Up to €20 million…
or four percent of your total worldwide annual turnover of the previous financial year, whichever higher.
That’s the penalty for failing to comply with the General Data Protection Regulation (GDPR), the EU’s new data privacy law.
Okay, sorry to start this post on such a heavy note, but the GDPR is very important to comply with. And not only that, I believe that the new regulation is something we should fully embrace as I can see it bringing around positive changes that could be beneficial to both customers and businesses.
In this post, I’ll share some benefits of the GDPR for your business and your customers. I’ll also cover several key things to note for social media marketing.
Disclaimer: This is my personal understanding of the GDPR based on my research and only covers social media marketing. To ensure that you’re in compliant with all aspects of the GDPR, you should consult your legal advisor.
The General Data Protection Regulation (GDPR) is a new data privacy regulation that aims to give individuals in the EU protection and control over their personal data. This affects how businesses can collect and use personal data.
The regulation will be enforceable from May 25, 2018.
While it is an EU law, it is applicable to any organization with personal data of EU citizens and residents. So if you are a business with customers in the EU, the GDPR will be applicable to you when you are handling personal data of your EU customers.
If you have read the regulation or started preparing for it, you might notice that it requires some effort to be fully compliant with the regulation. But I think there are several potential wins for your business:
And these are just from the marketing perspective. For more benefits that being GDPR-compliant can bring to your business, check out this article by Michael Fimin, CEO and co-founder of Netwrix, an IT security software company.
Besides benefiting your business, the GDPR is also favorable for your customers in many ways.
For example, visitors on mailchimp.com can now customize their cookie preferences.
Organic social media is probably a big part of your role as a social media marketer. The good news is that I believe organic social media marketing (i.e. excluding social media advertising) is largely unaffected by the new regulation.
This is because most organic social media activities such as posting content and engaging fans do not collect personal data from people who view or engage with it.
But there are several instances you want to be mindful of:
Under the GDPR, if you want to use your customers’ data or track their behavior for advertising, you must obtain the legal basis to do so. That is, you have to obtain an explicit opt-in consent from your customers.
Here are a few key points to know:
As there are very stringent requirements for obtaining consent, it’s best to refer to the regulations directly and check with your legal advisor.
Several social media advertising features use customer data that you upload, collect personal data, or track behavior on your site. If you use any of the following features, it’ll be great to look further into the actions you should take before May 25, 2018:
For more information about advertising on social media platforms under the GDPR, check out the following resources by the respective platforms:
(I can’t seem to find Pinterest’s information about GDPR. If you know of any, would you mind sharing the link to their page in the comments section below? Thanks!)
There have also been some changes to lead form ads on Facebook and LinkedIn to help you stay in compliant with the GDPR. As you would be collecting data through lead forms, you’ll need to state how the data will be processed and establish a legal basis (e.g. consent) for processing the data.
Before you can create a lead ad on Facebook, you’ll have to explicitly accept their lead ad terms. You can view and accept their terms here. (Also as a refresher, here are Facebook’s advertising policies.)
In addition to your privacy policy, Facebook now allows you to add a custom disclaimer and optional consent checkboxes to your lead form. I believe this is to enable you to include all the necessary legal information for collecting personal data under the GDPR on the form.
To help you comply with the GDPR, LinkedIn has updated its lead generation form so that you can add a link to your privacy policy and a custom text that states how you’ll be using the collected data.
LinkedIn also has some suggestions for the custom text. For example, if you are collecting email addresses for your newsletter, you could use “We’ll use your information to register you to receive our newsletters.”
The GDPR is a huge and important topic. Here are some of the resources that I have found helpful:
Do you know of any other helpful resources?
As a quick reminder, GDPR comes into effect on May 25, 2018. It’ll be best to prepare your business for it before that date.
At Buffer, we are working hard to be compliant with the GDPR before the enforcement date. We’ll be sharing an update soon so keep an eye out for it!
In the meantime, if you have any questions, feel free to leave a comment below. We’ll try our best to answer them.
—
Image credit: Joshua Sortino on Unsplash, LinkedIn
It’s worth repeating — I am not a lawyer. Personally, I believe that Judge Mehta…
Traditional content marketers focus on creating campaigns and individual articles. When they use AI, it’s…
So first off, what is duplicate content?Essentially, duplicate content is content that appears in more…
Every few years, a shiny new acronym takes over the SEO industry. This time, it's…
Here are a few recommendations for lunch, dinner, snacks - you name it! All within…
When you pair it with an SEO tool like Moz Pro, you can show how optimising…