Is your website ready for the new GDPR privacy law?

The General Data Protection Regulation (GDPR) comes into effect on 25 May 2018. The same rules on privacy will then apply for all EU member states. For websites, this new regulation has major consequences.
Not complying with the rules can, from May 2018, lead to a fine of up to 4% of annual turnover and up to an amount of €20 million. So read this blog carefully and check whether your website meets the new requirements.

The new GDPR legislation in brief

The GDPR is quite a bit stricter than its predecessor (the Dutch Personal Data Protection Act). It’s a fairly extensive law, with the most important components for a website being:

  • Visitors must actively give consent for the recording of personal data
  • A person may request the data and also demand that the data be corrected/deleted
  • All data you collect must be recorded
  • You may only collect data you can demonstrably justify needing
  • The security of the information must be strong and up to date.

These are the things you need to sort out now

This regulation has major consequences. So you need to get the following things in order before 25 May 2018.

SSL certificate

The biggest consequence for many websites is that an SSL certificate is now mandatory for webshops and websites that process user data (for example with a contact form). Such a certificate demonstrates that you protect personal data properly.
Below are two examples of SSL certificates. You’ll see https, the company name or “secure” and a padlock in the address bar.
SSL GDPR
SSL certificate example
With such a certificate you prevent being in breach, visitors gain more trust, and you prevent Google from removing you from the search results, since they don’t want to display unsafe websites.
We can arrange this SSL certificate for you. Get in touch and we’ll help you further.

Cookie consent

There’s a difference between functional cookies, analytical cookies and tracking cookies. The same rules apply to the first two, and a cookie notice suffices. But for tracking cookies (for example for remarketing and affiliate marketing), visitors don’t need to accept these to continue on the website. So cookie walls will no longer be allowed.
You therefore need to make sure visitors can also access the website without accepting tracking cookies.

Email opt-in

It’s now also legally forbidden to have the newsletter checkbox switched on automatically. You see on many websites that you’re automatically signed up for a mail campaign or newsletters. This is no longer allowed. Visitors must actively give consent for this by ticking the box themselves.
Newsletter opt-in checkbox
So this checkbox may no longer be switched on by default.

Storing personal data.

The personal data you collect must be demonstrably useful for your business and collected in a structured way. Citizens are, after all, allowed to request the collected information from you and demand that it be changed/deleted. So make sure you keep track of this clearly. Should your database of customer data get hacked, or should this data leak in some other way, you have a duty to report it. You can report that here.

Please note:

Webba is not a legal firm. We’ve looked into the consequences, and based on that we’ve written this article to help our clients get started with this legislation. For certainty, seek advice from a specialist.