Logo Logo
  • Platform
    • Products
      • Why Core dna
        See how Core dna transforms your digital business.
      • eCommerce
        Power your eCommerce ambition
      • CMS
        For marketers with vision, not code
      • Automations
        Automate your way to success
      • DXP
        Build, manage, and scale your digital properties in one place.
      By Role
      • Developers
        Modernize your web presence without ripping or replacing anything.
      • Executives
        Empower marketers, free up IT team and slash costs at the same time.
      • Marketers
        Total control, without the development team.
      Company
      • Customers
        Helping power the digital presence of hundreds of customers
      • Features
        Content and commerce features.
      • Services
        From digital transformation strategy to scaling your digital business.
      • Admin login
        Access to Core dna DXP 1 admin
  • Solutions
    • Use Cases
      • B2B
        Go directly to customers with an all-in-one B2B platform.
      • B2C
        Connect to shoppers anytime, anywhere with our B2C eCommerce solution
      • Marketplace
        Multi-vendor eCommerce marketplace platform.
      • Content
        Craft content with ease, then deliver it anywhere.
      • Headless
        A hybrid headless platform loved by marketers and developers.
      • Infrastructure
        Advanced cloud infrastructure built for scale and security.
      By Industry
      • Direct to Consumers / Manufacturing
        Get the tools and experience to thrive in the new direct-to-consumer world.
      • Education
        Create a powerful online presence with your school website.
      • Franchises
        Seamlessly push brand-approved marketing to all locations or specific locations - easily.
      • Retail
        Sell with excellence in-store and online.
      • Media
        Don’t just break news, break news everywhere.
      • Travel & Tourism
        Give travellers the speed and reliability they demand.
      • Membership Organizations
        Empower Your Membership Management with Smart Technology
  • Resources
    • Insights
      • Blog
      • Guides
      • FAQ
      Developers
      • Getting started
      • Documentation
      • API
  • Pricing
  • Partners
    • Why Partner?
    • Program Overview
    • Become a partner
Get started
 
  1. Home
  2. Core dna insights

Top GDPR Questions You’re Asking — And What You’re Missing

Top GDPR Questions You’re Asking — And What You’re Missing
Sam Saltis
January 18, 2021 - ( min read)

Content Management | Security | Digital Marketing

Everyone’s talking about GDPR, but are you asking the right questions? Let’s dive into the essential GDPR questions businesses often overlook — and why the answers could make or break your compliance.

Your CMS vendor should make it easier for you to achieve GDPR compliance. Of course, the brunt of this responsibility will fall squarely on your shoulders, but making sure your CMS vendor is up to par will make it that much easier to satisfy the GDPR requirements.

Below we’ve listed seven questions you should ask your CMS vendor to see if they’re ready for GDPR — and more importantly, if they’re ready to help you get ready for GDPR!

But first, let’s recap.

Key takeaways

  • Ensure CMS vendor staff are trained on GDPR: Regular education on data protection across all teams is essential.
  • CMS must support GDPR features: Vendors should offer tools for privacy by design, easy data deletion, consent management, and data export.
  • Third-party data access must be controlled: You need to know who can access your customer data and ensure they meet strict security standards.
  • Strong data breach protocols are critical: Your CMS should detect breaches quickly and have procedures in place to manage and report incidents.
In a hurry? Get How to Choose a CMS: The Ultimate Guide

On this page:

    What is General Data Protection Regulation (GDPR)?

    In case you’ve forgotten GDPR is the latest digital privacy regulation that effectively brought the EU’s old-school data protection framework into the 21st century. But, far from just impacting the EU, it has a far-reaching effect on any person or business who collects data from EU citizens.

    The overall goal is to help citizens gain more control over their data, while making data collection and use a more transparent process overall. There are numerous rules built into this new legislation that are causing businesses to upgrade their security practices and protocols worldwide.

    Learn everything you need to know about GDPR in five minutes.

