GDPR stands for General Data Protection Regulations and is a new regulation coming out of the EU that affects the way we collect and manage data.
From a marketing perspective, GDPR has huge ramifications. That’s because, as we move toward a more personalised marketing world, we’re making greater use of personal data than ever before. Whether you’re running simple email marketing campaigns, postal campaigns or SMS campaigns, right through to more complex data use such as Facebook lookalike audiences, you’ll need to be compliant. We’re heading quickly toward an opt-in world – where the opt-in must be explicit and not inferred (which isn’t too much of a departure from what we have now anyway).
Successful data compliance is essentially going to be about culture. Often, data breaches are a result of a genuine mistake, where someone hasn’t had data compliance in mind when they were organising they data or using it. By educating your team, you can help to improve data protection in your business across all areas.
The deadline for GDPR is the 25th May 2018. That means your business needs to be ready and fully compliant by then. It’s not likely to be a quick task, but is is essential… here are some tips to help you get there.
The legal side of GDPR
Essentially, GDPR is not too different to the Data Protection Act (DPA) – but unlike many regulations, which can be adapted by the country in question, the GDPR regulations have to be complied with as is across all member countries (note: even after Brexit, the UK will continue to be an ‘adequate representative’ so we can continue to trade in the EU).
The reasons that GDPR is being implemented are around the advances in the way we’re able to gather and use data and changes in the way we use and share information. This could be for all sorts of reasons, including marketing, insurance, service provision, HR and lots more. GDPR is therefore something that’s going to affect all businesses in the UK and EU, and businesses outside of those areas who carry EU data.
There have also been significant advances in the way we’re able to identify personal data, which has led to a need for a harmonised approach.
The key concepts and changes within GDPR are:
- Increased fines and enforcement powers
- Consent will be harder to obtain
- Binding corporate rules for the lawful transfer of data
- Pseudonymisation – changes to data so it can’t be personally identified
Holding data under the new GDPR regulations
This means you need to let people know:
- The lawful bases upon which the data is being processed
- Your data retention periods
- The person’s right to complain to the ICO if they feel their information is misused
The data subject (this being the person who’s data you have kept) has various rights as part of the new regulations too, including the right to be forgotten (where you have to remove their data), right to object to processing (where they object to data being held) and right to data portability (choice over where their data can be sent).
There are pretty hefty fines for those companies who don’t comply, so now’s the time to get things right.
What we need to do as marketers in light of the new GDPR regulations
- Create a welcome email that welcomes new subscribers to your list and that includes an ‘opt in’. Alternatively, add an opt in tick box on your data capture form
- Make it possible for users to opt out at any time. Piwik have implemented this with an ‘opt out‘ link in their footer
The ICO have created a 12 step plan, which you can find in full here.
GDPR and Digital Marketing
From a specific digital marketing perspective, GDPR gets a little more complex.
GDPR and Google Analytics
The important thing to understand here is the term ‘personal data’. While you might think this only relates to anything personally identifiable, such as a name or email address, unfortunately you’d be wrong.
Cookies and tracking codes fall into the scope of GDPR.
Cookie tracking is done by the vast majority of websites.
Some cookies enable certain functionalities within the site and make it possible for us to surface content in a way that will best suit that particular user’s needs – such as showing the correct currency for the user’s country, for example. If these cookies aren’t used, the website won’t work in the way it’s meant to – to the best of our knowledge, this kind of cookie isn’t within the GDPR remit.
As a user, you can change your settings to not allow this tracking, by turning on ‘do not track’.
To do this in Chrome, simply navigate to your settings, choose ‘advanced’ and check ‘do not track’:
If a user does choose to set their browser to ‘do not track’, it’s worth noting that data will not be provided in the form of reports or be identifiable – e.g. user’s location won’t be tracked – but this doesn’t mean the cookie source won’t still store the data and it would be up to their own policies to explain how that data is used. E.g. as a marketer, you aren’t responsible for the way Google manages its data.
- Require users to opt in
- Allow users to opt out at any time
GDPR and remarketing ads
Remarketing ads are those ads that follow you around the web and encourage you to convert. They work really well, and many of our clients use them very successfully.
GDPR and Facebook
Now let’s say you’re using email addresses for the purposes of creating Facebook lookalike audiences, or to target people whose details you have.
Under the new regulations, you’ll need to tell users about this too – asking them to opt in, and giving them the option to opt out.
If you do upload email address to Facebook to create new audiences, and you’ve got the consent of your users to do this, the onus is then on Facebook to protect that information once they have it.
GDPR and email marketing
If you have an email subscribe box on your website, you should make the user aware of the way their information will be used if they do sign up.
What to do if you’re not sure about GDPR
If you’re not sure about how your activities relate to GDPR and whether or not you’re compliant, it’s more important than ever that you do find out.
While we’re more than happy to talk to you about your specific problem, it’s better if you can find a legal partner to advise. Feel free to leave any comments below and we’ll be happy to help you where we can.
Big thanks to Jemma, Hilary and the team at Vformation who organised a seminar on the topic of GDPR, and to Ed Wright from Shakespeare Martineau, Simon McNidder from Database First Aid and Neale Maude from Arena Group who spoke to us about the new regulations. We’d also like to thank Joe Burns from Pyranet for his further insights into cyber security. This blog is based on their insights as well as our own research.