Is Your Website GDPR Ready? Follow this 7-step Checklist

  Рет қаралды 41,716

AdEvolver

AdEvolver

Күн бұрын

Пікірлер: 54
@crowley144
@crowley144 3 жыл бұрын
Amazing, such a comprehensive but short overview
@goodguyhenri2090
@goodguyhenri2090 3 ай бұрын
fun fact: deleting user data also counts as "processing" data by the definition. So, without any legal basis, deleting data is thereby illegal
@dabrahgo
@dabrahgo 2 ай бұрын
Would stating this in a privacy policy help? Also if the data is just something like an anonymised ip, would deleting it still be illegal?
@EdLeake
@EdLeake 6 жыл бұрын
What's that coming over the hill, is it a monster, is it a monster? No, it's GDPR.
@Meleeman011
@Meleeman011 6 жыл бұрын
As an American, I will not recognize gdpr or European law as my servers are not located outside the EU. But I do find some of the ideas nice.
@gallaghergreen2053
@gallaghergreen2053 6 ай бұрын
Great video! Would you say this is all still relevant, or have there been changes that would apply here?
@mrsdesireerose
@mrsdesireerose 6 жыл бұрын
This list is great!! Thank you for making it simple
@AdEvolver
@AdEvolver 6 жыл бұрын
thanks Desiree! :)
@littlecookingtips
@littlecookingtips 6 жыл бұрын
It seems people in EU who made GDPR didn't think another legal aspect of this however: If you DON'T keep past communications, or if someone asks to Remove his/her data (which may be an email correspondence), then how can you PROVE in writing, that something did or did not take place with this person?
@aidanclarke6106
@aidanclarke6106 6 жыл бұрын
Little Cooking Tips - Blog - Is that really important? To my understanding you are only required to tell if you have data about someone or not. So your answer to a user would be something like: "we have no data about you. Either we never had or you asked us to delete them"
@littlecookingtips
@littlecookingtips 6 жыл бұрын
Hi Aidan! I mean something different, perhaps wasn't clear as much as I should. If you remove any communication with a person, because this person requested it (email and such), then how can you be safe from legal action/liability from this person? He/she may make false claims and you wouldn't have proof that you answered - in writing - to these claims. Moreover, does one keep the request for the deletion, that itself contains personal information? If not, then how - again - can one prove that he deleted information at someone's request? I'm honestly quite baffled by some of the logic behind GDPR.
@aidanclarke6106
@aidanclarke6106 6 жыл бұрын
Oh I see. As I understand, your "data protection implementation", i.e. all the softwares you use to collect/process/delete data, must create audit logs to keep track of every action of end users and privileged/administrative users. So basically, whatever happens to personal data (even data breach detection) must be written to audit logs which serve as a proof.
@Ywamnorthcascades
@Ywamnorthcascades 5 жыл бұрын
Starts at 2:22
@TonyFisherPuzzles
@TonyFisherPuzzles 6 жыл бұрын
Will they be checking my bins then?
@AdEvolver
@AdEvolver 6 жыл бұрын
Haha! But that might be a breach of your data privacy... touche bureaucrats! It's like Schrödinger's cat, but for data. The data both exists and does not exist, until someone looks for it... and finds it in your bin.
@Dexter101x
@Dexter101x 5 жыл бұрын
Best to shred any paper with phone numbers and addresses on, with a paper shredder
@hectorisandro3583
@hectorisandro3583 4 жыл бұрын
This was very helpful. I am curious as to what steps/policies are in place for the USA & Canada? Someone informed me that GDPR is at the pinnacle of data protection and if your website is GDPR compliant it means your probably covered in the USA and Canada. Is this true?
