{"id":24782,"date":"2021-09-03T14:30:50","date_gmt":"2021-09-03T13:30:50","guid":{"rendered":"https:\/\/www.alioze.com\/?p=24782"},"modified":"2021-09-03T14:47:56","modified_gmt":"2021-09-03T13:47:56","slug":"rgpd-which-is-affected-and-how-to-comply","status":"publish","type":"post","link":"https:\/\/www.alioze.com\/en\/gdpr-compliance\/","title":{"rendered":"GDPR: who is concerned and how to comply?"},"content":{"rendered":"<p>A source of concern for many businesses and e-tailers, the <strong>GDPR<\/strong>\u00a0came into force on <strong>25 May 2018<\/strong>.<\/p>\n<p>If you handle online payments or manipulate data of EU residents for commercial and marketing purposes, you are one of the organizations concerned!<\/p>\n<p>To put an end to your worries, we help you to see more clearly by giving you all the <strong>GDPR<\/strong><strong>\u00a0best practices<\/strong> to <strong>comply<\/strong>.<\/p>\n<p>But first, let&#8217;s start with the basics: <strong>what is the GDPR<\/strong>?<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>GDPR<\/strong>: definition<\/h2>\n<p>Established by the EU Council in April 2016, the <strong>General Data Protection Regulation<\/strong> (GDPR) is the European Union&#8217;s new <strong>data privacy<\/strong> law.<\/p>\n<p>Its entry into force took place on 25 May 2018, when it replaced the old EU Directive on the protection of personal data dating from 1995.<\/p>\n<p>The GDPR is an 88-page text that sets out the rules that organisations processing data must follow in terms of collection, storage, use, protection and security.<\/p>\n<p>Its stated aim is to extend the rights of European citizens with regard to their personal data, by strengthening their protection and giving them the means to manage the way it is used by companies.<\/p>\n<p>Specifically, the GDPR gives individuals the right to access, correct, delete and strictly process their data.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>GDPR<\/strong>: who is concerned?<\/h2>\n<p>It is legitimate that you ask yourself the question: <strong>who is the GDPR for<\/strong>? To answer this question, here are three things you should know.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-ue.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-4757 img-responsive center-block lazyload\" data-src=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-ue.png\" alt=\"RGPD UE\" width=\"100\" height=\"98\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 100px; --smush-placeholder-aspect-ratio: 100\/98;\" \/><\/a><\/p>\n<p style=\"text-align: center;\">1 &#8211; Business activities in the EU<\/p>\n<p>Even if your company is not based in the European Union but you do business there, you need to comply with the <strong>GDPR<\/strong>.<\/p>\n<p>This new regulation concerns all companies in the European Union, but also all those who sell products or services to European residents.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-donnees.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-4756 img-responsive center-block lazyload\" data-src=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-donnees.png\" alt=\"RGPD donn\u00e9es\" width=\"100\" height=\"95\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 100px; --smush-placeholder-aspect-ratio: 100\/95;\" \/><\/a><\/p>\n<p style=\"text-align: center;\">2 &#8211; Data processing activities<\/p>\n<p>You are concerned by the GDPR as soon as you collect and\/or process personal data.<\/p>\n<p><strong>What data is affected by the GDPR<\/strong>? Any customer information that identifies an individual. Photos, posts on social networks, IP addresses, bank details and all identification numbers such as the NIR: the <strong>GDPR<\/strong> applies to all marketing, sales, advertising, HR and accounting databases.<\/p>\n<p>In short, if you use your customers&#8217; data for purposes other than simply filling orders, then you are particularly concerned!<\/p>\n<p>Don&#8217;t worry, you are not alone in this. The GDPR\u00a0does not only apply to e-commerce owners, associations or any other organisations. Tools, software, CMS and social networks such as Google, Facebook, MailChimp or Shopify, to name but a few, are also concerned and must comply.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-qui-est-concerne.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-4759 img-responsive center-block lazyload\" data-src=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-qui-est-concerne.png\" alt=\"RGPD qui est concern\u00e9\" width=\"100\" height=\"110\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 100px; --smush-placeholder-aspect-ratio: 100\/110;\" \/><\/a><\/p>\n<p style=\"text-align: center;\">3 &#8211; VSEs, SMEs, associations, major accounts&#8230; all in the same boat<\/p>\n<p>The GDPR affects private AND public companies of any size or sector.