Page 14 - 10052 WORSH Marketor Issue 79.indd
P. 14
GDPR Richard Christou
Master
Now that May 25 has come and gone, I felt that some consideration of the practical
aspects of the implementation of GDPR, with which we are all struggling as marketing
SURIHVVLRQDOV GRHV ÀW LQ ZLWK P\ WKHPH RI 7KH &02 <RX FDQQRW EH D &02 LQ
let alone 2020, if you do not have some understanding of GDPR.
1. BASIC PRINCIPLES ,03/(0(17$7,21 21 0$< Amazon. Registered customers have
Lawful Processing The pressing problem was, and an account with Amazon, and
clearly still is, that of dealing with the Amazon processes the data it
In essence, the GDPR is based on the REWDLQV IURP WKRVH FXVWRPHUV WR IXOÀO
implementation of GDPR to cover
grounds upon which a data the orders they place with it and also
controller can rely to ensure that personal data held on May 25 2018. I to send them information about
have attempted to make a short
processing of personal data is lawful. other products that might be of
survey of the way in which businesses
These are: are trying to deal with the situation. interest. In addition, all customers
have direct access to the
(a) the data subject has given A. The Privacy Policy information that Amazon holds
consent;
7KH ÀUVW VWHS LV WR SURGXFH D SULYDF\ about them, such as past orders.
(b) processing is necessary for the policy, taking account of all the Communicating the privacy policy
performance of a contract to which content prescribed by the GDPR. This to the customer
the data subject is party or in order is clearly a job for an expert, and,
to take steps at the request of the however much one tries to make this In such cases all that is really
data subject prior to entering into a XVHU IULHQGO\ LW LV OLNHO\ WR EH TXLWH D necessary is to make sure a
contract; long document and quite a stiff compliant privacy policy is available
read. One wonders just how many on the controller’s website, with a
(c) processing is necessary for
data subjects will actually read these notice on the site drawing attention
compliance with a legal obligation documents. to its existence. Where the controller
or to protect the vital interests of the does not deal with the data subject
data subject or of another natural B. Nature of the Controller’s through electronic communications,
person; Relationship with Data Subjects it will be necessary to send a hard
As marketers the two relationships
(d) processing is necessary for the copy by post with a covering letter.
performance of a task carried out in that are of the most interest are The role of the marketing professional
the public interest or in the exercise those with a data subject who is an
existing customer and those with a
RI RIÀFLDO DXWKRULW\ YHVWHG LQ WKH It is here that the marketer has the
data subject who is a prospective
controller; chance to intervene in the process,
customer, merely on the circulation WR SURYLGH D XVHU IULHQGO\ VXPPDU\ RI
(e) processing is necessary for the list for information about the the privacy policy and to convince
purposes of the legitimate interests controller’s products and services the data subjects that their personal
pursued by the controller or by a without the existence of any business data is in the safe hands of a
third party. relationship.
conscientious controller. Many of the
Guides to the GDPR C. Current Customers communications I have received
make a very good job of this task.
The legislation is extremely complex Grounds for lawful processing
DQG GLIÀFXOW WR XQGHUVWDQG (YHQ WKRVH The most likely basis for lawful This is really the best opportunity to
who would regard themselves as processing is performance of a put the legalities to one side and
experts on the subject are frequently contract or of the preliminaries concentrate on the essence of the
QRW DV GHÀQLWLYH DV RQH PLJKW ZLVK 7KLV necessary to enter into a contract. message:
has led to a great many guides to the The controller can also rely on the “We care about you and your data. We
GDPR, from many different sources, legitimate interest ground to process will keep it private and store it securely.
attempting to explain this detail in information about the data subject’s We will not misuse your data. We want
simple language, and many giving past dealings with the controller so to make use of it to provide you with a
FRQÁLFWLQJ DGYLFH 1HYHUWKHOHVV QR as to provide him or her with better and more targeted service, and to
JXLGH FDQ EH UHJDUGHG DV GHÀQLWLYH information about other products KHOS XV UXQ RXU EXVLQHVV PRUH HIÀFLHQWO\
In the end, the interpretation of the and services which might be of This is not just a routine compliance
legislation is a matter for the Courts. interest. A simple example here is project imposed by bureaucrats.”
14 marketors.org WORSHIPFUL COMPANY of MARKETORS

