🎃 Need a website? LIMITED OCTOBER SPACES available. Get in touch to book in 👻

How to Make Your Business & Website GDPR Compliant

3 May 2018

In just 3 weeks, a new European-wide data protection law called the General Data Protection Regulation (or GDPR) will come into effect. It applies to all businesses in the UK, and is an improvement of the current Data Protection Act. With technology continually advancing, this new legislation is being put in place to help protect customer data and give them more control over what information a business holds over them. The Information Commissioners Office has put together an Overview of GDPR to help you understand the new regulation changes. We’ve created this guide on how your business can become GDPR compliant, and how this affects your website.

Your Business Practices & Data Handling

If you’re already compliant with the Data Protection Act (which all UK businesses, even sole traders, should be), then most of your approach to compliance will remain valid under the GDPR and can be the starting point to build from.  However, there are new elements and significant enhancements, so you will have to do some things for the first time and some things differently. Here are some steps to take now, as advised by the ICO (click headings to view details):

[ultimate-faqs ]

Read these 12 Steps in more depth on the ICO’s website

Your Business Website

Every website will have to update their Privacy & Cookie Policies to include their GDPR compliance and include additional information, such as explaining your lawful basis for processing the data, your data retention periods and that individuals have a right to complain to the ICO if they think there is a problem with the way you are handling their data. This handy toolkit from thrive will help you to write a GDPR Compliant Privacy Notice. If your website has Content Management, allowing you to edit the website yourself, this makes it very easy to update your Privacy Policy. You will need to contact your web designer if you need to make changes to your Privacy Notice and you don’t have Content Management.

Every website will need a cookie/privacy notice pop-up on their site, linking to the new Privacy Policy, if they haven’t got one already.

Any part of your website that requires user to submit personal data (such as blog comments, online store, contact form or booking form), should have a clear link to your Privacy Policy. If you wish to use customer’s personal data for marketing purposes, they will have to manually opt-in and give their consent for you to do this. The GDPR specifically bans pre-ticked opt-in boxes.

What CRJ Design Will Do

As a client of CRJ Design, we’ll make it easy for you to update your website to become GDPR Compliant. Clients with Content Management in place will be able to update their Privacy Policy with ease, but we will ensure that all of our client websites have an up-to-date cookie notice, and that all areas of the site which require users to submit data has a clear link to the new Privacy Policy. For clients without Content Management, you may send us an updated copy of your Privacy Policy for us to place on your website for you, free of charge. Please get in touch with us if you have any further questions or requirements.

Note: This is intended to provide an overview of GDPR and is not a definitive statement of the law.

For a definitive guide, check out the Information Commissioner’s Office website.

Share This: