Categories
Best practice Europe Legal & Compliance Strategy and Management UK

Customer consent and new regulations: check-out your ‘golden ticket’

Do you have clear permission to contact your customers, a ‘golden ticket’ of consent? And can your customers easily opt-out and withdraw that consent? Scrutinise your data protection and ePrivacy strategy now, as new regulations come into force next year – and millions of pounds in fines will doubtless be levied on companies that have failed to prepare and follow the guidelines.

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Data Protection Europe GDPR Legal & Compliance Strategy and Management UK

Get your house in order ready for incoming data protection rule

Shape up or ship out: that’s the warning for those who fail to prepare for the imminent data protection rule. The European Commission’s plan for the first overhaul in data protection legislation in more than 20 years is unrelenting – and fast approaching. Are you ready?

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Europe In the News Legal & Compliance Strategy and Management USA

Data privacy fears threaten $250bn transatlantic trade

us-eu-flags-2The uncertainty is being fuelled by a double whammy of scepticism about how robust Privacy Shield is and fears that the alternative method, used by 80% of companies – the so-called standard contractual clauses (SCCs) – could be soon be rendered illegal.

According to a survey of 600 data professionals in the US and EU, only 40 US firms have so far adopted Privacy Shield, with just 34% intending to use the new data privacy framework, compared with 50% which used its Safe Harbour forerunner.

The situation is not being helped by EU data regulators sitting on the Article 29 Working Party (WP29). Although they approved the framework in late July, they have set off alarm bells by pledging to keep a close eye on how Privacy Shield develops.

Data privacy Shield assessment

At the time, they released a statement which said: “The first joint annual review will be a key moment for the robustness and efficiency of the Privacy Shield mechanism to be further assessed.”

US think tank the Brookings Institution has estimated that “digitally delivered services” between the EU and the US – including customer data storage – were worth nearly $250bn (£188bn) in 2015.

IAPP president and chief executive Trevor Hughes commented: “The legal uncertainty of standard contractual clauses and the scepticism about Privacy Shield may be a hangover effect from the Max Schrems case that invalidated Safe Harbour in the European courts. Clearly, organisations face an extremely complex regulatory landscape as they look to build their businesses for the digital future.

“It will be vital for them to employ privacy professionals at the highest levels of management to help navigate that landscape and capitalise on opportunity.”

Categories
Europe In the News Legal & Compliance Strategy and Management UK

Data protection: gulf widens between customer expectation and reality

A series of white papers are being released, addressing the potential impact of the upcoming European General Data Protection Regulation (GDPR) on business-critical processes.

The first white paper focuses on Permission – how consumers give consent to a company to use their personal information, how aware individuals are of the process and how important permission-to-market is for companies.

The research, conducted by DataIQ in association with DST (global provider of specialised technology, strategic advisory and operations outsourcing to the financial and healthcare industries), reveals a disconnect between the way that consumers want businesses to treat their data and how businesses currently approach their customers’ data.Privacy

Among the paper’s key data protection findings:

– 78% of companies say it is vitally important to process data for legitimate business interests

– 28% of consumers believe they should always be asked for permission to use their data

– 21% of consumers believe that data consent should only be valid for six months

– 21% of consumers believe their data should be deleted straight away

– Only 15% of businesses track permission company-wide

– 41% of consumers don’t mind providing their data if they understand how it will be used

According to Ruaraidh Thomas (pictured), managing director at DST Applied Analytics, with so few companies currently tracking permission as a key performance indicator, there is a lot of work to be done in order for businesses to be ready for the GDPR.Discussing GDPR

“With such a high degree of connectivity and internet activity, consumers are increasingly faced with requests for their personal information and their permission to make use of it,” says Thomas. “It’s clear from this research that companies need to work to understand their customers’ expectations when it comes to sharing data in order to build long lasting relationships, especially given the upcoming GDPR.”

The GDPR is an important update to laws covering the capture, control and consent to use of personal information. While built on the core principles already established by the Data Protection Directive in 1998, GDPR also introduces new rights for consumers and new obligations for businesses.

According to DataIQ/DST research, a quarter of consumers said incentives like better price or money-off can work as a driver for the data-value exchange. The research also found that a large percentage of people just need to understand why their data is needed.

“In preparation for the GDPR, businesses must take note of how consumers wish to be engaged, especially since so many businesses rely on data as part of their business model,” says Thomas. “The fact that some consumers are happy to provide their data if they understand what it is to be used for, demonstrates just part of the opportunity available for businesses that respond appropriately.”

Categories
Data Protection Europe GDPR In the News Legal & Compliance Strategy and Management UK

EU: May 25 2018 is data protection rule implementation date

eu-yet-againAlthough the data protection reforms have already been passed, the date has only just been released following the GDPR’s publication in the EU Official Journal.

The move comes as the Information Commissioner’s Office has revealed it will be publishing GDPR compliance guidance in stages over the two-year implementation period – rather than as a single document – with each piece of guidance addressing a specific topic.

DMA group chief executive Chris Combemale (pictured) said: “Data is at the heart of the modern economy, so as an industry we must be responsible for our actions when handling consumer data and create new frameworks that fit with the GDPR over the next 24 months.DMA group chief executive Chris Combemale

“The new legislation will not only help protect the consumer, but also safeguard brands’ own reputations by ensuring their customers are at the heart of everything they do. The starting pistol has now fired and the two-year countdown has begun, but successful businesses will be those that treat this time as a full distance race rather than a last minute sprint.”

The ICO has also confirmed that the EU plans to have conducted its review into the ePrivacy Directive within the two-year implementation period for the GDPR, although many have described this as “ambitious”.

The Commission has launched a consultation on the current text of the Directive, as well as possible changes to the existing legal framework to make sure it is up to date with the new challenges of the digital area.

The Directive was last updated in 2009 to provide clearer rules on customers’ rights to privacy. In particular, new requirements were introduced such as on “cookies” and on personal data breaches.

Categories
Best practice In the News Legal & Compliance Strategy and Management UK

Compliance: consent should be given not taken, says watchdog

“It’s simply not good enough for people to buy and sell data if they have no means of satisfying themselves that the people involved have given consent for the information to be shared in the way proposed.”

This content is for Free membership members only.
Register
Already a member? Log in here
Categories
Best practice Europe Insight Legal & Compliance Strategy and Management UK

Privacy and social media: incompatible or indispensable?

Do ‘digital natives’ care about privacy? Whether they do or not, Richard Beaumont says its a deep-seated cultural expectation that businesses should remain well aware of.

This content is for Free membership members only.
Register
Already a member? Log in here