Skip to content
Digital marketing · Development · E-commerce · Digital planning · Mobile

What Is GDPR?

Learn what GDPR (General Data Protection Regulation) is and how it can impact your digital project and digital marketing activities, whether you run a website, e-commerce store, app, blog, or platform.

What Is GDPR?

GDPR (General Data Protection Regulation) is a new regulation created by the European Union. It came into effect on 25/05/2018 and aims to define the obligations of companies that handle data belonging to people who are residents of the European Union.

Data breaches on the Internet have become commonplace, especially when they involve major players in the global market, such as the social network Facebook. For this reason, the desire to protect user privacy has now become a regulatory issue.

What is the main goal of GDPR?

GDPR’s main goal is to increase user privacy in the online world.

Although initially a protection rule for users in the European Union, it already affects all companies that use information provided by consumers who have some kind of connection to groups in the European Union.

In short, any personal data provided by users must be handled in accordance with the new standards.

What is considered personal data?

GDPR considers personal data to be any information provided by a user that, alone or combined with other data, can be used to identify an individual.

Examples include identity documents (CPF, RG, etc.), name, IP address, photos, comments, reviews, physical address, email, financial data, information about behavior when using websites or apps, and any other similar information.

Does GDPR have any impact in Brazil?

The answer is easy: absolutely.

Brazilian laws are still unclear when it comes to the points already established in GDPR. However, given the many cases of data breaches, many of the measures imposed by the European Union are also expected to be adopted in our legislation.

But since commercial transactions are now global, it is natural for companies around the world, including Brazilian companies, to comply with this new regulation.

In other words, any company that collects consumer data for any reason today not only can, but must, take GDPR seriously.

Which countries make up the European Union?

The EU is an economic, political, and social bloc made up of 28 countries: Germany, Austria, Belgium, Bulgaria, Cyprus, Croatia, Denmark, Slovakia, Slovenia, Spain, Estonia, Finland, France, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands (Holland), Poland, Portugal, the United Kingdom (a popular referendum approved its departure from the EU on 23/06/2016), the Czech Republic, Romania, and Sweden. Macedonia, Croatia, and Turkey are in the negotiation phase.

Source: Wikipedia, European Union countries

What is the impact on digital marketing?

If your company or agency stores personal data about its contacts, whatever the purpose, you need to understand what changes with GDPR.

This regulation applies to any company that stores or processes the personal data of any user who resides in the European Union (EU), regardless of where the company is located. In other words, if an EU consumer decides to buy something from a Brazilian e-commerce store, whether they are in Brazil or their country of origin, the Brazilian company must comply with the new regulation.

Under GDPR, the primary parties targeted by the regulation are companies known as data controllers (data controllers), that is, companies that control user data, whether through software or otherwise.

Software companies, known as data processors (data processors), must adopt technical measures to ensure information is always processed securely, respecting the privacy of the data owners (the users).

What if my company does not comply? What are the GDPR fines?

The penalty for companies that fail to comply with GDPR can reach 4% of the company’s global annual revenue or 20 million euros, whichever is greater. At current exchange rates, the maximum amount is more than 80 million reais.

This means that, for companies such as Google, Microsoft, and Facebook, the penalty could cost billions of dollars.

What now? How can I comply with GDPR?

There are several points to consider. We recommend reading the GDPR website (in English), which covers the main changes. To read the full regulation, visit the Eurlex website, where you can also access the final text of the regulation in Portuguese.

Here are a few tips to get started with GDPR compliance:

User consent

It is extremely important to clearly explain why each piece of user data is being collected. In addition, when users provide their data, the opt-in must be clear and straightforward. You can no longer use tricks such as fine print, preselected boxes, or omitted text. In other words, users must be aware that their data will be collected when they take a particular action.

Access to collected data

Users have the right to access the data a company holds about them at any time, and to have that data sent to them in electronic format at no cost.

Data transfers between systems

Users can request that their data be transferred (data portability) to another system, rather than the one that collected it, without losing any information. In other words, they can have a “backup” of everything a particular system has about them so it can be “retrieved” by another system.

Complete deletion of collected data

This is the right to be “forgotten.”

If a user requests it, the company must permanently delete their data and may not use it for any purpose from that point on.

Notifications in the event of a data breach (security)

If, for any reason, a company’s data is breached, stolen, exposed, or made vulnerable in any way, the company must notify all affected users within 72 hours of discovering the breach. This applies to data processors and data controllers, and failure to comply may result in a fine.

Use of cookies

Add a notice about the use of cookies to every page being monitored.

Technical lead for data protection

Companies that regularly carry out activities requiring the use of large amounts of personal data (such as Digital Marketing companies) need to have a professional who is technically responsible for protecting that data.

Terms of use, privacy policies, and more

Update your terms of use, privacy policies, contracts, and other important documents to make it clear that you are meeting the regulatory requirements and to specify which services are used to store and process user data.

Conclusion

It is never too late to get started. Now more than ever, we need to rethink how we interact with our user base and store their data. Increasingly targeted actions will ensure that we deliver what our users really want and never use their information in a way that bothers them.

These changes have a significant impact on technology and digital marketing, but an even greater impact on companies around the world, which need to change their mindset for a new era of data protection and privacy.

GDPR may not solve every privacy-related problem, but it is undoubtedly the most aggressive effort to protect personal data. 


Read also: Key players in LGPD: learn who is responsible for implementing and complying with the law