SlideShare a Scribd company logo
1 of 39
Actionable GDPR Advice from the experts
What does the GDPR mean for marketing?
#DigitalPriorities Digital Marketing Priorities 2018 brought to you by
Recommended Smart Insights toolkit update
Search ‘GDPR briefing’
One month to go!
Agenda
What is personal data and special categories of data?
What are the lawful basis for marketing?
Consent, what it is and what it isn’t
PECR
Legitimate Interest and why not?
Balancing tests and Privacy Impact assessments
Profiling
B2B
The good bits about GDPR
About the speaker and partner
• Tim Roe
• Compliance Director for RedEye
• British Computer Society Certified Data
Protection Practitioner
• Chair of the Direct Marketing
Associations GDPR taskforce
- Not legal advice
- Broad based practitioner guidance, drawn from ICO publications,
DMA guidance and the WP29 guidance
- Best advice, be cautious, document your decisions and cite your
references
- It will be unlikely that you will be caught out by genuinely trying
to do the right thing
Before we start… house keeping
A recording for the webinar will be sent via
Email.
Slides will be available via Smart Insights
Slideshare
Please get involved with the interactions:
- Do ask questions at any point via the
Questions panel
What data does the GDPR cover?
What is personal data?
What are special categories of data?
What is personal data?
Personal data is "any information
relating to an identifiable person
who can be directly or indirectly
identified in particular by reference
to an identifier" ICO
Name
Email Address
ID numbers
Cookies
IP addresses
Profile information
Segments they belong to
Special Categories of data
• Race;
• Ethnic origin;
• Politics;
• Religion;
• Trade union membership;
• Genetics;
• Biometrics
• Health;
• Sex life; or Sexual orientation.
Special Category data is more sensitive,
and so needs more protection.
Processing Special Categories
of Data is generally Prohibited
Lawful basis, you need one
To process personal data under GDPR, you
require a legal basis:
- Consent
- To perform a contract
- Legal compliance
- Protection of vital interests of a person
- Public interest or official authority
- Legitimate Interest
Consent for GDPR
What is consent?
What does valid consent need?
What if consent is too difficult?
GDPR not e-Privacy
It’s all about consent!
What is consent?
“any freely given, specific, informed and unambiguous
indication of the data subject's wishes by which he or she, by a
statement or by a clear affirmative action, signifies agreement
to the processing of personal data relating to him or her”
ICO - “The GDPR sets a high standard for consent.”
What does valid consent need?
Consent is not just a tick box:
To be informed, enough
information must be made
available at the time.
Segmentation, channels,
tracking, profiling.
Its got to be specific
enough to be valid.
What if consent is too difficult to achieve?
“Remember – you don’t always need consent. If
consent is too difficult, look at whether another lawful
basis is more appropriate.” The ICO
GDPR not e-Privacy (PECR)
GDPR is not about permission
to send electronic marketing
(that’s another law)!
Just because you’ve got a tick box for
electronic marketing, doesn’t make
you GDPR ready.
Electronic marketing needs
to be compliant with GDPR
and Privacy and Electronic
Communication Regulations
Do I need to reconsent my database?
WP259 page 30 that states;
“If a controller finds that the consent
previously obtained under the old legislation
will not meet the standard of GDPR consent,
then controllers must assess whether the
processing may be based on a different lawful
basis, taking into account the conditions set by
the GDPR. However this is a one off situation
as controllers are moving from applying the
Directive to applying the GDPR. Under the
GDPR, it is not possible to swap between one
lawful basis and another.”
There may be no need to
reconsent your database if there
is no requirement for consent to
that processing under GDPR.
Does electronic marketing need consent?
Maybe not:
If the contact details meet these requirements:
- Gathered during the process of a sale or in the context of a sale
- The marketing relates to similar goods or services
- The individual was given the opportunity to opt out at the time
- The individual has been given the opportunity to opt out since
Can I use another lawful basis?
Privacy Impact Assessments Legitimate Interest
The Balancing Test Using Legitimate Interest
Privacy Impact Assessments
Once a detailed audit of your marketing data processing is undertaken.
Privacy Impact Assessments are undertaken on the processing to
determine the privacy risks to individuals.
Justifications must be documented.
Decisions relating to the most appropriate
lawful basis, can only be made:
Legitimate Interests
Necessary for the purposes of legitimate interests pursued by the
controller or a third party, except where such interests are overridden by
the interests, rights or freedoms of the data subject
“the processing of personal data for direct marketing purposes may be
regarded as carried out for a legitimate interest.”
Rec 47
Balancing tests
Marketing is a legitimate interest of the data
controller, but:
Is the processing necessary for the direct marketing?
Is any third party processing necessary for the purpose
of direct marketing?
Is their another way of achieving your legitimate
interest?
Would the individual reasonably expect this
processing?
Balancing tests
Is the processing relevant to your relationship with
the individual?
Are you processing the minimum personal data
required to meet your needs?
Is this processing likely to harm or disadvantage the
individual (what type of marketing are you
doing??!!!)?
Watch out for processing that leads to special
categories of data
Using legitimate interest
This right to object must
be explicitly stated,
prominently displayed
and it’s easy to exercise
that right
Ensure you have a valid
reason to process an
individual’s personal
data using your legal
legitimate interests
Collect the minimum
data necessary and
delete records after use
“The processing of personal data for direct marketing purposes
may be regarded as carried out for a legitimate interest.”
Rec 47
The privacy notice
Explain why you need an individual’s personal
data
Use a layered privacy notice/policy
Make it easy for people to understand
Profiling
The text of the regulation refers to profiling in
Article 4(4) as:
“…any form of automated processing of
personal data consisting of the use of personal
data to evaluate certain personal aspects
relating to a natural person, in particular to
analyse or predict aspects concerning that
natural person’s performance at work,
economic situation, health, personal
preferences, interests, reliability, behaviour,
location or movements.”
Profiling Example
An airline studies the behaviour of its online
customers. It examines what they search for,
look at and how much time they spend
considering each destination. This data will
be combined with the location and route the
customer is most likely to use based on their
previous flight history. The profile will then
be used to serve the customer with a
marketing communication that highlights
the destination and route they are most
likely to be interested in.
Personal data in profiling
The scope of personal is now much wider:
47
Internet search and
browsing history
Existing customer
relationships and
buying habits
Credit cards, store
cards and other
transactions
Credit scoring Consumer complaints
or enquiries
Location and
lifestyle habits
Social media Property ownership
Special categories of data
Profiling can infer special categories of data​.
Example, profiling food consumption or musical tastes
might lead to the inference of ethnic origin or religion.
If you infer special categories of data, the profiling may be
prohibited without explicit consent.
How can profiling be a legitimate interest?
Article 6(1) (f) – necessary for the legitimate interests
pursued by the controller or by a third party Profiling is
allowed if it is necessary for the purposes of the legitimate
interests pursued by the controller or by a third party.
However, Article 6(1) (f) does not automatically apply just
because the controller has a legitimate interest.
The balancing test still needs to be undertaken.
How can profiling have a significant effect?
Profiling can make ads more effective
For example, if individuals believe that they
receive advertising as a result of their online
behaviour, an advert for diet products and
gym membership might spur them on to join
an exercise class and improve their fitness
levels. Conversely it may make them feel that
they are unhealthy or need to lose weight. This
could potentially lead to feelings of low self-
esteem.
Ohio State University found that
behaviourally targeted adverts can
have psychological consequences and
affect individuals’ self-perception.
What is the impact of B2B?
tim.roe@redeye.com has been personal data since 1998
GDPR covers personal data
GDPR does not differentiate between B2B and B2C
A business needs a legal basis to process personal data
It could be either Legitimate Interest or Consent
.
How does a B2B business
use legitimate interest?
To qualify to use LI, you must undertake the same Impact Assessment as B2C
When the data is captured, you must prominently inform about direct
marketing not hide it in T’s and C’s
People must be told they can object and shown how to do it
If you obtain personal data from a third party, you must contact within 30 days
and tell them you are processing the data and they can object
Remember, PECR is still not relevant for B2B
Is it all doom and gloom?
The great bits about GDPR!
GDPR gives rights and protections to individuals
1. It is a positive step for people
2. We are all people!
The GDPR is an opportunity to build trust:
1. Transparency will build trust
2. Transparency and trust could become a key differentiator in business
relationships
3. More powerful even than “targeted campaigns and lifecycle
marketing”
More great bits about GDPR
Transparency and control
1. On the first contact and data exchange
2. And ongoing control of the data the
individual is sharing.
GDPR could educate people in their
information rights
1. People become less tolerant of bad practice
2. More aware of organisations efforts to “do the
right thing”
In conclusion
It’s not all doom and gloom
Marketers face some challenges in GDPR
There is lots of advice from the ICO, DMA, DPN
The first step is the marketing data audit. If you haven’t
started yet, start one tomorrow.
Thank you for listening!
Please ask questions via the
Questions tab

