GDPR - General Business Tools in Privacy Policy?

Devcorp

Free Member
Apr 25, 2018
10
0
Hi
I'm trying to get ourselves GDPR compliant but there's so much scaremongering and random guesswork around the GDPR topic right now its hard to know whats what.

I'm trying to rewrite our website privacy policy but I'm a bit unsure about what to include.

We're a small service company with a "brochure" website, so we have a contact form but no actual shop, database, etc. However as a business we do use many cloud services such as office365, quickbooks, salesforce, etc. I see some sites set out all the services they use and what sorts of data go into them but these are all companies that sell services online. We use some similar tools to these guys but since they are business tools and not linked to the website operations I am correct in thinking these don't go into the privacy policy?

Do we need to have a list of each tool, its use, and data it holds out in public somewhere or we just keep that as an internal record should there ever be a data breach?
Thanks
 
Hi Devcorp

You're right ... there's still a fair amount of confusion and scaremongering around GDPR. The ICO website has a lot of useful information and their '12 Steps' summary is particularly good. We wrote a blog article about it last week, especially aimed at small businesses with straightforward websites so you might also find that useful.

Your starting point is to identify what personal data you actually 'process' and what you do with it. One of your obligations as a data controller, under the GDPR, is to document your internal processes and how/what personal data they use, how the data is secured etc. For you, a simple spreadsheet should suffice (the ICO website provides a sample spreadsheet that you can simplify). This is an internal document that you need to keep up-to-date.

Your privacy policy will probably need to be updated/enhanced since you are now obliged to specifically set out (amongst other things): the lawful bases you use to process personal data, data subjects' right to raise a complaint, your data retention policy (where relevant). So, there's a bit there but it's not as scary as it sounds.

You will also want to review and make sure that you're only capturing, using and retaining personal data that you really need.

There's certainly more to the GDPR that those few things, but if you're only capturing and using basic contact information then the burden on your business should not be great ... providing you're not doing anything dodgy with personal data.

Strongly suggest you have a look at the '12 Steps to Take Now' infographic at the ICO website to get started. GDPR is as much a 'mindset' change as well as a process change.

Hope that helps.
 
Upvote 0
Thanks Clickdocs, the sample spreadsheet from the ICO is really helpful as is their examples of good / bad privacy notices. I've seen a fair few of the "bad" ones out there these last few days while researching GDPR, its hard to imagine all these being updated within a few weeks.
 
Upvote 0
Very much agree, Devcorp. I think many struggle with the idea of 'legal basis'. Some people fall into the trap of thinking that they need consent to do anything with personal data. In fact consent, as the legal basis, is often the wrong reason to use.

Email marketing remains a minefield, and that's where consent plays a significant role. Email marketing is covered by additional legislation. And we also have the prospect of new cookie legislation before too long.
 
Upvote 0
I started off my GDPR quest with cookies - I thought it was going to be the short easy one to do but I was so wrong! Even figuring out what category Google Analytics cookies fall into was hard work, that was before I started trying and figure out what sort of consent is required for each cookie type and how then what to technically do about it. But I've read the eprivacy law isn't coming into effect until mid 2019 so I'm not sure what all the fuss is about - I'm going back to burying me head in the sand over cookies.
 
Upvote 0
My reading of the delaying legislation on eprivacy is that unobtrusive cookies such as Google Analytics and basic shopping cart facilities will not require consent but obtrusive cookies and/or those that collect sensitive personal data will require a higher level of consent and control than currently required (and certainly not implied consent). So, I can well understand you position on cookies.

What can be interesting, though, is what turns up when you do a proper cookie audit!

CIVIC have launched a new cookie control widget, which looks very good if you need a mechanism to manage cookie consent.
 
Upvote 0
Yes thanks I've seen that one - it might be very sophisticated but it is not really the first impression I'd like my site to give.

But in general how do track cookie consent - with another cookie? Removing consent removes their cookie preference cookie? I like the privacy principle but in reality it starts to sound like crazy talk...

Do you think a cookie banner is required just for Google Analytics cookies?
 
Upvote 0
You can always go 'cookieless' with Google Analytics. OK you loose a little bit of information, but actually 90% on analytics users don't use ( or even understand ) 5% of the information available.

There are many Cookieless implementation for GA - here is one that uses browser fingerprinting

I've been looking for an easy to implement solution for some time already. This is brilliant.

Thanks - others will be helped by your comment.
 
Upvote 0

Latest Articles