{"id":2481,"date":"2018-10-08T07:30:52","date_gmt":"2018-10-08T07:30:52","guid":{"rendered":"https:\/\/devbloglavaprotocols.nityo.in\/gdpr-for-marketing-what-you-need-to-know\/"},"modified":"2018-10-08T07:30:52","modified_gmt":"2018-10-08T07:30:52","slug":"gdpr-for-marketing-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/gdpr-for-marketing-what-you-need-to-know\/","title":{"rendered":"GDPR for Marketing: What You Need to Know"},"content":{"rendered":"<div style=\"margin-top: 0px; margin-bottom: 0px;\" class=\"sharethis-inline-share-buttons\" ><\/div><p><em><strong>By Brian Bergen,\u00a0Senior Director, Product Marketing, Salesforce\u00a0<\/strong><\/em><\/p>\n<p><!--more--><\/p>\n<p>Rumours around the European Union\u2019s\u00a0<b>General Data Protection Regulation (GDPR)<\/b>\u00a0turned into full-on rumblings earlier this year, as the new rules went into effect in May. The EU regulation affects how marketers across every business and industry interact with consumers.<\/p>\n<p>In practice, GDPR will shield consumers from the default position of having their personal data tracked across the internet. If an EU consumer wants their personal data to be accessible for collection and tracking, they must take specific steps to consent.<\/p>\n<p>The details matter, so here\u2019s an overview of the regulation and its implications \u2014 note this is not legal advice. As always, it is encouraged that you consult with your own legal counsel to familiarise yourself with the requirements that govern your specific situation. Salesforce and all its partners<em> (including Lava Protocols)<\/em> is committed to help you remain successful in this new environment, and believes that understanding the ins and outs is the best place to start.<\/p>\n<p>\u00a0<\/p>\n<h2><b>What Is the GDPR and How Is It Related to Marketing?<\/b><\/h2>\n<p>GDPR stands for General Data Protection Regulation. It regulates how companies can collect, process, and use personal data from EU individuals. It was adopted in 2016 and went into effect on May 2018.\u00a0For marketers in particular, the regulation impacts how you keep track of and communicate with consumers.<\/p>\n<p>\u00a0<\/p>\n<h2><b>Who\u00a0Does the GDPR Apply To?<\/b><\/h2>\n<p>While the GDPR applies to companies headquartered in the EU, it also applies to any business or organisation processing the personal data of EU individuals, regardless of where they are headquartered.<\/p>\n<p>The consequences for non-compliance are steep. Serious infractions carry\u00a0<a href=\"https:\/\/www.eugdpr.org\/key-changes.html\" target=\"_blank\" rel=\"noopener\">a fine\u00a0<\/a>of up to \u20ac20 million (approx. RM95 million) or 4% of a company\u2019s annual earnings, whichever is greater.<\/p>\n<p>The EU is sending a clear message that it\u2019s taking a strong stance on data protection. For that reason, marketers need to be ready to comply.<\/p>\n<p>\u00a0<\/p>\n<h2><b>GDPR for Marketing and Its Impact<\/b><\/h2>\n<p>While, for now, the new law <strong>only affects brands located or doing business in the EU<\/strong>, all marketers should be aware of GDPR requirements for how companies must collect, process, and delete consumer data.<\/p>\n<p>\u00a0<\/p>\n<h3><b>Collecting Data<\/b><\/h3>\n<p>A big push behind the GDPR is the desire for more transparency between consumers and companies when it comes to personal data. Consumers want to know when, how, and why their personal data is being collected.<\/p>\n<p>The GDPR requires companies to inform consumers of all the personal data collected about them and how it will be used. Companies must also notify consumers that they may revoke their permission to collect and use that data at any time.<\/p>\n<p>Since GDPR doesn\u2019t recognise opt out consent as the default, this means that when a new consumer opens an account, makes a transaction, or signs up for a newsletter, pre-checking a consent box to collect or use their data for any other reason will no longer cut it. Consumers must be given the opportunity to decide whether to give consent (or opt-in) to any use of their data for communications, tracking, or anything else.<\/p>\n<p>This means marketers will need to come up with more creative tactics to encourage consumers to opt in for things like product suggestions and communications.<\/p>\n<p>\u00a0<\/p>\n<h2><b>What About Data That\u2019s Already Been Collected?\u00a0<\/b><\/h2>\n<p>These rules apply to data collected not only after the regulation goes into effect, but also to\u00a0<a href=\"https:\/\/www.gdpreu.org\/the-regulation\/who-must-comply\/\" target=\"_blank\" rel=\"noopener\">data collected\u00a0<\/a>before, as well. Unless marketers have been following practices that would meet GDPR standards all along, they must obtain opt-in consent from consumers or discontinue use of the data they\u2019ve collected.<\/p>\n<p>\u00a0<\/p>\n<h3><b>Processing Data<\/b><\/h3>\n<p>Once you have obtained consent to use a consumer\u2019s data, the important thing to remember is to use it only for that reason. If you want to use it for another reason or to share it with another party, you must obtain separate permission from the consumer to do so.