    Questions to ask your Content Management System (CMS) vendor about GDPR

    If you’re collecting, using or storing any data relating to EU citizens, you need to ask your CMS vendor the following questions:

    Image. Questions to ask your Content Management System (CMS) vendor about GDPR

    1. Do you train your staff regularly on data protection? 

    All it takes is a single link in the chain to break for your data to become compromised. From support staff to marketing, to development, and even the CEO. You need to be aware of your CMS vendors educational practices for ensuring their team understands the implications of the latest GDPR regulations and what changes this might bring about in their day-to-day workflow.

    It’s not enough to have a single team member concerned about GDPR, at the very least their team needs to be aware of the proposed changes.

    2. What features are you working on to help us become GDPR compliant?

    One component of GDPR is privacy by design. The concept seems sort of vague, but essentially it refers to the need to have business systems designed with proper security and privacy measures in mind.

    Most CMS vendors will probably be rolling out new features to comply with this point, so ask if they have any new features they’re developing out to bolster their security and data collection practices.

    3. Can you process customer data deletion requests from us? If so, how quickly?

    Those whose data you’ve collected can request their data to be forgotten aka deleted, once the original use of the data has ended. This can be due to withdrawing consent, the original purpose of the collection has been fulfilled, or the data has even been used in an unlawful manner.

    As soon as the request occurs, there needs to be a process in place for removing the data as quick as possible.

    A GDPR-ready CMS should be able to help you sort through the personal data, to see if any of it can be retained per the regulation, plus there should be a built-in method for removing data and notifying the appropriate parties.

    Recommended reading: How to Choose a SaaS CMS: The 9-Point Checklist

    4. Do any third-parties have access to our customer's data?

    Third party access to data is all too common. If you’re the person collecting the data, then it’s your job to keep your data safe. The umbrella of this extends out to third parties who might be using the same data. So, if a third party ends up abusing customer data you’ve let them access, then you could be on the hook.

    It’s your responsibility to ensure that your CMS provider has strict data protection policies in place. Plus, you need to be aware of any other parties who might have access to the data you’re collecting through your CMS provider.

    5. What data breach protection and protocols do you have? Can you detect data breaches?

    The last thing you want is to find out about a data breach from your users and valuable customers. This is a surefire way to lose trust. Are there proper security protocols in place that will detect data breaches when they occur?

    Or, at least very least are there detection methods available so you can determine how the breach occurred, and avoid similar breaches in the future?

    Data security needs to be a priority for you, so it’ll need to be a priority for your CMS as well.

    Image 2. Questions to ask your Content Management System (CMS) vendor about GDPR

    6. Is there a built-in way to manage user consent in ways that make GDPR compliance easy?

    Consent to data collection is a large part of GDPR. Your CMS should be able to help you record a history of given consent so you can maintain accurate records. Consent can be given in various ways, such as email, a contact form on the website, a check-box on your landing page, and more.

    Your consent records should specify the time and date when consent was given as well as the exact means they delivered consent. This data should be able to be readily exported and accessed when needed.

    7. How easy is it to export data? Is all data ready for portability requests?

    Per GDPR regulations, user data needs to have the ability to be exported and transferred to any other existing data controller.

    The CMS you choose needs to be equipped to handle both exporting customer data that’s been collected, but also importing the same kind of data. Easy data addition and migration should be a core feature of your CMS.

    How to choose a CMS

    Time to get real about GDPR compliance

    If you’re working with third-party software vendors, you need to start looking outward as well as inward when it comes to GDPR compliance.

    What other questions should brands be asking their CMS vendors? Share your suggestions in the comments below.

    Want to see how high-growth companies use Core dna’s all-in-one content management platform? Let’s chat.
    Have questions? Speak with our experts to find your ideal content solution
    Sam Saltis
    Sam Saltis

    Sam Saltis is the founder and CEO of Core dna, a digital experience platform (DXP) that helps digital teams build and optimize complex, dynamic websites with less code than ever before. Sam has more than 30 years’ experience building technology solutions for various industries and sectors, such as government, business and tourism. 

    He leads a team of technology experts who share his vision of empowering clients to harness the Internet to scale their businesses and enhance their relationships.

