SlideShare una empresa de Scribd logo
1 de 29
Practical
recommendations
for holiday rental
owners
to prepare for
GDPR
ORGANISED BY
Practical recommendations for holiday
rental owners to prepare for GDPR
Speaker:
Nicola Erlich
Holiday Rental Industry Analyst
Host:
Amelia Sutton
Marketing
Disclaimer
This session provides general information and comments for
holiday rental home owners and rental managers on their
obligations under GDPR and recommendations for moving
towards GDPR compliance.
It is not intended to be a comprehensive description of GDPR
and does not constitute official legal advice which should be
sought before drawing any conclusions on your particular
circumstances.
The biggest change to our data protection laws in 20 years. Are you ready?
Deadline: 25th May 2018
Overview
This webinar will cover:
- What is GDPR
- GDPR – the myths, the responsibilities and the
opportunities
- GDPR and the Holiday Rental Industry
- Practical recommendations for becoming GDPR-
compliant
What is
GDPR?
General Data Protection Regulation
Europe’s new data protection laws, replacing the
previous 1995 data protection directive.
Comes into effect on 25th May 2018.
New law applies if:
◦ Establishment is in the EU
◦ Offers goods/services to EU residents
◦ Customer is located in the EU
◦ Web visits from users located in the EU
Holds businesses more accountable for the data
they hold.
Greater protection and rights to individuals.
Personal data definition expanded.
Evolution not
Revolution!
Your business should already
have a pretty robust system
in place regarding data
protection, usage and
security practices so you will
not be starting from zero.
Improving on the existing
foundation of good practices
is a positive step in building
trust with your customers.
GDPR & the Travel
Industry
The travel industry will be particularly affected
by GDPR due to the everyday use of personal
data.
Examples of personal data in the travel industry:
• Bookings and reservation data,
• Existing customer lists and
• Correspondence with customers.
Also it is the most targeted industry for
cyberattacks so tight security measures &
breach procedures are crucial.
GDPR - Separating Fact from Fiction
• Regulators have corrective powers
• Can issue a reprimand or corrective order
High risk of
penalties
• No special skills/knowledge/tools needed
• Improving on your existing good practices
Time consuming
& costly
• An opportunity to offer a personalised service
• Target customers who want your services
Direct marketing
is dead
GDPR & Holiday Rentals:
5 Key Areas
Part 1:
Controller v Processor
Who is responsible for
what?
1
Part 2:
Personal Data
What is it, and how to
manage it?
2
Part 3:
Individual Rights
What new rights do
people now have?
3
Part 4:
Consent & Privacy
How to get permission
to use people’s data.
4
Part 5:
Roadmap
What steps must you
take to comply?
5
What you need to know about GDPR, with industry specific examples for your holiday rental
business.
Part 1:
Data Controller
& Processor
Data Controller
A controller is an entity that decides the
purpose and manner that personal data is
used.
Processor
The person/group that processes the data on
behalf of the controller. Processing is
obtaining, recording, using and storing
personal data.
Not everyone that handles the personal data of individuals is the
same.
The data protection law has defined two types of people that
handle personal data: controller and processor.
Part 1:
Personal Data Flow Chart
Third Parties
Processor
Data Controller Holiday Rental Website
Home Owner
Rental
Manager
Legal Others
Rental Manager
Legal Others
Part 2:
Personal Data
ID / Passport details:
name, address, race,
origin, biometric data
Contact information:
email address,
telephone number
Sensitive data:
financial and
payment information
“Personal Data” means any information relating to a person that enables them to be
identified directly or indirectly.
This includes sensitive data such as payment information.
COLLECT – STORE – USE – SHARE DATA? You have to abide by the rules.
From a travel industry aspect, personal data could include the following types and sources of
information:
Part 3:
Individual Rights
Right to be informed
Individuals need to
be informed when
you collect or
process their data.
Right to be forgotten
Individuals can ask to
have all their data
deleted from your
records.
Right to access
Individuals can now
ask for access to
their data, and why
you are processing it.
Part 4:
Consent &
Privacy
Consent is the permission given by individuals to allow you
to process personal data.
What data do you need to provide service to your
customers?
How do you get their consent to use their data?
All personal data must be:
• Freely given,
• Specific,
• Informed, and
• Unambiguous
Sensitive personal data must have:
• Explicit consent
Part 5:
Roadmap to
GDPR-
