What Is It? What Do We Need To Know? What Should We Do?
If you don’t know what the GDPR is, and if you’re not ready for it, you’re going to get caught short because this is a legal deadline and it’s coming up fast. The General Data Protection Regulation goes into effect May 25, 2018. It’s a privacy law that the European Union is enforcing to protect the personal data businesses collect. Even if your business is outside of the EU, you must comply.
What is the GDPR?
The GDPR affects all internet business worldwide. It’s a very complex law, so we can’t explain everything here. We’ve provided some resources below that you should check out. Keep in mind that there are many gray areas where this law is concerned. So, you should do some research to determine how the law affects your organization’s unique situation.
The GDPR is an internet privacy law. All businesses, small or large, and even entrepreneurs who do business on the Internet with consumers located in the European Union need to be aware of how the law affects them.
It doesn’t matter if your company is inside the EU, or anywhere else in the world– If you do business with anyone in the following countries, you must comply with this new law by May 25th:
The GDPR is a consumer data protection law. It ensures that individuals can:
The GDPR applies to the acquisition, processing, and storage of personal data – from initial gathering to final deletion of this data and every point in between. It applies specifically to personal data and anything that pertains to identifiable data such as:
This could be information you collect automatically from Google, an opt-in, or other collection method online – anything that would identify an individual.
How Will The GDPR Affect My Business?
If your business has a website or an email list, you may be affected.
The GDPR affects any business relationship or transaction whether commercial or free where one or more of the entities are in the European Union. It’s not based on citizenship, rather location. Any business within the EU must comply with the GDPR across its entire audience. If your business is in any of the 28 European Union Member States, you must comply with the law if you conduct a transaction with anyone located anywhere. If your business is located in the U.S. and you collect data about any business or person in the EU, you must comply with the GDPR.
How Should We Prepare For The GDPR?
There are three requirements you must meet before May 25th.
Controls and Notifications
IT and Training
Before the GDPR:
Let’s say you offer a whitepaper or free video to people online. Before the GDPR, your prospect provided their information, you gave them the freebie, and the consent was assumed because they accepted your gift. Pretty easy, right?
After the GDPR:
You can no longer assume that their consent is given if they accept your gift. Now you must specifically obtain their consent. It must be given freely, specifically, and be unambiguous. Nor can you require them to give their consent to receive the gift.
Note: This new standard applies to all of your existing lists. Beginning May 25th, you can no longer send marketing emails to anyone who hasn’t given their precise consent for you to keep their personal information. Plus, you cannot go back and ask them for their consent. You’ll need a stand-alone system to do this.
What Can We Do To Comply With These Strict Rules?
This is important. You must do this BEFORE May 25, 2018.
Step 1. Segment your email mailing lists into two parts.
You want to continue to build goodwill with your Non-EU contacts so reach out to them as you would have before. The EU-based and unknowns you’ll need to re-engage with. Here’s what we mean:
Step 2. Reengage EU-based and Unknowns.
Remember, storing and deleting their information is considered processing. That’s why you must do this BEFORE May 25th.
Breach Notification Requirements
The 2018 GDPR replaces the old Data Protection Directive of 1995. The most recent GDPR breach notification requirement was enacted in April 2016. It set a higher compliance standard for data inventory, and a defined risk management process and mandatory notification to data protection authorities.
Breach notification is a huge endeavor and requires involvement from everyone inside an organization. In-house tech support and outsourced Technology Service Providers should have acquired a good understanding of the consequences a data breach causes and the data breach notification requirements for their organization. They must be prepared in advance to respond to security incidents.
The Following Are Additional Steps You Should Take To Prepare Your Technology Before May 25th
Your Technology Solutions Provider Can Help
Resources To Check Out For More Information
The European Commission’s website regarding the GDPR:
General Data Protection Regulation
Information from the service vendors you use:
These and other services have GDPR-centric webpages with helpful information that impacts your relationship with them, how they handle processing, and how they can help you comply with the new regulations