More Related Content

What's hot

Email marketing predictions that matter!
Email marketing predictions that matter!Email marketing predictions that matter!
Email marketing predictions that matter!Smart Insights
 
Top tips for driving leads and optimising conversions in 2020
Top tips for driving leads and optimising conversions in 2020Top tips for driving leads and optimising conversions in 2020
Top tips for driving leads and optimising conversions in 2020Smart Insights
 
Best Practice To Take Your Digital Content And Brand Global
Best Practice To Take Your Digital Content And Brand GlobalBest Practice To Take Your Digital Content And Brand Global
Best Practice To Take Your Digital Content And Brand GlobalSmart Insights
 
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...Adobe
 
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...Big Cloud Analytics, Inc.
 
Future-proofing your AdWords for 2016.
Future-proofing your AdWords for 2016. Future-proofing your AdWords for 2016.
Future-proofing your AdWords for 2016. Smart Insights
 
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2B
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2BMarketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2B
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2BReally B2B
 
5 game-changing Marketing Automations for 2017
5 game-changing Marketing Automations for 20175 game-changing Marketing Automations for 2017
5 game-changing Marketing Automations for 2017Smart Insights
 
Demystifying Shopping: Uncover buying patterns & optimize for profit
Demystifying Shopping: Uncover buying patterns & optimize for profitDemystifying Shopping: Uncover buying patterns & optimize for profit
Demystifying Shopping: Uncover buying patterns & optimize for profitMike Ryan
 
Modern marketing and digital tools (overview)
Modern marketing and digital tools (overview)Modern marketing and digital tools (overview)
Modern marketing and digital tools (overview)Mohamed Almalik
 
Secrets of Successful B2B Lead Generation
Secrets of Successful B2B Lead Generation Secrets of Successful B2B Lead Generation
Secrets of Successful B2B Lead Generation Pinpointe On-Demand
 
Grow Revenue with the Right Marketing Strategy
Grow Revenue with the Right Marketing StrategyGrow Revenue with the Right Marketing Strategy
Grow Revenue with the Right Marketing StrategyMarketo
 
A Whole New Approach to Audiences in Today’s Privacy Landscape
A Whole New  Approach to Audiences in Today’s Privacy LandscapeA Whole New  Approach to Audiences in Today’s Privacy Landscape
A Whole New Approach to Audiences in Today’s Privacy LandscapeTinuiti
 
Importance of Digital Marketing For Ecommerce Business
Importance of Digital Marketing For Ecommerce BusinessImportance of Digital Marketing For Ecommerce Business
Importance of Digital Marketing For Ecommerce BusinessRavin Kapadia
 
