GDPR marketing self-audit.

Free skill · MIT · 30 rules · Verdict per rule, with rewrites · v1.0.0

Full GDPR + ePrivacy marketing self-audit.

Install.

No account, no key, no runtime.

npx skills add jukkablomberg/northpoint --skill gdpr-marketing-self-audit-pro

Read the full file on GitHub

When to use it.

Invoke when you submit a marketing asset (email, signup form, cookie banner, landing page, privacy notice, ad creative, KOL contract, marketing automation flow) for the full 30-rule audit.

The 30 rules.

Lawful basis & consent quality (rules 1, 6–9)
  • 1Consent must be freely given (no forced/bundled consent)
  • 6Granularity of consent (per purpose, per channel)
  • 7Withdrawability of consent (as easy to withdraw as to give)
  • 8Pre-ticked or silence-as-consent
  • 9Children's consent (under 16, or 13 in some MS)
Right to object & unsubscribe (rules 2, 10–11)
  • 2Unsubscribe / opt-out mechanism in marketing emails
  • 10One-click unsubscribe (RFC 8058 + ePrivacy)
  • 11Right to object disclosure (separate from unsubscribe)
Cookie consent & ePrivacy specifics (rules 3, 12–15)
  • 3No implied or pre-checked cookie consent
  • 12"Reject" button parity with "Accept"
  • 13Granular cookie categories
  • 14Consent or pay (cookie wall) validity
  • 15Tracking technologies beyond cookies
Transparency at point of collection (rules 4, 16–19)
  • 4Controller identity & contact disclosed
  • 16Purpose of processing disclosed
  • 17Lawful basis disclosed per purpose
  • 18Recipients / categories of recipients
  • 19Retention period disclosure
Profiling & automated decision-making (rules 5, 20–21)
  • 5Profiling & personalization disclosed
  • 20Significance and consequences of automated decisions (Art. 22)
  • 21Right to opt out of profiling for marketing
International data transfers (rules 22–24)
  • 22Third-country transfer disclosure (Art. 44+)
  • 23Adequacy decision references
  • 24SCCs / BCRs / Transfer-Impact-Assessment visibility
Sensitive category data (rules 25–27)
  • 25Special categories require explicit consent (Art. 9)
  • 26Crypto-specific: financial data sensitivity in marketing
  • 27Children's data extra protection (Art. 8 + Recital 38)
Direct marketing & ePrivacy specifics (rules 28–30)
  • 28Soft opt-in (existing customer + similar products)
  • 29Frequency restrictions
  • 30Cross-channel consent (email vs SMS vs push vs WhatsApp vs in-app)

What you get back.

Returns verdict + per-rule analysis + rewrite suggestions.

Run it without installing.

Paste an asset, get a verdict.

Rules are free. Judgment is the job.