The buzzword lately has been GDPR, but what is it and should you even care? Basically, you need to care if sell to people in the UK or even if some of your readers are from the UK. That’s right, even if you only collect email addresses for your blog posts you still have to protect yourself or it could cost you a small fortune!
What Is GDPR?
The GDPR was designed to harmonize data privacy laws across Europe, to protect and empower all EU citizens data privacy and to reshape the way organizations approach data privacy. The requirements of EU General Data Protection Regulation (GDPR) that will be enforced on the 25th May 2018.
So what information might you be gathering?
There may be information that you are collecting via your website but you’re not actually aware of it happening – such as cookies and IP addresses. However, there will be some data that you are aware of – such as contact forms, newsletter sign-ups, and e-commerce transactions.
Say that again in English, please?
Practically speaking, from a website perspective, you need to first think about how your company acquires data through your website – we’re talking about personal data that can be used to identify an individual. Things like names, email address, contact numbers, IP address etc.
When individuals visit your website and interact with it, you need to make it as clear and as transparent as possible what’s happening.
You need to show what information you are gathering, offering options for consent at a granular level. You need to provide the ability for individuals to view the information you have gathered and be able to remove that information from your systems as soon as people ask you to.
2. Peace of mind for you & your customers with an SSL certificate
Privacy is the number one priority as part of GDPR. People want to be safe in what information they provide and, how they provide it.
A Single Socket Layer, or SSL certificate is a small file that digitally binds a cryptographic key to an organisations details. When you have one as part of your website, it activates the ‘padlock’ symbol that you see in web browsers. It provides you with that https:// in your address bar – making all of your content secure between servers, it increases your Google search engine optimisation (SEO) rankings which is a bonus and builds/enhances customer trust, resulting in improved conversion rates – especially within e-commerce websites.
3. Website Forms
Forms on your website must no longer include pre-ticked boxes. This is considered implied consent and not freely given.
Users should be able to provide separate consent for different types of processing. For example, an option to be contacted by post, email, or telephone as three separate tick boxes.
If you are asking for permission to past details onto a third party – again, you need another tick box. If you are collecting data through one website on behalf of several third-parties, then you need to clearly give an opt-in option for each party.
Offering them something like a whitepaper if they sign up to something is a great way of getting more user signup’s, but you still need to provide an opt in tick box, otherwise, consent has still not been given freely.
4. Easy to Withdraw Permission or Opt-Out
It must be a simple process to remove a user’s consent as it was to grant it, and individuals always need to know they have the right to withdraw their consent.
6. IP Tracking
If your website has a blog element to it where users can leave comments or sign up to a news feed, the chances are their IP address is being stored in your websites database and therefore, you need to let people know about this.
7. Social Media Advertising
If you’re planning on using email addresses to build lists for social media advertising, you will need to tell your users about this. They will need to opt into the social media marketing (as a granular tick box) and, also be offered the option to opt out too.
9. Online Payments
If you are an e-commerce business, you are likely to be using a payment gateway for financial transactions – PayPal, Stripe, SagePay etc.
Your own website may be collecting personal data before passing these details onto the payment gateway. If this is the case, you will most certainly require an SSL certificate to make sure this information is properly encrypted.
The GDPR legislation is not explicit about the number of days, it is your own judgement as to what can be defended as reasonable and necessary. You simply need to be prepared to provide the details you have to an individual who asks for it and, remove the data if an individual asks you to.
10. Data Breaches
The GDPR introduces a duty on all organisations to report certain types of data breach to the Information Commissioner’s Office website (ICO), and in some cases, to individuals. You only have to notify the ICO of a breach where it is likely to result in a risk to the rights and freedoms of individuals – if, for example, it could result in discrimination, damage to reputation, financial loss, loss of confidentiality or any other significant disadvantage.
Just want the short version?
- The GDPR says that your privacy information must be ‘concise, transparent, intelligible and easily accessible; written in clear and plain language – particularly if addressed to a child; and free of charge.
- The key point here is the language that is used is simple and easy to understand, as jargon will not be acceptable under the GDPR rules.
- Make yourself aware of where data on your website is coming from, where it is being stored and how it is being processed.
- Give everyone the choice to opt into any data, give them the ability to opt out and view/have their data removed from your systems easily.
- Encrypt your website with an SSL certificate which not only brings confidence to your users but also helps to boost your rank in search engines
If you have less than 100 pages Cookiebot is free they scan them and count every subpage, post, etc so don’t be surprised if you have more. If you have less than 500 it’s $10 a month if you pay annually or $20 monthly.
Latest posts by Rena (see all)
- The Ultimate Guide to the Future of E-commerce - October 14, 2018
- Life In A Small Town Pt 15 - October 12, 2018
- Using Instagram Stories effectively to Reach More Audiences - October 7, 2018