<\/p>\n<p>It doesn&#8217;t matter if you have one employee or 10,000: as long as you manage data on European citizens, the GDPR applies. However, small e-tailers and VSEs do not have to comply with the same requirements as a large company or an e-commerce monster.<\/p>\n<p>A company in the health sector, which manages medical data considered as &#8220;sensitive&#8221; will not have the same requirements as a company selling beauty products.<\/p>\n<p>However, many of the requirements of the GDPR apply to all businesses.<\/p>\n<p>&nbsp;<\/p>\n<h2>GDPR: best practices for compliance<\/h2>\n<p style=\"text-align: center;\">[Editor&#8217;s note: our best recommendation is to consult a <a href=\"https:\/\/www.alioze.com\/en\/gdpr\/\" target=\"_blank\" rel=\"noopener\">specialist GDPR agency<\/a> to help you get compliant]<\/p>\n<p>&nbsp;<\/p>\n<h3>Obtaining client consent<\/h3>\n<p style=\"text-align: center;\">&#8221; <em>Consent should be given by a clear positive act by which the data subject freely, specifically, knowledgeably and unambiguously expresses his or her agreement to the processing of personal data concerning him or her<\/em>.&#8221;<\/p>\n<p>The GDPR requires organisations to be clear in how they obtain customer consent. In other words, an individual&#8217;s consent to hand over their data must be explicitly given.<\/p>\n<p>In this sense, previously checked boxes are not a valid indication of consent.<\/p>\n<p>Data subjects must also be able to withdraw their consent easily. In this case, they must also be able to request the deletion of their data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Good practices for obtaining client consent :<\/strong><\/p>\n<ul>\n<li>Perform a complete audit of your current forms and privacy notices across your entire e-commerce site. In particular, make sure they are easy to understand. Also check that the mandatory information is mentioned.<\/li>\n<li>Check to see if additional consents will be required.<\/li>\n<li>Disable any default opt-ins you have in place.<\/li>\n<li>Ensure that separate consents are in place for separate data processing activities.<\/li>\n<li>Allow customers to easily withdraw their consent and exercise their right to be forgotten, for example by allowing them to easily delete their account and erase their data. Rather than an online deletion process, you can redirect your customers to your customer service department, as Amazon does:<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-conformite-amazon.jpg\"><img decoding=\"async\" class=\"alignnone size-full wp-image-4748 img-responsive center-block lazyload\" data-src=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-conformite-amazon.jpg\" alt=\"RGPD conformit\u00e9 Amazon\" width=\"640\" height=\"748\" data-srcset=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-conformite-amazon.jpg 640w, https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-conformite-amazon-257x300.jpg 257w\" data-sizes=\"(max-width: 640px) 100vw, 640px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 640px; --smush-placeholder-aspect-ratio: 640\/748;\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>Allow access to data<\/h3>\n<p style=\"text-align: center;\">&#8221; <em>Arrangements should be made to facilitate the data subject [&#8230;] to request and, where appropriate, obtain without charge, access to and rectification or erasure of personal data and the exercise of a right of objection. <\/em>&#8220;<\/p>\n<p>The GDPR gives affected individuals the right to simple access to any information held on them and to obtain a copy of that data within one month.<\/p>\n<p>This means that you need to store the data you hold in a way that it can be accessed quickly.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Best practices for granting access to data :<\/strong><\/p>\n<ul>\n<li>Collect only the data you need to make your job easier. For example, if you have no business or marketing interest in asking a client what company they work for, then don&#8217;t.<\/li>\n<li>Gather all the data you hold in one place and make sure you can retrieve it in a structured, readable and downloadable format so you can send it easily.<\/li>\n<li>Make sure you are in control of the information you hold, by carrying out a full mapping of your data and recording it in a data processing register. The CNIL provides you with model registers to download here: <a href=\"https:\/\/www.cnil.fr\/fr\/cartographier-vos-traitements-de-donnees-personnelles\" target=\"_blank\" rel=\"noopener noreferrer\">cnil.fr\/cartographing-your-personal-data-processing<\/a>.