SlideShare a Scribd company logo
E-Mail Insider Summit
February 2018
E-Mail Marketing and GDPR : a
game changer?
Signal Spam
• A non for profit organisation
• A public/private partnership
Law enforcement, ISP, E-mail security vendors, Reputation Providers, ESP, Marketers &
Brands, Web Hosting companies, Data Protection Authority
• The National French Spam & Phishing Reporting Center
• A FBL, spamtraps and aggregated data on IP level
program for senders
• A Real-Time Phishing Blacklist for trusted members
SIGNAL SPAM
• Internet users register to Signal Spam and
download a plugin for their messaging environment
• End users report anything they consider to be a
spam
• Signal Spam qualifies the report and extracts
relevant information
• Signal Spam sends data to its members best suited
to take relevant action against a specific spam
END USERS REPORTS
AUTORITÉ DE PROTECTION
DES DONNÉES
HÉBERGEURS WEB
ROUTEURS
EXPÉDITEURS DE MESSAGES
POLICE
GENDARMERIE
FAI
FOURNISSEURS D’ACCÈS INTERNET
ET SERVICE DE MESSAGERIES
SÉCURITÉ
ANNONCEURS
Identify Cyber-Criminals
Inform the Data Protection Authority of law breaches
Identify and clean compromised devices
Unsubscribe Internet Users from ESP and marketers lists
Improve best practices, promote Signal Spam’s code of ethics, raise
technical standards
Improve messaging protective tools
Reports allow to:
What will change with GDPR ?
• European Regulation : 2016/679, April 2016
‣ Published May the 4th 2016
‣ Application delay : 2 years —> May the 24th 2018
• Direct application
‣ No transposition
‣ All member states
‣ Repeals directive 95/46/CE from October the 24th 1995
• GDPR makes provisions for fines of up to 20
millions € for violations
GENERAL INFORMATION
Rules commonly admitted From May 25th 2018
Consent
• Required
• Existing customer relationship
• Required
• Weighing up of interests
• Existing customer relationship
Requirements for
Consent
• Voluntary
• Explicit
• Transparent
• Voluntary
• Active, explicit
• Informed
• Written form not explicitly required though highly
recommended
• Prohibition of coupling
Ability to give consent • Not always defined • From 16 years of age
Obligation of proof
• Not always defined, double opt-in
encouraged
• Burden of proof for the user of the declaration of
consent
Possibility to revoke
• Mandatory, though the way to do
it is not always defined
• Must be included in every e-mail
Legal Notice required? • Not always defined • Must be included in every e-mail
Sanctions • Different within EU countries
• Fines up to 20 000 000 € or 4% of the total annual
turnover of the company, whichever is higher
WHAT GRPD WILL CHANGE IN THE FIELD OF EMAIL
MARKETING
PRIVACY
Reducing Data Privacy By Design Reducing Data Accountability Security
Data Process Register PIA DPO Breach Notification Secure People
Rights
Principles
Obligations
General Notions
Only collect strictly
relevant data
Reduce number of
files containing data
Ban free fields
Set up purge
measures once the
purpose is achieved
How to minimise data
Profiling is
regulated
art 22 GDPR
When personal data enables
decision based on automated
processing
People can oppose
Requires
PIA
(Privacy Impact Assessment)
Specific
information
Profiling Requirements
« Any freely given, specific, informed and unambiguous indication of the data
subject’s wishes by which he or she, by a statement or by a clear affirmative
action, signifies agreement to the processing of personal data relating to him or
her »
• Unambiguous
• Freely Given
• Separate from other declarations
• Informed
• Capacity to provide consent
• Burden of proof
Declaration of Consent For E-Mail Marketing
Quality of Data
Lawfullness of Data Processing
Sustainability
Reducing Data
Data Process Register Specific information to
prospects
Secure People
Rights
DPO
A facilitator to
exercice people
rights
Data conservation Data Update
Opt-In
Portability Modification &
Suppression
Opposition &
Opt-out
About Your Databases …
• Identity and contact details of the Data Processor
• Identity and contact details of the DPO
• To what end the data is collected and the legal basis
for it ( for instance : legitimate interest, consent, etc.)
• Third parties
• Duration for data conservation / date of deletion
• Mention of applicable rights for the data owner giving
consent - art. 15/20 (opt-out, etc.)
• Mention of any automated process resulting in
decision making
Focus on Consent
CRITICAL DATA
• Article 9 about « critical data »
‣ Political, religious, philosophical opinions
‣ Race, sexuality, health…
• Principle : critical data processing is
forbidden
• Exceptions
‣ Health / Public / Research interests
‣ Processing by a NGO
‣ When the data was made public by its owner
General guidelines
(with or without GDPR)
LEGAL FRAMEWORK DOESN’T MATTER SO MUCH !
• Spam is all about perception
• Auto-regulation mechanisms in France (IP, domains,
and lists reputation) and Germany (whitelisting)
• Best practices & code of ethics
Authentification
SPF
DKIM
DMARC
Reputation
Reports
Spamtraps
E-Mail Content
IP Identification
Domain From
Identification
Brand/Content
Identification
Blocking
Spamhaus
Reports
Threshholds
1% /
3000
0,3 % 0,3 % 0,3 %
Other
FBL & IP
aggregated
Stats
SNDS
Sender
Score
Return Path
Connections
Up
Connections
Up
• Image
Display
• Default
links
activated
• No limit
to hourly
sendings
• Connecti
ons Up
• Improved
Inbox
Deliverab
ility
• No false-positives at 0.6% of reports on a
campaign
• Blacklisting at 1% or 2 000 reports
• Campaigns/Domains fragmentation is dangerous
• Learning to work with ISPs and their messaging
security editors
• Watch out for bad customers
DELIVERABILITY ISSUES
• Full ARF reports
• IP level aggregated data from ISPs
• Spamtrap data on Orange recycled addresses
SUBSCRIBING TO FBL AND REPUTATION DATA
Ask for data sample on your IP setup
(thomas.fontvielle@signal-spam.net)

