A Quick Guide To GDPR For Your Website

I’m sure by now you will be aware that the new EU General Data Protection Regulation (GDPR) begins on the 25th of May 2018. In simple terms, the GDPR says that Users (those visiting your website) have complete control over their data, and you have to tell them why you need it. At that point, the User can say yes or no.

It sounds easy enough, but in practice, it’s a little more complicated.

We can’t advice you on how to adapt your business internally to comply with GDPR but we can offer some tips on what to do with data on your website. All businesses within the EU are affected but note that even if you are trading outside of the EU, you still need to comply if your Users are in the EU.

So, make sure you get advice if this applies to you as non-compliance means you could be fined up to 20 million Euros!

For more information on GDPR check out the Information Commissioners Office website, but here’s what you are responsible for:

  • Explaining who you are, how long you’re keeping the data, why you need it, and who on your team (or externally) has access to it.
  • Getting explicit and clear consent to collect data through an opt-in on your website.
  • Giving Users access to their own data, the ability to download it, and to delete it from your records completely.
  • In the event of a hack or security breach, letting your Users know about it.

So, with that being said, let’s get specific. What does it mean in practicable terms?

  • Big Fines

    Monetary administrative penalties of 20 million Euros or 4% of worldwide revenue if your organisation is not in compliance.

  • EU Citizens

    You are subjected to GDPR even if you don’t have a physical presence in the EU; if you provide goods or services to EU citizens, it affects you.

  • Personal Data

    The definition of personal data is expanded and clarified to include IP addresses, cookie identifiers, and GPS locations.

  • Consent

    Explicit consent and transparency is required; this means that inactivity and pre-checked boxes are not considered consent.

  • Right To Be Forgotten

    EU citizens have the right to be forgotten and personal data must be erased upon request.

GDPR – Opt-in’s On Your Website

Many of our Clients have an opt-in on their website and this is one of the most important aspects regarding GDPR compliance. Note that an opt-in is very different to an opt-out. Under GDPR, you must get Users clear consent to process the data.

That means that Users on your website have to explicitly say yes, and not just have the option to say no.GDPR_Barnstaple_ North Devon

Example…

If you have an online contact form with a checkbox and text that reads

“[x] Yes, I want to sign up for your Monthly Newsletter.”

If the [x] box is checked by default, then you are not complying – and you are at fault. In this example, you’re giving Users the chance to opt-out – but that’s not what the GDPR opt-in rule says. Users must explicitly choose to share their information with you.

GDPR – What Information Do YOU Need?

The rule of thumb needs to be to take no information by default and take as little as possible even when you do get explicit permission.

A lot of websites with contact forms ask for information they really don’t need. It is worth asking yourself what information you need from an enquiry or opt-in on your site. If you don’t need a Users name at that point, don’t take it. Do you need a full name, or just the first name? Maybe just an email is enough?

It’s not that you can’t ask for that information – you need to state WHY you need it!

If you are going to ask for first and last names, tell your Users why; “We ask for your full name so that we can personalise our correspondence with you”.

If you require a Users’ date of birth make it very clear that you are asking because you send them a birthday gift or card.

So, due to GDPR, you now only ask for information that is essential – it’s not something to keep just in case you may need it sometime in the future.

Having thought about what is required from your Users, you can then add notes beside, above, or below contact form fields. For example, if you ask for their phone numbers, you could have something next to the field such as “We ask for your phone number so our customer service representatives can contact you without delay”.

Additionally, you have to disclose who you are, how long the data will be stored, and who uses it – or receives it. For the purposes of online contact form pages on your website, it means putting that information clearly at the same time as you are requesting Users information.

This is no different than the required footers that email services require you to provide. So, for any contact forms, sign-up forms, checkout pages, or wherever, Users may give you their information online, you need to clearly identify who you are and what you do with the information.

For example…

“This website’s data is handled by Mrs. A. B. Childs, the owner, operator of XY Systems.”

Or…

“Data submitted using this form will be used by XY Systems and no one else.”

GDPR – Your Privacy Policy Page

The most important update to your Privacy Policy under GDPR is that your policy needs to be written in a way that is clear, understandable, and concise. Just as it always should have been, the intent of the Privacy Policy is to describe what you do in a clear manner and then, most importantly, your company needs to follow through and do what it says.

Remember that your audience for the Privacy Policy is the User and not a solicitor!

Create explicit required fields on every form indicating acceptance of your Privacy Policy before processing anything. Checkboxes are preferable but you can add text fields where Users could type “I agree” (btw, these are horrible for Users, so we wouldn’t recommend!). The changes you make to your online forms need to be added to your Privacy Policy pages. Once again, include the details on the data’s why, how, and who.

Add a paragraph(s) into your Privacy Policy stating exactly how your site manages data to comply with GDPR. You should consider the following questions when writing:

  • What information is being collected?GDPR_Barnstaple_Devon_Date
  • Who is collecting it?
  • How is it collected?
  • Why is it being collected?
  • How will it be used?
  • Who will it be shared with?
  • What will be the effect of this on the individuals concerned?
  • Is the intended use likely to cause individuals to object or complain?

Specifically, you will need to provide detailed instructions explaining each of the following:

  • How to access and download a complete record of any data you have on them.
  • The process through which Users can fully delete their data from your records (and not simply unsubscribe, etc.) as a part of the ‘right to be forgotten’ laws previously passed in the EU.
  • Exactly how you will inform Users of data breaches if they ever happen.
  • Detailed explanations of who you are, what you use the data for, who has access to it, and how long you retain it.

