SlideShare ist ein Scribd-Unternehmen logo
1 von 37
GDPR, OnePageCRM and Your Business
Tackling GDPR - one bite at
a time
Please wait. The webinar will start shortly....
Carmel Granahan
Head of Customer
Success, OnePageCRM
Your speakers today….
Philipa Jane Farley
Data Protection and Privacy Law
Specialist
Andrea Manning
GDPR Lead, OnePageCRM
WE’VE SPENT A LOT OF TIME WITH GDPR AND LIKE TO THINK WE’VE BEEN THOUGHTFUL ABOUT
ITS INTENT AND MEANING. BUT THE APPLICATION OF GDPR IS HIGHLY FACT-SPECIFIC, AND
NOT ALL ASPECTS AND INTERPRETATIONS OF GDPR ARE WELL-SETTLED.
AS A RESULT, THIS PRESENTATION IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY AND
SHOULD NOT BE RELIED UPON AS LEGAL ADVICE OR TO DETERMINE HOW GDPR MIGHT APPLY
TO YOU AND YOUR ORGANISATION. WE ENCOURAGE YOU TO WORK WITH A LEGALLY
QUALIFIED PROFESSIONAL TO DISCUSS GDPR, HOW IT APPLIES SPECIFICALLY TO YOUR
ORGANISATION, AND HOW BEST TO ENSURE COMPLIANCE.
DISCLAIMER
Welcome
Today’s Agenda
❏ An overview of GDPR, the roles, lawful processing of
data, consent v’s legitimate interest
❏ How to utilize fields in OnePageCRM to enable you to
implement better GDPR compliant processes (demo)
❏ How to do a legitimate interest assessment
❏ Most frequently asked GDPR questions
❏ Live Q & A
GDPR requirements and OnePageCRM
Individual rights
❏ The right to access information (subject access request) - Export
data
❏ The right to erasure - Delete the data from OnePageCRM (option in
bulk / individually) & also delete your account
❏ The right to data portability - Export data
❏ The right to rectification - Edit contact and update user profile
Lawful processing and OnePageCRM
1. Explicit consent (Marketing)
How to achieve with OnepageCRM? Webform > OnePageCRM (custom fields)
2. Performance of contract
How to achieve with OnepageCRM? (Status labels)
3. Legitimate interest
How to track with OnepageCRM? (Status labels, lead source, date created, custom fields)
Repermissioning
Step 2
Existing list (Mailchimp & OnePageCRM integration connected)
Step 1
WELCOME
DOES GDPR APPLY TO YOU?
▸ The GDPR is applicable to the processing of personal data by businesses
established in and operating outside the European Union (“the EU”). If your
company is established in the EU, the provisions of the GDPR are
applicable to your processing of personal data in the context of the activities
of your EU establishment(s).
▸ If your company is not established in the EU, the new law is applicable to
your processing of the personal data of individuals in the EU with
regard to the offering of goods or services (regardless of whether payment
is involved) and to the monitoring of an individual’s behaviour (in so far as
that behaviour takes place within the EU).
▸
CONTROLLER VERSUS PROCESSOR
The Yellow Hat Company
CUSTOMER/DATA SUBJECT
PROCESSORCONTROLLER
PROCESSOR
GDPR AND YOU
ONEPAGECRM - YOUR PROCESSOR
1. Processor needs to be GDPR compliant
2. The data processor can’t bring in other data processors unless he has notified the Controller, and has permission to do so
3. There also must be a contract between the data processor and data controller that should clearly mention the subject-matter, duration, nature and purpose
of the involved data processing
3. Keep records of all processing and provide secure processing
4. Common duties and shared liability
5. Assist the Controller in meeting their responsibilities
GDPR &
YOUR CRM
GDPR AND YOU
TELL YOUR SALESPEOPLE
1. Gather only data you need and make
sure you have lawful grounds to
process this
2. Be open about your actions and
prepare for data subject requests
3. Keep the data safe and delete it when
you’re finished with it
TRANSPARENCY
GDPRBUILD
TRUST
THROUGH
TRANSPARENCY
Article 12: Transparent information, communication and
modalities for the exercise of the rights of the data subject
Article 13: Information to be provided where personal
data are to be collected from the data subject
TRANSPARENCY
6 Principles
▸ PURPOSE - Disclose your purpose for processing, current and future
▸ LEGITIMATE INTEREST - Disclose your grounds for legitimate interest
▸ RETENTION PERIODS - Disclose your expected data retention periods
▸ 3RD PARTY PROCESSORS - Disclose where you’re sending the data
▸ DATA SAFEGUARDS - Disclose the data safeguards you have in place to secure and protect your user’s data
▸ EASY OPT OUT - You must make it easy to opt out
TRANSPARENCY
RETENTION
PERIODS
▸ Disclose your
expected data
retention
periods
HOW
‣ PRIVACY POLICY
‣ ADD DATE FIELDS TO TRACK WHEN
CONTACT WAS ADDED, LAST
CONTACT
‣ BULK UPDATE FOR HOUSEKEEPING
‣ GENERAL GUIDELINE:
- CUSTOMERS = 12 MONTHS
- PROSPECTS = 3-6 MONTHS
TRANSPARENCY
MECHANISMS FOR TRANSFERRING DATA OUTSIDE OF THE EU/EE
LAWFUL
PROCESSING
GDPR
PICK
ONE
ONLY
TRANSPARENCY
LAWFUL
PROCESSING
1. Explicit consent for each purpose of
use
2. Performance of Contract
3. Legal Obligation
4. Vital Interest of Individual
5. Public Interest - Official Authority
6. Legitimate Interest
Article 6: Lawfulness of processing
TRANSPARENCY
CONSENT
1. Explicit consent for each purpose of use
2. Unambiguous
3. Freely Given
4. Informed
5. Clear affirmative action
6. As easy to withdraw as it is to provide
7. Maintained as proof that it was provided
Article 7: Conditions of Consent
LEGITIMATE INTEREST
Would the person
receiving this
reasonably expect to
receive this?
PERSONAL
DATA
GDPREVERY PIECE
OF DATA THAT
CAN BE USED
TO UNIQUELY
IDENTIFY A
PERSON
TRANSPARENCY
PERSONAL DATA
1. Name
2. Email
3. ID numbers
4. Physical address
5. Other location data
6. IP address and cookies
(online identifiers)
INDIVIDUAL
RIGHTS
GDPR
STRENGTHENED
INDIVIDUAL RIGHTS
TRANSPARENCY
INDIVIDUAL RIGHTS
ARTICLE 16: RIGHT TO RECTIFICATION
ARTICLE 17: RIGHT TO ERASURE
ARTICLE 18: RIGHT TO
RESTRICTION
ARTICLE 20: RIGHT TO PORTABILITYARTICLE 15: RIGHT OF ACCESS
LEAD
GENERATION
AND
NURTURING
MARKETING
MARKETING
GETS
PERSONAL
TRANSPARENCY
LEAD GENERATION
EMAIL
MARKETING
MARKETING
MARKETING
GETS
PERSONAL
THE GDPR STATES THAT THE
PROCESSING OF PERSONAL DATA FOR
DIRECT MARKETING PURPOSES MAY BE
CARRIED OUT FOR LEGITIMATE
INTEREST
With proviso’s…..
RECITAL 70
RECITAL 70
DIRECT MARKETING
▸ Have a relevant and appropriate relationship with them
▸ Show that there is a balance of interests between the
organisation and the person receiving the marketing.
▸ Tell them you are going to market to them
▸ Show them how to opt out of receiving marketing from you
80/20
RULEPARETO’S PRINCIPLE
SUMMARY
▸ LOG YOUR LEGAL BASIS
▸ GET CONSENT FOR MARKETING
▸ LOG THE DATE
▸ KEEP A REGISTER OF YOUR RATIONALISATIONS/DECISIONS
▸ LIMIT OR EXCLUDE STORING SENSITIVE DATA
▸ IF DOESN’T FEEL RIGHT, IT OFTEN ISN’T
▸ DELETE, DELETE, DELETE
Useful resources / links
▸ http://gdprandyou.ie
▸ https://gdpr-info.eu (official pdf of the regulation, neatly arranged as a
website)
▸ https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regul
ation-gdpr/
▸ https://philipajane.com
▸ https://www.onepagecrm.com/sales-resources/gdpr-cheat-sheet
HOW DO YOU
EAT AN
ELEPHANT?
(OR TACKLE GDPR)
ONE BITE
AT A TIME!

