GDPR: Receiving business cards

At a recent networking event i received several business cards from people i held conversations with and agree to contact said persons at a later date to further the discussions. A friend working on GDPR for her employer informed me that being given a business card does NOT give me authorisation to call the person that gave me the card, therefore I would be in breach of the regs.

Has anyone else heard or seen evidence of this?
 
Last edited by a moderator:

Flatspin

Free Member
Dec 14, 2017
50
2
Ashford
Well, technically you need to have a record of such consent being given, because people can be full of nonsense.

I would just write the date, time & place on the back of the card & keep it somewhere safe in the unlikely event that anything bothersome arose out of your communications. Going a step further, perhaps create a spreadsheet with the same details so you don't have to go sifting through cards.

Anyone is legally entitled to ask you what information you have on them.

Personally, I have an excel spreadsheet with all the details of all my clients, including any usernames & passwords they have given me. I can just delete their record from this should I be required.

Just a safeguard.
 
Upvote 0

paulears

Free Member
Jan 7, 2015
5,667
1,667
Suffolk - UK
My experience so far ism the GDPR has been lifeblood for the spammers. Contacting people on the pretence of confirming things but actually rebuilding a sagging email list. The people trying to be 100% compliant are suffering, and the people who really don't care are taking advantage. Spreading disinformation is rampant. I concluded nothing I do crosses any line from my own interpretation and I'm happy to defend my interpretation if I had to. The idea that people are being truthful when asked for the data just makes me laugh. If they are keeping data on you that perhaps you would not like, do you really expect them to own up? It's like the person you know sells drugs. You are entitled to ask him if he sells drugs, so you do. He says he doesn't. So what exactly do you then do?

Are we really saying that if you have a little collection of rumours about dodgy clients - those ones that you don't grant credit to, if they ask you - you will actually confirm the contents of the information? I can see it really becoming a big company problem, and smaller businesses and self-employed are right at the really doesn't matter end.

If I get a business card, then I am not going to write the date time and their inside leg measurement, plus a witness statement - I give them a call, and this will make them think their £10 to vista print was a good deal after all. Why would anyone have business cards printed at their own expense if they did NOT want people to contact them? Plain silliness.
 
Upvote 0

cjd

Business Member
  • Nov 23, 2005
    16,002
    3,436
    www.voipfone.co.uk
    *You* are allowed to call people that have given you their card. That's confirmed legal advice.

    You're not allowed to put the card details in a CRM system and let your call centre call and email them incessantly
     
    Upvote 0

    Bob Morgan

    Free Member
    Apr 15, 2018
    2,216
    922
    ‘Pure Silliness’ indeed! (paulears) Only last week on another thread regarding the necessity for Email Disclaimers, I responded with “Do you add a Disclaimer to Business Cards and Letterheads?” – Albeit this was rather facetious, it is astonishing that there are people who believe this to be the case!
     
    Upvote 0

    Flatspin

    Free Member
    Dec 14, 2017
    50
    2
    Ashford
    At the moment there doesn't seem to be any solid way of reporting on any of these issues, anyway, I have looked.

    I think the enforcers will catch up with the legislation at some point, and companies/people will twig that they can eliminate some of their competition by reporting on non-compliant websites/businesses.

    One of the biggest culprits is Twitter, which just sets Google Analytics cookies on your computer without so much as a "by-your-leave".

    I don't think having someone's business card implies consent as this may have been acquired through a 3rd party.

    I am not here to scaremonger anyone, but it will come back to bite people in the ass if they don't comply with the new legislation. Most likely you will get a warning first, so it's not all bad, giving you enough time to prove compliance upon further inspection.
     
    Upvote 0

    Chris Ashdown

    Free Member
  • Dec 7, 2003
    13,399
    3,011
    Norfolk
    It does make you think about new laws, things like the GDPR or Human Rights are often drawn up by some of the best lawyers in the world and debated by many politicians before coming law, yet little erks and others easily manage to interpreat the laws which they can exploit or take definitions to the extreme to scare people

    Maybe all new laws should have a trial period of say three years on which after they go back to the law makers who make adjustments based upon experience on how the law is working and any changes that are required
     
    • Like
    Reactions: Flatspin
    Upvote 0

    cjd

    Business Member
  • Nov 23, 2005
    16,002
    3,436
    www.voipfone.co.uk
    The dumbest part of the regulation is not being able to send marketing emails to your own customers without their specific consent. If the regulation allowed the sending of emails to your own customers so long as it had a prominent unsubscribe link a lot of heat would go out of this.
     
