SlideShare una empresa de Scribd logo
1 de 22
Taking the Fear Out of GDPR
- What It Means for US Companies
Nate Stockard
President – Blue Atlas Marketing
Started:
May 25, 2018
When?
Unified rules
for all EU countries
What?
GDPR Definition
GDPR
European Union
General Data
Protection
Regulation
Protection
Protect personal data
& strengthen privacy
rights of EU individuals
Control
Give users control
over their data
Goals of EU’s General Data Protection Regulation
GOALS
Protection
• Lawfulness, Fairness, and Transparency
• Purpose Limitation
• Data Minimization
Principles of EU’s General Data Protection Regulation
Control
• Accuracy
• Storage Limitation
• Integrity and Confidentiality
• Accountability (as controller)
PRINCIPLES
Stakeholders of GDPR
An individual person, resident
of European Union countries,
the subject of the personal
data.
Data Subject
Subject (company, institution…)
processing a data on behalf
of the controller e.g. Google,
Facebook, CRM app…
Data Processor
Person appointed by the Data
Controller responsible for
overseeing data protection
practices.
Data Protection Officer
Public institution monitoring
implementation of the
regulations in the specific EU
member country.
Data Authority
Institution, business or a person
processing the personal data
e.g. e-commerce website.
Data Controller
Who is affected by GDPR?
All businesses
collecting or
holding personal
data on EU citizens.
No matter where
they reside!
3 Question Test – Does GDPR Apply To You?
Do you offer goods or services to someone who
lives in Europe?
Even U.S.-based, but offer goods/ services to EU resident… 1
Does your company use predictive analytics or other
“monitoring” of individuals in your marketing?
EU Residents could fall within your data, resulting in compliance needs… 2
Does your company have any U.S. citizen expats living abroad?
The regulation applies to your company if your company employs people living in
the EU. 3
Name
Address
Phone
Bank / Credit cards
Email address
IP address
Cookies
Online identifiers
Data to identify someone
PersonalData
Biometric data
Genetic data
Health data
Sex life, sexual orientation
The List Goes On!
SensitiveData
Types of Personal & Private Data
GDPR – Individual User Point of View
For individual: must be ensured
Getting consent to process personal data
Right to be forgotten
Right to modify personal data
Transparency - right for get information
what data are collected, how data are going to be used
(where stored, who will have access)
Can request data in portable format
GDPR – Regulator Point of View
For Regulators: have the ability to
Ask for records
Processing and Proof of Compliance
Impose temporary bans, data notifications, or order
erasure of data
Suspend cross-border data flows
Enforce penalties and fines
Breaking GDPR Penalties & Fines
If your data is breached:
GDPR
FINES
You must
report it within
72
hours
OR
Face a fine up to
20M € or 4%
global turnover
GDPR – Is There A US Equivalent Coming?
Chairman of Information Technology Subcommittee says
could be possibility with changes (Rep. Will Hurd R-TX)
White House Says Looking Forward to Working With
Congress on Data Privacy Issues
California Passes AB375 in 2018 -> Mirrors GDPR
What Do We Do About It?
-Why Does This Matter To Marketers?
Data Collection – Think About It Differently
You have to ask for permission:
No more checked boxes
User must Opt-in (and Double Opt-in to be safe)
Only ask for pertinent data for this step
Transparency
- Terms & Conditions, Privacy Policy, GDPR FAQ
Data Storage that can be accessed by Officer
Form Example
GDPR – Company (Data Controller) View
Controller - Company processing data of EU users
Check Data Processors
Appointing DPO = Data Protection Officer
Audit data usage (what is collected, where stored…)
Monitoring data breach
72 hours to report data breach
Update Your Privacy Policy
If/How your use cookies and social media data
Remarketing, pixels, etc. 1
How data is obtained, where you got it, third-party usage
Who has access, where is shared, and so on 2
Storage timeframe
How long you store it, for what purpose
3
Opt-in, opt-out, and no obligation
How do they opt-out, they aren’t obligated to opt-in 4
Review your CRM
Your CRM has to do more:
Record how/when data was captured
Duration to be kept on file (or process to clean)
Any criteria used to purchase the list
Easy Export for Data Protection Officer
Rebuild the database and have them
opt-in again. Offer something in return
to get them to opt-in again for your
marketing
Re-Opt-In
Communication
Use all communication channels to
share your updates and compliance
actions.
Multiple Channels
Explain the actions taken and effective
dates of the changes
Effective Dates
Include the updated privacy policy or
pertinent documentation to help the
user understand their rights and what
you are doing to be compliant
Distribute the Privacy Policy
Online Tools & Apps related to GDPR
Mail collection & Mailing
• Double opt-ins
• Agreement boxes
not pre-checked
• Clear data consent
& usage statement
• Unsubscribe option
Cookie Control Banner
• Use WordPress and
other plugins
Privacy Policies
• Consult with lawyer
• Buy Templates
GDPR Tools & Applications
Data Processors
(e.g. CRM, Cloud
storage)
• See Their GDPR
statements &
features
GDPR Checklist
Privacy and Security
• Update Privacy Policy and share
across multiple platforms
• Confirm SSL encryption is in place
• Establish a data breach plan of action
Technical
• Make changes to web form, data
collection activities
• Update your CRM with additional
tracking and info
• Ensure customer opt-outs are
expiring according to schedule
• Ensure cookies and pixels are
disclosed in Privacy Policy and online
• Talk to subject-matter experts about
data safety and protection in place
General
• Reach out to an attorney
• Communicate with your contacts
• Designate your company’s data
protection officer (DPO)
• Cooperate with Information
Commissioner’s Office should they
reach out
• Establish a team accountable for
web, social, email, and marketing
updates
What Next?
1) Download Guide at blueatlasmarketing.com/GDPR
2) Reach out to Nate with specific questions and
information needed: nate@blueatlasmarketing.com,
TW:@blueatlastweet, FB:/blueatlasmarketing
3) Get Compliant!!

