What GDPR Could Mean to Your Online Business Activities

What GDPR Could Mean to Your Online Business Activities

Well, we made it. We got through all the scaremongering and the what ifs and maybes and we lived through the arrival, the official arrival of the General Data Protection Regulation (the GDPR as we will call it until it’s changed to GDPR-UK or whatever it becomes in the UK after Brexit).

Gosh that was a mouthful. It’s June. June 2018 and that means we no longer live in a transition period and we should all be compliant with GDPR now. Not sort of, not almost, not just starting, but all compliant. But is that the case? Not even close and the powers that be know it.

So let’s just look at what GDPR could mean to your online business activities because, although there’ll be lots of panic going on, it’s important that it is looked at in it’s simplest form;

All personal identifiable data (that’s data that can identify a person in the EU – and that includes the UK now and always will) you recieve must not be collected without permission; the data has to be kept private, secure and not shared without permission; only people who need to see the data can see it; you must get rid if you don’t really need it; you have to be transparent about how you will use it; the data subject can ask to see data what you’ve got about them and can request that you remove it if they don’t want you to have it.

That’s the main nutshell version. It applies to your customers, clients, employees, shareholders, managers, contractors, service providers (like your IT support people and accountants for example), agency workers, temp staff, etc.

It doesn’t matter if you are a one person business or a global company with thousands of staff, GDPR applies to you.

If you are a gardener, a window cleaner, a painter and decorator or a local handyman with a handful of customers written in your notepad, GDPR applies to you.

Data means any information that could be used to identify an EU citizen so a name and address, name and email address, phone number and home address, etc.

GDPR extends the Data Protection Act and is a huge step in the right direction

Taking over from a fairly unpoliced and unenforced Data Protection Act (DPA), the GDPR is a huge step in the right direction and it is pleasing to hear that GDPR is just one step with many to follow. We have to have our data protected and we, as individuals, should be entitled to have our data protected and the law to say it is our data not the property of businesses.

Online business activities that must comply with the General Data Protection Regulation

  • The hosting location of your website; is it in the EU or not? If it is outside the EU then you need to document where it is and do an assessment of the privacy in place at the hosting company.
  • How you recieve customer / client contact details should be documented; do you collect them through a form on a website, through social media, over the phone or in person? Do you explain to the data subject why you need the information and what you will use it for?
  • Where you store data that you receive; is it in an online database, is it in an office database, is it stored in hard copy (printed on paper).
  • How you protect, backup, store and use the data you collect.
    Who has access to your data, your computer and devices, your emails and social media messages (all of which may contain data that comes under GDPR)?
  • What do you do with data you can no longer justify keeping? Unless you can demonstrate legitimate reason for having the data, you need to delete it.
  • Privacy and cookies; you must have a privacy policy and cookie policy on your website and anyone giving you their contact details must have been told about them and asked to read them.
  • How you send out marketing material and who to; this is a big one because you can’t just willy nilly send out emails to people without permission. Despite all the spam we still get from people ignoring regulations, here in the EU we have laws and must comply with them.

In years to come we will look back on the day GDPR arrived as a hugely positive turning point in our individual data rights!

My writing:

I don’t write for the algorithms here. I write for you, the reader. So I am so grateful for your time. Thank you for reading.

Comments:

To keep this site free from spam, comments have been turned off. You are very welcome to contact me via my Facebook profile using the link in the footer.

About me…