Privacy

GDPR Scheduling Checklist for 2026 (10 Requirements)

April 2026 · 6 min read · By

If you book clients in the EU, your scheduling tool is processing personal data under GDPR — which means it needs a lawful basis, a data-processing agreement, transparent sub-processor list, a documented retention policy, and a Data Subject Request (DSR) response process. Here's a practical 10-item checklist.

1. Lawful basis: contract, not legitimate interest

Most scheduling data should be processed under contract (the invitee is entering into a contract by booking a meeting), not legitimate interest (which is the loophole tools use to justify analytics). If your tool says analytics run on legitimate-interest basis, it's defensible but fragile under DPA enforcement.

2. Data minimization: collect only what the meeting requires

Name, email, meeting reason, and timezone. Everything else (phone number, company, job title) should be optional and clearly marked. Auto-fill via marketing pixel? Not GDPR-compliant unless you have separate consent.

3. Retention limits with published timeframes

GDPR requires retention limits to be specific, not open-ended. "We keep data as long as necessary" doesn't pass muster. Pick 30/60/90 days for most booking metadata and document it.

4. Data Processing Agreement (DPA)

If you're a business processing EU data, you need a DPA with your scheduling tool (you're the controller, they're the processor). Most SaaS tools provide this as a standard contract. Ask for it explicitly before you sign up.

5. Sub-processor transparency

Your scheduling tool probably uses a mail-sending service (SendGrid, Postmark), an analytics tool (if any), and a cloud provider (AWS, GCP). You're entitled to know who these are and where they're located. Named sub-processor lists with update notifications are best practice.

6. Data Subject Request (DSR) response within 30 days

GDPR Article 12: response within one month, extendable by two. Your scheduling tool should have a one-click self-serve export and deletion flow. If they need 30 days to process a DSR, that's a red flag.

7. Breach notification protocol

GDPR requires breach notification to supervisory authorities within 72 hours of discovery. Your tool's breach notification SLA should be documented publicly.

8. Standard Contractual Clauses (SCCs) for US transfers

If your scheduling data crosses the Atlantic, you need SCCs in place. The new EU-US Data Privacy Framework (2023) provides an additional legal basis, but SCCs remain the belt-and-suspenders standard.

9. No cross-context behavioral advertising

This one is CCPA (California) but is becoming a GDPR question too. Your scheduling tool should not use booking data to retarget the invitee for advertising on other platforms.

10. Documented DPIA for high-risk processing

If your booking tool collects sensitive data (health, financial, legal context), you need a Data Protection Impact Assessment. Work with your tool's DPO or legal team to produce one.

This is part of our privacy-first scheduling pillar guide — 18 articles covering every privacy angle.

Frequently Asked Questions

Is Calendly GDPR-compliant?

Calendly provides a DPA and claims GDPR alignment, but ships Google Analytics and Mixpanel on booking pages under 'legitimate interest' — a position that's contested by EU regulators. If you're in a high-risk profession (healthcare, legal, therapy), prefer tools that minimize third-party data sharing by default.

Does Cal Clear sign a DPA?

Yes. Cal Clear provides a standard DPA for business customers. Contact support to request it.

What's the easiest way to stay GDPR-compliant when scheduling?

Use a tool that minimizes data collection by default, publishes a clear retention policy, and doesn't load third-party analytics on booking pages. Cal Clear is designed for exactly this.

Try privacy-first scheduling, free

Cal Clear runs zero trackers on booking pages and auto-deletes booking data on your schedule. Start at calclear.app.