Más contenido relacionado

La actualidad más candente

MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
Huub de Jong
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 

La actualidad más candente (20)

What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
GDPR: why your contracts need updating
GDPR: why your contracts need updatingGDPR: why your contracts need updating
GDPR: why your contracts need updating
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
 
GDPR
GDPRGDPR
GDPR
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
GDPR in a nutshell
GDPR in a nutshellGDPR in a nutshell
GDPR in a nutshell
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) DashboardGDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
 

Similar a Taking the Fear Out of GDPR

GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
Jim Wilson
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
Spain-Holiday.com
 

Similar a Taking the Fear Out of GDPR (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance Primer
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 

Último

FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
dollysharma2066
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
dlhescort
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 

Último (20)

Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 

Taking the Fear Out of GDPR

  • 1. Taking the Fear Out of GDPR - What It Means for US Companies Nate Stockard President – Blue Atlas Marketing
  • 2. Started: May 25, 2018 When? Unified rules for all EU countries What? GDPR Definition GDPR European Union General Data Protection Regulation
  • 3. Protection Protect personal data & strengthen privacy rights of EU individuals Control Give users control over their data Goals of EU’s General Data Protection Regulation GOALS
  • 4. Protection • Lawfulness, Fairness, and Transparency • Purpose Limitation • Data Minimization Principles of EU’s General Data Protection Regulation Control • Accuracy • Storage Limitation • Integrity and Confidentiality • Accountability (as controller) PRINCIPLES
  • 5. Stakeholders of GDPR An individual person, resident of European Union countries, the subject of the personal data. Data Subject Subject (company, institution…) processing a data on behalf of the controller e.g. Google, Facebook, CRM app… Data Processor Person appointed by the Data Controller responsible for overseeing data protection practices. Data Protection Officer Public institution monitoring implementation of the regulations in the specific EU member country. Data Authority Institution, business or a person processing the personal data e.g. e-commerce website. Data Controller
  • 6. Who is affected by GDPR? All businesses collecting or holding personal data on EU citizens. No matter where they reside!
  • 7. 3 Question Test – Does GDPR Apply To You? Do you offer goods or services to someone who lives in Europe? Even U.S.-based, but offer goods/ services to EU resident… 1 Does your company use predictive analytics or other “monitoring” of individuals in your marketing? EU Residents could fall within your data, resulting in compliance needs… 2 Does your company have any U.S. citizen expats living abroad? The regulation applies to your company if your company employs people living in the EU. 3
  • 8. Name Address Phone Bank / Credit cards Email address IP address Cookies Online identifiers Data to identify someone PersonalData Biometric data Genetic data Health data Sex life, sexual orientation The List Goes On! SensitiveData Types of Personal & Private Data
  • 9. GDPR – Individual User Point of View For individual: must be ensured Getting consent to process personal data Right to be forgotten Right to modify personal data Transparency - right for get information what data are collected, how data are going to be used (where stored, who will have access) Can request data in portable format