More Related Content

PDF
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
PPT
Websites: do you tick all the boxes?
PPTX
Simple GDPR Overview
PDF
Gdpr in a nutshell
PDF
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
PDF
Trade Secret Asset Management
PPTX
GDPR: Key Article Overview
PPTX
Preparing for GDPR: What Every B2B Marketer Must Know
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
Websites: do you tick all the boxes?
Simple GDPR Overview
Gdpr in a nutshell
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Trade Secret Asset Management
GDPR: Key Article Overview
Preparing for GDPR: What Every B2B Marketer Must Know

What's hot (20)

PDF
The GDPR for B2B Marketers
PDF
Top Questions Asked About the CCPA
PPTX
Domain management and brand protection in the era of the EU's GDPR
PDF
GDPR: Are you EU Compliant?
PPT
GDPR FAQ'S
PPTX
European GDPR for Good Technology Collective (GTC)
PPTX
Ed Wright - Staying on the right side of the law in the digital world
PPTX
GDPR Compliance: What You Need to Know Before May 2018
PDF
GDPR Overview
PPTX
Intercity technology - GDPR your training toolkit
PPTX
Impact of GDPR on Data Collection and Processing
PPTX
GDPR Is Coming – Are Search Marketers Ready?
PPTX
Balancing Privacy and Digitization
PPTX
GDPR training
 
PPTX
PDF
Protection des données et de la vie privée : nouvelles obligations pour les e...
PPTX
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
PPTX
Data privacy presentation
PDF
California Consumer Privacy Act (CCPA): Countdown to Compliance
PDF
Data Protection and IDEA
The GDPR for B2B Marketers
Top Questions Asked About the CCPA
Domain management and brand protection in the era of the EU's GDPR
GDPR: Are you EU Compliant?
GDPR FAQ'S
European GDPR for Good Technology Collective (GTC)
Ed Wright - Staying on the right side of the law in the digital world
GDPR Compliance: What You Need to Know Before May 2018
GDPR Overview
Intercity technology - GDPR your training toolkit
Impact of GDPR on Data Collection and Processing
GDPR Is Coming – Are Search Marketers Ready?
Balancing Privacy and Digitization
GDPR training
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
Data privacy presentation
California Consumer Privacy Act (CCPA): Countdown to Compliance
Data Protection and IDEA
Ad

Similar to Exploring GDPR (20)