GDPR – Google Analytics On Your Site

Google have posted plenty of information in their developer blogs regarding GDPR. With Google Analytics installed on your site, Google is your Data Processor. Your company is the Data Controller since you control what data is sent to Google Analytics.

There are 5 main points with Google Analytics that need to be addressed. If you are technically minded, you can make the changes neccessary yourself by following Google’s developer blog. As part of being a Data Processor, Google must provide a data processing agreement that you’ll need to accept – once you’ve completed the steps below.

  • Audit Your Data for Personally Identifiable Information (PII).

Collecting Personally Identifiable Information (PII) is against the Google Analytics Terms of Service. Check your Page URLs, Page Titles, and other data to ensure that no PII is being collected. A common example of PII data collection is when you capture a Page URL that contains an “email= querystring” parameter. If this is the case, you are most likely leaking PII to other marketing software in use on your site.

When a User enters information into forms on your website, if it is collected by Google Analytics, ensure that it does not contain PII.

Filtering out PII via Google Analytics filters is not sufficient; you must address this at the code-level to prevent the data from ever being sent to Google Analytics in the first place.

  • Turn on IP Anonymisation.

An IP address is considered PII under GDPR. Even though the IP address is never exposed in reporting, Google does use it to provide geo-location data.

We recommend turning on IP Anonymisation in Google Analytics. Note that this requires a code change to enable. If you use Google Tag Manager, adjust your tag or Google Analytics Settings by clicking into More Settings -> Fields to Set and then add a new field named ‘anonymizeIp’ with a value of ‘true’.

If you don’t use Google Tag Manager, your tag management system may have this setting exposed as an option, or you may need to edit the code directly.

Google will now anonymise the IP address as soon as technically possible by removing the last octet of the IP address. This will happen before storage and processing begins. “The full IP address is never written to the disk” when this features is enabled.

This change on your data is that geographic reporting accuracy is slightly reduced, ensuring GDPR compliance.

  • Audit your Collection of Pseudonymous Identifiers (hashed Emails, User ID’s).

Your Google Analytics setup may already be using pseudonymous identifiers, such as…

User ID: This should be an alphanumeric database identifier. This should never be plain-text PII such as email, username, etc.

Hashed/Encrypted Data such as Email Address: “Google has a minimum hashing requirement of SHA256 and strongly recommends the use of a salt, minimum 8 characters.” We do not recommend collecting data in this manner.

Transaction ID’s: Technically, this is a pseudonymous identifier since, when linked with another data source, it can lead to the identification of an individual. So, this ID should be changed to an alphanumeric database identifier.

Under both GDPR and the Google Analytics Terms of Service, this appears to be acceptable. This is why we recommend that your Privacy Policy is updated to reflect this data collection and purpose, as well as to gain explicit consent (via opt-in) from Users on your website.

In both cases, it needs to be clear to the User – so no technical or legal terms – and it needs to answer the questions of “what data is collected?” and “how it will be used?”.

At this point, you may be asking yourself how can you complete a request for a User to be forgotten?

This is very tricky as Google Analytics does not provide a method for selective data deletion. From a business point of view, it should suffice that you delete the User data or ID from your database or CRM to satisfy GDPR. This will prevent the record in Google Analytics from being associated to a known individual.

  • Update your Privacy Policy (see above).
  • Build an Opt In/Out Capability (see above).

What Next – Do The GDPR Changes Yourself?

As you can see, there are a lot of hoops to jump through prior to the 25th of May!

GDPR_Barnstaple_DevonThis is our interpretation and we recommend contacting a GDPR Consultant or solicitor to assess if there are any other measures you need to apply to your business.

Most of our Clients will require the changes above such as your Privacy Policy, Opt-In’s, Contact Forms, and Google Analytics. It’s what we will be doing to our website prior to the deadline too.

You can do all of this yourself using your website login provided when your site went live – we’ve provided some links below with more information on GDPR and how to comply – including all 99 pages of the full GDPR Document.

Or….

You Can Do It The Easy Way!

If you can’t make head nor tale of it all (and you’re not the only one!), we can get your website GDPR compliant within about 7 days of booking!

What changes will we make?

1. We will complete a GDPR audit of your entire website.

2. We will make essential changes to your Privacy Policy.

3. We will make essential changes to your Opt-In’s.

4. We will make essential changes to your Contact Forms.

5. We will make essential changes to your Google Analytics.

6. We will make any further changes found on your GDPR audit.

Leave it to us and you don’t need to trawl through all the techie stuff we had to read!

Simply complete the Form below and make payment using the PayPal button. We’ll get you booked in, run an audit and make all the necessary changes for you.

If you don’t have a PayPal account we accept payment by bank transfer too. Just let us know on the Form and we can forward our bank details.

If your business has any specific issues or requirements regarding GDPR that we may not be aware of, just let us know on the Form.

Book Your GDPR Website Compliance

£197

GDPR Audit. Online Marketing Devon: Right Click Digital

Book NOW!

* Indicates required field









Right Click Digital take your privacy seriously. This form collects your name, company, telephone, website address, email, and content so that we can administer your account, and to provide the products and services you have requested from us.

From time to time, we would like to contact you with details of our services, offers, and information regarding IT and marketing news relevant to online marketing.

Please check our privacy policy where you'll get more information on where, how, and why we store your data.




You're not a robot...are you? Then you know what to do now!

Some Light Reading – GDPR Style!