<\/p>\n<p>For example, if a consumer opted in to receive product offers via email and now you\u2019d like to track their activity across your website as well, you\u2019ll have to obtain separate consent to do so.<\/p>\n<p>The other important part of the GDPR that pertains to using <a href=\"https:\/\/lavaprotocols.com\/2016\/04\/19\/cloud-security-secured-not\/\" target=\"_blank\" rel=\"noopener\">data is the safe and secure<\/a> storage of it. This encompasses many definitions of \u201csafe and secure,\u201d including:<\/p>\n<ul>\n<li>Storing it in a way that it cannot be stolen, lost, or altered.<\/li>\n<li>Encrypting it during transit to prevent it from being accessed by unauthorised people or systems. If you already use<a href=\"https:\/\/lavaprotocols.com\/marketing-automation\/\" target=\"_blank\" rel=\"noopener\"> Salesforce Marketing Cloud<\/a>, you don\u2019t need to worry about this.<\/li>\n<li>Ensure that only the people \u2014 marketers, for example \u2014 who need to access it for the specified purpose are able to do so. Marketing Cloud already segregates data at the account level, so that only properly designated people can access it.<\/li>\n<\/ul>\n<p>The GDPR stresses that protection is especially critical for biometric data \u2014 for example, a fingerprint that can be used to unlock a phone \u2014 or data about children.<\/p>\n<p>\u00a0<\/p>\n<h3><b>Deleting Data<\/b><\/h3>\n<p>Finally, the GDPR governs how companies relinquish data once their relationships with consumers have ended. To protect consumers\u2019 \u201cRight to Erasure,\u201d companies must now have a plan in place for deleting data.<\/p>\n<p>As mentioned above, the GDPR says that companies may only use personal data with clear consent by the consumer and for a specified purpose. Once that purpose has been fulfilled, a company must justify any reason for continuing to hold onto personal data.<\/p>\n<p>If at any time, a consumer requests their personal data be deleted by a company, the company must respond within thirty days (keeping in mind the right to deletion is not absolute under the GDPR).\u00a0Similarly, if a person requests a correction or updates to their personal information, the company must respond to that request within 30 days.<\/p>\n<p>\u00a0<\/p>\n<h2><b>Redefining the Relationship Between Consumers and Brands<\/b><\/h2>\n<p>The GDPR is all about transparency and protecting the rights of consumers. Companies that do business in the EU can protect themselves by following GDPR requirements and keeping detailed records to demonstrate their compliance.<\/p>\n<p>At the end of the day, the GDPR clarifies the relationship between consumers and brands, encourages transparency, and protects the rights of EU individuals. Brands that comply \u2014 and many already have practices in place that do so \u2014 can benefit from a more trusting and open relationship with the people they depend on.<\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.salesforce.com\/blog\/2018\/04\/gdpr-what-marketers-need-to-know.html\" target=\"_blank\" rel=\"noopener\">Article<\/a> first appeared on the Salesforce blog.<\/span><\/p>\n<p><strong><i>Lava is an <\/i><a href=\"https:\/\/lavaprotocols.com\/crm\/\"><i>authorised Salesforce Partner <\/i><\/a><i>in Malaysia and has more than a decade of experience in cloud solutions which includes marketing automation, CRM implementation, change management, and consultation. We pride ourselves in not just being a CRM partner but in also understanding the needs of our customers and taking their business to the next level.<\/i><\/strong><\/p>\n<p><span class=\"et_bloom_bottom_trigger\"><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Did you know that the GDPR rules apply to\u00a0data collected\u00a0even before the regulation came into effect? Dear marketers, read on to know more.<\/p>\n","protected":false},"author":1,"featured_media":2482,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[18,130],"class_list":["post-2481","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-blog","tag-brian-bergen"],"jetpack_featured_media_url":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-content\/uploads\/2024\/10\/analysis-business-close-up-1179800.jpg","_links":{"self":[{"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/posts\/2481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/comments?post=2481"}],"version-history":[{"count":0,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/posts\/2481\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/media\/2482"}],"wp:attachment":[{"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/media?parent=2481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/categories?post=2481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lavaprotocols.com\/the-cloud-blog\/wp-json\/wp\/v2\/tags?post=2481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}