The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union. The GDPR aims to give control back to individuals regarding their personal data. The regulation has been around since 2016 but is coming into force on 25th May 2018 with hefty fines for non-compliance.

There are lots of great articles explaining GDPR in more detail. I’ve included links to these in the footer of this post. However, this article is specific to your website and contains our guidance to the 3 essential steps we suggest you take to get your website GDPR compliant.

There is lots to cover so this is a no-fluff post where we’ll get straight into exactly what we suggest you do.

The 3 steps are:

  • Step 1 – Obtain and add to your website the necessary legal documents
  • Step 2 – Install a GDPR compliant cookie consent tool on your website
  • Step 3 – Ensure all website forms are GDPR compliant

Step 1 – Obtain and add to your website the necessary legal documents

GDPR Compliant Privacy Policy

The new regulations require that you have a GDPR compliant Privacy Policy on your website which covers all aspects of how you collect, store and process data within your business. This document is the backbone of your GDPR website compliance.

GDPR Compliant Cookie Policy

Cookies are small pieces of code that are downloaded to your visitor’s browser so your website can track certain events. You are required to have a GDPR Compliant Cookie Policy on your website which details any cookies your website uses and what it uses them for.

Terms and Conditions of Use

Terms and Conditions of Use are not a GDPR requirement, however, there are two reasons we strongly recommended you use them:
1. You are required by law to provide certain information on your website. Including this information in your website terms and conditions is the most common and arguably the most effective method of doing so.
2. You can protect your business from a variety of risks by including specific clauses in your terms and conditions which exclude or limit your liability towards website users and protect your intellectual property rights.

Where can you get these legal documents?

These legal documents can either be drawn up by a solicitor or you can purchase a set of templated documents which you can then customise to your business. We do not recommend using a free template off the internet as it is unlikely these will offer adequate cover.

There are some very good services available and the one which we are recommending to our customers is called GDPR Privacy Policy. We have negotiated a discount with them which enables you to get all three documents for just £480+VAT. The three documents come with excellent guidance notes to help you customise them. Please get in touch if you’d like help with your GDPR privacy documents.

Once you have customised the documents, ask your web developer to add them to your website. The most common place is to include links to each document in the bottom section of each page of your website.

Step 2 – Install a GDPR compliant cookie consent tool on your website

Depending on what cookies your website uses, you will need to get your users consent before cookies are placed on your users’ computers. Cookies for which you require consent include:

  • Cookies used for analytical purposes e.g. to count the number of unique visits to your website
  • First and third party advertising cookies
  • Cookies used to recognise a user when they return a website so that the greeting they receive can be tailored

As most websites have some kind of analytical tracking, we suggest installing a tool which requires users to click to opt-in to cookies before they are placed on their machine. There are a number of tools available but we recommend the same tool that is used on the ICO (The Information Commissioners Office) website. This tool is called Cookie Control v8 and is by Civic. There is a free version which should be adequate in most circumstances.

To set this up…

  • Go to https://www.civicuk.com/cookie-control/v8/download
  • Select the free community edition of the tool
  • Complete the form and then submit
  • This creates an account for your domain and issues you with a snippet of code
  • Copy and paste this code and send it to your web developer and ask them to add it to your website

If your website has been built using a modern CMS (content management system), such as WordPress, it shouldn’t take your web developer more than an hour to install and test this functionality.

Step 3 – Ensure all website forms are GDPR compliant

Depending on the purposes for which you process (i.e. collect, obtain or use) an individual’s personal data (i.e. information that relates to an individual from which that individual can be identified, directly or indirectly e.g. name, address, email address etc.), you must obtain that individual’s consent prior to processing it.

The exception to this is if you are responding to an enquiry relating to your goods or services. In this case, you do not need consent or an opt-in box. However, what you would need consent for (and therefore an opt-in box), is for marketing to that person at a later date e.g. to sign up for your mailing list. You could not simply add someone who had made an enquiry to your mailing list.

To ensure all your forms are compliant make sure…

  • You are only asking for essential information
  • You include an explanation for any non-essential information
  • You include an opt-in tick box if you want to use their information for future marketing
  • You ensure that the delivery of the information is covered in your Privacy Policy

Check all the forms on your website and if you need to remove any non-essential fields or add opt-in boxes, speak to your website developer to get this done to ensure they are GDPR compliant.

Summary

If you work through these three steps and get the help of your web developer, you should end up with a GDPR compliant website.

Disclaimer

This blog post is meant as guidance only and NOT legal advice. In most cases, these three steps should ensure your website is compliant. However, we do recommend that you get a solicitor or GDPR professional to check your website once you have implemented these three steps to confirm it is compliant.

Resources

Here are a few links to some of the many articles and resources relating to GDPR:

 

 

Article written by:

Previous Post
Is Content Marketing For You?
Next Post
Getting better search engine results in 2018