GDPR or General Data Protection Regulation laws cover everyone about whom you keep personal data. Including clients, members, suppliers, leads, and staff. To be able to demonstrate GDPR compliance as a business, you need to ensure that the data collected is processed securely and is retained only as long as necessary.

GDPR Compliance

In this blog, we cover some of the things you need to know about GDRP compliance, failure to comply, important website legal checklist and Data Protection Law. 

Here are the steps you can take to make your website GDPR compliant.

Privacy and Cookie Policy

If your business collects personal data from your users, a Privacy Policy is mandatory under the data protection legislation. Having a privacy policy in place helps inform your users/customers about how their personal data is being processed and managed. With the right privacy policy, your users can also make informed decisions about the handling of their personal information. 

If your website uses cookies you will also need to include a cookie policy. This policy should explain the different types of cookies. It should also include all of the cookies that you have on your site, what type of cookie they are and their purpose. 

Compliant Cookie Popup

When a user visits a website, a cookie banner or popup message should be displayed. This gives the users the option to either give consent, reject, or change cookie preferences. It’s important that the cookie popup conveys a clear message regarding the types of cookies your website uses, for what purpose, and for how long they’ll be stored on your user’s device. In addition to that,  you must ensure to regularly update consent preferences.

Data Processing Agreement (DPA)

As a company, you may hire a third party to process user’s personal data. Which usually requires a robust Data Processing Agreement  (DPA). A DPA is a legally binding document that is required under the GDPR. This document outlines how to process personal data in accordance with the law. It must be signed by both parties: the company that needs personal data to be processed and the company that processes data.

GDPR Compliance

Clear Consent and Contact Forms

Users should be able to understand what information they are agreeing to share when checking off tick boxes. For that purpose, it’s vital that all your consent forms have the correct wording and opt-in consent tick boxes on any lead magnets and newsletter signups. You should have two separate tick boxes. One for users agreeing to their data being processed and another one for users giving consent to receiving advertising in the future. Both must be unticked by default. If you use lead magnets then read our blog on how they should be set up in a legally compliant way.

Transfers to Third Parties

While there’s nothing wrong in sharing a user’s personal data with third parties. It has to be done right to comply with GDPR. For instance, you have to be clear about your intentions, and you must provide a lawful basis. This information should be included in your Privacy Policy. With a clear message to your users that personal information could be transferred to third parties. 

Conclusion

Ensuring GDPR compliance can be a complicated and confusing process. By implementing these steps, you’re on your way to ensure that your site is GDPR-compliant and secure. Should you fail to comply and breach the Data Protection Law, the fines go up to €20m or 4% of annual turnover (whichever is higher). Besides paying a hefty sum, you could also risk damaging your company’s reputation.

If you want to ensure your website demonstrates GDPR compliance under the Data Protection Law and whether you’ve ticked every box on your website legal checklist, don’t hesitate to contact us. We audit websites for businesses all the time to ensure compliance. Why not book your website compliance check today.