  • 10. GDPR – Regulator Point of View For Regulators: have the ability to Ask for records Processing and Proof of Compliance Impose temporary bans, data notifications, or order erasure of data Suspend cross-border data flows Enforce penalties and fines
  • 11. Breaking GDPR Penalties & Fines If your data is breached: GDPR FINES You must report it within 72 hours OR Face a fine up to 20M € or 4% global turnover
  • 12. GDPR – Is There A US Equivalent Coming? Chairman of Information Technology Subcommittee says could be possibility with changes (Rep. Will Hurd R-TX) White House Says Looking Forward to Working With Congress on Data Privacy Issues California Passes AB375 in 2018 -> Mirrors GDPR
  • 13. What Do We Do About It? -Why Does This Matter To Marketers?
  • 14. Data Collection – Think About It Differently You have to ask for permission: No more checked boxes User must Opt-in (and Double Opt-in to be safe) Only ask for pertinent data for this step Transparency - Terms & Conditions, Privacy Policy, GDPR FAQ Data Storage that can be accessed by Officer
  • 16. GDPR – Company (Data Controller) View Controller - Company processing data of EU users Check Data Processors Appointing DPO = Data Protection Officer Audit data usage (what is collected, where stored…) Monitoring data breach 72 hours to report data breach
  • 17. Update Your Privacy Policy If/How your use cookies and social media data Remarketing, pixels, etc. 1 How data is obtained, where you got it, third-party usage Who has access, where is shared, and so on 2 Storage timeframe How long you store it, for what purpose 3 Opt-in, opt-out, and no obligation How do they opt-out, they aren’t obligated to opt-in 4
  • 18. Review your CRM Your CRM has to do more: Record how/when data was captured Duration to be kept on file (or process to clean) Any criteria used to purchase the list Easy Export for Data Protection Officer
  • 19. Rebuild the database and have them opt-in again. Offer something in return to get them to opt-in again for your marketing Re-Opt-In Communication Use all communication channels to share your updates and compliance actions. Multiple Channels Explain the actions taken and effective dates of the changes Effective Dates Include the updated privacy policy or pertinent documentation to help the user understand their rights and what you are doing to be compliant Distribute the Privacy Policy
  • 20. Online Tools & Apps related to GDPR Mail collection & Mailing • Double opt-ins • Agreement boxes not pre-checked • Clear data consent & usage statement • Unsubscribe option Cookie Control Banner • Use WordPress and other plugins Privacy Policies • Consult with lawyer • Buy Templates GDPR Tools & Applications Data Processors (e.g. CRM, Cloud storage) • See Their GDPR statements & features
  • 21. GDPR Checklist Privacy and Security • Update Privacy Policy and share across multiple platforms • Confirm SSL encryption is in place • Establish a data breach plan of action Technical • Make changes to web form, data collection activities • Update your CRM with additional tracking and info • Ensure customer opt-outs are expiring according to schedule • Ensure cookies and pixels are disclosed in Privacy Policy and online • Talk to subject-matter experts about data safety and protection in place General • Reach out to an attorney • Communicate with your contacts • Designate your company’s data protection officer (DPO) • Cooperate with Information Commissioner’s Office should they reach out • Establish a team accountable for web, social, email, and marketing updates
  • 22. What Next? 1) Download Guide at blueatlasmarketing.com/GDPR 2) Reach out to Nate with specific questions and information needed: nate@blueatlasmarketing.com, TW:@blueatlastweet, FB:/blueatlasmarketing 3) Get Compliant!!