PDF
Introduction to data protection
PDF
Legal and data protection update
PDF
An introduction to data protection - 26 March 2014
PDF
GDPR Ready Presentation - Marc Michaels
PPTX
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
PPT
An introduction to data protection - 30 Jan 2014
PPTX
How will GDPR affect your business - Marketing Fox & Birkett Long
PDF
Data privacy and email permission marketing trends by Alastair Tempest
PPTX
GDPR and email marketing: an opportunity for transformation?
PDF
An introduction to data protection - Edinburgh
PPTX
An introduction to data protection - Manchester - 24/06/15
PPT
Data protection janine paterson - direct marketing association
PPTX
An Introduction to Data Protection (London) - June 2015
PPTX
An introduction to data protection - 2/09/2015
PPTX
Managing GDPR and Other Uses of Integrated Email Marketing | Gold-Vision CRM
PDF
GDPR changes affect direct marketing
PPTX
Data Protection for Marketing Professionals
PPTX
Travelodge GDPR Case Study
PDF
The power of the post
PDF
The power of the post
Introduction to data protection
Legal and data protection update
An introduction to data protection - 26 March 2014
GDPR Ready Presentation - Marc Michaels
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
An introduction to data protection - 30 Jan 2014
How will GDPR affect your business - Marketing Fox & Birkett Long
Data privacy and email permission marketing trends by Alastair Tempest
GDPR and email marketing: an opportunity for transformation?
An introduction to data protection - Edinburgh
An introduction to data protection - Manchester - 24/06/15
Data protection janine paterson - direct marketing association
An Introduction to Data Protection (London) - June 2015
An introduction to data protection - 2/09/2015
Managing GDPR and Other Uses of Integrated Email Marketing | Gold-Vision CRM
GDPR changes affect direct marketing
Data Protection for Marketing Professionals
Travelodge GDPR Case Study
The power of the post
The power of the post
Ad

More from MediaPost (20)

PPTX
Visible Wireless: Grass Roots Branding and Media Planning
PPTX
MediaPost Data & Programmatic Insider Summit - Survey Results
PPTX
Can the Past Predict the Future of CTV?
PPTX
First-Party Data Takes The Cake In A Post-Cookie World
PPTX
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
PDF
The Right Audience for the Job: Cadillac’s First Party Data Engine
PPTX
Sustained Innovation Through Creativity, Technology & Data
PPTX
Search and Performance Insider Summit - Survey Results
PPTX
Reaching Buyers Without Cookies
PPTX
Cookie Apocalypse!!!
PPTX
Leveraging Performance Video on Amazon
PPTX
MediaPost Publishing Insider Summit Survey
PPTX
When Less is More: Building a Successful Advertising Business from a Subscrip...
PDF
What Do First Party Data and Golf Have In Common?
PPTX
Turning Customers Into Fans: Church’s New Social Media Playbook
PPTX
Restaurant Customer Engagement: The Path to Personalization
PPTX
Delivery & Streaming, the Ultimate Experience with Roku
PPTX
Focus Brands’ Licensing Calculus
PDF
Three Tips to Maximize Creative Asset Efficiency
PPTX
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
Visible Wireless: Grass Roots Branding and Media Planning
MediaPost Data & Programmatic Insider Summit - Survey Results
Can the Past Predict the Future of CTV?
First-Party Data Takes The Cake In A Post-Cookie World
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
The Right Audience for the Job: Cadillac’s First Party Data Engine
Sustained Innovation Through Creativity, Technology & Data
Search and Performance Insider Summit - Survey Results
Reaching Buyers Without Cookies
Cookie Apocalypse!!!
Leveraging Performance Video on Amazon
MediaPost Publishing Insider Summit Survey
When Less is More: Building a Successful Advertising Business from a Subscrip...
What Do First Party Data and Golf Have In Common?
Turning Customers Into Fans: Church’s New Social Media Playbook
Restaurant Customer Engagement: The Path to Personalization
Delivery & Streaming, the Ultimate Experience with Roku
Focus Brands’ Licensing Calculus
Three Tips to Maximize Creative Asset Efficiency
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers

Recently uploaded (20)