Weitere ähnliche Inhalte

Was ist angesagt?

Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRPrecisely
 
Paul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolPaul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolSagittarius
 
Gdpr compliance critical changes
Gdpr compliance critical changesGdpr compliance critical changes
Gdpr compliance critical changesAngela Nubbert
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoDaniel Smith
 
GDPR - What you need to know about the General Data Protection Regulation
GDPR - What you need to know about the General Data Protection RegulationGDPR - What you need to know about the General Data Protection Regulation
GDPR - What you need to know about the General Data Protection RegulationLauren Olson
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidencePrecisely
 
Australia Privacy Act of 1988
Australia Privacy Act of 1988Australia Privacy Act of 1988
Australia Privacy Act of 1988termsfeed
 
Tackling GDPR in Sitecore Versions 8 & 9
Tackling GDPR in Sitecore Versions 8 & 9Tackling GDPR in Sitecore Versions 8 & 9
Tackling GDPR in Sitecore Versions 8 & 9Sagittarius
 
GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GreenRope
 
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)Precisely
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policytermsfeed
 
GDPR - What You Need To Know
GDPR - What You Need To KnowGDPR - What You Need To Know
GDPR - What You Need To KnowAndrew Marks
 
DCH Data Protection Training Presentation
DCH Data Protection Training PresentationDCH Data Protection Training Presentation
DCH Data Protection Training PresentationMark Gracey
 
Data protectionpolicyliec
Data protectionpolicyliecData protectionpolicyliec
Data protectionpolicyliecvrishi31
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Jon Rathbone
 

Was ist angesagt? (18)

GDPR
GDPRGDPR
GDPR
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPR
 
Paul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore ToolPaul Stephen - GDPR The Opportunity & Sitecore Tool
Paul Stephen - GDPR The Opportunity & Sitecore Tool
 
Gdpr compliance critical changes
Gdpr compliance critical changesGdpr compliance critical changes
Gdpr compliance critical changes
 
Run bunprivacy
Run bunprivacyRun bunprivacy
Run bunprivacy
 
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith DooghenoGDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
 
GDPR - What you need to know about the General Data Protection Regulation
GDPR - What you need to know about the General Data Protection RegulationGDPR - What you need to know about the General Data Protection Regulation
GDPR - What you need to know about the General Data Protection Regulation
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with Confidence
 
Australia Privacy Act of 1988
Australia Privacy Act of 1988Australia Privacy Act of 1988
Australia Privacy Act of 1988
 
Tackling GDPR in Sitecore Versions 8 & 9
Tackling GDPR in Sitecore Versions 8 & 9Tackling GDPR in Sitecore Versions 8 & 9
Tackling GDPR in Sitecore Versions 8 & 9
 
GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant?
 
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policy
 
GDPR - What You Need To Know
GDPR - What You Need To KnowGDPR - What You Need To Know
GDPR - What You Need To Know
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
DCH Data Protection Training Presentation
DCH Data Protection Training PresentationDCH Data Protection Training Presentation
DCH Data Protection Training Presentation
 
Data protectionpolicyliec
Data protectionpolicyliecData protectionpolicyliec
Data protectionpolicyliec
 
Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18Gdpr powerpoint 15.01.18
Gdpr powerpoint 15.01.18
 

Ähnlich wie OnePageCRM: Tackling GDPR - one bite at a time

How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burdenIRIS
 
How GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneHow GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneThomas Goubau
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. dan hyde
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersSpain-Holiday.com
 
GDPR - A Concise Treatise
GDPR - A Concise TreatiseGDPR - A Concise Treatise
GDPR - A Concise TreatiseDevopam Mittra
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceSarah Fox
 
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?MediaPost
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Gdprplan.com affiliate huddle 10th may 2018
Gdprplan.com   affiliate huddle 10th may 2018Gdprplan.com   affiliate huddle 10th may 2018
Gdprplan.com affiliate huddle 10th may 2018Micky Khanna
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
Information Privacy?! (GDPR)
Information Privacy?! (GDPR)Information Privacy?! (GDPR)
Information Privacy?! (GDPR)Michel Bitter
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliantSiddharth Ram Dinesh
 

Ähnlich wie OnePageCRM: Tackling GDPR - one bite at a time (20)

