Jump to content

Recommended Posts

Posted

Hi Guys,

 

Some of the guys in my writers group have just heard about GDPR (I know..), and are wondering how it plays with mailing lists?

 

So, If someone has a site/blog with a mailing list (like mailchip/mailsquid), what, if anything, do they have to do to be GDPR compliant?

I've done some reading around and gotten different messages from, "as long as the mailing list company is GDPR compliant, you're good" to "you need to register with the ICO"

 

Thanks for any help/advice.

 

Rob.

Posted

http://www.wired.co.uk/article/pecr-gdpr-emails

 

"We’ve heard stories of email inboxes bursting with long emails from organisations asking people if they’re still happy to hear from them," Steve Wood, the deputy information commissioner for the UK wrote in a blog post earlier this week. "Think about whether you actually need to refresh consent before you send that email and don’t forget to put in place mechanisms for people to withdraw their consent easily," Wood says.

 

But, it turns out, most of these emails are pointless. "In the UK it has been the law since 2003 that you can only send a marketing email to an individual recipient when they have consented to receive it or you have an existing customer relationship with them and have offered them the opportunity to opt out," explains Jon Baines, data protection advisor at law firm Mishcon de Reya.

 

So why are they sending these emails? It's largely around the fear of GDPR. The regulation says companies can be fined up to €20 million or four per cent of their annual global turnover. Many companies are keen to get their systems in order. Although in the UK the Information Commissioner has made it clear it won't be heavy-handed with fines.

 

Baines believes a big reason why these emails are being sent at the moment is because of an "increased awareness around the fact that sending marketing emails requires either the consent of the recipient or an existing customer relationship". That awareness has been amplified because of the hype around GDPR.

 

However, the Privacy and Electronic Communications (EC Directive) Regulations – known as PECR for short – govern marketing messages. These are based upon a European e-privacy Directive and cover messages used for marketing – everything from the pesky emails to text messages.

 

GDPR doesn't replace PECR but sits alongside it and European regulators are coming up with a new set of e-privacy rules to replace it. Confused? So are the companies emailing you. The result is a slightly messy mix of rules: both GDPR and PECR are dense, legally complex and have a plethora of caveats with exemptions for different scenarios.

 

But the existence of PECR means that in a large amount of cases, companies may not have necessarily needed to send the emails re-asking for permission to keep in touch. "I think a lot of the emails people are receiving are unnecessary, because people have either already consented or are receiving them to business addresses," Baines says. Business email addresses – for instance, [email protected] – fall under GDPR as personal data, but for marketing messages consent to receive them may not be needed.

 

If people haven't already consented to receive marketing messages, the company sending them will have been in breach of PECR, potentially for many years.

 

But what is considered consent is a slightly murky affair. With the introduction of GDPR comes an updated definition of what consent is. It's complex but states consent has to be unambiguous and involve someone actively saying yes. For instance, a pre-ticked box saying you are willing to receive marketing emails doesn't count as unambiguous consent. But a box you have to actively tick does.

 

"If consent is the appropriate lawful basis then that energy and effort must be spent establishing informed, active, unambiguous consent," the ICO's Wood says. As well as consent, there are other ways for companies to obtain and process a person's data and still be inline with the requirements of GPDR.

 

Ultimately, the overlap between PECR and GDPR has meant some companies will lose subscribers to their mailing lists that have just ignored the deluge of messages being received. In an almost ironic twist, last year the ICO fined Honda and Flybe for sending emails asking people to agree to getting more emails. "Sending emails to determine whether people want to receive marketing without the right consent, is still marketing and it is against the law," the ICO said at the time.

 

But there also have been more malicious examples of email consent messages being sent. UK-based cybersecurity firm Redscan discovered phishing emails have been sent that were disguised as GDPR-related emails. The firm spotted a fake email that had been made to look like it was from Airbnb, stating its customers should click on a particular link to update their privacy settings.

 

When clicked, the link would take users to a spoofed Airbnb website that collected all the details entered and saved them to systems belonging to the hackers that created the website. “The irony won’t be lost on anyone that cybercriminals are exploiting the arrival of new data protection regulations to steal people’s data,” Redscan's director of cybersecurity Mark Nicholls, said in a statement.

 

https://iconewsblog.org.uk/2018/05/09/raising-the-bar-consent-under-the-gdpr/

 

From marketing agencies, to clubs and associations, to local authorities, consent has been a hotly debated topic.

 

Some of the myths we’ve heard are, “GDPR means I won’t be able to send my newsletter out anymore” or “GDPR says I’ll need to get fresh consent for everything I do.”

 

I can say categorically that these are wrong, but if misinformation is still being packaged as the truth, I need to bust another myth.

 

Myth #9 We have to get fresh consent from all our customers to comply with the GDPR.

 

You do not need to automatically refresh all existing consents in preparation for the new law. But the GDPR sets the bar high for consent, so it’s important to check your processes and records to be sure existing consents meet the GDPR standard. If they do there is no need to obtain fresh consent.

 

Where you have an existing relationship with customers who have purchased goods or services from you it may not be necessary to obtain fresh consent.

 

It’s also important to remember that in some cases it may not be appropriate to seek fresh consent if you are unsure how you collected the contact information in the first place, and the consent would not have met the standard under our existing Data Protection Act.

 

We’ve heard stories of email inboxes bursting with long emails from organisations asking people if they’re still happy to hear from them. So think about whether you actually need to refresh consent before you send that email and don’t forget to put in place mechanisms for people to withdraw their consent easily.

 

If consent is the appropriate lawful basis then that energy and effort must be spent establishing informed, active, unambiguous consent.

 

Organisations risk non-compliance if their emails are difficult to follow and key information is lost at the end of long text – people must clearly understand what they are consenting to.

 

Being open and transparent is key a component of the GDPR and the ICO has provided guidance on informing people about how their data is used.

 

Before sending emails consider what the most effective way is to reach your customer – it may not be email. Consider a data protection by design approach – where can this information be embedded to have the best impact.

 

Some have said that they will lose customers by bringing their consents to the GDPR standard. I say you will have better engagement with them and build customer trust.

 

Our research found that only one fifth of the UK public (20%) have trust and confidence in companies and organisations storing their personal information.

 

Consent is not the ‘silver bullet’

 

As the Commissioner said in her blog ‘consent is not the ‘silver bullet’ for GDPR compliance’ consent is one way to comply with the GDPR, but it’s not the only way.

 

Scaremongering about consent still persists but the headlines often lack context or understanding about all the different lawful bases organisations could use for processing personal information under the GDPR.

  • Thanks 2
Posted

Thanks for the information.

But I'm still not clear what (if anything) the admin of a mailing list would need to do to be compliant.

I'd taken the assumption that they would be Data Controllers, but mailsquid says they act as both processor and controller. Would that mean the admin (the person who's list it is) wouldn't need to do anything? (That doesn't seem right)

  • 2 weeks later...
Posted
I've gone down the route that I can't send out mailers to anyone on a mailing list unless I can expressly prove that they have opted in to receive marketing emails. If you can already prove that you're good to go!
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...