SlideShare una empresa de Scribd logo
1 de 18
How do we stay compliant to GDPR for EU citizens.
GDPR Compliance
May 22, 2018
Background
What GDPR means to us as a marketers
What is the
General Data
Protection
Regulatation?
To process, collect, store & use personal
information on EU citizens (UK), there
are 6 legal grounds:
a)Consent to receive communication
b)Contract
c)Legal obligation
d)Vital interests
e)Public interest
f) Legitimate interests.
Key Terms
➡ Data Processor: Tools Hubspot, Google Analytics, Facebook are data
processors. All tools are rolling out features to support GDPR and data
retention.
➡ Data Controller: Company - you control what we ask for on forms, e.g.
phone numbers, emails and other personal identifiable information.
➡ Right to be forgotten: We have the ability to purge a users data if they ask
us to do so.
➡ Consent: Explicit consent with clearly worded terms.
Consent
Do we need to email our entire
database?
No. Previously gained consent is still valid when
GDPR goes into effect. We do not need to email
our entire database to regain consent.
How do we get consent?
1. On forms, we have a
checkbox that asks
for consent to email
& contact them via
phone.
2. A checkbox to ask for
consent to include
their personal
information in
Facebook Custom
Audiences
3. Cookie & tracking
notification on the
website, i.e. we use
cookies & third party
tracking tools like
Google Analytics &
Hubspot.
4. Direct Mail -
Consent to use their
mailing address for
marketing purposes
Consent must be
provided freely and
without using pre-
checked boxes or
assumed otherwise.
1. Cookie Consent Notice on the website - explicitly mention
Facebook, Google Analytics in the text. Links to privacy policy to
learn more about how Hudoc & third party vendors (Facebook,
Google) use personal data.
2. Point users to blockers like Ghostery or Incognito mode if they
want to avoid being being tracked.
3. Align any third party CPL Vendors & Rev Gen on GDPR
compliance: Ensure they have mentioned Hubdoc as the data
processor & ask for consent on forms & have the ability to delete
all associated information
How do we put this in
practice?
Next Steps
Legitimate Interests
What if we don’t have a record of
previous consent?
We can cite Article 6, including Section B, F and
Recital 47 as basis for retaining & processing
personal data & using it for business/marketing
communication.
What counts as a legitimate interest?
“The processing of personal data for direct
marketing purposes may be regarded as carried
out for a legitimate interest. “ - Article 6
As a business, it’s a legitimate interest to pursue
profit & create jobs. However this needs to be
balanced with the individual rights. Individuals
must be given a way to opt-out and have their
information removed or appended.
Data Management
Data Management:
Prospects are be able to:
● Opt-out of any marketing communications
● Request their information be deleted (right to be
forgotten)
● Append any data the company has on them.
● Request a copy of all data & be able to review it.
Systems & Process
1. Create a privacy@companyname email to process all data requests & send copies of marketing emails to as an
audit record.
2. Enabled GDPR features in Hubspot. This helps us:
○ Add GDPR consent to all Forms
○ Create subscription types to enable users to opt-in to specific communications
■ Email
■ Third Party Advertising
■ Data Processing
○ Delete contacts & all associated data
○ Track consent with new ‘Legal Basis for processing contact data
3. Google Analytics is rolling out ability to remove cookie & data and auto deletion tools.
Summary & Next Steps
Systems Item Next Steps Status
Hubspot Enabled GDPR Features
Remove old consent
checkboxes from forms.
Add GDPR Compliance
fields to forms.
In Progress
Hubspot
Add lawful basis for
processing data
Segment list into
Customers, Partners &
Prospects. Add basis for
processing data
properties
In Progress
Hubspot
Add ‘User Data for
Advertising’ Subscription
Enable optin for using
data for third party data
processing
(Facebook/Google)
Done.
Hubspot
Cookie Notice on
Hubspot hosted pages
Ask for dev help on
consent status & cookie
removal
Pending
GDPR Compliance Summary
Systems Item Next Steps Status
Salesforce - - -
Google Analytics Delete user data
Feature rolling out May
25th
In Progress
Facebook
Add Privacy Policy to
Facebook Lead Ads
Update privacy policy to
include data usage.
Pending
Facebook
Custom Audience
Consent
Only create custom
audiences from contacts
who have expressly
offered consent.
In Progress
Third Party Vendors
Ensure all third party
vendors are GDPR
Complaint
CPL Vendors need to
mention Hubdoc. RevGen
needs to follow any opt-
out requests
In Progress.
GDPR Compliance Summary
General Data Protection Regulation for Ops