<\/li>\n<li>Set up a contact form so that people can request access to their data if they wish.<\/li>\n<li>Be able to respond to potential data access requests, for example by drafting a standard email template.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>Implementation of confidentiality<\/h3>\n<p style=\"text-align: center;\">&#8221; <em>Personal data should be processed in a way that ensures appropriate security and confidentiality.<\/em> &#8220;<\/p>\n<p>As a company or e-commerce, you collect sensitive information: credit card numbers, location, e-mail addresses&#8230;<\/p>\n<p>Since the implementation of the GDPR, you will need to be explicit about what happens to that data. Where are they going? Who will use them? Who is responsible for their storage and processing?<\/p>\n<p>You must prove that data security is ensured by all departments of your company: marketing, IT, communication, etc.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Good privacy practices :<\/strong><\/p>\n<ul>\n<li>Share information internally about security processes to ensure your team and supply chain are comfortable and compliant with the GDPR.<\/li>\n<li>Include a confidentiality clause in your contracts with your subcontractors. To help you, the CNIL provides you with several <a href=\"https:\/\/www.cnil.fr\/fr\/sous-traitance-exemple-de-clauses\" target=\"_blank\" rel=\"noopener noreferrer\">examples of clauses<\/a>.<\/li>\n<li>Appoint a DPO (Data Protection Officer), if you are one of the companies that are obliged to do so (public body, organisation with large-scale surveillance activities and organisation processing so-called &#8220;sensitive&#8221; data).<\/li>\n<li>Take the necessary security measures by implementing the basic precautions gathered by the CNIL in this <a href=\"https:\/\/www.cnil.fr\/fr\/principes-cles\/guide-de-la-securite-des-donnees-personnelles\" target=\"_blank\" rel=\"noopener noreferrer\">guide<\/a>.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<blockquote><p><em>Also find out how to <a href=\"https:\/\/www.alioze.com\/en\/protect-cyberattack\/\" target=\"_blank\" rel=\"noopener\">protect your business and e-commerce from a cyber attack<\/a><\/em><\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<h3>Data transparency<\/h3>\n<p style=\"text-align: center;\">&#8221; <em>The principle of transparency requires that any information and communication relating to the processing of such personal data be easily accessible, easy to understand, and formulated in clear and simple terms.<\/em> &#8220;<\/p>\n<p>The <strong>GDPR<\/strong> emphasizes data transparency.<\/p>\n<p>You must therefore ensure that the information you provide is clear and easily understandable, and that individuals can easily assert their rights in relation to their personal data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Good practices for data transparency :<\/strong><\/p>\n<ul>\n<li>Provide &#8220;information notices&#8221; informing individuals of the purpose of the various data collected. To help you, the CNIL offers a <a href=\"https:\/\/www.cnil.fr\/fr\/modeles\/mention\" target=\"_blank\" rel=\"noopener noreferrer\">generator of mentions<\/a> for different sectors of activity (marketing, banking and insurance, health, real estate, etc.).<\/li>\n<li>In the context of an e-commerce business, be very clear about how you will use the data you collect, both in your terms and conditions and in your privacy policy.<\/li>\n<li>Link your general terms and conditions (GTC), as well as your privacy policy, in the footer of your website.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<blockquote><p><em>See also our article on tips for\u00a0<\/em><a href=\"https:\/\/www.alioze.com\/en\/general-terms-conditions-sale\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>drafting your GTCs<\/em><br \/>\n<\/a><\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ul>\n<li>If you have &#8220;Third Party Use of Data&#8221; checkboxes on your website, specifically list the &#8220;third parties&#8221; who may have access to the data.