Use whenever code touches authentication, login, session management, audit logging, or application logging — even if the user's prompt doesn't mention DSGVO, GDPR, privacy, or "personal data". Triggers on bcrypt/argon2/scrypt, jsonwebtoken/jose, passport/next-auth/Auth.js/authjs/lucia, express-session/iron-session…
Use whenever code touches newsletter, marketing-email, drip-campaign, re-engagement, win-back, lead-magnet, or any outbound email with promotional content — even if the user's prompt doesn't mention DSGVO, GDPR, UWG, privacy, or "personal data". Triggers on Mailchimp / @mailchimp/mailchimpmarketing, Brevo /…
DSGVO Drittlandtransfer (Kapitel V, Art. 44-49). Use whenever code or infrastructure handles user data and touches a non-EU service or region — even if the user's prompt doesn't mention DSGVO/GDPR/privacy. Any user data (names, emails, IPs, user IDs, avatars, profile pictures, uploaded files, user-generated content…