@AdEvolver
@AdEvolver 4 жыл бұрын
As GDPR is quite strict, but also logical when it comes to opt-in, then it is highly likely a GDPR compliant website is US/CA compliant.
@tobycarrington7643
@tobycarrington7643 6 жыл бұрын
Very useful. Thanks
@AdEvolver
@AdEvolver 6 жыл бұрын
our pleasure Toby!
@francesco_m
@francesco_m 6 жыл бұрын
Also, without this explicit consent, we can't send him any email? Not even if he forgot the password and wants to restore it?
@AdEvolver
@AdEvolver 6 жыл бұрын
No, you can send email related to the original interest. So if I registered on your website, you can send me email about registrations and my account. That's completely okay! :)
@francesco_m
@francesco_m 6 жыл бұрын
thank you very much :)
@jackiecameron2764
@jackiecameron2764 4 жыл бұрын
Is it ok to have your cookie policy, privacy policy and GDPR statement in discrete tabs at the bottom of your page for the visitor to click on if they choose and not in a pop up? I've seen so many web design sites do this, I assume because it's not intrusive for the visitor....is this ok?
@StevenDeLosSantos
@StevenDeLosSantos 6 жыл бұрын
So do we not need to be "GDPR" compliant if we are just gathering info from local customers (in texas)???
@AdEvolver
@AdEvolver 6 жыл бұрын
No you're fine, you could just exclude those people from all your cookies - but you'd still need to outline in your privacy policy what you're doing and what happens if someone from the EU sends you data (contacts you).
@kynchan3332
@kynchan3332 5 жыл бұрын
The EU should just stop using the internet for ultimate privacy. The people will need to search your bins to get your personal data, how safe would that be?
@francesco_m
@francesco_m 6 жыл бұрын
Can these checkboxes be required? So that if you don't allow us to email you, you can't complete the registration? Also how about backups? If someone wants to be forgotten, it's very hard to erase his data from the aggregated backups
@AdEvolver
@AdEvolver 6 жыл бұрын
Hey Francesco, good question. If a legitimate interest exists - such as a registration - then sending an email without a consent 'tick box' is okay. In that case the data is being gathered out of necessity. Where it becomes an issue is if you then email that person anything that isn't related to the original registration action. So if you plan to 'market' to them after registration, then you must ask them if they're okay with that. You can do that on your form with a 'tick box' or in a following email that asks them to confirm the additional opt-in. Does that make sense? Backups are a big issue for all of us. It will mean disposing of older backups that contain 'deleted' users. We'd recommend a decay type policy whereby you as the data holder are given a grace period of say 30-days, to remove the user from backups. That means that if someone asks to be forgotten entirely, you have a little leeway on cleansing backup data, which is typically harder to get hold of and manage.
@kysfggt
@kysfggt 6 жыл бұрын
Can I just delete the data on the person that starts to complain?
@countryfinds
@countryfinds 6 жыл бұрын
Thank you for the help!
@luxdelight8336
@luxdelight8336 5 жыл бұрын
Thanks, that helps a lot!
@tamil_tamilian
@tamil_tamilian Жыл бұрын
Nice clear explanation
@digitalimpact483
@digitalimpact483 3 жыл бұрын
This is great content. Thanks!
@digitalbrain4012
@digitalbrain4012 3 жыл бұрын
Thank you so much
@snehal254
@snehal254 3 жыл бұрын
thank you so much :)
@tradigitalx
@tradigitalx 6 жыл бұрын
What about the log to prove consents?
@EdLeake
@EdLeake 6 жыл бұрын
Now that is a good question and honestly, I'm not sure because that in itself seems like it could fall under GDPR... which is insane! How do you prove it if the person opted out and therefore left no footprint, other than an anonymous visit to your site (or similar)?