    • Like
    Reactions: 4PYQU7
    Upvote 0

    obscure

    Free Member
    Jan 18, 2008
    3,370
    879
    The world
    The dumbest part of the regulation is not being able to send marketing emails to your own customers without their specific consent.
    Errr no, that is actually by far the best bit of the GDPR.
    Just because I buy widgets from you that doesn't mean I want to know about all the other rubbish you sell thanks. Ditto with my bank, insurance company, mobile provider..... If I wanted to know about those products I would have asked when I bought the widgets. If I want to know about them in the future I will ask then (or just google). Really, really fed up with people who believe they know what I want (and just happen to sell it).
     
    • Like
    Reactions: arnydnxluk
    Upvote 0

    cjd

    Business Member
  • Nov 23, 2005
    16,002
    3,436
    www.voipfone.co.uk
    Errr no, that is actually by far the best bit of the GDPR.
    Just because I buy widgets from you that doesn't mean I want to know about all the other rubbish you sell thanks. Ditto with my bank, insurance company, mobile provider..... If I wanted to know about those products I would have asked when I bought the widgets. If I want to know about them in the future I will ask then (or just google). Really, really fed up with people who believe they know what I want (and just happen to sell it).

    So you unsubscribe and never receive another, how difficult is that?

    It puts the onus on the company to be cautious about what it does - only send information that is likely to be useful.

    The problem is that everyone now clicks don't send me anything without thinking because there's so much cr@p being sent. (Actually, in our case about 50%.) With most one-off buys this is ok, but if you've bought into a recurring and developing service, like ours, they won't get to hear when the next new feature that they've begged for becomes available.
     
    Upvote 0

    talksalot81

    Free Member
    May 31, 2011
    81
    7
    I must presume that a lot of the stuff being pushed is nonsense. I was told that I could not contact people by pulling their details from the internet. I can see this as fair if you mean that you cannot stick them into your CRM and send them marketing emails but I was told I could not email them personally, or call them! If that is accurate, I am happily going to ignore it!

    As far as I am concerned, a business card has the sole purpose of making your and your contact details known to someone else. If you do not wish to be contacted, you wouldn't have given out your business card.

    More fundamentally, I am operating under the principle that I don't send faceless marketing emails. Any marketing is done on by a personalised message. If that is against the rules, it is only so long until you won't be able to call into a business without an invite, which you cannot get because you can't communicate with them before they communicate with you, which they wouldn't be able to do until you communicate with them. Madness.
     
    Upvote 0

    cjd

    Business Member
  • Nov 23, 2005
    16,002
    3,436
    www.voipfone.co.uk
    Actually GDPR doesn’t prevent you from emailing individuals using a corporate email address, it simply reiterates the existing rule that you must have a clear unsubscribe.

    If someone has signed up for a service and has clicked on 'do not send me marketing emails' you can't send them - period.
     
    Upvote 0
    I must presume that a lot of the stuff being pushed is nonsense. I was told that I could not contact people by pulling their details from the internet. I can see this as fair if you mean that you cannot stick them into your CRM and send them marketing emails but I was told I could not email them personally, or call them! If that is accurate, I am happily going to ignore it!

    As far as I am concerned, a business card has the sole purpose of making your and your contact details known to someone else. If you do not wish to be contacted, you wouldn't have given out your business card.

    More fundamentally, I am operating under the principle that I don't send faceless marketing emails. Any marketing is done on by a personalised message. If that is against the rules, it is only so long until you won't be able to call into a business without an invite, which you cannot get because you can't communicate with them before they communicate with you, which they wouldn't be able to do until you communicate with them. Madness.

