GDPR · 11 March 2018

The GDPR and newsletters

What does the GDPR mean for your email database? We go through the requirements for storing and processing personal data, consent on sign-up and on import, and why opt-in emails are crucial.

The GDPR and newsletters

What does the GDPR mean for newsletters?

At the moment we are getting a great many enquiries from existing and potential customers. They are all interested in hearing more about the forthcoming General Data Protection Regulation (GDPR) and the impact it will have on their email database.

The GDPR is an EU initiative whose aim is to harmonise the legislation of the member states in relation to the storage and processing of personal information and personal data.

Before you close the window because the subject seems dry and boring (and yes, unfortunately it is), consider this: are you ready to pay up to 20 million euros, or 4% of your company’s annual turnover, in fines for breaching the regulation? That is the level of fines the regulation opens for, and that is why it has attracted so much attention.

Relevance for newsletters

There are several elements of the GDPR that make it relevant to companies that send newsletters and email marketing.

On the one hand there are requirements for how personal data is stored and processed, and on the other there are requirements for how consent is collected.

What is personal data?

Personal data is data about people – the name says it all. The following are examples of types of personal data: name, address, email address, telephone number, date of birth, education, occupation, employment matters, housing situation, car, examinations, salary, tax and sickness absence.

Since an email address appears on the list, you are subject to the GDPR if you store email addresses – and you do, if you send newsletters.

It makes no difference whether you use a service such as Ubivox to send the newsletters. In this situation you are the data controller, and Ubivox is the data processor on your behalf.

It also means that you must enter into a data processing agreement with the service you use to send newsletters. At Ubivox we have the agreement ready, and you can ask to have it sent to you by contacting us.

When you store personal data, you must have consent to do so. The owner of the data must give you permission to store and process their data.

That has always been the case. In Denmark the GDPR takes over from the Danish Data Protection Act (Persondataloven), which has/had the following to say about consent (our translation, as the Act was never published in English):

Any freely given, specific and informed indication of wishes by which the data subject agrees that information relating to them may be made the subject of processing.

The GDPR says, in Article 4(11):

Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

There is no notable difference between the Danish Data Protection Act’s text on consent and the GDPR’s text on the same matter. Our impression is that a number of companies have not been aware of the consent requirements in the Danish Data Protection Act, and that the GDPR therefore comes as a surprise to them.

Fundamentally, then, the GDPR does not mean a great deal if you have previously had your consents in order. Within Ubivox you can, as a customer, store consent information about your recipients in two situations: on sign-up and on import.

When a sign-up takes place in Ubivox, we automatically record information about the sign-up that you can use to document a consent.

It can look like this:

Signed up on ‘2016-10-20 12:15:07.872609+00:00’ from IP address ‘123.123.123.123’ via the form on ‘https://hjemmeside.dk/underside/’. Confirmed by email on ‘2016-11-08 09:41:05.543726+00:00’ from IP address ‘123.123.123.123’.

So we automatically collect the date and time of the sign-up, the IP address used for the sign-up, the page the sign-up took place on, as well as the date, time and IP for the confirmation of the sign-up.

If you have the above information available, you can document a consent if a recipient asks for it.

When you import recipients to your lists in Ubivox, you have the option of filling in consent information for the recipients you import. That means you can, for example, state that the recipients gave their consent by taking part in a competition, in connection with a trade fair, or through a physical sign-up in a shop.

With import, it is your job to make sure that you have enough information to be able to document a consent.

About opt-in emails

If you use Ubivox without having changed your settings, the platform automatically sends an email when a sign-up takes place via your website. This email ensures that only the owner of an email address can sign that email address up to your newsletter.

But, more importantly: it ensures that the owner of the personal information confirms that the personal information may be stored and processed by you.

In the end, the opt-in email thereby ensures that you have your consent in order in relation to the GDPR. If you do not send an opt-in email, Bjarne’s neighbour Per can sign Bjarne up to your newsletter, and now you are storing and processing Bjarne’s personal data without consent from Bjarne. You only have Per’s consent, and Per cannot give consent on Bjarne’s behalf.

So do make sure to send opt-in emails, and to keep doing so. It has only become more important with the GDPR, and it was already rather important.

Rounding off

That was the first post about the GDPR, and over the coming months we will be writing more on the subject. If you are in the slightest doubt about the GDPR and newsletters, do get in touch with our support team.