Leverage Real-Time Purchase Intent to Boost Sales & Customer Growth
Leverage Real-Time Purchase Intent to Boost Sales & Customer GrowthLeverage Real-Time Purchase Intent to Boost Sales & Customer Growth
Leverage Real-Time Purchase Intent to Boost Sales & Customer GrowthTinuiti
 
Email marketing trends 2018
Email marketing trends 2018Email marketing trends 2018
Email marketing trends 2018Smart Insights
 
Show Me You Care: Why You Should Be Talking About Privacy and Value-Exchange
Show Me You Care: Why You Should Be Talking About Privacy and Value-ExchangeShow Me You Care: Why You Should Be Talking About Privacy and Value-Exchange
Show Me You Care: Why You Should Be Talking About Privacy and Value-ExchangeTealium
 
What's Next: Big Data – Beyond the Buzzword
What's Next: Big Data – Beyond the BuzzwordWhat's Next: Big Data – Beyond the Buzzword
What's Next: Big Data – Beyond the BuzzwordOgilvy Consulting
 

What's hot (20)

Email marketing predictions that matter!
Email marketing predictions that matter!Email marketing predictions that matter!
Email marketing predictions that matter!
 
Top tips for driving leads and optimising conversions in 2020
Top tips for driving leads and optimising conversions in 2020Top tips for driving leads and optimising conversions in 2020
Top tips for driving leads and optimising conversions in 2020
 
Best Practice To Take Your Digital Content And Brand Global
Best Practice To Take Your Digital Content And Brand GlobalBest Practice To Take Your Digital Content And Brand Global
Best Practice To Take Your Digital Content And Brand Global
 
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...
Adobe Visitor Insights – How Adobe Used Its Experience Platform to Create Beh...
 
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...
Big Data & Analytics 101: How Customer Lifetime Value Enhances Predictive Mar...
 
SEO Trends 2016
SEO Trends 2016SEO Trends 2016
SEO Trends 2016
 
Future-proofing your AdWords for 2016.
Future-proofing your AdWords for 2016. Future-proofing your AdWords for 2016.
Future-proofing your AdWords for 2016.
 
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2B
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2BMarketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2B
Marketing Week Live 2017 - "B2B Marketing, The Fundamentals" by Really B2B
 
5 game-changing Marketing Automations for 2017
5 game-changing Marketing Automations for 20175 game-changing Marketing Automations for 2017
5 game-changing Marketing Automations for 2017
 
Demystifying Shopping: Uncover buying patterns & optimize for profit
Demystifying Shopping: Uncover buying patterns & optimize for profitDemystifying Shopping: Uncover buying patterns & optimize for profit
Demystifying Shopping: Uncover buying patterns & optimize for profit
 
Modern marketing and digital tools (overview)
Modern marketing and digital tools (overview)Modern marketing and digital tools (overview)
Modern marketing and digital tools (overview)
 
Secrets of Successful B2B Lead Generation
Secrets of Successful B2B Lead Generation Secrets of Successful B2B Lead Generation
Secrets of Successful B2B Lead Generation
 
Grow Revenue with the Right Marketing Strategy
Grow Revenue with the Right Marketing StrategyGrow Revenue with the Right Marketing Strategy
Grow Revenue with the Right Marketing Strategy
 
A Whole New Approach to Audiences in Today’s Privacy Landscape
A Whole New  Approach to Audiences in Today’s Privacy LandscapeA Whole New  Approach to Audiences in Today’s Privacy Landscape
A Whole New Approach to Audiences in Today’s Privacy Landscape
 
Importance of Digital Marketing For Ecommerce Business
Importance of Digital Marketing For Ecommerce BusinessImportance of Digital Marketing For Ecommerce Business
Importance of Digital Marketing For Ecommerce Business
 
Leverage Real-Time Purchase Intent to Boost Sales & Customer Growth
Leverage Real-Time Purchase Intent to Boost Sales & Customer GrowthLeverage Real-Time Purchase Intent to Boost Sales & Customer Growth
Leverage Real-Time Purchase Intent to Boost Sales & Customer Growth
 
Email marketing trends 2018
Email marketing trends 2018Email marketing trends 2018
Email marketing trends 2018
 
Show Me You Care: Why You Should Be Talking About Privacy and Value-Exchange
Show Me You Care: Why You Should Be Talking About Privacy and Value-ExchangeShow Me You Care: Why You Should Be Talking About Privacy and Value-Exchange
Show Me You Care: Why You Should Be Talking About Privacy and Value-Exchange
 
Digital Marketing Overview - Adaptra
Digital Marketing Overview - AdaptraDigital Marketing Overview - Adaptra
Digital Marketing Overview - Adaptra
 
What's Next: Big Data – Beyond the Buzzword
What's Next: Big Data – Beyond the BuzzwordWhat's Next: Big Data – Beyond the Buzzword
What's Next: Big Data – Beyond the Buzzword
 

Similar to GDPR Briefing for marketers

Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing MindsetNetworkIQ
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoDaniel Smith
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsPost Media
 
How to get prepared for the GDPR
How to get prepared for the GDPRHow to get prepared for the GDPR
How to get prepared for the GDPRRedEye
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leadersDeeson
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketingSpotler
 
GDPR and email marketing: an opportunity for transformation?
GDPR and email marketing: an opportunity for transformation?GDPR and email marketing: an opportunity for transformation?
GDPR and email marketing: an opportunity for transformation?Claire Braunstein Barnes
 
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
EU GDPR Changes: What do you need to know? - CommuniGator SeminarEU GDPR Changes: What do you need to know? - CommuniGator Seminar
EU GDPR Changes: What do you need to know? - CommuniGator SeminarSpotler
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR readyPremier EPOS
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUser Vision
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesStephen Denning
 
Consumer Law Seminar ABTA
Consumer Law Seminar ABTAConsumer Law Seminar ABTA
Consumer Law Seminar ABTARedEye
 
GDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowGDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowHannah Flynn
 

Similar to GDPR Briefing for marketers (20)

Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
 
How to get prepared for the GDPR
How to get prepared for the GDPRHow to get prepared for the GDPR
How to get prepared for the GDPR
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
GDPR and email marketing: an opportunity for transformation?
GDPR and email marketing: an opportunity for transformation?GDPR and email marketing: an opportunity for transformation?
GDPR and email marketing: an opportunity for transformation?
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
EU GDPR Changes: What do you need to know? - CommuniGator SeminarEU GDPR Changes: What do you need to know? - CommuniGator Seminar
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
Consumer Law Seminar ABTA
Consumer Law Seminar ABTAConsumer Law Seminar ABTA
Consumer Law Seminar ABTA
 
GDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowGDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To Know
 

More from Smart Insights

Smart insights and Force 24: The secrets to successful email marketing
Smart insights and Force 24: The secrets to successful email marketingSmart insights and Force 24: The secrets to successful email marketing
Smart insights and Force 24: The secrets to successful email marketingSmart Insights
 
10 omnichannel strategy essentials for 2021
10 omnichannel strategy essentials for 202110 omnichannel strategy essentials for 2021
10 omnichannel strategy essentials for 2021Smart Insights
 
What's new in B2B marketing? 2021 B2B Digital Marketing trends
What's new in B2B marketing? 2021 B2B Digital Marketing trendsWhat's new in B2B marketing? 2021 B2B Digital Marketing trends
What's new in B2B marketing? 2021 B2B Digital Marketing trendsSmart Insights
 
10 recession-beating digital marketing tactics for business growth
10 recession-beating digital marketing tactics for business growth10 recession-beating digital marketing tactics for business growth
10 recession-beating digital marketing tactics for business growthSmart Insights
 
What do people really search for? How to tackle unclear keyword research topics
What do people really search for? How to tackle unclear keyword research topicsWhat do people really search for? How to tackle unclear keyword research topics
What do people really search for? How to tackle unclear keyword research topicsSmart Insights
 
The impact of Covid19 on your digital strategy
The impact of Covid19 on your digital strategyThe impact of Covid19 on your digital strategy
The impact of Covid19 on your digital strategySmart Insights
 
Improve Lead Quality with AI powered call tracking
Improve Lead Quality with AI powered call trackingImprove Lead Quality with AI powered call tracking
Improve Lead Quality with AI powered call trackingSmart Insights
 
7 rockstar tips for growth marketing
7 rockstar tips for growth marketing7 rockstar tips for growth marketing
7 rockstar tips for growth marketingSmart Insights
 
10 strategies for increasing sales with conversion funnels
10 strategies for increasing sales with conversion funnels10 strategies for increasing sales with conversion funnels
10 strategies for increasing sales with conversion funnelsSmart Insights
 
10 content marketing growth hacks
10 content marketing growth hacks10 content marketing growth hacks
10 content marketing growth hacksSmart Insights
 
6 steps to create a data-driven content strategy
6 steps to create a data-driven content strategy6 steps to create a data-driven content strategy
6 steps to create a data-driven content strategySmart Insights
 
Top social media trends for 2020 with Matt Navarra
Top social media trends for 2020 with Matt NavarraTop social media trends for 2020 with Matt Navarra
Top social media trends for 2020 with Matt NavarraSmart Insights
 
How to maintain vibrancy in your marketing workforce
How to maintain vibrancy in your marketing workforceHow to maintain vibrancy in your marketing workforce
How to maintain vibrancy in your marketing workforceSmart Insights
 
Future proofing your marketing - Dave Chaffey
Future proofing your marketing - Dave ChaffeyFuture proofing your marketing - Dave Chaffey
Future proofing your marketing - Dave ChaffeySmart Insights
 
Panel Discussion: Create a 360-degree view of your customers journey to engag...
Panel Discussion: Create a 360-degree view of your customers journey to engag...Panel Discussion: Create a 360-degree view of your customers journey to engag...
Panel Discussion: Create a 360-degree view of your customers journey to engag...Smart Insights
 
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROI
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROIWhy A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROI
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROISmart Insights
 
How To Measure The Performance Of Your Content And Track ROI
How To Measure The Performance Of Your Content And Track ROIHow To Measure The Performance Of Your Content And Track ROI
How To Measure The Performance Of Your Content And Track ROISmart Insights
 
Omnichannel marketing tips and techniques
Omnichannel marketing tips and techniques  Omnichannel marketing tips and techniques
Omnichannel marketing tips and techniques Smart Insights
 
TFM Martech giants panel - Technology for Marketing visuals
TFM Martech giants panel  - Technology for Marketing visuals TFM Martech giants panel  - Technology for Marketing visuals
TFM Martech giants panel - Technology for Marketing visuals Smart Insights
 

More from Smart Insights (19)

Smart insights and Force 24: The secrets to successful email marketing
Smart insights and Force 24: The secrets to successful email marketingSmart insights and Force 24: The secrets to successful email marketing
Smart insights and Force 24: The secrets to successful email marketing
 
10 omnichannel strategy essentials for 2021
10 omnichannel strategy essentials for 202110 omnichannel strategy essentials for 2021
10 omnichannel strategy essentials for 2021
 
What's new in B2B marketing? 2021 B2B Digital Marketing trends
What's new in B2B marketing? 2021 B2B Digital Marketing trendsWhat's new in B2B marketing? 2021 B2B Digital Marketing trends
What's new in B2B marketing? 2021 B2B Digital Marketing trends
 
10 recession-beating digital marketing tactics for business growth
10 recession-beating digital marketing tactics for business growth10 recession-beating digital marketing tactics for business growth
10 recession-beating digital marketing tactics for business growth
 
