.2 deliverability and basic hygiene exemption, under your responsibility (validated by your DPO). By default, non-consenting recipients stay on the anonymous aggregated count.
- DPO informed and Ediware architecture document received (on simple request to support).
- Register export at a fixed date (monthly or quarterly), as proof of compliance over time.
Optional
- §7 information module via the platform used to delegate the
informed_attraceability to Ediware, as an alternative to your own template. - Pixel clause added to the contracts or data processing agreements with your own processors (agencies, CRM providers) who access your open statistics.
- Re-solicitation process in place: do not re-solicit a contact who has refused or withdrawn their consent for at least 6 months (recommendation §4.2).
What you do not have to do
The platform automatically handles the following, with no configuration on your side:
- the consenting / non-consenting branching when the emails are sent;
- the absence of individual data collection for non-consenting recipients, from the moment of writing (anonymous aggregated count by default);
- the detection and exclusion of robots from the statistics (reliable for your consenting contacts, limited on the anonymous aggregated count);
- the optional insertion of the withdrawal link in the footer of every email;
- the retention of consent proofs.
The detailed workings of these mechanisms are described in the compliance guide.
Last updated on