Home » Business Email Etiquette Articles » Do You Understand GDPR, Privacy, and Data Collection?

Do You Understand GDPR, Privacy, and Data Collection?

GDPR and your email and data privacy statement.

It has become common to land on a website and have a banner or pop-up appear, talking about cookies. These notices are often in place to inform you about the website’s cookie and data collection practices.

What exactly are Cookies?

  • Cookies are small files stored in your browser that do not contain personally identifiable information about you. They help websites understand your behavior patterns while you visit them.
  • Cookies and scripts from Google Analytics track your browsing activity, including where you go and what you click on. No personal data is gathered unless you specifically provide it, for example, through a website form.
  • Data is also collected regarding how long you stay in various site areas. Your browser also relays the browser and version you are using, as well as your platform (Mobile, PC, or Mac).

All this information helps site creators ensure their websites cater to visitors’ interests. In addition, the types of devices accessing a website are logged, as different devices can display content differently.

However, when you do fill out forms or place an order, how is that resulting data handled? Where is it stored, and for how long? What exactly is it used for, if anything?

This is why you need a privacy policy on your website, so site visitors know your policies and can read them at their convenience. Flip that coin, and it is a good idea for you to get in the habit of reviewing the privacy policies of the websites you frequent as well.

Privacy is the Topic of the Day

On May 25, 2018, the EU’s General Data Protection Regulation (GDPR) went into effect. This required visible disclosure of how data is stored and handled, and must include the ability for individuals to request what information you have and to delete it if they so desire.

What if you are a website owner and do not do business in the EU? In that case, you should still become familiar with the regulation and consult a legal expert for their recommendations as it pertains to your specific operations.

  • How does this impact American businesses?

    Recognizing that data can travel well beyond the borders of the EU, the GDPR protects EU citizens regardless of where their data is stored or processed. This means that any company, anywhere in the world that has a database that includes EU citizens, is bound by its rules. Businesses of all sizes are affected — from micro to multinational. No one is exempt.

    To comply, American companies can either block EU users altogether (an impractical choice for a multinational brand) or implement processes to ensure compliance.

Privacy is a huge concern, period, regardless of what continent you are on. So I advise my clients to review or create a Privacy Policy if they don’t have one, and to have a cookie statement (like the one on this site).

As a business owner, you want to be transparent about your data collection policies and procedures. Regardless of GDPR, that’s just good business! This includes your email newsletters and communications as well.

Now that almost every website is displaying and updating its policies, it’s just wise for you to do the same. You don’t want customers wondering why everyone but you is upfront about this topic while you remain silent, do you?

GDPR Resources

Here are a few resources from when these regs were put in place that are still relevant for those who are playing catch-up.

If you are in the United States and do not conduct business in the EU, consider the GDPR as an opportunity to be upfront and transparent about your policies. It is highly beneficial for your brand to clearly state that you take great care of your customers’ data.

Especially online, transparency is a trust factor.

Business Email Etiquette eBook
Share the knowledge!

Similar Posts