What do people really search for? How to tackle unclear keyword research topics
What do people really search for? How to tackle unclear keyword research topicsWhat do people really search for? How to tackle unclear keyword research topics
What do people really search for? How to tackle unclear keyword research topics
 
The impact of Covid19 on your digital strategy
The impact of Covid19 on your digital strategyThe impact of Covid19 on your digital strategy
The impact of Covid19 on your digital strategy
 
Improve Lead Quality with AI powered call tracking
Improve Lead Quality with AI powered call trackingImprove Lead Quality with AI powered call tracking
Improve Lead Quality with AI powered call tracking
 
7 rockstar tips for growth marketing
7 rockstar tips for growth marketing7 rockstar tips for growth marketing
7 rockstar tips for growth marketing
 
10 strategies for increasing sales with conversion funnels
10 strategies for increasing sales with conversion funnels10 strategies for increasing sales with conversion funnels
10 strategies for increasing sales with conversion funnels
 
10 content marketing growth hacks
10 content marketing growth hacks10 content marketing growth hacks
10 content marketing growth hacks
 
6 steps to create a data-driven content strategy
6 steps to create a data-driven content strategy6 steps to create a data-driven content strategy
6 steps to create a data-driven content strategy
 
Top social media trends for 2020 with Matt Navarra
Top social media trends for 2020 with Matt NavarraTop social media trends for 2020 with Matt Navarra
Top social media trends for 2020 with Matt Navarra
 
How to maintain vibrancy in your marketing workforce
How to maintain vibrancy in your marketing workforceHow to maintain vibrancy in your marketing workforce
How to maintain vibrancy in your marketing workforce
 
Future proofing your marketing - Dave Chaffey
Future proofing your marketing - Dave ChaffeyFuture proofing your marketing - Dave Chaffey
Future proofing your marketing - Dave Chaffey
 
Panel Discussion: Create a 360-degree view of your customers journey to engag...
Panel Discussion: Create a 360-degree view of your customers journey to engag...Panel Discussion: Create a 360-degree view of your customers journey to engag...
Panel Discussion: Create a 360-degree view of your customers journey to engag...
 
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROI
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROIWhy A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROI
Why A ‘Channel Agnostic’ Approach To Search Can Deliver Greater ROI
 
How To Measure The Performance Of Your Content And Track ROI
How To Measure The Performance Of Your Content And Track ROIHow To Measure The Performance Of Your Content And Track ROI
How To Measure The Performance Of Your Content And Track ROI
 
Omnichannel marketing tips and techniques
Omnichannel marketing tips and techniques  Omnichannel marketing tips and techniques
Omnichannel marketing tips and techniques
 
TFM Martech giants panel - Technology for Marketing visuals
TFM Martech giants panel  - Technology for Marketing visuals TFM Martech giants panel  - Technology for Marketing visuals
TFM Martech giants panel - Technology for Marketing visuals
 

Recently uploaded

Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxMarkAnthonyAurellano
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607dollysharma2066
 
India Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportIndia Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportMintel Group
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaoncallgirls2057
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...ShrutiBose4
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 

Recently uploaded (20)

Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607FULL ENJOY Call girls in Paharganj Delhi | 8377087607
FULL ENJOY Call girls in Paharganj Delhi | 8377087607
 
India Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample ReportIndia Consumer 2024 Redacted Sample Report
India Consumer 2024 Redacted Sample Report
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
Ms Motilal Padampat Sugar Mills vs. State of Uttar Pradesh & Ors. - A Milesto...
 
