Use whenever code touches authentication, login, session management, audit logging, or application logging — even if the user's prompt doesn't mention DSGVO, GDPR, privacy, or "personal data". Triggers on bcrypt/argon2/scrypt, jsonwebtoken/jose, passport/next-auth/Auth.js/authjs/lucia, express-session/iron-session…
Use whenever code touches newsletter, marketing-email, drip-campaign, re-engagement, win-back, lead-magnet, or any outbound email with promotional content — even if the user's prompt doesn't mention DSGVO, GDPR, UWG, privacy, or "personal data". Triggers on Mailchimp / @mailchimp/mailchimpmarketing, Brevo /…
Use whenever code or infrastructure handles user data and touches a non-EU service or region — even if the user's prompt doesn't mention DSGVO, GDPR, privacy, or "personal data". Any user data (names, emails, IPs, user IDs, avatars, profile pictures, uploaded files, user-generated content…
Use whenever code generates or modifies marketing-email content with AI/LLM APIs (OpenAI openai / @openai/sdk, Anthropic @anthropic-ai/sdk, Mistral @mistralai/mistralai, Cohere cohere-ai, Vertex AI @google-cloud/vertexai, Azure OpenAI) — even if the user prompt only says "Subject-Line mit GPT generieren"…
Use whenever code touches authentication, login, session management, audit logging, or application logging — even if the user's prompt doesn't mention DSGVO, GDPR, privacy, or "personal data". Triggers on bcrypt/argon2/scrypt, jsonwebtoken/jose, passport/next-auth/Auth.js/authjs/lucia, express-session/iron-session…
Datensouveränität, Art. 48 DSGVO, US CLOUD Act, BCRs. Use whenever US/UK/CN-headquartered cloud providers host EU data — even in EU regions. Triggers on AWS, Azure, GCP, Cloudflare, Microsoft 365, Google Workspace in EU regions; questions about CLOUD Act risk, US lawful access, BYOK/HYOK, EU-souveräne Alternativen…
DSGVO Datenschutz-Folgenabschätzung (DSFA / DPIA, Art. 35). Use when planning systems involving sensitive data (Art. 9 — health, biometric, etc.), large-scale tracking, profiling, automated decision-making, employee monitoring, KI/ML systems with personal data, KRITIS, or any processing on the German DSK Muss-Liste.…
Use whenever code touches newsletter, marketing-email, drip-campaign, re-engagement, win-back, lead-magnet, or any outbound email with promotional content — even if the user's prompt doesn't mention DSGVO, GDPR, UWG, privacy, or "personal data". Triggers on Mailchimp / @mailchimp/mailchimpmarketing, Brevo /…
Schweiz — revDSG, Swiss-US DPF, EDÖB. Use whenever Swiss users/customers are involved or a Swiss controller deploys US tools. Triggers on .ch domains, Schweizer Kunden, EDÖB, revDSG, Swiss-US Data Privacy Framework, FADP, Bundesgesetz über den Datenschutz, DSG, Art. 16-19 revDSG cross-border transfer rules, Schweizer…
Abgrenzung Service-Mail vs werbliche E-Mail nach BGH-/OLG-Linie (BGH I ZR 218/07 vom 20.05.2009 — „E-Mail-Werbung II" / B2B-Eingriff; VI ZR 225/17 vom 10.07.2018 — Bewertungsbitte = Werbung; VI ZR 134/15 vom 15.12.2015 — „No-Reply" / Auto-Reply mit Werbezusatz = Eingriff Persönlichkeitsrecht). Use when classifying…
DSGVO Drittlandtransfer (Kapitel V, Art. 44-49). Use whenever code or infrastructure handles user data and touches a non-EU service or region — even if the user's prompt doesn't mention DSGVO/GDPR/privacy. Any user data (names, emails, IPs, user IDs, avatars, profile pictures, uploaded files, user-generated content…
DSGVO Open-Tracking-Pixel, Click-Redirects und externe Bilder in Marketing-Mails. Use when implementing Mail-Open-Pixel (1x1.gif, /open?id=), Click-Tracking-Redirects (/c/ ?u=), externe CDN-Bilder im Mail-Template, Personalisierungs-/Profiling-Tracking, A/B-Tests pro Empfänger. Erfasst TDDDG § 25 als Norm (Wohnsitz…
DSGVO One-Click-Unsubscribe (Art. 7 III + Art. 21 II + RFC 8058) und Aufbewahrungsfristen für Marketing-Mail. Use when implementing /unsubscribe-Endpoints, List-Unsubscribe + List-Unsubscribe-Post Header, Suppression-Hash-Schema, Bounce-Handling (hard/soft/spam-complaint), Re-Permission bei Inaktivität, Gmail/Yahoo…
DSGVO + UWG-Lauterkeitsrecht für werbliche E-Mail in DACH. Use when discussing UWG § 7 (DE) inkl. § 7 II Nr. 3 + § 7 III Bestandskunden-Privileg-Voraussetzungen, AT TKG 2021 § 174, CH UWG Art. 3 I o, Cold-B2B-Mailing, LinkedIn-/XING-Plattform-DMs als elektronische Post (OLG Hamm 18 U 154/22 vom 03.05.2023)…