Más contenido relacionado

La actualidad más candente

Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 

La actualidad más candente (17)

General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
Privacy Access Letter I Feb 5 07
Privacy Access Letter I   Feb 5 07Privacy Access Letter I   Feb 5 07
Privacy Access Letter I Feb 5 07
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 

Similar a General Data Protection Regulation for Ops

Similar a General Data Protection Regulation for Ops (20)

GDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to KnowGDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to Know
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
Treasure Data Marketers Guide to GDPR (Global Data Protection Regulation)
Treasure Data Marketers Guide to GDPR (Global Data Protection Regulation)Treasure Data Marketers Guide to GDPR (Global Data Protection Regulation)
Treasure Data Marketers Guide to GDPR (Global Data Protection Regulation)
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPR
 
GDPR 
- The Do’s and Don'ts for Marketeers
GDPR 
- The Do’s and Don'ts for Marketeers GDPR 
- The Do’s and Don'ts for Marketeers
GDPR 
- The Do’s and Don'ts for Marketeers
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist Whitepaper
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPR
 
GDPR - What You Need To Know
GDPR - What You Need To KnowGDPR - What You Need To Know
GDPR - What You Need To Know
 
Gdpr zilla
Gdpr zillaGdpr zilla
Gdpr zilla
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policy
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 

Último

Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
DigiMarCon - Digital Marketing, Media and Advertising Conferences & Exhibitions
 
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
dollysharma2066
 

Último (20)

Situation Analysis | Management Company.
Situation Analysis | Management Company.Situation Analysis | Management Company.
Situation Analysis | Management Company.
 
Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
Riding the Wave of AI Disruption - Navigating the AI Fear Cycle in Marketing ...
 
Generative AI Content Creation - Andrew Jenkins
Generative AI Content Creation - Andrew JenkinsGenerative AI Content Creation - Andrew Jenkins
Generative AI Content Creation - Andrew Jenkins
 
Pillar-Based Marketing Master Class - Ryan Brock
Pillar-Based Marketing Master Class - Ryan BrockPillar-Based Marketing Master Class - Ryan Brock
Pillar-Based Marketing Master Class - Ryan Brock
 
BDSM⚡Call Girls in Sector 150 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 150 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 150 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 150 Noida Escorts >༒8448380779 Escort Service
 
A.I. and The Social Media Shift - Mohit Rajhans
A.I. and The Social Media Shift - Mohit RajhansA.I. and The Social Media Shift - Mohit Rajhans
A.I. and The Social Media Shift - Mohit Rajhans
 
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 144 Noida Escorts >༒8448380779 Escort Service
 
Major SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain DigitalMajor SEO Trends in 2024 - Banyanbrain Digital
Major SEO Trends in 2024 - Banyanbrain Digital
 
personal branding kit for music business
personal branding kit for music businesspersonal branding kit for music business
personal branding kit for music business
 
Foundation First - Why Your Website and Content Matters - David Pisarek
Foundation First - Why Your Website and Content Matters - David PisarekFoundation First - Why Your Website and Content Matters - David Pisarek
Foundation First - Why Your Website and Content Matters - David Pisarek
 
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
Five Essential Tools for International SEO - Natalia Witczyk - SearchNorwich 15
 
Navigating the SEO of Tomorrow, Competitive Benchmarking, China as an e-Comme...
Navigating the SEO of Tomorrow, Competitive Benchmarking, China as an e-Comme...Navigating the SEO of Tomorrow, Competitive Benchmarking, China as an e-Comme...
Navigating the SEO of Tomorrow, Competitive Benchmarking, China as an e-Comme...
 
Unraveling the Mystery of the Hinterkaifeck Murders.pptx
Unraveling the Mystery of the Hinterkaifeck Murders.pptxUnraveling the Mystery of the Hinterkaifeck Murders.pptx
Unraveling the Mystery of the Hinterkaifeck Murders.pptx
 
The Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdfThe Science of Landing Page Messaging.pdf
The Science of Landing Page Messaging.pdf
 
How to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail SuccessHow to Leverage Behavioral Science Insights for Direct Mail Success
How to Leverage Behavioral Science Insights for Direct Mail Success
 
Turn Digital Reputation Threats into Offense Tactics - Daniel Lemin
Turn Digital Reputation Threats into Offense Tactics - Daniel LeminTurn Digital Reputation Threats into Offense Tactics - Daniel Lemin
Turn Digital Reputation Threats into Offense Tactics - Daniel Lemin
 
Kraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentationKraft Mac and Cheese campaign presentation
Kraft Mac and Cheese campaign presentation
 
