Why GDPR Applies to You, and You Don’t Know It
Global Data Privacy Regulation (GDPR) is a European law that goes into effect in May and regulates personal data collection. It aims to give people control of what information a company might know about you and how that information is used.
It is easy for most of us to stop reading once we see the word “Europe”. Don’t be too quick to brush it off. The law applies to any company with a E.U. presence, selling into the E.U., or in possession of (or monitoring the behavior of) E.U. residents. To see if the law applies to you, ask yourself these questions:
- Does my company have anyone working in the E.U.?
-
-
- This includes the UK, for the time being. In fact, the UK and Germany have added their own addendum which adds additional conditions and complexity.
-
- Does my company have an employee from E.U. working outside the EU?
-
-
- As long as our European or British friend maintains residence or citizenship in any way, the rules apply.
-
- Are we selling to people in the E.U.?
-
-
- Do you have a website? Most of the life science companies have the intent to sell globally. We know all the regulations and filing procedures for drug development or medical device certification, because of the global market.
- Does your website contact us page have a form? The global market we love to sell to can easily fill out contact us forms or request downloaded material. Once that happens their name enters a sales or marketing database.
-
- Do you have the name of any E.U. resident in your CRM, marketing automation system, bulk email system, website membership (login), project management system, or Outlook/email directory?
-
- This is the one that gets most of us. Maybe you are not directly intending to sell into Europe, but you probably have someone’s name or email. Any personal information or highly sensitive information is regulated.
GDPR provides a uniform approach to data collection in a large group of countries. Many other countries and some US states have data protection laws. What makes GDPR unique is the size of the effort and the size of the penalty. The max fine is 4% of gross revenue up to ~$24 million. Big companies, like Google, were very quick to get in line with the regulation. Even certain apps, like Waze, are being much more explicit by using notifications to indicate they know where you are.
By Olga Torres, Chief Optimization Officer, Covalent Bonds & Director of Marketing, SAMPS
Archives
- September 2023
- August 2023
- July 2023
- June 2023
- April 2023
- March 2023
- February 2023
- January 2023
- October 2022
- May 2022
- February 2022
- January 2022
- December 2021
- October 2021
- August 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2019
- May 2019
- January 2019
- July 2018
- April 2018
- March 2018
- February 2018
- December 2017
- November 2017
- September 2017
- August 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- December 2016
- October 2016
- July 2016
- June 2016
- May 2016
- March 2016
- January 2016
- November 2015
- October 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
- December 2013
- November 2013
- October 2013
- September 2013
- August 2013
- July 2013
- June 2013
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013