How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
How GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneHow GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect Everyone
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
GDPR - A Concise Treatise
GDPR - A Concise TreatiseGDPR - A Concise Treatise
GDPR - A Concise Treatise
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Gdprplan.com affiliate huddle 10th may 2018
Gdprplan.com   affiliate huddle 10th may 2018Gdprplan.com   affiliate huddle 10th may 2018
Gdprplan.com affiliate huddle 10th may 2018
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
Information Privacy?! (GDPR)
Information Privacy?! (GDPR)Information Privacy?! (GDPR)
Information Privacy?! (GDPR)
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 

Kürzlich hochgeladen

NEON LIGHT CITY pitch deck for AR PC GAME
NEON LIGHT CITY pitch deck for AR PC GAMENEON LIGHT CITY pitch deck for AR PC GAME
NEON LIGHT CITY pitch deck for AR PC GAMEtess51
 
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...Authentic No 1 Amil Baba In Pakistan
 
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCRsoniya singh
 
About Entrepreneur ELON MUSK .pptx...
About  Entrepreneur  ELON  MUSK .pptx...About  Entrepreneur  ELON  MUSK .pptx...
About Entrepreneur ELON MUSK .pptx...lahiruherath654
 
blank inception deck powerpoint template
blank inception deck powerpoint templateblank inception deck powerpoint template
blank inception deck powerpoint templatericardojunco4
 
Viet Nam Inclusive Business Accreditation System
Viet Nam Inclusive Business Accreditation SystemViet Nam Inclusive Business Accreditation System
Viet Nam Inclusive Business Accreditation SystemTri Dung, Tran
 
Entrepreneur street first Edition is now out
Entrepreneur street first Edition is now outEntrepreneur street first Edition is now out
Entrepreneur street first Edition is now outentrepreneur street
 
Role of social media marketing in digital marketing.pdf
Role of social media marketing in digital marketing.pdfRole of social media marketing in digital marketing.pdf
Role of social media marketing in digital marketing.pdftopsearchexperts
 
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证0622mpom
 
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...LHelferty
 
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAO
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAOCATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAO
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAOTMTerraplanagem
 

Kürzlich hochgeladen (14)

NEON LIGHT CITY pitch deck for AR PC GAME
NEON LIGHT CITY pitch deck for AR PC GAMENEON LIGHT CITY pitch deck for AR PC GAME
NEON LIGHT CITY pitch deck for AR PC GAME
 
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...
Authentic No 1 Amil Baba In Pakistan Amil Baba In Faisalabad Amil Baba In Kar...
 
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Sriniwaspuri 🔝 Delhi NCR
 
About Entrepreneur ELON MUSK .pptx...
About  Entrepreneur  ELON  MUSK .pptx...About  Entrepreneur  ELON  MUSK .pptx...
About Entrepreneur ELON MUSK .pptx...
 
blank inception deck powerpoint template
blank inception deck powerpoint templateblank inception deck powerpoint template
blank inception deck powerpoint template
 
Viet Nam Inclusive Business Accreditation System
Viet Nam Inclusive Business Accreditation SystemViet Nam Inclusive Business Accreditation System
Viet Nam Inclusive Business Accreditation System
 
Hot Sexy call girls in Rajouri Garden🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rajouri Garden🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rajouri Garden🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rajouri Garden🔝 9953056974 🔝 Delhi escort Service
 
young call girls in kailash Nagar, 🔝 9953056974 🔝 escort Service
young call girls in kailash Nagar, 🔝 9953056974 🔝 escort Serviceyoung call girls in kailash Nagar, 🔝 9953056974 🔝 escort Service
young call girls in kailash Nagar, 🔝 9953056974 🔝 escort Service
 
Entrepreneur street first Edition is now out
Entrepreneur street first Edition is now outEntrepreneur street first Edition is now out
Entrepreneur street first Edition is now out
 
Role of social media marketing in digital marketing.pdf
Role of social media marketing in digital marketing.pdfRole of social media marketing in digital marketing.pdf
Role of social media marketing in digital marketing.pdf
 
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证
办昆士兰大学UQ毕业证书/成绩单GPA修改 - 留学买假毕业证
 
Why Powderless DTF Printer is T-shirt Printing Game Changer.pptx
Why Powderless DTF Printer is T-shirt Printing Game Changer.pptxWhy Powderless DTF Printer is T-shirt Printing Game Changer.pptx
Why Powderless DTF Printer is T-shirt Printing Game Changer.pptx
 
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
Report about the AHIABGA-UnityNet UNDRIPDay / Earth-Day 2024 Gathering in Mar...
 