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 

GDPR Briefing for marketers

  • 1. Actionable GDPR Advice from the experts What does the GDPR mean for marketing? #DigitalPriorities Digital Marketing Priorities 2018 brought to you by
  • 2. Recommended Smart Insights toolkit update Search ‘GDPR briefing’
  • 4. Agenda What is personal data and special categories of data? What are the lawful basis for marketing? Consent, what it is and what it isn’t PECR Legitimate Interest and why not? Balancing tests and Privacy Impact assessments Profiling B2B The good bits about GDPR
  • 5. About the speaker and partner • Tim Roe • Compliance Director for RedEye • British Computer Society Certified Data Protection Practitioner • Chair of the Direct Marketing Associations GDPR taskforce
  • 6. - Not legal advice - Broad based practitioner guidance, drawn from ICO publications, DMA guidance and the WP29 guidance - Best advice, be cautious, document your decisions and cite your references - It will be unlikely that you will be caught out by genuinely trying to do the right thing
  • 7. Before we start… house keeping A recording for the webinar will be sent via Email. Slides will be available via Smart Insights Slideshare Please get involved with the interactions: - Do ask questions at any point via the Questions panel
  • 8. What data does the GDPR cover? What is personal data? What are special categories of data?
  • 9. What is personal data? Personal data is "any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier" ICO Name Email Address ID numbers Cookies IP addresses Profile information Segments they belong to
  • 10. Special Categories of data • Race; • Ethnic origin; • Politics; • Religion; • Trade union membership; • Genetics; • Biometrics • Health; • Sex life; or Sexual orientation. Special Category data is more sensitive, and so needs more protection. Processing Special Categories of Data is generally Prohibited
  • 11. Lawful basis, you need one To process personal data under GDPR, you require a legal basis: - Consent - To perform a contract - Legal compliance - Protection of vital interests of a person - Public interest or official authority - Legitimate Interest
  • 12. Consent for GDPR What is consent? What does valid consent need? What if consent is too difficult? GDPR not e-Privacy
  • 13. It’s all about consent!
  • 14. What is consent? “any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her” ICO - “The GDPR sets a high standard for consent.”
  • 15. What does valid consent need? Consent is not just a tick box: To be informed, enough information must be made available at the time. Segmentation, channels, tracking, profiling. Its got to be specific enough to be valid.
  • 16. What if consent is too difficult to achieve? “Remember – you don’t always need consent. If consent is too difficult, look at whether another lawful basis is more appropriate.” The ICO
  • 17. GDPR not e-Privacy (PECR) GDPR is not about permission to send electronic marketing (that’s another law)! Just because you’ve got a tick box for electronic marketing, doesn’t make you GDPR ready. Electronic marketing needs to be compliant with GDPR and Privacy and Electronic Communication Regulations
  • 18. Do I need to reconsent my database? WP259 page 30 that states; “If a controller finds that the consent previously obtained under the old legislation will not meet the standard of GDPR consent, then controllers must assess whether the processing may be based on a different lawful basis, taking into account the conditions set by the GDPR. However this is a one off situation as controllers are moving from applying the Directive to applying the GDPR. Under the GDPR, it is not possible to swap between one lawful basis and another.” There may be no need to reconsent your database if there is no requirement for consent to that processing under GDPR.
  • 19. Does electronic marketing need consent? Maybe not: If the contact details meet these requirements: - Gathered during the process of a sale or in the context of a sale - The marketing relates to similar goods or services - The individual was given the opportunity to opt out at the time - The individual has been given the opportunity to opt out since
  • 20. Can I use another lawful basis? Privacy Impact Assessments Legitimate Interest The Balancing Test Using Legitimate Interest
  • 21. Privacy Impact Assessments Once a detailed audit of your marketing data processing is undertaken. Privacy Impact Assessments are undertaken on the processing to determine the privacy risks to individuals. Justifications must be documented. Decisions relating to the most appropriate lawful basis, can only be made:
  • 22. Legitimate Interests Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject “the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” Rec 47
  • 23. Balancing tests Marketing is a legitimate interest of the data controller, but: Is the processing necessary for the direct marketing? Is any third party processing necessary for the purpose of direct marketing? Is their another way of achieving your legitimate interest? Would the individual reasonably expect this processing?
  • 24. Balancing tests Is the processing relevant to your relationship with the individual? Are you processing the minimum personal data required to meet your needs? Is this processing likely to harm or disadvantage the individual (what type of marketing are you doing??!!!)? Watch out for processing that leads to special categories of data
  • 25. Using legitimate interest This right to object must be explicitly stated, prominently displayed and it’s easy to exercise that right Ensure you have a valid reason to process an individual’s personal data using your legal legitimate interests Collect the minimum data necessary and delete records after use “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” Rec 47
  • 26. The privacy notice Explain why you need an individual’s personal data Use a layered privacy notice/policy Make it easy for people to understand
  • 27. Profiling The text of the regulation refers to profiling in Article 4(4) as: “…any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.”
  • 28. Profiling Example An airline studies the behaviour of its online customers. It examines what they search for, look at and how much time they spend considering each destination. This data will be combined with the location and route the customer is most likely to use based on their previous flight history. The profile will then be used to serve the customer with a marketing communication that highlights the destination and route they are most likely to be interested in.
  • 29. Personal data in profiling The scope of personal is now much wider: 47 Internet search and browsing history Existing customer relationships and buying habits Credit cards, store cards and other transactions Credit scoring Consumer complaints or enquiries Location and lifestyle habits Social media Property ownership
  • 30. Special categories of data Profiling can infer special categories of data​. Example, profiling food consumption or musical tastes might lead to the inference of ethnic origin or religion. If you infer special categories of data, the profiling may be prohibited without explicit consent.
  • 31. How can profiling be a legitimate interest? Article 6(1) (f) – necessary for the legitimate interests pursued by the controller or by a third party Profiling is allowed if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. However, Article 6(1) (f) does not automatically apply just because the controller has a legitimate interest. The balancing test still needs to be undertaken.
  • 32. How can profiling have a significant effect? Profiling can make ads more effective For example, if individuals believe that they receive advertising as a result of their online behaviour, an advert for diet products and gym membership might spur them on to join an exercise class and improve their fitness levels. Conversely it may make them feel that they are unhealthy or need to lose weight. This could potentially lead to feelings of low self- esteem. Ohio State University found that behaviourally targeted adverts can have psychological consequences and affect individuals’ self-perception.
  • 33. What is the impact of B2B? tim.roe@redeye.com has been personal data since 1998 GDPR covers personal data GDPR does not differentiate between B2B and B2C A business needs a legal basis to process personal data It could be either Legitimate Interest or Consent .
  • 34. How does a B2B business use legitimate interest? To qualify to use LI, you must undertake the same Impact Assessment as B2C When the data is captured, you must prominently inform about direct marketing not hide it in T’s and C’s People must be told they can object and shown how to do it If you obtain personal data from a third party, you must contact within 30 days and tell them you are processing the data and they can object Remember, PECR is still not relevant for B2B
  • 35. Is it all doom and gloom?
  • 36. The great bits about GDPR! GDPR gives rights and protections to individuals 1. It is a positive step for people 2. We are all people! The GDPR is an opportunity to build trust: 1. Transparency will build trust 2. Transparency and trust could become a key differentiator in business relationships 3. More powerful even than “targeted campaigns and lifecycle marketing”
  • 37. More great bits about GDPR Transparency and control 1. On the first contact and data exchange 2. And ongoing control of the data the individual is sharing. GDPR could educate people in their information rights 1. People become less tolerant of bad practice 2. More aware of organisations efforts to “do the right thing”
  • 38. In conclusion It’s not all doom and gloom Marketers face some challenges in GDPR There is lots of advice from the ICO, DMA, DPN The first step is the marketing data audit. If you haven’t started yet, start one tomorrow.
  • 39. Thank you for listening! Please ask questions via the Questions tab