    A key point here is that even well-intentioned and informed commentators are largely guessing re interpretations - the act itself is so broad that it could mean many, many things

    What is fairly certain is that the risk factors revolve around disgruntled (ex) staff and customers and malicious competitors

    Intelligent marketing, with clear opt-out is unlikely to present a problem
     
    Upvote 0

    talksalot81

    Free Member
    May 31, 2011
    81
    7
    If someone has signed up for a service and has clicked on 'do not send me marketing emails' you can't send them - period.

    Of course there is then the interpretation of 'marketing'. Is a marketing email something that is mail merged? Is a personal email still marketing? Is a telephone call marketing? Is a site visit marketing? What if they opt out but your order process emails have marketing elements?

    Bit of a screwball mess.
     
    Upvote 0

    obscure

    Free Member
    Jan 18, 2008
    3,370
    879
    The world
    So you unsubscribe and never receive another, how difficult is that?
    More difficult than not having to unsubscribe because some jerk thought he knew better than me what I want.

    It puts the onus on the company to be cautious about what it does - only send information that is likely to be useful.
    Except that business' proven inability to do that is the whole reason we have GDPR.

    With most one-off buys this is ok, but if you've bought into a recurring and developing service, like ours, they won't get to hear when the next new feature that they've begged for becomes available.
    Of course they will. If there is a legitimate reason to contact them about the product they bought (an upgrade, a recall, contract renewal) you can email a customer. You just can't email them about all the other stuff you want to flog them unless they give you permission.
     
    Upvote 0

    cjd

    Business Member
  • Nov 23, 2005
    16,002
    3,436
    www.voipfone.co.uk
    More difficult than not having to unsubscribe because some jerk thought he knew better than me what I want.

    Almost all of the spam I get now comes from outside the EU and/or has no unsubscribe link. Most of it is fraud so never will have. If you're buying from reputable companies there's no problem with this. The problem is elsewhere.

    Of course they will. If there is a legitimate reason to contact them about the product they bought (an upgrade, a recall, contract renewal) you can email a customer. You just can't email them about all the other stuff you want to flog them unless they give you permission.

    Obviously you can contact them about contracts, renewals and upgrades, that is allowable data processing under your contract with the customer. But new products, services or features are classed as marketing. That's from both the ICO and our lawyers.

    People are now knee-jerking non-consent because of bad experiences and it's shame, they're going to miss out when dealing with reputable companies.
     
    Upvote 0
    You’ve agreed to contact them, therefore there is no problem

    Also, in reality who is going to complain?

    People working on GDPR love to spread fear.
    Hi Mark,
    Thanks for your response.
    It became a heated discussion which bothered me because it made no sense. Her point is people collect biz cards in glass bowls which they keep forever and use to email etc.
    I found nothing in the GDPR Regs on the Gov website so everyone i agreed to call I have called and or emailed
     
    • Like
    Reactions: Mark T Jones
    Upvote 0
    Well, technically you need to have a record of such consent being given, because people can be full of nonsense.

    I would just write the date, time & place on the back of the card & keep it somewhere safe in the unlikely event that anything bothersome arose out of your communications. Going a step further, perhaps create a spreadsheet with the same details so you don't have to go sifting through cards.

    Anyone is legally entitled to ask you what information you have on them.

    Personally, I have an excel spreadsheet with all the details of all my clients, including any usernames & passwords they have given me. I can just delete their record from this should I be required.

    Just a safeguard.
    Hi
    Thanks for replying it was helpful to let me know what i'm doing is ok
    We have a spreadsheet list of contacts which we created from business cards or networking events we've attended.
    We usually note on the card where and when we received it, and tbh if people don't want to be contacted if they ignore my email or call i leave them alone.
     
    • Like
    Reactions: Flatspin
    Upvote 0

    Chris Ashdown

    Free Member
  • Dec 7, 2003
    13,399
    3,011
    Norfolk
    Dont over complicate things, they gave you there card so legitimate contact, making a log etc is rather over the top and a waste of valuable time you could be spending on improving your profits

    The whole purpose of GDPR is to cut out unsolicited contact. unless you have a good reason, and if asked supply any data on them. If anyone complains do what they request and that's the end of it

    That old business idea of using common sense still has a role to play in modern life
     
    • Like
    Reactions: obscure
    Upvote 0

    Latest Articles

    Join UK Business Forums for free business advice