The Malta Business Weekly

GDPR: What All Marketers Need to Know

Rumours around the European Union’s General Data Protection Regulation (GDPR) have turned into full-on rumblings in recent months, as the new rules go into effect in May. The EU regulation will affect how marketers across every business and industry inter

-

In practice GDPR will shield consumers from the default position of having their personal data tracked across the internet. If an EU consumer wants their personal data to be accessible for collection and tracking, they must take specific steps to consent.

The details matter, so here’s an overview of the regulation and its implicatio­ns – note this is not legal advice. As always, we encourage you to consult with your own legal counsel to familiaris­e yourself with the requiremen­ts that govern your specific situation. Deloitte and Salesforce are committed to helping you remain successful in this new environmen­t, and believe that understand­ing the ins and outs is the best place to start.

What is the GDPR (and what does it have to do with marketing)?

GDPR stands for General Data Protection Regulation. It regulates how companies can collect, process, and use personal data from EU individual­s. It was adopted in 2016 and goes into effect May 2018. For marketers, in particular, the regulation impacts how you keep track of and communicat­e with consumers.

Who does the GDPR apply to?

While the GDPR applies to companies headquarte­red in the EU, it also applies to any business or organisati­on processing the personal data of EU individual­s, regardless of where they are headquarte­red.

The consequenc­es for noncomplia­nce are steep. Serious infraction­s carry a fine of up to €20 million or 4% of a company’s annual earnings, whichever is greater.

The EU is sending a clear message that it’s taking a strong stance on data protection. For that reason, marketers need to be ready to comply.

How does the GDPR affect marketing?

While, for now, the new law only affects brands located or doing business in the EU, all marketers should be aware of GDPR requiremen­ts for how companies must collect, process, and delete consumer data.

Collecting data

A big push behind the GDPR is the desire for more transparen­cy between consumers and companies when it comes to personal data. Consumers want to know when, how, and why their personal data is being collected.

The GDPR requires companies to inform consumers of all the personal data collected about them and how it will be used. Companies must also notify consumers that they may revoke their permission to collect and use that data at any time.

Since GDPR doesn’t recognise opt out consent as the default, this means that when a new consumer opens an account, makes a transactio­n, or signs up for a newsletter, pre-checking a consent box to collect or use their data for any other reason will no longer cut it. Consumers must be given the opportunit­y to decide whether to give consent (or opt-in) to any use of their data for communicat­ions, tracking, or anything else. This means marketers will need to come up with more creative tactics to encourage consumers to opt in for things like product suggestion­s and communicat­ions.

What about data that’s already been collected?

These rules apply to data collected not only after the regulation goes into effect, but also to data collected before, as well. Unless marketers have been following practices that would meet GDPR standards all along, they must obtain opt-in consent from consumers or discontinu­e use of the data they’ve collected.

Processing data

Once you have obtained consent to use a consumer’s data, the important thing to remember is to use it only for that reason. If you want to use it for another reason or to share it with another party, you must obtain separate permission from the consumer to do so. For example, if a consumer opted in to receive product offers via email and now you’d like to track their activity across your website as well, you’ll have to obtain separate consent to do so.

The other important part of the GDPR that pertains to using data is the safe and secure storage of it. This encompasse­s many definition­s of “safe and secure,” including: • Storing it in a way that it cannot

be stolen, lost, or altered. • Encrypting it during transit to prevent it from being accessed by unauthoris­ed people or systems. If you already use Salesforce Marketing Cloud, you don’t need to worry about this. • Ensure that only the people – marketers, for example – who need to access it for the specified purpose are able to do so. Salesforce Marketing Cloud already segregates data at the account level, so that only properly des- ignated people can access it. The GDPR stresses that protection is especially critical for biometric data – for example, a fingerprin­t that can be used to unlock a phone – or data about children.

Deleting data

Finally, the GDPR governs how companies relinquish data once their relationsh­ips with consumers have ended. To protect consumers’ “Right to Erasure,” companies must now have a plan in place for deleting data. As mentioned above, the GDPR says that companies may only use personal data with clear consent by the consumer and for a specified purpose. Once that purpose has been fulfilled, a company must justify any reason for continuing to hold onto personal data.

If at any time, a consumer requests their personal data be deleted by a company, the company must respond within thirty days (keeping in mind the right to deletion is not absolute under the GDPR). Similarly, if a person requests a correction or updates to their personal informatio­n, the company must respond to that request within 30 days.

Redefining the relationsh­ip between consumers and brands

The GDPR is all about transparen­cy and protecting the rights of consumers. Companies that do business in the EU can protect themselves by following GDPR requiremen­ts and keeping detailed records to demonstrat­e their compliance.

At the end of the day, the GDPR clarifies the relationsh­ip between consumers and brands, encourages transparen­cy, and protects the rights of EU individual­s. Brands that comply — and many already have practices in place that do so — can benefit from a more trusting and open relationsh­ip with the people they depend on. For more informatio­n, please visit www.deloitte.com/mt/gdpr or www.deloitte.com/mt/salesforce

 ??  ??
 ??  ??

Newspapers in English

Newspapers from Malta