24 May How Europe’s New GDPR Could Affect Your Website
Do you get any website traffic from the EU?
If the answer is yes (hint: it probably is), then you should be aware that Europe’s new sweeping data privacy laws, GDPR, will affect you.
What is GDPR?
GDPR stands for General Data Protection Regulation. It’s a data privacy and protection regulation slated to officially begin on May 25, 2018.
Data protection in Europe is getting a major upgrade and is the biggest legal change in the Internet age
It’s a legislation which focusses on the way in which private data belonging to EU citizens is collected, stored and distributed. Everyone is required to take action before the given date — this applies to all companies across the world who appeal or work with EU citizens. It doesn’t matter where you are located in the world, if you’re dealing with EU citizens, you need to comply to GDPR.
Why has it been introduced?
GDPR focusses on giving control back to consumers. It’s important for people to have more control over their personal data, and to know exactly how companies are using that data IF they’ve allowed a business to use or store their private data.
What If you business does not comply?
Organisations that fail to comply with the regulation requirements could be slapped with administrative fines up to €20 million, or in the case of an undertaking, up to 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher.
The laws do not stop at European boundaries, however, with those in the rest of the world, including Australia, bound by the GDPR requirements if they have an establishment in the EU, if they offer goods and services in the EU, or if they monitor the behaviour of individuals in the EU.
Who is affected by the GDPR?
The GDPR affects anyone with a website that stores/processes/tracks “personal data.” This often happens automatically through different services—we’ll get to that soon. The GDPR understands personal data as (among other things):
- First name and last name
- Email address
- Bank accounts
- Location data
- IP addresses
- Cookie ID
This definition means that virtually all website owners and shop owners have to review their site and adapt it, where necessary.
A website is affected by the GDPR if:
- IP addresses of website visitors are transmitted/stored
- There’s a comment function where you can input an email address
- User registrations
- Visitors can comment
- There’s a contact form
- There’s a subscription or a newsletter subscription
- The behavior of visitors is analyzed through tracking and cookies
- Security tools and Plugins
- It uses social media plugins that don’t offer a two-click solution to limit tracking
How can I ensure that my website contact forms will be compliant?
- Checkboxes need to be defaulted to “no” & users can’t be forced to opt-out with pre-selected tick-boxes.
- Different options and terms and conditions need to be clear and separated accordingly.
- Users need to be able to provide separate consent for different methods of communication such as email, post, telephone etc.
- Make sure it is as easy to withdraw consent as much as it is easy to sign up.
The website GDPR compliance checklist:
1. The GDPR Opt-In
The single most important aspect of all this is the GDPR opt-in. Let me be clear on this. An opt-in is under no circumstances the same thing as an opt-out. The EU has said that you must “get their clear consent to process the data.” That means that users have to explicitly say yes, not only have the option to say no.
Here’s an example: you have an online dropshipping business, and maybe you use WooCommerce. When users get to your checkout page, you have a checkbox that reads “[x] Yes, I want to sign up for your amazing email list!”
No problem, right? If you have the box checked by default, you’re at fault. That’s giving them the chance to opt-out. That’s not what the GDPR opt-in rule says. They must say explicitly choose to share their information with you.
Don’t just copy and paste someone else’s user policy. It is unlikely to contain the proper information for your site. If appropriate, you might include items like:
- We do not sell data.
- We do not share data unless compelled by law.
- We only ask for personal information if it’s needed to provide a service.
- How to access and download a complete record of any data you have on them
- The process through which users can fully delete their data from your records (and not simply unsubscribe, etc.) as a part of the ‘right to be forgotten’ laws previously passed in the EU
- Exactly how you will inform users of data breaches if they ever happen
- Detailed explanations of who you are, what you use the data for, who has access to it, and how long you retain it
3. Website Forms
Forms on your website must no longer include pre-ticked boxes. This is considered implied consent and not freely given.
Users should be able to provide separate consent for different types of processing. For example, an option to be contacted by post, email, or telephone as three separate tick boxes.
If you are asking for permission to past details onto a third party – again, you need another tick box. If you are collecting data through one website on behalf of several third-parties, then you need to clearly give an opt-in option for each party.
- No pre-ticked boxes to automatically sign the enquirer up to a newsletter.
4. Encrypt data with an SSL certificate
Privacy is the number one priority as part of GDPR. People want to be safe in what information they provide and, how they provide it.
A Single Socket Layer, or SSL certificate is a small file that digitally binds a cryptographic key to an organisations details. When you have one as part of your website, it activates the ‘padlock’ symbol that you see in web browsers. It provides you with that https:// in your address bar – making all of your content secure between servers, it increases your Google search engine optimisation (SEO) rankings which is a bonus and builds/enhances customer trust, resulting in improved conversion rates – especially within e-commerce websites.
5. Clean up your mailing lists
It must be a simple process to remove a user’s consent as it was to grant it, and individuals always need to know they have the right to withdraw their consent.
6. IP Tracking
You must obtain clear, specific consent from users to place cookies and track them. This could be handled by a popup on a user’s first visit that allows users to consent to or decline cookie use. To comply, you cannot have a default answer (such as accept) but must require the user to pick an option. If the user doesn’t explicitly consent, you can’t place cookies on their browser.
Helpful plugins are also beginning to appear in the WordPress plugin section.
10. Online Payments
If you are an e-commerce business, you are likely to be using a payment gateway for financial transactions – PayPal, Stripe, SagePay etc.
Your own website may be collecting personal data before passing these details onto the payment gateway. If this is the case, you will most certainly require an SSL certificate to make sure this information is properly encrypted.
The GDPR legislation is not explicit about the number of days, it is your own judgement as to what can be defended as reasonable and necessary. You simply need to be prepared to provide the details you have to an individual who asks for it and, remove the data if an individual asks you to.
11. Live Chats
The GDPR says that your privacy information must be ‘concise, transparent, intelligible and easily accessible; written in clear and plain language – particularly if addressed to a child; and free of charge.’
Make yourself aware of where data on your website is coming from, where it is being stored and how it is being processed.
Give everyone the choice to opt into any data, give them the ability to opt out and view/have their data removed from your systems easily.
Encrypt your website with an SSL certificate which not only brings confidence to your users, but also helps to boost your rank in search engines.
If you have any questions or would like to discuss how your website is effected feel free to Contact us.
These are our recommendations and suggestions based on the research that we have undertaken. In order to ensure full compliance, we would advise that you seek legal advice and take the time to conduct some further reading on the subject yourself.