    Previous PostA Hollywood-Worthy B2B Storytelling Framework That Will Increase Your Conversion
    Back
    Next PostAmazon Is Winning: Agencies, Here's What To Tell Your eCommerce Clients

    Related guides

    • Guide: How to Choose the Right CMS: The Definitive Guide
    • Headless vs Decoupled CMS Architecture
    • Intranet CMS: Guide to Choose the Right Platform
    • The 8-Point Checklist for Choosing the Right Mobile app CMS
    • CMS and eCommerce RFP Templates
    • Digital Experience Platform (DXP) vs CMS
    • 70+ MVMT Facebook Ads
    See all guides

    Related posts

    Why Evergreen Content Matters More Than Ever—and How to Create It

    Content Marketing

    Why Evergreen Content Matters More Than Ever—and How to Create It
    April 03, 2025 ( 15 min read )
    A Practical Guide to Content Optimization with AI

    eCommerce Business

    A Practical Guide to Content Optimization with AI
    March 30, 2025 ( 9 min read )
    Is SEO Dead? How to Update your Seo Strategy to 2025

    Content Marketing

    Is SEO Dead? How to Update your Seo Strategy to 2025
    March 21, 2025 ( 9 min read )
    How Hyper-personalization is Impacting Digital Experiences

    eCommerce Business

    How Hyper-personalization is Impacting Digital Experiences
    March 18, 2025 ( 9 min read )
    Improve your Digital Customer Experience for Better Conversion

    Content Management

    Improve your Digital Customer Experience for Better Conversion
    March 15, 2025 ( 12 min read )
    Composable CMS in 2025: The Guide to content Flexibility

    Content Marketing

    Composable CMS in 2025: The Guide to content Flexibility
    March 15, 2025 ( 11 min read )
    Mastering Digital Content Strategy in 2025

    Content Marketing

    Mastering Digital Content Strategy in 2025
    March 11, 2025 ( 14 min read )
    Content Management Systems in 2025 - Everything to Know

    Content Management

    Content Management Systems in 2025 - Everything to Know
    February 15, 2025 ( 4 min read )
    Elevate Your CX with the Best Digital Experience Platforms

    Content Marketing

    Elevate Your CX with the Best Digital Experience Platforms
    February 08, 2025 ( 6 min read )
    How AI is Changing Content Marketing in 2025

    Content Marketing

    How AI is Changing Content Marketing in 2025
    January 29, 2025 ( 10 min read )
    Social Media Advertising: Resources & Latest AI Tools to Boost Your Campaigns

    Content Marketing

    Social Media Advertising: Resources & Latest AI Tools to Boost Your Campaigns
    January 27, 2025 ( 8 min read )
    CMS vs HTML: The Key Differences You Need to Know

    Content Management

    CMS vs HTML: The Key Differences You Need to Know
    January 21, 2025 ( 4 min read )
    Solutions by Role
    • Partners
    • Developers
    • Executives
    • Marketers
    Solutions by Need
    • Intranet
    • Event Management
    • Content Management
    • B2b eCommerce
    • B2c eCommerce
    • Headless
    • Marketing
    Solutions by Industry
    • Community
    • Healthcare
    • Finance
    • Technology
    • Hospitality
    • Franchise
    • Education
    • Travel & Tourism
    Company
    • About Us
    • Why Core dna
    • Partner Ecosystem
    • Customers
    • Careers
    • Contact Us
    • G2Crowd Reviews
    Resources
    • Blog
    • Guides
    • Admin login
    • RSS Feed
    • Documentation
    Support
    • Help
    • Videos
    • Network Status
    • GDPR
    • Privacy Policy
    • Terms & Conditions
    • Fair Use Policy
    Get our latest articles
    Success! You've been added to our email list.
    Melbourne

    348 High Street

    Prahran, VIC 3181

    Australia

    +61 3 85639100

    Boston

    55 Court St, Level 2

    Boston, MA 02108

    USA

    +1 617 274 6660

    Berlin

    Belziger Str. 71

    Berlin 10823

    Germany

    +1 617 274 6660

    Go wow them! ™ | Core dna copyright ©  2025.