The GDPR, General Data Protection Regulation, is a European regulation aimed at strengthening the protection of personal data. Personal data is data that directly or indirectly identifies a natural person. The new regulation will come into force from May 25th, 2018. From this date onwards, many players in the professional world will have to make some changes to the way they operate.
Who are these players? What changes need to be made? What impact will this have on digital communications? And how is Mailify involved in this area on a daily basis?
In the GDPR there two types of players: data controllers and subcontractors.
To sum it up: The controller determines the purpose and means of processing applied to the personal data. Subsequently, they may use one or more subcontractors at certain stages of the data processing. These subcontractors act on behalf of and according to the instructions of the controller. Under the GDPR, subcontractors may also be held liable in some cases.
Example: Are you a Marketer, Communication Manager, Sales Representative, Operational Manager, IT Administrator, Legal Assistant, eCommerce specialist, or in charge of Human Resources?
If yes, then you certainly play a role in the purpose and means of processing applied to personal data in your company. However, it's your company, the legal entity, and not yourself who is the controller. Unless it is demonstrated that you personally, have acted independently in determining the particular purposes and means of data processing.
From May 25, 2018, two main principles are to be taken into account: privacy by design and privacy by default and responsibility.
Data protection by design or by default is the need to systematically integrate the necessary measures to ensure protection of personal data when creating a new product or a service. Any player at whatever stage in the creation process of a product of a service, must comply with this principle.
Added to this is the principle of accountability. Personal data controllers and subcontractors must also implement processes that safe guard protection of personal data, and be able to provide evidence of their conformity with the European regulation at all times (In other words: To be able to permanently track and confirm the efficiency of these processes through documentation and internal measures).
The scope is as follows: Those who will be impacted are controllers and subcontractors based in the European Union (EU), and those located outside the EU providing goods or services to people located within the EU or monitoring their behaviour in the EU.
How should you prepare to comply with this regulation?
The rights and obligations foreseen in the European regulation include:
Data portability: Your customer will be able to require you to send them all their data on a legible medium, to be given to your competitors, should they choose to change suppliers.
Notification of personal data violation: If the protection of data has been violated (mistakes, non-authorization, etc) the controller of the data processing is obligated to inform Authorities within 72 hours. In some cases even the people whose data has been violated need to be informed if the risk of infringement of their rights and freedoms is high.
Keeping a register of data processing, with conditions, is highly recommended.
Appoint a Data Protection Officer (DPO) who ensures the protection of personal data.
Carrying out impact assessments in the event of high risk of damaging personal data protection, before implementing a new process. This is particularly recommended for processes that are already in place presenting a high risk.
In the case of non-compliance with personal data protection regulations, a new scale of sanctions applies. A fine can reach up to 20 million euros, or 4% of the total annual global revenue, whichever amount is higher will be issued.
It isn't just the message (nature, meaning) you send that will need to change in order to meet the requirements of GDPR, but also the way in which you treat the personal data of your contacts. Be transparent by informing them prior to the data processing. In the case where legal justification is based on consent, you must be able to provide valid evidence that consent was given.
Personal data is an information that can be used to directly or indirectly identify a natural person.
An email address such as 'email@example.com' directly identifies a person, while a client number identifies a person indirectly.
On the other hand, a generic email address by itself does not identify an individual (unless you have additional information). Email addresses like 'firstname.lastname@example.org' are coordinates to a legal entity and are not considered to be 'personal data' under the GDPR.
The rules applicable to electronic communication are not questioned by the GDPR.
Note that the draft for European regulation regarding electronic privacy, which is still under debate, touches on topics that combine digital communication and user consent. This topic will continue to develop over the next few months.
When we talk about personal data, we are inclined to think about the consent from the people whose data we are processing. Today, the internet is full of information about the concept of consent and how it has evolved over the years to the current definition set by the GDPR.
The European text reminds us that consent is a legal justification that can serve as a basis for data processing. But it isn't the only justification possible for data processing (ex: the execution of a contract) and, in that sense, it is wrong to affirm that consent is systematically mandatory and will be made a strict rule under the GDPR.
The GDPR reinforces the conditions that apply when data processing based on consent is necessary (for example, in the case of commercial prospecting in B2C) or when you choose to justify data processing by means of consent. You must:
- Obtain valid consent in compliance with the GDPR:
This is a clear declaration or act from the person in question. Pre-checked boxes, passive or implicit consent are strictly forbidden.
- Consent should be informed: Inform the person in question in clear language about the intended use for their information. The person must be made fully aware of the data processing and its scope.
- Inform the person that they have the right to revoke the given consent at any moment, stating that revoking the consent is as easy as granting it.
- Keep the proof of consent (the burden of proof is on you): what the person has consented to, the moment when they consented, and to whom. Traceability of consent actions must be implemented: the consent, its purposes and revoked consents.
- Provide an easy way for users to revoke consent. (In the account settings, for example)
In addition, the right to be informed about the processing of data is reinforced by the European regulation. Users must be clearly informed of the use of their data, of the recipients, of the duration of data preservation, of the possibility of rectifying, deleting or limiting the data, or even the possibility of opposing processing.
Keep in mind: The controller should only use subcontractors who demonstrate sufficient safeguards in the implementation of appropriate technical and organizational data protection measures, so that the processing meets the requirements of the GDPR.
As a customer of an email marketing solution, you take on the position controller using the subcontractor for the routing of your newsletters or email campaigns, sent on your behalf and under your instructions. It is therefore your responsibility to ensure that this email marketing solution implements the necessary means to ensure the protection of personal data.
Mailify is involved on all levels of the ecosystem.
A dedicated GDPR compliance team was appointed several months ago. It's formed by several technical and legal professionals, who promote concrete and weekly advances on this matter.
One of them being: A well-defined action plan that evolves on a daily basis, notably through the appointment of a Data Protection Officer.
The implementation of a registry that allows for an up-to-date view of personal data treatment.
Moreover, Mailify's teams receive training regarding new developments concerning GDPR.
Mailify has a statement regarding the protection of personal data available to all its clients to achieve increasingly transparent communication.
A note on the processing of data by Mailify, a topic not covered by the GDPR: Your email and SMS campaigns are hosted in France. With regards to the sending of SMS, your data is equally stored within the EU. As for our own communication with clients, i.e. when they communicate with our support team, the emails and content of the communication are hosted in the USA with the Freshdesk society, which is part of the Privacy Shield Program.
Here you will find Mailify's statement on the protection of personal data.