Webflow focuses on GDPR compliance to ensure user data is handled lawfully and transparently.
1. Data Processing Agreements
- Webflow offers a Data Processing Agreement (DPA) which outlines how personal data is processed in compliance with GDPR.
- This agreement is available to all users under their account settings for review and acceptance.
2. Cookie Consent
- Webflow sites can utilize third-party cookie consent tools to manage visitor consent for cookies.
- These tools help ensure that visitors voluntarily opt-in to data collection methods implemented via cookies.
3. Form Submissions
- Webflow provides the ability to create custom forms that can be configured to include consent checkboxes for GDPR-compliant form submissions.
- Ensure that the form's terms and conditions are visible and that a clear opt-in/opt-out option is included.
4. Storage and Security
- Visitor data and form submissions are encrypted both in transit and at rest to improve data security.
- Webflow ensures that personal data storage aligns with GDPR data protection requirements.
5. User Rights
- Webflow allows site creators to access and delete personal data upon request, facilitating user rights such as the right to access and the right to be forgotten.
- Admin panels enable easy management and export of form submissions if required by data subjects.
Summary
Webflow ensures GDPR compliance by offering a Data Processing Agreement, integrating cookie consent tools, configuring forms for consent, encrypting data, and facilitating user rights to access and delete data. Make sure to actively manage these settings and tools within your site to maintain compliance.