Data protection marketing.

On 25 May 2018, a new era in data protection marketing began. This was the date that new rules came into effect in respect of collecting, storing and handling personal data.
Under the General Data Protection Regulation (GDPR), organisations need to keep transparent records of how (and when) an individual gives consent to store and use personal data.
Built-in, not bolted on
This wasn't just an evolution of the Data Protection Act – it ushered in wider implications for the way that companies operate. It ensures that data is protected by design and default at an intrinsic level.
Organisations need to know exactly what personal data they hold and where it is located (on PCs, servers or in the cloud). They must also have procedures in place to remove data permanently when an EU citizen requests that.
Why the change?
Put simply, we moved on.
The previous Data Protection Act dated from the 1990s, when only the largest companies had the means to collect and store significant amounts of data. Times have changed and the digital revolution is upon us. Thousands of SMEs now routinely access and store data about their customers.
As many of our clients are SMEs, we figured it would be useful to outline some key points about the regulations. You have better things to do than read the official documents that are 200+ pages thick with details!
What does GDPR mean for your data protection marketing?
You will need to use simple language when asking for consent to collect data.
You must explain clearly to your customers what you intend to do with their information.
You’ll also need to have the functionality in place to respond to requests to delete data. In the future, all software will need to be capable of erasing data, rather than suppressing it.
Quite a challenge.
What changed in terms of data protection marketing?
The world of data collection changed.
Huge amounts of digital information are collected, exchanged and used every second around the globe. The GDPR includes, for the first time, things such as genetic, mental, cultural, economic or social information that can be used to identify an individual.
It doesn’t matter where your business is based – since 25 May 2018, if you’re processing data about someone in the EU, you need to follow the rules. Data protection marketing is serious business, and nobody is exempt.
We’re all familiar with the small print on marketing materials. Things like the pre-ticked boxes that imply consent unless customers choose to opt-out.
Under the new rules, individuals have to actively give consent, which means they have to tick the box, you can't pre-complete it.
And they can also withdraw their consent at any time. When this happens, their details must be permanently erased – not just deleted from mailing lists. It’s the right to be forgotten.
What effect does Brexit have on GDPR?
At the moment, we don't know the answer to that question.
Until we're informed otherwise, the GDPR is still in full force and effect all of us in business have to comply with it.
If that changes on January 01 2021, we'll update this article.
What happens in the event of proven non-compliance?
The penalty for breaching these regulations is eye-watering.
Serious violations will set you back up to £17 million or 4% of your annual global turnover, whichever is higher.
Here in the UK, the Information Commissioner’s Office (ICO) will enforce the GDPR. It’s worth following their updates.
Their intention isn’t to make early examples of organisations for minor infringements or to threaten big fines. There are other sanctions that they’ll use in cases of non-compliance, such as reprimands, warnings, and corrective orders. As a result, it’s your reputation rather than your bank account that’s more likely to suffer.
Let’s end on a positive note: You’re very likely to already comply with the terms of the Data Protection Act.
If your website stores information about your customers, it’s a good idea to get in touch for an audit so we can help you identify the changes – if any – you might need to put in place.