25/May/2017
Gone are the days when retailers could just collect customer emails in bulk to be used at later date for a purpose that hasn’t been identified yet. Why? The GDPR makes it very clear that those who collect personal information for purposes they haven’t been given explicit consent for will face heavy consequences.
If you are a sales person in one of the shopping centres in London and you want to offer the next promotion to your customers by e-mail, you must inform your customer what your company will do with that email address.
From the customer perspective, GDPR constraints are effective and good because they put responsibility on the retailer to pursue the customer for consent, and also explain to them in plain terms what they plan to do with the data.
From the retailer perspective, this might seem as a daunting task. Not only because most of the today’s marketing strategies include e-mail marketing, promotions, and even targeted product advertisements to their pool of customers, but also because retailers themselves will most likely be data controllers, which make them responsible for actions, or lack of actions, of their supply chain. Not having full visibility of your supply chain is no longer an excuse. If a processor mishandles data, both controller and processor are on the hook. That is why it’s so important to ensure your supply chain is compliant and you make sure you have a complete visibility of it.
Here are the requirements on how personal data must be collected and handled according to GDPR:
Not all of these principles are new, since most of them are present in the Data Protection Act. However, there are some additions, particularly to the data subjects’ rights:
Being compliant with any of these requirements means that retailers should first make sure whether customers have given informed consent to process their data, how this data is processed and where it is stored.
Retailers might be struggling to manage customer data due to the sheer amount of it which they operate. This means they may find it challenging to comply and have to start their journey as soon as possible.
Time is running out for retailers to take actions to prepare for the regulation to come into effect and retailers must be prepared for their customers requests, should they wish to exercise their rights.
Read our blog 7 steps to get ready for GDPR.
Ask how CyReg™ GDPR can help you to address the challenges that the regulation brings.
contact@cynation.com
+44 020 3190 5000
PopHub Leicester Square
41 Whitcomb Street
London WC2H 7DT
contact@cynation.com
Oude Udenseweg 29
5405 PD Uden
The Netherlands