GDPR and Marketing: A Guide

GDPR and marketing are closely linked. Since 2018 the General Data Protection Regulations (GDPR) has mandated rules about how and why personal data may be used. This has significantly reshaped the marketing industry. This regulation has placed significant compliance on marketers, and abiding by the GDPR’s rule is not just a legal necessity but also a way to build trust with consumers and enhance brand reputation.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is the GDPR?

The GDPR aims to protect individuals’ personal data and privacy. It sets forth comprehensive principles that dictate how personal data should be collected, processed, and stored. For marketers, it’s crucial to grasp these principles to navigate the compliance landscape effectively. Key principles include lawfulness, fairness, and transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.

At its core the GDPR sets out that the processing of personal data must be:

  • transparent

  • limited to what is necessary

  • have a clear lawful basis

  • done safely and securely

It is also important to comply with a range of rights people have to control how their data are used.

 

gdpr and marketing - laptop with social media icons

 

GDPR Compliance for Marketers

There are three key things marketers need to get right at the start when thinking about GDPR compliance.

  1. Knowing clearly the purposes you need personal data for

  2. Understanding what personal data you need for those purposes

  3. Being able to identify a lawful basis for processing the personal data for those purposes.

Purposes for Processing

Marketing is a broad concept. It might be you want to reach out to new people to interest them in your products and services. Alternatively you might want to make further sales to existing customers.

If you think you might need to collect or re-use personal data you must plan for this as part of your data processing activity. You cannot decide to use personal data for new purposes because people are entitled under the GDPR to know what their data are being used for at the point it is being collected.

One of the cornerstones of GDPR compliance is obtaining explicit consent from individuals before processing their personal data. This consent must be freely given, specific, informed, and unambiguous. Marketers must ensure that their privacy notices are clear, concise, and easily accessible. Transparency involves providing detailed information about data processing activities, ensuring individuals understand how their data will be used.

Therefore your marketing activity and the personal data you need for it have to be planned for.

The Personal Data You Need

As part of your planning you should think about the data that you need.

One of the main GDPR principles is that the personal data you collect you be “adequate, relevant and not excessive”. You should also take reasonable steps to keep it accurate and up to date.

Naturally for email marketing you need email addresses, or for telephone marketing calls you need telephone numbers. However, you might also need information about people’s lifestyles, preferences and personal circumstances in order to target the right people with your marketing messages.

One of the great things about modern technology is the ability to use it to target specific cohorts of people with highly refined marketing. There is absolutely nothing in the GDPR that prevents you from doing this. You must, however, think carefully about the data you need to deliver you granular marketing strategy.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

The Lawful Basis for Processing

All processing of personal data must have a lawful basis. Very few of these lawful bases will apply to marketing so let’s focus on the two main ones that may apply:

  • consent

  • legitimate interests

Consent

Consent is likely to be the main lawful basis most marketers use to process personal data for direct marketing.

Under the GDPR consent must be:

  • specific

  • informed, and

  • given through positive action

That means consent has to be broken down – you should get consent separately for all consent based activities. You also need to explain fully what you are seeking consent for.

Finally people must opt-in when giving consent. This is because you must show that people gave you consent, which you cannot do with an opt-out model.

Legitimate Interests

Another lawful basis is legitimate interests. As the name suggests if you have a legitimate interest and the impact on people’s privacy is small you can process people’s data on the basis of that legitimate interest. An example of this is making existing customers aware of wider products and services they may be interested in.

You must be able to clearly define the legitimate interests you are pursuing the use this lawful basis.

The Right to Object

One of the rights people have under the GDPR is the right to object. This means they can object to the use of their data for a range of purposes. These rights are rarely absolute but when it comes to marketing it is.

That means people have an absolute right to stop their data being used for marketing purposes. If people tell you they do not want to hear marketing messages from you then you must stop.

 

Get More Support

If you found this content helpful, why stop there? Take the next step in your journey by exploring this comprehensive range of support options. Whether you’re looking to deepen your knowledge through training courses, access free resources, or attend expert-led events, we have something for everyone. And if you have any questions don’t hesitate to reach out to us directly for personalised guidance and support. We’re here to help

legal requirement

Training

Explore the learning opportunities available to you with WuDo Solutions. Click here to learn more

Quick Win

Resources

Explore free resources to help you understand this topic, all curated by our team of experts

Top Tip

Events

Join one of our regular, expert led events explore a range of topics in depth

Signpost

Contact

If you have any questions or there is something else we can help you with get in touch

Other Things to Consider

Alongside the basic fundamentals there are a number of other things to consider. These will help you ensure your marketing activity is GDPR compliant.

Data Collection Practices

Marketers should adopt best practice for data collection, emphasising the need to collect only the minimum necessary data. Implementing proper data collection strategies not only aids in compliance but also enhances data quality and relevance.

Data Processing and Usage

Marketers must ensure that data processing activities are lawful and transparent. This involves clearly defining the purpose of data processing and ensuring that it aligns with the expectations of the data subjects. That means limiting the use of people’s data for the activities you told people about.

Rights of Data Subjects

GDPR grants several rights to data subjects alongside the right to object. For example, people can make subject access requests, have their data updated if they believe it is inaccurate, or even have it deleted. Marketers must respect these rights and facilitate them. This involves setting up mechanisms to identify when people are exercising their rights and ensuring that these requests are addressed promptly.

Profiling and Automated Decision Making

Profiling and automated decision-making may be used in marketing. However, GDPR imposes specific regulations on these activities. Marketers must ensure that profiling is conducted transparently and that individuals are informed about the logic, significance, and potential consequences of profiling. Where significant decisions are made solely by automated means, individuals must be informed about this and given the right to human intervention.

Data Security Measures

Ensuring the security of personal data is key to avoiding a data breach. Marketers must implement appropriate technical and organisational measures to protect data from unauthorised access, loss, or damage. These measures include encryption, pseudonymisation, regular security assessments, and training staff on data protection.

In the event of a data breach, prompt action is crucial. Marketers must have a response plan in place that includes potentially notifying the relevant supervisory authority within 72 hours of becoming aware of the breach. Affected individuals should also be informed if the breach poses a high risk to their rights and freedoms.

International Data Transfers

Transferring personal data overseas presents additional compliance challenges. Marketers must ensure that such transfers are conducted in accordance with GDPR, which often involves using standard contractual clauses, binding corporate rules, or ensuring that the receiving country has an adequate level of data protection.

Regular Audits and Compliance Checks

Regular audits and compliance checks are vital in maintaining GDPR compliance. Marketers should conduct periodic reviews of their data processing activities, privacy policies, and security measures. This helps in identifying potential compliance gaps and taking corrective actions promptly.

Disposing of Data

When you no longer need a person’s data you should put in place processes to delete it. This will vary depending on your relationship with the people involved. For example, if someone has exercised their right to object then you may need to keep their data indefinitely to ensure you do not accidently include them in your marketing communication in the future.

Conclusion

GDPR compliance is essential for marketing but it can be done. By carefully planning your marketing activity, the data you need, and the lawful basis you are relying on you can get your GDPR fundamentals right. You also need to be mindful of people’s rights – especially their right to stop receiving marketing messages.

Effective and GDPR compliant marketing systems will help you avoid the reputational harm and operational impact of a data breach. The GDPR doesn’t prevent the use of data for marketing but it does set certain rules that it is important you understand.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial