Conducting Compliant Marketing & SARs Workshop - CMG Events

Slides:



Advertisements
Similar presentations
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Advertisements

Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Finance and Governance Workshop Data Protection and Information Management 10 June 2014.
Topic 4 How organisations promote quality care Codes of Practice
EU Data Protection IT Governance view Ger O’Mahony 12 th October 2011.
Data Protection Act AS Module Heathcote Ch. 12.
Digital Banking and Data Protection Achieving balance of compliance with customer experience and opportunity 30 September 2015 Paula Barrett Partner.
INTRODUCTION TO DATA PROTECTION An overview of the Irish Data Protection legislation.
Serving the Public. Regulating the Profession. CANADA’S ANTI-SPAM LEGISLATION (CASL) Training for Chapters Based on Guidelines for Chapters First published.
Castlebridge associates | | Castlebridge changing how people think about information How to Implement the.
The Data Protection Audit How to prepare What to expect The end results Dublin Chamber of Commerce, March 24 th.
Commissioning Services: with the DPA in mind South Yorkshire Information and Data Sharing Group Sheffield 14 th August 2014 Lynne Shackley Lead Policy.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
General Data Protection Regulation (EU 2016/679)
Political campaigning: data protection & electronic marketing
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Data Protection Officer’s Overview of the GDPR
Fundraising Regulation: What does it mean for charities?
Running Compliant Direct Marketing
Ian De Freitas, Partner, Farrer & Co 6 September 2017
What Does GDPR mean for you
Privacy principles Individual written policies
Viewing the GDPR Through a De-Identification Lens
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
KEY CHANGES TO THE DATA PROTECTION LANDSCAPE
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Data Protection Legislation
GDPR Overview Gydeline – October 2017
Research Ethics Matthew Billington
GDPR Road map to Compliance.
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
6 Principles of the GDPR and SQL Provision
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
helping to create effective and efficient tax systems
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
Are you processing personal data lawfully?
G.D.P.R General Data Protection Regulations
Current Privacy Issues That May Affect Your Credit Union
The new data protection rules
Ethical questions on the use of big data in official statistics
The gdpr – one month down the line
General Data Protection Regulation
Ground Rules. Ground Rules Technology We can provide details of all data electronically All data is securely stored We can fulfil the ‘right.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
Preparing for GDPR Sharing experiences of the process and using the British Canoeing Toolkit bit.ly/BCGDPRToolkit
How we’ll prepare for the General Data Protection Regulation (GDPR)
General Data Protection Regulations (GDPR) Training
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
GDPR – Data Protection Law on Steroids?
GDPR Quiz Today’s trainer: Click here to use Kahoot! 1
The General Data Protection Regulation Six months on – What’s changed
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
#eaThinkData Get Ready for GDPR #eaThinkData.
GDPR – General Data Protection Regulation
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
GDPR Session
General Data Protection Regulation “11 months in”
General Data Protection Regulation Community Councils
GDPR Workshop – Partnerships for Jewish Schools
Data Privacy and GDPR Jane Shvets
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Conducting Compliant Marketing & SARs Workshop - CMG Events www.castlebridge.ie Data Privacy Information Governance Information Quality (c) 2015-2016 Castlebridge - distributed with permission

Direct Marketing & GDPR Understanding the Link between Marketing activity, Subject Access Request, and GDPR Hosted by

G GDPR overview

Gdpr Enhanced rights for data subjects Accountability, Transparency, Security Fines and enforcement by Regulator

rights for data subjects Right to object to processing Right to withdraw consent to processing Right to Subject Access Request

Responsibilities for companies Fair and lawful obtaining of data Adherence to standards of GDPR Document processes to demonstrate compliance

gdpr – A risk based approach Identify risks Assess level of risk aversion Minimise exposure and implement best practice

RISKS AND IMPLICATIONS OF direct marketing

Direct marketing Information about products, services, events Linked by a call to action Asking subject to exchange money, data, or time

direct marketing risks Bad/unlawful marketing annoys customers Customers are more aware of their rights Angry customers more likely to complain

Risks to business Reputational damage/loss of customer faith Subject Access Request or prosecution by DPC Operational risks: fines or cease processing of data

Dpc and complaints 58% increase in complaints to DPC in 2016 Data subjects increasingly exercising SAR rights Bad marketing is a driver of Subject Access Requests

Subject access requests Data subject has right to request copy of all data held  Estimated cost in resourcing and outsourcing single SAR:  Minimum: €700                Maximum: over €100k

Other sanctions Fines of 2% / 4% of turnover, or €10m / €20m Notice to stop processing could be more damaging Potential to massively disrupt business 

GDPR and Direct marketing

direct marketing methods Electronic mail Calls and texts Landline / Postal

Obtaining data Processes for obtaining data must comply with GDPR Must be able to explain where data came from Must be able to explain nature of processing 

Consent and electronic mail Opt-in required Inform at time of data capture of DM purpose Must tell customer who is sending email/sms Simple and free mechanism for contact/opt-out  

Consent and calling Landlines Opt-out Inform at time of data capture of DM purpose Check on NDD for “Do-Not-Call” notice Simple and free mechanism for opt-out  

Consent and calling mobiles Opt-in required Inform at time of data capture of DM purpose Simple and free mechanism for opt-out  

Marketing to existing customers Needs to be for similar product as originally bought New consent required if done on behalf of third-party Best practice requires Opt-in at point of sale Simple and free mechanism for opt-out on every message  

Marketing and OTT services OTT = Twitter, Facebook, WhatsApp, Skype etc. Best practice = do not use these channels Loss of control over data through use of OTT services

Marketing essentials Rules apply to both B2C and B2B Simple and free opt-outs must be provided Do not use pre-ticked boxes Do not use OTT services 

RISK mitigation strategies

First steps Review how you engage in direct marketing Review consent, and ensure adherence to GDPR  Document processes to demonstrate compliance

Assess direct marketing methods How do you market? Document these processes  Ensure data has been lawfully obtained Ensure highest standards of consent 

Minimising exposure Principle of Data Minimisation Ethical approach to data processing Application of best practice checks and balances

Ethical data handling Care for your customer or client Respect data and privacy rights of individual Acquire data in a lawful manner

Demonstrate compliance Document all processes around data processing Ensure transparency and clarity in policies, T&Cs, etc. Ensure highest standards of security 

To conduct marketing in a compliant manner under GDPR, you will need to document processes and information flows relating to marketing activities.

Benefits of compliance G Benefits of compliance

Customer care Greater customer trust Greater customer engagement through transparency Enhanced reputation for your company  

Risk minimisation Lower chance of complaints re: direct marketing Lower chance of receiving Subject Access Request Lower exposure to fines from regulator (DPC) 

Streamlined business Data Minimisation good for any organisation Process documentation = good information governance Documentation allows for better marketing  

G Key takeaways

Direct marketing & gdpr DM is a legitimate business interest under GDPR Responsibilities towards customers and their data Risk of fines/Subject Access Requests for non-compliance

Better direct marketing Risk mitigation through data minimisation Lawful obtaining of data and GDPR compliance Better customer engagement through transparency

Conducting Compliant Marketing & SARs Workshop - CMG Events www.castlebridge.ie Data Privacy Information Governance Information Quality (c) 2015-2016 Castlebridge - distributed with permission