From the archive: written ahead of the GDPR becoming applicable on 25 May 2018.
The GDPR, or General Data Protection Regulation, known in the Netherlands as the AVG, has featured regularly in the news over the past few years. This year, the topic is even more relevant, as the new European privacy rules become applicable on 25 May 2018.
Compliance with the GDPR means better protection for every European citizen’s data, including yours and mine. Companies that fail to comply risk fines. They need to take appropriate security measures to protect personal data and communicate clearly about how they use it.
What stood out in articles about the privacy rules in 2017 was their emphasis on warnings to businesses: make sure you comply to avoid huge fines. They conveyed anxiety about failing to meet the requirements in time. Headlines such as “Organisations not ready for new European privacy rules” and “GDPR: 10 tips to avoid substantial fines” illustrate this. The rules were also frequently linked to mandatory data-breach reporting. Less attention was paid to the GDPR as an opportunity to connect, or reconnect, with customers.
I also noticed that coverage mainly addressed businesses rather than consumers. That appears to be changing. The Dutch Data Protection Authority, for example, has launched a campaign to make consumers more aware of their privacy rights.
Businesses would do well to embrace that awareness too. One reason is the human role in security incidents, as Inger discussed earlier. Another is that, however much preparation and compliance affect processes and IT infrastructure, the GDPR serves a worthwhile purpose. It is important to keep that purpose in mind and communicate the value you attach to it. Facebook, for example, took a step in this direction by sharing its own privacy principles.
Think carefully about which data you really need to collect and explain how it helps you support the consumer. It is also important to make clear where customers can go to have their information changed or deleted. Ultimately, you need to demonstrate how much you value the customer relationship and that you do not want to damage it. Following privacy rules closely also helps protect the company’s reputation. Ruud explored this in more depth in a blog about why SMEs and start-ups should not let privacy issues damage their reputations.
Trust is therefore becoming even more important, which is precisely one of the reasons for strengthening privacy protection. Use this opportunity to deepen your relationship with customers.
Would you like to discuss how privacy can play a role in your communications strategy? Contact us for more information.
More news ›