<\/li>\n<li>If you have certified or verified processes, don&#8217;t hesitate to mention them on your e-commerce site, as Zalando does:<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-e-commerce-zalando.jpg\"><img decoding=\"async\" class=\"alignnone size-full wp-image-4750 img-responsive center-block lazyload\" data-src=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-e-commerce-zalando.jpg\" alt=\"RGPD e-commerce Zalando\" width=\"693\" height=\"376\" data-srcset=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-e-commerce-zalando.jpg 693w, https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-e-commerce-zalando-300x163.jpg 300w\" data-sizes=\"(max-width: 693px) 100vw, 693px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 693px; --smush-placeholder-aspect-ratio: 693\/376;\" \/><\/a><\/p>\n<h3><\/h3>\n<p>&nbsp;<\/p>\n<h3>Data breach notification<\/h3>\n<p style=\"text-align: center;\">&#8221; <em>As soon as the controller becomes aware that a personal data breach has occurred, it should notify the supervisory authority<\/em> as soon as possible.&#8221;<\/p>\n<p>With the GDPR, you are required to report any data breach to the CNIL within 72 hours of discovery and be able to demonstrate your data security and privacy procedures very quickly.<\/p>\n<p>The data subject must also be notified if the violation would result in a high risk to his\/her rights and freedoms.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Best practices for data breach notification :<\/strong><\/p>\n<ul>\n<li>Make sure you have procedures in place in the event of a data breach.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>GDPR: what sanctions if you do not comply?<\/h2>\n<p>Any company found to be in breach of the new GDPR guidelines can face an administrative fine of up to 4% of annual worldwide turnover or \u20ac20 million &#8211; whichever is higher. But it would take a serious breach of the rules for such a financial penalty. This type of fine will therefore be a last resort.<\/p>\n<p>However, this does not mean that there are no repercussions for non-compliance with the GDPR. Through public reminders and warnings, regulators will require non-compliant organisations to take the necessary steps to become compliant.<\/p>\n<p>Also consider the reputational damage that could result from a data breach. In addition, data subjects have the right to take legal action and claim compensation in the event of a data breach.<\/p>\n<p>&nbsp;<\/p>\n<p>In conclusion, use the GDPR as a guide on how you should collect, manage and store your customers&#8217; personal data! Beyond the workload that compliance may entail, consider the opportunity it presents to give your customers greater confidence and a better shopping experience.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>To go further, you can consult these GDPR resources:<\/strong><\/p>\n<ul>\n<li>CNIL guide to preparing for the GDPR: <a href=\"https:\/\/www.cnil.fr\/fr\/principes-cles\/rgpd-se-preparer-en-6-etapes\" target=\"_blank\" rel=\"noopener noreferrer\">www.cnil.fr\/fr\/principes-cles\/rgpd-se-preparer-en-6-etapes<\/a>.<\/li>\n<li><a href=\"https:\/\/www.alioze.com\/wp-content\/uploads\/2018\/02\/rgpd-texte-officiel.pdf\">PDF of the official GDPR text<\/a>.<\/li>\n<li>Video of youtuber Cookie made in collaboration with the CNIL to answer questions about the arrival of the GDPR :<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<div class=\"text-center\"><iframe src=\"https:\/\/www.youtube.com\/embed\/OUMGp3HHel4\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A source of concern for many businesses and e-tailers, the GDPR\u00a0came into force on 25 May 2018. If you handle online payments or manipulate data of EU residents for commercial and marketing purposes, you are one of the organizations concerned! To put an end to your worries, we help you to see more clearly by [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":24959,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[335,311,574],"tags":[797,796,798,779],"class_list":["post-24782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-e-commerce","category-good-practices","category-security","tag-gdpr","tag-gdpr-compliance","tag-gdpr-good-practises","tag-general-data-protection-regulation"],"acf":[],"aioseo_notices":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/posts\/24782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/comments?post=24782"}],"version-history":[{"count":3,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/posts\/24782\/revisions"}],"predecessor-version":[{"id":24943,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/posts\/24782\/revisions\/24943"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/media\/24959"}],"wp:attachment":[{"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/media?parent=24782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/categories?post=24782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.alioze.com\/en\/wp-json\/wp\/v2\/tags?post=24782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}