Digital Technology Inbound Marketing

What is the GDPR and How Will It Impact Your Business? [Video]

VictoriaChemko
ByVictoriaChemko

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) “is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU).” It comes into effect soon – on May 25th, 2018 – and even non-European businesses, or those who aren’t selling into the European market should be aware of it and prepare and consider the impacts. Regardless of being legal in the EU, it is still good practice to follow these recommendations no matter where your business originates or sells into.

Watch the video below to learn considerations you should keep in mind (note the following does not constitute legal advice, and you should consult your own lawyers for what applies to your particular business).

1. Legal Implications (EU & European Local Law)

Key to the GDPR, individuals have the right to:

Access their personal data, correct errors in and erase their personal data, object to the processing of their data, and also export it whenever they want

What this means for businesses is that you will need to review and update your Privacy Policy and make sure this policy is then updated on your website. All tools that are used for tracking need to be indicated on the privacy policy itself (including Google Analytics and other tools, such as marketing platforms, SaaS, etc.) and also whether the tools used comply with the GDPR.

The Privacy Policy will essentially need to be able to answer the following questions:

    • What information is being collected?
    • Who is collecting it?
    • How is it collected?
    • Why is it being collected?
    • How will it be used?
    • Who will it be shared with?
    • And what will be the effect of this on the individuals concerned?

Also key is addressing the Notification of Breaches: If there is a data breach, the users whom you have access to need to be notified immediately. 

2. Governance & Management

In terms of governance, organizations will need to:

    • Protect personal data using appropriate security,
    • Notify authorities of data breaches within 72 hours,
    • Obtain appropriate consents before processing data,
    • And keep records detailing data processing.

They will also be required to

    • Provide clear notice of data collection,
    • Outline processing purposes and use cases,
    • And define data retention and deletion policies.

3. Operations, Policies, & Procedures

All organizations will need to:

    • Train privacy personnel & employees,
    • Audit and update data policies,
    • And create & manage compliant vendor contracts

It’s also recommended to Employ a Data Protection Officer for larger organizations.

4. IT & Technology Infrastructure

For businesses that have contact forms and email subscription forms on their website, this may mean that: 

  • Every form needs a checkbox where the user accepts the Privacy Policy of the website,
  • And in the privacy policy, the user needs to be told how their data will be used, how and where their data will be stored, and how it will be processed. This checkbox needs to be disabled by default (and not already selected).
  • To comply with the Right to be forgotten
    • A business should give the user the option to ask for the deletion of their data at any point in time – either a user profile or that data which is submitted via a contact form or other form submission.
    • As a lot of websites use backups, in the privacy policy it needs to be communicated that a user’s data will be kept up to 12 months for business and operations reasons.
  • To comply with the right to download & change data
    • The website should also have a mechanism for users to download or change their data electronically.

5. Alignment Across the Whole Organization

Last of all, you’ll need to ensure that everyone within your business understands how the GDPR works, and what are the procedures and policies at your company so that they are able to follow them accordingly. This includes team members across all departments, including HR, marketing, IT, Finance and otherwise, as it will affect operations for everyone. 

Now that you know more about the GDPR and how it can have an impact on your business, please check out other recent blog posts covering useful Inbound Marketing tips.

If you liked this video, subscribe to the Umami Marketing YouTube Channel and the monthly Digital Marketing Postcard. I’ll be back again in May to answer more of your questions. See you soon!

About the Author

VictoriaChemko

VictoriaChemko

Founder & CEO
A successful three-time entrepreneur and Founder of Umami Marketing, Victoria works with companies around the world to build their digital presence and attract more customers.
Follow Me On: Facebook Twitter Instagram Linkedin

You may also like...

By continuing to browse or by clicking “Accept” you agree to the storing of first- and third-party cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
Cookie policy | Privacy Policy

Privacy Preference Center

Close

Your Privacy

Umami Marketing Inc. appreciates your interest in its products and your visit to this website and respects the privacy and the integrity of any information that you provide us as a user of this Site. The protection of your privacy in the processing of your personal data is an important concern to which we pay special attention during our business processes.

Privacy Policy

Required
Personal data collected during visits to our websites are processed by us according to the legal provisions valid for the countries in which the websites are maintained. Our data protection policy is also based on the data protection policy applicable to Umami Marketing Inc. Read more

Cookie Policy

Required
Umami Marketing uses cookies and similar technologies, such as HTML5 web storage and local shared objects (all referred to as ‘cookies’ below), to record the preferences of users and optimize the design of its websites. They make navigation easier and increase the user-friendliness of a website. Read more

Essential cookies

These cookies are essential for websites and their features to work properly. Without these cookies, services such as the vehicle configurator may be disabled.

Cookies used

  • WordPress Required

Performance Cookies

These cookies collect information about how you use websites. Performance cookies help us, for example, to identify especially popular areas of our website. In this way, we can adapt the content of our websites more specifically to your needs and thereby improve what we offer you. These cookies do not collect personal data. Further details on how the information is collected and analyzed can be found in the section ‘Analysis of usage data’.

Cookies used

Third-party cookies

These cookies are installed by third parties, e.g. social networks. Their main purpose is to integrate social media content on our site, such as social plugins.

Third-party cookies