News | GDPR and Website Policies | Eaton Smith | Law Firm & Solicitors Huddersfield Skip to main content

News

..with you every step of the way!

news


15/01/2018

GDPR and Website Policies

As you will no doubt be aware the General Data Protection Regulation (GDPR) comes into force in the UK on 25 May 2018. This new data protection legislation is set to affect how businesses run when they are processing individual’s personal data in common events such as dealing with website enquiries and orders.

GDPR will have an extensive impact on how businesses use their websites when they take information such as individual’s contact details as the new legislation is significantly different to the current data protection laws. Amongst many other things, GDPR requires transparency when collecting and processing personal data and it grants individuals with the right to have their personal data erased.

When individuals provide their personal data, GDPR requires opt ins for how personal data will be used rather than, what the (soon to be) old legislation allows, the individual to opt out of what they do not want their personal data to be used for. The new legislation repeats the current position even if an individual doesn’t request data erasure (which they can do), it should not be stored for any longer than is necessary, having regard to what it was collected for.

For example, if an individual visits your website and completes a contact form to enquire about a product or service which you offer, you can only use their personal data for dealing with their enquiry and not for any other purposes such as sending them marketing newsletters unless they expressly consent (opt in) for you to do so. If the enquiry does not progress, you should delete their personal data. Therefore, if you wanted to use their personal data for marketing purposes you must obtain their clear consent to be able to so contact them and keep a record of their consent; otherwise you will be in breach of GDPR.

If you have terms and conditions of website use and a privacy policy on your website, amongst other things, you can explain what information you are collecting from individuals and why you are collecting it when they use your website. These policies can assist you to comply with GDPR as you are providing transparency for collecting personal data if they accept your policies but you still need to have specific opt ins.

If you have cookies set up on your website to identify website users, you are required to have a cookies policy explaining the purposes for which the cookie is stored and accessed in accordance with the currently enforced Privacy and Electronic Communications Regulations 2003 (which have been updated 4 times since and which are due to be altered again shortly). Depending on what cookies your website has, and how identifiable the website users are from the information collected, you could be considered to have collected personal data by your cookies. This could mean that your cookies policy is not compliant with GDPR provisions and you may need to amend it before 25 May 2018.

If a business is found to be in breach of GDPR by the way they use personal data the Information Commissioner’s Office (ICO) can impose a fine of up to 4% of the organisation’s global annual turnover or €20 million, whichever is greater. In comparison, the ICO only currently has the power to impose a fine up to £500,000. This illustrates the importance for businesses to ensure that they are compliant with the GDPR provisions.

Eaton Smith Solicitors can help you prepare your website policies to be compliant with GDPR before it comes into force in May.

We can assist you on your website documentation with preparing the following:

  • Website terms of use;
  • Privacy policy;
  • Website acceptable use policy;
  • Your cookies policy; and
  • Terms and conditions of sale.

If you need to discuss any of the above further, please do contact Lewis Holroyd on 01484 821415.