Editor's Notes

  1. Regulation has been law for almost 2 years Loads of time to prepare Christopher Graham, if you are doing all you need to under DP98, you don’t have far to go to be GDPR ready Loads of advice out there, not all good
  2. Involved in data protection and e-privacy since 2010
  3. Not legal advice Broad based practitioner guidance, drawn from ICO publications, DMA guidance and the WP29 guidance. Best advice, be cautious, document your decisions and cite your references. It will be unlikely that you will be caught out by genuinely trying to do the right thing Data protection is a complex subject Absence of case law on GDPR makes giving advice difficult Knowledge of the subject requires a great deal of reading and study and input from industry organisations and the regulator Lots of authoritative advice from the ICO, WP29, DMA
  4. GDPR is quite specific about what personal data actually is. The scope has broadened considerably
  5. Personal data is "any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier" ICO   The scope of personal data is broad and will adapt to include new types of personal data collected or created Location data is personal data Name  Email Address  ID numbers  Cookies   IP addresses   Profile information   Segments they belong to
  6. “Special categories” of data have replaced “sensitive personal data” Special category data is more sensitive, and so needs more protection. Processing Special Categories of Data is generally Prohibited Race; Ethnic origin; Politics; Religion; Trade union membership; Genetics; Biometrics Health; Sex life; or Sexual orientation. Important to ensure that this is not being processed inadvertently Can be processed for marketing under consent
  7. You need to have a legal basis for processing personal or special categories of data To process personal data under GDPR, you require a legal basis: Consent To perform a contract Legal compliance Protection of vital interests of a person Public interest or official authority Legitimate Interest Each of the legal basis, have certain qualifying criteria For marketing, the two most appropriate basis are Consent or Legitimate Interest You must have a legal basis for the processing to be a lawful one. It also needs to be documented
  8. Lets talk about consent for marketing first What is consent What does valid consent need What if consent is too difficult? And what about e-privacy, and why GPDR has led many businesses to reconsent under a different law
  9. Lets face it, its all about consent at the moment Presentations, emails, webinars Consent seems to be the most popular answer to most questions on GDPR Sometimes it is appropriate, sometimes it is not
  10. So, what is consent “any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her” The ICO states that the GDPR has set a high standard for consent. You have to ensure that your consent is valid if challenged and you need to be able to prove it
  11. What is valid consent? To be informed, enough information must be made available at the time This can be in a layered privacy policy, but enough information must be available clearly at the time to be considered to be informed. Detail can go into lower layers, but not the key points Consent means offering individuals real choice and control. Genuine consent should put individuals in charge and build trust and engagement Check your consent practices and your existing consents. Refresh your consents if they don’t meet the GDPR standard. Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent. Explicit consent requires a very clear and specific statement of consent. Keep your consent requests separate from other terms and conditions. Be specific and ‘granular’ so that you get separate consent for separate things. Vague or blanket consent is not enough. Be clear and concise. Name any third party controllers who will rely on the consent. Make it easy for people to withdraw consent and tell them how. Keep evidence of consent – who, when, how, and what you told people. If changes are made to your processing activities, you might need new consent You should also avoid making consent a precondition of a service, such as brochure downloads.
  12. The GDPR sets a high standard for consent. But you often won’t need consent. If consent is difficult, look for a different lawful basis. Look for another basis that works. The impact of choosing the wrong basis could be: 1/ The loss of up to 80% of the marketing database in reconsenting campaigns 2/ The legal basis is so difficult to achieve, that the consent achieved is invalid In as much as it is not informed enough or specific enough to be valid And remember, GDPR is not the Privacy and Electronic Communications Regulations
  13. GDPR is not about permission to send electronic marketing. Electronic marketing needs to be compliant with GDPR and Privacy and Electronic Communication Regulations. Segmentation, profiling, targeting is not strictly necessary to send email marketing, SMS or social campaigns. You need a legal basis to do this under GDPR. Just because you’ve got a tick box for electronic marketing, doesn’t make you GDPR ready. Many brands have undertaken re-consenting campaigns, which will get them great consent to send email.
  14. Do you really need to reconsent your database There maybe no need to reconsent your database if there is no requirement for consent to that processing under GDPR. WP259 page 30 that states; “If a controller finds that the consent previously obtained under the old legislation will not meet the standard of GDPR consent, then controllers must assess whether the processing may be based on a different lawful basis, taking into account the conditions set by the GDPR. However this is a one off situation as controllers are moving from applying the Directive to applying the GDPR. Under the GDPR, it is not possible to swap between one lawful basis and another.” So the answer might be that you don’t need to reconsent your database
  15. Maybe not: If the contact details meet these requirements: - Gathered during the process of a sale or in the context of a sale or in the process of negotiation for goods or services - The marketing relates to similar goods or services - The individual was given the opportunity to opt out at the time - The individual has been given the opportunity to opt out since.
  16. Can you use another lawful basis How can you decide and what do you need to document to make your decisions valid So now, lets talk about privacy impact assessments, balancing tests and how legitimate interest can be used
  17. Decisions relating to the most appropriate lawful basis, should only be made once a detailed audit of your marketing data processing is undertaken. Check the different processing that you are doing for marketing Are you collecting more data that is necessary for the marketing that you are doing? What profiling do you do? Do you use social media? Once you have this information, you will be able to undertake a privacy impact assessment on the processing Privacy Impact Assessments are undertaken on the processing to determine the privacy risks to individuals. The process of the assessment should be documented and show how you have come to your decisions. Justifications must be documented.
  18. Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject “the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” Rec 47 This isn’t an automatic legal basis for processing marketing data You need to undertake a balancing test where you will balance the impact of processing you are doing, against the rights and freedoms of the individual.
  19. Marketing is a legitimate interest of the data controller, but: Is the processing necessary for the direct marketing? Is any third party processing necessary for the purpose of direct marketing? Is their another way of achieving your legitimate interest? Would the individual reasonably expect this processing?
  20. Is the processing relevant to your relationship with the individual? Are you processing the minimum personal data required to meet your needs? Is this processing likely to harm or disadvantage the individual (what type of marketing are you doing??!!!) Watch out for processing that leads to special categories of data
  21. This right to object must be explicitly stated, prominently displayed and it’s easy to exercise that right Collect the minimum data necessary and delete records after use Ensure you have a valid reason to process an individual’s personal data using your legal legitimate interests “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” Rec 47
  22. Explain why you need an individual’s personal data You’ve done the audit, you now know what processing you are doing. Explain what data you hold about people Why do you hold PI Where do you get PI from, for example social media What profiling is done on the PI and what is the purpose of the profiling Use a layered privacy notice/policy Make it easy for people to understand
  23. What is profiling “…any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.”  For marketing, the key words are personal preferences, interests, behaviour, and location. Depending on the context, profiling can also be quite intrusive if it includes online tracking.
  24. Here is a typical example of profiling, used to make sure that the content of marketing and some web pages, are made as relevant to the recipient An airline studies the behaviour of its online customers. It examines what they search for, look at and how much time they spend considering each destination. This data will be combined with the location and route the customer is most likely to use based on their previous flight history. The profile will then be used to serve the customer with a marketing communication that highlights the destination and route they are  most likely to be interested
  25. As soon as we start to profile, we are creating new personal data that relates to the individual. This “profile” could include data from many sources Website search and browsing history Customer relationships and buying habits Credit card, store card and transactional history Credit scoring Complaints, feedback or enquiries Location Lifecycle habits Social media Property ownership
  26. Profiling can trip you up Profiling can sometimes infer special categories of data​ Example, profiling food consumption or musical tastes might lead​ to the inference of ethnic origin or religion.​ If you infer special categories of data, the profiling maybe prohibited without explicit consent. This is why it is important to undertake privacy impact assessments when any new processing activity If privacy risks are identified, you can mitigate those risks by changing the process, or using a more appropriate legal basis, such as explicit consent
  27. Its possible that much of the profiling that is done for marketing, can be undertaken using legitimate interest. This is because it is unlikely to cause a legal or significant effect on the individual. The article 29 working party says: Article 6(1) (f) – necessary for the legitimate interests pursued by the controller or by a third party Profiling is allowed if it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. However, Article 6(1) (f) does not automatically apply just because the controller has a legitimate interest. The balancing test still needs to be undertaken
  28. Its also possible for the profiling to stray into the realms of having a significant effect. The ICO has cited some research that shows it is possible to for harm or a significant effect to be caused by profiling. Ohio State University found that behaviourally targeted adverts can have psychological consequences and affect individuals’ self-perception. ​ For example, if individuals believe that they receive advertising as a result of their online behaviour, an advert for diet products and gym membership might spur them on to join an exercise class and improve their fitness levels. Conversely it may make them feel that they are unhealthy or need to lose weight. This could potentially lead to feelings of low self-esteem.​ Profiling can make ads more effective ​and have a greater impact on the individual. This was one of the key concerns about the issues with Cambridge Analytica’s use of Facebook data, where the hidden profiling has allegedly been used to influence voting preferences.
  29. GDPR will impact on B2B processing of personal data, tim.roe@redeye.com has been personal data since 1998. All businesses, B2B or B2C will need to choose the most appropriate legal basis for their processing If its marketing related, it is likely to be either Legitimate Interest or Consent. What are the main differences between what happens now and GDPR?
  30. B2B will still need to use the Privacy Impact Assessment to see if the data processing is LI Context will be very important in the assessment. Where did you get the data, was the data made available by the data subject for the purpose you are using it for? Whenever personal data is captured, that is going to be used for marketing, you must prominently inform the data subject that you will be using the data in this way and telling them they can object. If you are obtaining the data from a third party, you must contact the data subjects within 30 days to tell them you have their data and they an object if they wish. B2B electronic marketing (email, SMS, social) are not caught under PECR, but there is a chance that under the new e-privacy regulations, they will apply the same as B2C. That means consent.
  31. Is this the end to all the fun we’ve been having in marketing? Is it doom and gloom now? Is the Data Protection Officer also the Sales Prevention Officer? Lets take a look at some great bits about GDPR!
  32. GDPR gives rights and protections to individuals 1) It is a positive step for people: The law has been created to protect people and ensure that our technology and developments, serve mankind and not harm it 2) We are all people: So we should be happy about this law, it is protecting us! The GDPR is an opportunity to build trust 1) Transparency will build trust The GDPR demands that firms become more transparent in their dealings with peoples personal data. 2) Transparency and trust could become a key differentiator in business relationships Transparency will become a key element used to build relationships with our customers. It will become another trust building opportunity, people prefer to deal with brands they trust 3) More powerful than “targeted campaigns and lifecycle marketing”. In building real one to one relationships with your customer, could the GDPR actually become the driver behind a different type of customer centric marketing strategy?
  33. Transparency and control 1) On the first contact and data exchange GDPR compliance will help break down the concern with exchanging data with brands, more customers willing to open accounts rather than using the guest checkout. 2) And ongoing control of the data the individual is sharing. Allowing the individual ongoing control over their data, should be more likely to instil confidence and foster long term customer relationships GDPR could educate people in their information rights People become less tolerant of bad practice Businesses that do not demonstrate proper compliance with GDPR, will loose the trust of customers and find it harder to turn prospects into customers. 2) More aware of organisations efforts to “do the right thing Customers will start to “look” for the pointers of compliance, transparent statements at point of data capture, banners relating to tracking cookies. Overall, GDPR should be seen as an opportunity for business and an opportunity to build stronger and more profitable relationships with their customers.
  34. Its not all doom and gloom Marketers face some challenges in GDPR There is lots of advice from the ICO, DMA, DPN Take off the marketing hat, how would your customers feel about what you are doing? If you are doing something that your customers might not expect or like, you are probably doing something wrong The first step is the data audit, if you haven’t started yet, start one tomorrow.