Skip to content
Annuaire
Sections
Communication

Creating a GDPR-compliant website

Creating a GDPR-compliant website
L’essentiel

In a few days, the General Data Protection Regulation (GDPR) will come into force, requiring companies to prove their compliance efforts regarding website construction and content.

À retenir

In a few days, the General Data Protection Regulation (GDPR) will come into force, requiring companies to prove their compliance efforts regarding website construction and content.

[vc_row][vc_column][vc_column_text][show-team ids=’19355′ url=’active_new’ layout=’grid’ style=’img-square,img-white-border,text-left,img-left,normal-float,card-theme’ display=’photo,freehtml,location,name’][/vc_column_text][vc_column_text]

In a few days, the General Data Protection Regulation (GDPR) will come into force (on May 25, 2018).

 

A large number of companies will have to prove their GDPR compliance efforts. This effort must be assessed at the level of the construction and content of websites.

 Don’t wait until the morning of May 25 to wonder about the compliance of your site!

 

What is the GDPR for?

The GDPR aims to better protect the personal data and privacy of individuals. It is a standard unifying existing legislations, with a view to strengthening and unifying personal data protection measures in the European Union.

 

What impact on the creation and management of websites?

The new regulation applies to any website that collects and uses the personal data of its visitors.

It is therefore important that the site be as transparent as possible and clearly indicate to visitors how their personal data is collected, stored, and used.

From now on, every website owner must implement a specific plan concerning data management and justify their processing by one of the six legitimate reasons (consent, contract, compliance with a legal obligation, vital interest, public interest mission, legitimate interest).

Note that the risk of data misuse is reduced if the collection is minimal and limited.

It will be important to obtain the consent of the individuals concerned by the collection, regardless of the type of information.

Regarding so-called “sensitive” personal data, consent must be given explicitly.

The consent of minors must meet specific requirements defined by the said regulation.

Recall that, although consent is a legitimate reason for data processing, the GDPR has nonetheless strengthened the rules regarding its acquisition and conservation.

 

How to make a website compliant with GDPR requirements?

It is recommended to create or update the privacy policy that must appear on the site and to ensure that the services and content offered to visitors comply with European and French provisions.

It is important, initially, to determine the type of data that will be collected, and to define, secondly, the reasons why the collection is necessary.

All this information must appear in the privacy policy.

Furthermore, the privacy policy must be written in clear, understandable, and precise language. It must indicate how the data will be used, collected, and stored.

The privacy policy must clearly indicate to the individuals concerned by the collection how they can exercise their rights.

From now on, every individual will have:

  • a right of access (to a copy of their data collected by the site)
  • a right to modification, if they believe the data is inaccurate or incomplete and request an update
  • a right to deletion or right to be forgotten (the individual may request the deletion of their personal data)
  • a right to limit processing (thus avoiding the total deletion of data)

 

Concerning cookies that contain personal data, it is essential to previously define a legitimate and specific reason for using them. Once defined, it must be clearly indicated on the website via a banner.

 Must it be reported in a separate document that the site has been brought into compliance?

All GDPR requirements must be documented. The company must be able to demonstrate that it has adopted good data protection practices.

Documentation must be available on the site and to the staff of the company that owns the site, in order to better meet the needs and expectations of the persons concerned by the data processing.

Note that at any time a supervisory authority may, at its discretion, act and sanction any non-compliance with the rights granted to persons whose data is processed by means of an arsenal of disciplinary measures (administrative and criminal fines).

Note that failure to comply with the regulations will expose any company to a fine that could amount to 4% of its annual global turnover or 20 million euros.

 

What about contact forms?

Forms must be modified to make them GDPR compliant.

It is essential to collect the consent of the person filling out the form and to inform them of the duration of their data’s storage. It will also be necessary to keep proof of their consent and inform them of their rights.

Finally, the transfer of personal data via the form must be secured.

 

Newsletters … ?

It is recommended to set up a double opt-in: one opt-in when filling out the form (informing about the reason for collecting the email) and another opt-in with the confirmation email in which the person agrees to receive information (after ticking a box).

 And marketing campaigns?

From now on, to be able to conduct GDPR-compliant marketing campaigns, it will be necessary to collect the consent of visitors before sending marketing documents. For example, consent can be given by clicking the “subscribe” button.

Furthermore, brands, distributors, or subcontractors must indicate to their customers what the collected data is used for and who it is intended for. They must also inform their customers of the storage duration, but also allow them to modify, erase, transfer, or access their data.

Finally, third-party applications or services deployed on a site must also be subject to GDPR compliance (e.g., Data analysis tools).

 

 

[/vc_column_text][/vc_column][/vc_row]

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi

Free, no spam, one-click unsubscribe.