compliance
Part 5:
Roadmap to GDPR-compliance
Audit
Review what
personal data is
held and why.
1
Review privacy
policy
Be transparent &
specific in your
data usage.
2
Establish
legitimate basis
Lawful basis to use
personal data
without consent.
3
Get consent
Users must give
opt-in consent.
4
Security
Review hardware,
software &
procedures.
5
Report breaches
Plan of action for
security breaches
6
Part 5.1:
Roadmap – Data Audit
Part 5.2:
Roadmap –
Privacy Policies
Customer privacy is at the heart of GDPR so must be at the
heart of your data protection policies
Update privacy policies:
• Easy to find online
• Clear and precise language
• Transparency on how personal data is:
• Obtained
• Controlled and used
• Retained for ongoing purposes
• Securely storage
Part 5.3:
Roadmap –
Legitimate legal
basis
Three ways you are allowed to use data
1. Contractual Data
Online travel bookings:
◦ are a contract
◦ a legitimate legal basis to use personal data
◦ NO consent required to carry out the task of making the
booking
◦ direct marketing considered a possible “legitimate
interest”
2. Legitimate Interests
• Legal obligations – passport details
• Fiscal obligations
• Protection against fraud
3. Explicit Consent
Part 5.4:
Roadmap –
Obtaining
consent
GDPR wants you to think about privacy and data protection
from the beginning, not just as an after-thought. This is
“Privacy By Design”
• Limited Data
Only collect what is necessary.
• Data Assessment
Keep checking the confidentiality of your systems.
• Limit Processing
Only use data for the purpose it was collected for.
• Record Keeping
Use good practices to record the data you have, how you
obtained it, how you used it and how you store it.
Part 5.4:
Consent –
Soft Opt-In
***IMPORTANT !! ***
There is a way to continue to use personal data (for
marketing) without legitimate legal basis or explicit
consent.
Privacy & Electronic Communications Regulations (PECR)
- Email and text marketing ONLY
- Allows for opt-OUT instead of opt-IN consent under GDPR
- Assumes interest in similar goods or services provided.
- PECR is currently under review so position may change.
Advice by Farina Azam, partner at Travlaw
Part 5.5:
Roadmap – Security
The threat is real. Data breaches are happening all the time.
The sensitive personal data and credit card information,
collected and shared makes the Travel Industry one of the
most vulnerable to data breaches.
Big travel brands have the resources and funds to protect
themselves against cyber threats.
Smaller businesses, such as holiday rental owners, are the
low hanging fruit – the easy targets – for hackers.
The tourism industry accounted for the largest number of
cyber attacks in 2016.
Part 5.5:
Roadmap-
Security
Where do you keep customer personal and sensitive data?
What online security do you have in place? Is it secure?
Areas to review:
• Hardware & software vulnerabilities
• Use encryption:
• Communications
• Cloud storage
• System passwords security
• Malware protection
Part 5.6:
Roadmap –
Breaches
In the case of a data breach, i.e. hacking, you must report
within 72 hours to:
- the relevant authorities;
- your affected customers.
Opportunities
The focus is usually
on the negatives of
non-compliance, but
there are a lot of
positives businesses
should take
advantage of.
Key Takeaways
Start now. Don’t wait until 25th May
Focus on these simple steps as priority to improving your business
procedures:
1. Audit – Start with an audit to get an overview of your current
procedures
2. Consent – Make the changes moving forward to getting opt-in
consent.
3. Security – Protect your business and the data you hold with good
security practices
Your clients, and the GDPR regulators, want to see that you are trying to
implement GDPR.
Trust is the cornerstone of good business practice.
Useful
Contacts
We don’t claim to have all the answers. In between a lot
of GDPR hype there are some incredibly useful resources
that have been published on the regulation. Here’s where
to go if you’re looking for more in-depth reading:
- The full regulation. It’s 88 pages long and has 99 articles.
- The ICO’s guide to GDPR has lots of useful tools and
information for small businesses.
- ICO Small Business Helpline: +44 0303 123 1113 Ext.4
- EU GDPR is the EU’s official website for the regulation.
Thank you
for
participating!
About Spain-Holiday.com
Spain-Holiday.com is the leading holiday rental platform offering
more than 15,000 quality holiday rental homes in Spain.
Their industry blog, RentalBuzz, provides the community of
holiday rental owners with the latest industry news, extensive
coverage on tourism laws in Spain, in-depth guides, travel trend
reports and useful tools.
Note: This document does not constitute official legal advice and we recommend that you consult with an expert
about your specific circumstances.

Más contenido relacionado

La actualidad más candente

General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsChris Doolittle
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Frank Dawson
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality Susan Moran
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics toolsRominaMariaBaltariu
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRImogenRutherford
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...Ardoq
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non expertsClaudio Bolla, CISM
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceIDERA Software
 

La actualidad más candente (20)

General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
GDPR Workshop
GDPR WorkshopGDPR Workshop
GDPR Workshop
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Data protection
Data protectionData protection
Data protection
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 

Similar a GDPR & the Travel Industry: Practical recommendations for holiday rental owners

A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPRNeha Patel
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPRMarketo
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issuesJagdeepSingh394
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolutionDan Brookman
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPRNate Stockard
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR PresentationLuke Kyte
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoDaniel Smith
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceSarah Fox
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-smIBM Sverige
 

Similar a GDPR & the Travel Industry: Practical recommendations for holiday rental owners (20)

GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Understanding & Working with the GDPR
Understanding & Working with the GDPRUnderstanding & Working with the GDPR
Understanding & Working with the GDPR
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolution
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 

Último

Top places to visit, top tourist destinations
Top places to visit, top tourist destinationsTop places to visit, top tourist destinations
Top places to visit, top tourist destinationsswarajdm34
 
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...mountabuangels4u
 
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelSiliguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelJalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelRudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
sample sample sample sample sample sample
sample sample sample sample sample samplesample sample sample sample sample sample
sample sample sample sample sample sampleCasey Keith
 
abortion pills in Riyadh+966572737505 Cytotec Riyadh
abortion pills in  Riyadh+966572737505    Cytotec Riyadhabortion pills in  Riyadh+966572737505    Cytotec Riyadh
abortion pills in Riyadh+966572737505 Cytotec Riyadhsamsungultra782445
 
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot ModelPithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
sample sample sample sample sample sample
sample sample sample sample sample samplesample sample sample sample sample sample
sample sample sample sample sample sampleCasey Keith
 
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot ModelChampawat Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNainital Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...samsungultra782445
 
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot GirlsDaman Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot GirlsDeepika Singh
 
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot ModelHowrah Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girls
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent GirlsMorbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girls
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girlsmountabuangels4u
 
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptx
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptxElevate Your Busy Season Email Marketing, Holly May Webinar.pptx
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptxRezStream
 
Top travel agency in panchkula - Best travel agents in panchkula
Top  travel agency in panchkula - Best travel agents in panchkulaTop  travel agency in panchkula - Best travel agents in panchkula
Top travel agency in panchkula - Best travel agents in panchkulauseyourbrain1122
 
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelPaschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot ModelTehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 

Último (20)

Top places to visit, top tourist destinations
Top places to visit, top tourist destinationsTop places to visit, top tourist destinations
Top places to visit, top tourist destinations
 
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...
Bhavnagar Escort💋 Call Girl (Komal) Service #Bhavnagar Call Girl @Independent...
 
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelSiliguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Siliguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot ModelJalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Jalpaiguri Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelRudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Rudrapur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
sample sample sample sample sample sample
sample sample sample sample sample samplesample sample sample sample sample sample
sample sample sample sample sample sample
 
abortion pills in Riyadh+966572737505 Cytotec Riyadh
abortion pills in  Riyadh+966572737505    Cytotec Riyadhabortion pills in  Riyadh+966572737505    Cytotec Riyadh
abortion pills in Riyadh+966572737505 Cytotec Riyadh
 
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot ModelPithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Pithoragarh Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
sample sample sample sample sample sample
sample sample sample sample sample samplesample sample sample sample sample sample
sample sample sample sample sample sample
 
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot ModelChampawat Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Champawat Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNainital Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Nainital Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...
Abortion pills in Jeddah +966572737505 <> buy cytotec <> unwanted kit Saudi A...
 
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot GirlsDaman Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
Daman Escorts 🥰 8617370543 Call Girls Offer VIP Hot Girls
 
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Dimapur‎ Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot ModelHowrah Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Howrah Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girls
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent GirlsMorbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girls
Morbi Escort💋 Call Girl (Komal) Service #Morbi Call Girl @Independent Girls
 
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptx
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptxElevate Your Busy Season Email Marketing, Holly May Webinar.pptx
Elevate Your Busy Season Email Marketing, Holly May Webinar.pptx
 
Top travel agency in panchkula - Best travel agents in panchkula
Top  travel agency in panchkula - Best travel agents in panchkulaTop  travel agency in panchkula - Best travel agents in panchkula
Top travel agency in panchkula - Best travel agents in panchkula
 
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot ModelPaschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Paschim Medinipur Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot ModelTehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Tehri Garhwal Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 

GDPR & the Travel Industry: Practical recommendations for holiday rental owners

  • 2. Practical recommendations for holiday rental owners to prepare for GDPR Speaker: Nicola Erlich Holiday Rental Industry Analyst Host: Amelia Sutton Marketing
  • 3. Disclaimer This session provides general information and comments for holiday rental home owners and rental managers on their obligations under GDPR and recommendations for moving towards GDPR compliance. It is not intended to be a comprehensive description of GDPR and does not constitute official legal advice which should be sought before drawing any conclusions on your particular circumstances.
  • 4. The biggest change to our data protection laws in 20 years. Are you ready? Deadline: 25th May 2018
  • 5. Overview This webinar will cover: - What is GDPR - GDPR – the myths, the responsibilities and the opportunities - GDPR and the Holiday Rental Industry - Practical recommendations for becoming GDPR- compliant
  • 6. What is GDPR? General Data Protection Regulation Europe’s new data protection laws, replacing the previous 1995 data protection directive. Comes into effect on 25th May 2018. New law applies if: ◦ Establishment is in the EU ◦ Offers goods/services to EU residents ◦ Customer is located in the EU ◦ Web visits from users located in the EU Holds businesses more accountable for the data they hold. Greater protection and rights to individuals. Personal data definition expanded.
  • 7. Evolution not Revolution! Your business should already have a pretty robust system in place regarding data protection, usage and security practices so you will not be starting from zero. Improving on the existing foundation of good practices is a positive step in building trust with your customers.
  • 8. GDPR & the Travel Industry The travel industry will be particularly affected by GDPR due to the everyday use of personal data. Examples of personal data in the travel industry: • Bookings and reservation data, • Existing customer lists and • Correspondence with customers. Also it is the most targeted industry for cyberattacks so tight security measures & breach procedures are crucial.
  • 9. GDPR - Separating Fact from Fiction • Regulators have corrective powers • Can issue a reprimand or corrective order High risk of penalties • No special skills/knowledge/tools needed • Improving on your existing good practices Time consuming & costly • An opportunity to offer a personalised service • Target customers who want your services Direct marketing is dead
  • 10. GDPR & Holiday Rentals: 5 Key Areas Part 1: Controller v Processor Who is responsible for what? 1 Part 2: Personal Data What is it, and how to manage it? 2 Part 3: Individual Rights What new rights do people now have? 3 Part 4: Consent & Privacy How to get permission to use people’s data. 4 Part 5: Roadmap What steps must you take to comply? 5 What you need to know about GDPR, with industry specific examples for your holiday rental business.
  • 11. Part 1: Data Controller & Processor Data Controller A controller is an entity that decides the purpose and manner that personal data is used. Processor The person/group that processes the data on behalf of the controller. Processing is obtaining, recording, using and storing personal data. Not everyone that handles the personal data of individuals is the same. The data protection law has defined two types of people that handle personal data: controller and processor.
  • 12. Part 1: Personal Data Flow Chart Third Parties Processor Data Controller Holiday Rental Website Home Owner Rental Manager Legal Others Rental Manager Legal Others
  • 13. Part 2: Personal Data ID / Passport details: name, address, race, origin, biometric data Contact information: email address, telephone number Sensitive data: financial and payment information “Personal Data” means any information relating to a person that enables them to be identified directly or indirectly. This includes sensitive data such as payment information. COLLECT – STORE – USE – SHARE DATA? You have to abide by the rules. From a travel industry aspect, personal data could include the following types and sources of information:
  • 14. Part 3: Individual Rights Right to be informed Individuals need to be informed when you collect or process their data. Right to be forgotten Individuals can ask to have all their data deleted from your records. Right to access Individuals can now ask for access to their data, and why you are processing it.
  • 15. Part 4: Consent & Privacy Consent is the permission given by individuals to allow you to process personal data. What data do you need to provide service to your customers? How do you get their consent to use their data? All personal data must be: • Freely given, • Specific, • Informed, and • Unambiguous Sensitive personal data must have: • Explicit consent
  • 17. Part 5: Roadmap to GDPR-compliance Audit Review what personal data is held and why. 1 Review privacy policy Be transparent & specific in your data usage. 2 Establish legitimate basis Lawful basis to use personal data without consent. 3 Get consent Users must give opt-in consent. 4 Security Review hardware, software & procedures. 5 Report breaches Plan of action for security breaches 6
  • 18. Part 5.1: Roadmap – Data Audit
  • 19. Part 5.2: Roadmap – Privacy Policies Customer privacy is at the heart of GDPR so must be at the heart of your data protection policies Update privacy policies: • Easy to find online • Clear and precise language • Transparency on how personal data is: • Obtained • Controlled and used • Retained for ongoing purposes • Securely storage
  • 20. Part 5.3: Roadmap – Legitimate legal basis Three ways you are allowed to use data 1. Contractual Data Online travel bookings: ◦ are a contract ◦ a legitimate legal basis to use personal data ◦ NO consent required to carry out the task of making the booking ◦ direct marketing considered a possible “legitimate interest” 2. Legitimate Interests • Legal obligations – passport details • Fiscal obligations • Protection against fraud 3. Explicit Consent
  • 21. Part 5.4: Roadmap – Obtaining consent GDPR wants you to think about privacy and data protection from the beginning, not just as an after-thought. This is “Privacy By Design” • Limited Data Only collect what is necessary. • Data Assessment Keep checking the confidentiality of your systems. • Limit Processing Only use data for the purpose it was collected for. • Record Keeping Use good practices to record the data you have, how you obtained it, how you used it and how you store it.
  • 22. Part 5.4: Consent – Soft Opt-In ***IMPORTANT !! *** There is a way to continue to use personal data (for marketing) without legitimate legal basis or explicit consent. Privacy & Electronic Communications Regulations (PECR) - Email and text marketing ONLY - Allows for opt-OUT instead of opt-IN consent under GDPR - Assumes interest in similar goods or services provided. - PECR is currently under review so position may change. Advice by Farina Azam, partner at Travlaw
  • 23. Part 5.5: Roadmap – Security The threat is real. Data breaches are happening all the time. The sensitive personal data and credit card information, collected and shared makes the Travel Industry one of the most vulnerable to data breaches. Big travel brands have the resources and funds to protect themselves against cyber threats. Smaller businesses, such as holiday rental owners, are the low hanging fruit – the easy targets – for hackers. The tourism industry accounted for the largest number of cyber attacks in 2016.
  • 24. Part 5.5: Roadmap- Security Where do you keep customer personal and sensitive data? What online security do you have in place? Is it secure? Areas to review: • Hardware & software vulnerabilities • Use encryption: • Communications • Cloud storage • System passwords security • Malware protection
  • 25. Part 5.6: Roadmap – Breaches In the case of a data breach, i.e. hacking, you must report within 72 hours to: - the relevant authorities; - your affected customers.
  • 26. Opportunities The focus is usually on the negatives of non-compliance, but there are a lot of positives businesses should take advantage of.
  • 27. Key Takeaways Start now. Don’t wait until 25th May Focus on these simple steps as priority to improving your business procedures: 1. Audit – Start with an audit to get an overview of your current procedures 2. Consent – Make the changes moving forward to getting opt-in consent. 3. Security – Protect your business and the data you hold with good security practices Your clients, and the GDPR regulators, want to see that you are trying to implement GDPR. Trust is the cornerstone of good business practice.
  • 28. Useful Contacts We don’t claim to have all the answers. In between a lot of GDPR hype there are some incredibly useful resources that have been published on the regulation. Here’s where to go if you’re looking for more in-depth reading: - The full regulation. It’s 88 pages long and has 99 articles. - The ICO’s guide to GDPR has lots of useful tools and information for small businesses. - ICO Small Business Helpline: +44 0303 123 1113 Ext.4 - EU GDPR is the EU’s official website for the regulation.
  • 29. Thank you for participating! About Spain-Holiday.com Spain-Holiday.com is the leading holiday rental platform offering more than 15,000 quality holiday rental homes in Spain. Their industry blog, RentalBuzz, provides the community of holiday rental owners with the latest industry news, extensive coverage on tourism laws in Spain, in-depth guides, travel trend reports and useful tools. Note: This document does not constitute official legal advice and we recommend that you consult with an expert about your specific circumstances.