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu.Ka.Tilla Delhi Contact Us 8377877756
 
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 128 Noida Escorts >༒8448380779 Escort Service
 
Unlocking the Mystery of the Voynich Manuscript
Unlocking the Mystery of the Voynich ManuscriptUnlocking the Mystery of the Voynich Manuscript
Unlocking the Mystery of the Voynich Manuscript
 

General Data Protection Regulation for Ops

  • 1. How do we stay compliant to GDPR for EU citizens. GDPR Compliance May 22, 2018
  • 2. Background What GDPR means to us as a marketers
  • 3. What is the General Data Protection Regulatation? To process, collect, store & use personal information on EU citizens (UK), there are 6 legal grounds: a)Consent to receive communication b)Contract c)Legal obligation d)Vital interests e)Public interest f) Legitimate interests.
  • 4. Key Terms ➡ Data Processor: Tools Hubspot, Google Analytics, Facebook are data processors. All tools are rolling out features to support GDPR and data retention. ➡ Data Controller: Company - you control what we ask for on forms, e.g. phone numbers, emails and other personal identifiable information. ➡ Right to be forgotten: We have the ability to purge a users data if they ask us to do so. ➡ Consent: Explicit consent with clearly worded terms.
  • 6. Do we need to email our entire database? No. Previously gained consent is still valid when GDPR goes into effect. We do not need to email our entire database to regain consent.
  • 7. How do we get consent? 1. On forms, we have a checkbox that asks for consent to email & contact them via phone. 2. A checkbox to ask for consent to include their personal information in Facebook Custom Audiences 3. Cookie & tracking notification on the website, i.e. we use cookies & third party tracking tools like Google Analytics & Hubspot. 4. Direct Mail - Consent to use their mailing address for marketing purposes Consent must be provided freely and without using pre- checked boxes or assumed otherwise.
  • 8. 1. Cookie Consent Notice on the website - explicitly mention Facebook, Google Analytics in the text. Links to privacy policy to learn more about how Hudoc & third party vendors (Facebook, Google) use personal data. 2. Point users to blockers like Ghostery or Incognito mode if they want to avoid being being tracked. 3. Align any third party CPL Vendors & Rev Gen on GDPR compliance: Ensure they have mentioned Hubdoc as the data processor & ask for consent on forms & have the ability to delete all associated information How do we put this in practice? Next Steps
  • 10. What if we don’t have a record of previous consent? We can cite Article 6, including Section B, F and Recital 47 as basis for retaining & processing personal data & using it for business/marketing communication.
  • 11. What counts as a legitimate interest? “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. “ - Article 6 As a business, it’s a legitimate interest to pursue profit & create jobs. However this needs to be balanced with the individual rights. Individuals must be given a way to opt-out and have their information removed or appended.
  • 13. Data Management: Prospects are be able to: ● Opt-out of any marketing communications ● Request their information be deleted (right to be forgotten) ● Append any data the company has on them. ● Request a copy of all data & be able to review it.
  • 14. Systems & Process 1. Create a privacy@companyname email to process all data requests & send copies of marketing emails to as an audit record. 2. Enabled GDPR features in Hubspot. This helps us: ○ Add GDPR consent to all Forms ○ Create subscription types to enable users to opt-in to specific communications ■ Email ■ Third Party Advertising ■ Data Processing ○ Delete contacts & all associated data ○ Track consent with new ‘Legal Basis for processing contact data 3. Google Analytics is rolling out ability to remove cookie & data and auto deletion tools.
  • 15. Summary & Next Steps
  • 16. Systems Item Next Steps Status Hubspot Enabled GDPR Features Remove old consent checkboxes from forms. Add GDPR Compliance fields to forms. In Progress Hubspot Add lawful basis for processing data Segment list into Customers, Partners & Prospects. Add basis for processing data properties In Progress Hubspot Add ‘User Data for Advertising’ Subscription Enable optin for using data for third party data processing (Facebook/Google) Done. Hubspot Cookie Notice on Hubspot hosted pages Ask for dev help on consent status & cookie removal Pending GDPR Compliance Summary
  • 17. Systems Item Next Steps Status Salesforce - - - Google Analytics Delete user data Feature rolling out May 25th In Progress Facebook Add Privacy Policy to Facebook Lead Ads Update privacy policy to include data usage. Pending Facebook Custom Audience Consent Only create custom audiences from contacts who have expressly offered consent. In Progress Third Party Vendors Ensure all third party vendors are GDPR Complaint CPL Vendors need to mention Hubdoc. RevGen needs to follow any opt- out requests In Progress. GDPR Compliance Summary