@AdEvolver
@AdEvolver 6 жыл бұрын
The cookie you store is not an 'online identifier'. if you are simply storing the preference of the user's consent (yes/no). There's no problem with setting cookies.
@mstarheelfan
@mstarheelfan 5 жыл бұрын
All I want to know is do I click yes or no! I’m very very new to this and I’m signing up with jvzoo and don’t know whether to say yes or no. Is your use of the JVZoo service regulated by GDPR?
@francesco_m
@francesco_m 6 жыл бұрын
A last question, since it seems you know a lot :) What if I issued invoices to him? I must delete the invoices? I think that's against the law... :)
@EdLeake
@EdLeake 6 жыл бұрын
Now that's an interesting question. I actually don't know the legalities around that but you're right, you can't just delete invoices! Safe filing system is a must but that leaves the question of what if you stop working with that person, can they then request you destroy their data (old invoices)? That wouldn't make sense because of legal accounting requirements.
@aidanclarke6106
@aidanclarke6106 6 жыл бұрын
Invoices are part of the justified purposes which are outside the scope of GDPR: _“if data processing is needed for a contract, for example, for billing, a job application or a loan request; or if processing is required by a legal obligation …”_ However, GDPR applies right after the legal obligation ends. For example, if local laws require you to keep invoices for 12 years, you must delete them immediately after the 12 year period.
@EdLeake
@EdLeake 6 жыл бұрын
Thanks Aidan, that makes sense.
@thedigitalemotion
@thedigitalemotion 6 жыл бұрын
If we cover these 7 steps correctly then are we all good & legal? Theres so many snake oil salesmen out there asking for £250 to be GDRP compliant and filling out 100 page forms etc!!?
@AdEvolver
@AdEvolver 6 жыл бұрын
If you're unsure ASK the user to opt-in and be very CLEAR in your privacy policy: - how you collect data - why you need it / what you do with it - how you store it - how they remove themselves (contacting you is okay) - and how they can contact you (email address and/or person)
@thedigitalemotion
@thedigitalemotion 6 жыл бұрын
AdEvolver, thank you very much, you're a lifesaver! Much appreciated :)
@watchlessons
@watchlessons 3 жыл бұрын
change intro from 17 seconds to 1.5 second. This way less irritation is caused.
@banqueteurocom
@banqueteurocom 6 жыл бұрын
You're not hard on the eyes, BTW!
@AdEvolver
@AdEvolver 6 жыл бұрын
We work hard on the lighting! :-D
@dancoulson6579
@dancoulson6579 3 жыл бұрын
Couldn't I just host my website on a remote server in a normal country, like the US, or Korea, so I don't have to comply with these crazy EU dictatorship rules?
10 Steps to GDPR Compliance
8:40
Privacy Kitchen
Рет қаралды 24 М.
How To Disappear Completely and Never Be Found
14:20
Sumsub
Рет қаралды 3,8 МЛН
Секрет фокусника! #shorts
00:15
Роман Magic
Рет қаралды 44 МЛН
这三姐弟太会藏了!#小丑#天使#路飞#家庭#搞笑
00:24
家庭搞笑日记
Рет қаралды 94 МЛН
拉了好大一坨#斗罗大陆#唐三小舞#小丑
00:11
超凡蜘蛛
Рет қаралды 14 МЛН
5 MIND BLOWING Logo Design Tips ✍
10:50
Will Paterson
Рет қаралды 2,4 МЛН
What's Your Password?
3:47
Jimmy Kimmel Live
Рет қаралды 2,9 МЛН
What are the 7 principles of GDPR?
8:00
Privacy Kitchen
Рет қаралды 93 М.
BEACH HOUSE // Space Song
5:36
carlosocarnero
Рет қаралды 49 МЛН
WordPress GDPR Compliance Update & Privacy Policy Generator
17:23
WPCrafter.com WordPress For Non-Techies
Рет қаралды 51 М.
What is GDPR? - BBC Click
24:25
BBC Click
Рет қаралды 42 М.
GDPR Compliance - The steps that I take to prepare
13:39
MeasureSchool
Рет қаралды 6 М.
Секрет фокусника! #shorts
00:15
Роман Magic
Рет қаралды 44 МЛН