The GDPR is neither a formality nor a disaster. For most websites it concerns a handful of concrete things.
The GDPR, General Data Protection Regulation, is the European privacy law that regulates how organisations handle personal data. For a website, this mainly means: collect only what you need, explain what you do with it, don't keep it longer than necessary and secure it properly. Internationally, the same law is called GDPR.
IN COMMON LANGUAGE
What it means practically
A name, e-mail address or IP address is personal data. A contact form therefore processes personal data, which means that almost every business website falls under the law.
The core is limitation and openness. Don't ask for a phone number if you're just emailing. In your privacy statement, say in plain language what you keep, why, how long and with whom you share it. Throw away what you no longer need.
You also require prior permission for analytics and marketing cookies. A bar with only an agree button is not sufficient: refusing should be as easy as accepting.
WHY IT MATTERS
What we pay attention to during construction
Analytics is turned off by default until someone gives permission, and refusing is as easy as accepting. Form data goes to a processor within the EU.
We are not lawyers. We build in such a way that it is technically correct and point out what is missing, but you need someone else for the legal test of your statements and processing agreements.
- Only ask for what you need — every additional field is additional responsibility.
- Privacy statement in plain language — legally boarded up and illegible doesn't help anyone.
- Consent before analytics — and refuse as easily as accept.
- Agree on a retention period — and act accordingly.
- Processing agreement — with any party that processes data on your behalf.
- Processing within the EU — saves a lot of legal detours.
FREQUENTLY ASKED QUESTIONS
More about the GDPR
Do I need a cookie notification?
Only if you place cookies that are not strictly necessary, such as analytics or advertising cookies. Purely functional cookies are allowed without permission. Many sites show a notification without posting anything that requires it: that's unnecessary friction.
What is a processing agreement?
An agreement with every party that processes personal data on your behalf: your hosting party, your email platform, your CRM. It states what they are allowed to do, how they protect themselves and what happens in the event of a data breach. It is mandatory and often forgotten.
What if something goes wrong?
In the event of a data breach with a risk for those involved, you must report this within 72 hours to the Dutch Data Protection Authority, and sometimes also to the people themselves. Make sure you know in advance who will do this - figuring out who does this during an incident is the problem.
CONTINUE READING
Of course, continue reading about this subject.
Technically neat arranged?
We look at your forms, cookies and analytics and tell you what is technically missing.