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAO
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAOCATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAO
CATALOGO MF 650 COMPLETO COM PEÇAS DE TRANSMISSAO
 

OnePageCRM: Tackling GDPR - one bite at a time

  • 1. GDPR, OnePageCRM and Your Business Tackling GDPR - one bite at a time Please wait. The webinar will start shortly....
  • 2. Carmel Granahan Head of Customer Success, OnePageCRM Your speakers today…. Philipa Jane Farley Data Protection and Privacy Law Specialist Andrea Manning GDPR Lead, OnePageCRM
  • 3. WE’VE SPENT A LOT OF TIME WITH GDPR AND LIKE TO THINK WE’VE BEEN THOUGHTFUL ABOUT ITS INTENT AND MEANING. BUT THE APPLICATION OF GDPR IS HIGHLY FACT-SPECIFIC, AND NOT ALL ASPECTS AND INTERPRETATIONS OF GDPR ARE WELL-SETTLED. AS A RESULT, THIS PRESENTATION IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY AND SHOULD NOT BE RELIED UPON AS LEGAL ADVICE OR TO DETERMINE HOW GDPR MIGHT APPLY TO YOU AND YOUR ORGANISATION. WE ENCOURAGE YOU TO WORK WITH A LEGALLY QUALIFIED PROFESSIONAL TO DISCUSS GDPR, HOW IT APPLIES SPECIFICALLY TO YOUR ORGANISATION, AND HOW BEST TO ENSURE COMPLIANCE. DISCLAIMER
  • 4. Welcome Today’s Agenda ❏ An overview of GDPR, the roles, lawful processing of data, consent v’s legitimate interest ❏ How to utilize fields in OnePageCRM to enable you to implement better GDPR compliant processes (demo) ❏ How to do a legitimate interest assessment ❏ Most frequently asked GDPR questions ❏ Live Q & A
  • 5. GDPR requirements and OnePageCRM Individual rights ❏ The right to access information (subject access request) - Export data ❏ The right to erasure - Delete the data from OnePageCRM (option in bulk / individually) & also delete your account ❏ The right to data portability - Export data ❏ The right to rectification - Edit contact and update user profile
  • 6. Lawful processing and OnePageCRM 1. Explicit consent (Marketing) How to achieve with OnepageCRM? Webform > OnePageCRM (custom fields) 2. Performance of contract How to achieve with OnepageCRM? (Status labels) 3. Legitimate interest How to track with OnepageCRM? (Status labels, lead source, date created, custom fields)
  • 7. Repermissioning Step 2 Existing list (Mailchimp & OnePageCRM integration connected) Step 1
  • 8. WELCOME DOES GDPR APPLY TO YOU? ▸ The GDPR is applicable to the processing of personal data by businesses established in and operating outside the European Union (“the EU”). If your company is established in the EU, the provisions of the GDPR are applicable to your processing of personal data in the context of the activities of your EU establishment(s). ▸ If your company is not established in the EU, the new law is applicable to your processing of the personal data of individuals in the EU with regard to the offering of goods or services (regardless of whether payment is involved) and to the monitoring of an individual’s behaviour (in so far as that behaviour takes place within the EU). ▸
  • 9. CONTROLLER VERSUS PROCESSOR The Yellow Hat Company CUSTOMER/DATA SUBJECT PROCESSORCONTROLLER PROCESSOR
  • 10. GDPR AND YOU ONEPAGECRM - YOUR PROCESSOR 1. Processor needs to be GDPR compliant 2. The data processor can’t bring in other data processors unless he has notified the Controller, and has permission to do so 3. There also must be a contract between the data processor and data controller that should clearly mention the subject-matter, duration, nature and purpose of the involved data processing 3. Keep records of all processing and provide secure processing 4. Common duties and shared liability 5. Assist the Controller in meeting their responsibilities
  • 11.
  • 13. GDPR AND YOU TELL YOUR SALESPEOPLE 1. Gather only data you need and make sure you have lawful grounds to process this 2. Be open about your actions and prepare for data subject requests 3. Keep the data safe and delete it when you’re finished with it
  • 14. TRANSPARENCY GDPRBUILD TRUST THROUGH TRANSPARENCY Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject Article 13: Information to be provided where personal data are to be collected from the data subject
  • 15. TRANSPARENCY 6 Principles ▸ PURPOSE - Disclose your purpose for processing, current and future ▸ LEGITIMATE INTEREST - Disclose your grounds for legitimate interest ▸ RETENTION PERIODS - Disclose your expected data retention periods ▸ 3RD PARTY PROCESSORS - Disclose where you’re sending the data ▸ DATA SAFEGUARDS - Disclose the data safeguards you have in place to secure and protect your user’s data ▸ EASY OPT OUT - You must make it easy to opt out
  • 16. TRANSPARENCY RETENTION PERIODS ▸ Disclose your expected data retention periods HOW ‣ PRIVACY POLICY ‣ ADD DATE FIELDS TO TRACK WHEN CONTACT WAS ADDED, LAST CONTACT ‣ BULK UPDATE FOR HOUSEKEEPING ‣ GENERAL GUIDELINE: - CUSTOMERS = 12 MONTHS - PROSPECTS = 3-6 MONTHS
  • 17. TRANSPARENCY MECHANISMS FOR TRANSFERRING DATA OUTSIDE OF THE EU/EE
  • 19. TRANSPARENCY LAWFUL PROCESSING 1. Explicit consent for each purpose of use 2. Performance of Contract 3. Legal Obligation 4. Vital Interest of Individual 5. Public Interest - Official Authority 6. Legitimate Interest Article 6: Lawfulness of processing
  • 20. TRANSPARENCY CONSENT 1. Explicit consent for each purpose of use 2. Unambiguous 3. Freely Given 4. Informed 5. Clear affirmative action 6. As easy to withdraw as it is to provide 7. Maintained as proof that it was provided Article 7: Conditions of Consent
  • 21. LEGITIMATE INTEREST Would the person receiving this reasonably expect to receive this?
  • 22. PERSONAL DATA GDPREVERY PIECE OF DATA THAT CAN BE USED TO UNIQUELY IDENTIFY A PERSON
  • 23. TRANSPARENCY PERSONAL DATA 1. Name 2. Email 3. ID numbers 4. Physical address 5. Other location data 6. IP address and cookies (online identifiers)
  • 25. TRANSPARENCY INDIVIDUAL RIGHTS ARTICLE 16: RIGHT TO RECTIFICATION ARTICLE 17: RIGHT TO ERASURE ARTICLE 18: RIGHT TO RESTRICTION ARTICLE 20: RIGHT TO PORTABILITYARTICLE 15: RIGHT OF ACCESS
  • 29. THE GDPR STATES THAT THE PROCESSING OF PERSONAL DATA FOR DIRECT MARKETING PURPOSES MAY BE CARRIED OUT FOR LEGITIMATE INTEREST With proviso’s….. RECITAL 70
  • 30. RECITAL 70 DIRECT MARKETING ▸ Have a relevant and appropriate relationship with them ▸ Show that there is a balance of interests between the organisation and the person receiving the marketing. ▸ Tell them you are going to market to them ▸ Show them how to opt out of receiving marketing from you
  • 32.
  • 33.
  • 34. SUMMARY ▸ LOG YOUR LEGAL BASIS ▸ GET CONSENT FOR MARKETING ▸ LOG THE DATE ▸ KEEP A REGISTER OF YOUR RATIONALISATIONS/DECISIONS ▸ LIMIT OR EXCLUDE STORING SENSITIVE DATA ▸ IF DOESN’T FEEL RIGHT, IT OFTEN ISN’T ▸ DELETE, DELETE, DELETE
  • 35. Useful resources / links ▸ http://gdprandyou.ie ▸ https://gdpr-info.eu (official pdf of the regulation, neatly arranged as a website) ▸ https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regul ation-gdpr/ ▸ https://philipajane.com ▸ https://www.onepagecrm.com/sales-resources/gdpr-cheat-sheet
  • 36. HOW DO YOU EAT AN ELEPHANT? (OR TACKLE GDPR)
  • 37. ONE BITE AT A TIME!