PDF
Digital Marketing Agency in Thrissur with Proven Strategies for Local Growth
PDF
20K Btc Enabled Cash App Accounts – Safe, Fast, Verified.pdf
PPTX
Assignment 2 Task 1 - How Consumers Use Technology and Its Impact on Their Lives
PDF
Mastering Bulk Email Campaign Optimization for 2025
PDF
exceptionalinsights.group visitor traffic statistics 08-08-25
PDF
Proven AI Visibility: From SEO Strategy To GEO Tactics
PPTX
Sumit Saxena IIM J Project Market segmentation.pptx
PDF
Wondershare Filmora Crack Free Download 2025
PPTX
The evolution of the internet - its impacts on consumers
PDF
Digital Marketing - clear pictire of marketing
PDF
Master Fullstack Development Course in Chennai – Enroll Now!
PDF
UNIT 1 -3 Factors Influencing RURAL CONSUMER BEHAVIOUR.pdf
PDF
Unit 1 -2 THE 4 As of RURAL MARKETING MIX.pdf
PDF
5 free to use google tools to understand your customers online behavior in 20...
PDF
How to Break Into AI Search with Andrew Holland
PPTX
Mastering eCommerce SEO: Strategies to Boost Traffic and Maximize Conversions
PPTX
PRINCIPLES OF MANAGEMENT and functions (1).pptx
DOCX
procubiz_modern digital marketingblog.docx
PDF
UNIT 2 - 5 DISTRIBUTION IN RURAL MARKETS.pdf
PDF
Digital Marketing in the Age of AI: What CEOs Need to Know - Jennifer Apy, Ch...
Digital Marketing Agency in Thrissur with Proven Strategies for Local Growth
20K Btc Enabled Cash App Accounts – Safe, Fast, Verified.pdf
Assignment 2 Task 1 - How Consumers Use Technology and Its Impact on Their Lives
Mastering Bulk Email Campaign Optimization for 2025
exceptionalinsights.group visitor traffic statistics 08-08-25
Proven AI Visibility: From SEO Strategy To GEO Tactics
Sumit Saxena IIM J Project Market segmentation.pptx
Wondershare Filmora Crack Free Download 2025
The evolution of the internet - its impacts on consumers
Digital Marketing - clear pictire of marketing
Master Fullstack Development Course in Chennai – Enroll Now!
UNIT 1 -3 Factors Influencing RURAL CONSUMER BEHAVIOUR.pdf
Unit 1 -2 THE 4 As of RURAL MARKETING MIX.pdf
5 free to use google tools to understand your customers online behavior in 20...
How to Break Into AI Search with Andrew Holland
Mastering eCommerce SEO: Strategies to Boost Traffic and Maximize Conversions
PRINCIPLES OF MANAGEMENT and functions (1).pptx
procubiz_modern digital marketingblog.docx
UNIT 2 - 5 DISTRIBUTION IN RURAL MARKETS.pdf
Digital Marketing in the Age of AI: What CEOs Need to Know - Jennifer Apy, Ch...

Exploring GDPR

  • 1. E-Mail Insider Summit February 2018 E-Mail Marketing and GDPR : a game changer?
  • 3. • A non for profit organisation • A public/private partnership Law enforcement, ISP, E-mail security vendors, Reputation Providers, ESP, Marketers & Brands, Web Hosting companies, Data Protection Authority • The National French Spam & Phishing Reporting Center • A FBL, spamtraps and aggregated data on IP level program for senders • A Real-Time Phishing Blacklist for trusted members SIGNAL SPAM
  • 4. • Internet users register to Signal Spam and download a plugin for their messaging environment • End users report anything they consider to be a spam • Signal Spam qualifies the report and extracts relevant information • Signal Spam sends data to its members best suited to take relevant action against a specific spam END USERS REPORTS
  • 5. AUTORITÉ DE PROTECTION DES DONNÉES HÉBERGEURS WEB ROUTEURS EXPÉDITEURS DE MESSAGES POLICE GENDARMERIE FAI FOURNISSEURS D’ACCÈS INTERNET ET SERVICE DE MESSAGERIES SÉCURITÉ ANNONCEURS
  • 6. Identify Cyber-Criminals Inform the Data Protection Authority of law breaches Identify and clean compromised devices Unsubscribe Internet Users from ESP and marketers lists Improve best practices, promote Signal Spam’s code of ethics, raise technical standards Improve messaging protective tools Reports allow to:
  • 7. What will change with GDPR ?
  • 8. • European Regulation : 2016/679, April 2016 ‣ Published May the 4th 2016 ‣ Application delay : 2 years —> May the 24th 2018 • Direct application ‣ No transposition ‣ All member states ‣ Repeals directive 95/46/CE from October the 24th 1995 • GDPR makes provisions for fines of up to 20 millions € for violations GENERAL INFORMATION
  • 9. Rules commonly admitted From May 25th 2018 Consent • Required • Existing customer relationship • Required • Weighing up of interests • Existing customer relationship Requirements for Consent • Voluntary • Explicit • Transparent • Voluntary • Active, explicit • Informed • Written form not explicitly required though highly recommended • Prohibition of coupling Ability to give consent • Not always defined • From 16 years of age Obligation of proof • Not always defined, double opt-in encouraged • Burden of proof for the user of the declaration of consent Possibility to revoke • Mandatory, though the way to do it is not always defined • Must be included in every e-mail Legal Notice required? • Not always defined • Must be included in every e-mail Sanctions • Different within EU countries • Fines up to 20 000 000 € or 4% of the total annual turnover of the company, whichever is higher WHAT GRPD WILL CHANGE IN THE FIELD OF EMAIL MARKETING
  • 10. PRIVACY Reducing Data Privacy By Design Reducing Data Accountability Security Data Process Register PIA DPO Breach Notification Secure People Rights Principles Obligations General Notions
  • 11. Only collect strictly relevant data Reduce number of files containing data Ban free fields Set up purge measures once the purpose is achieved How to minimise data
  • 12. Profiling is regulated art 22 GDPR When personal data enables decision based on automated processing People can oppose Requires PIA (Privacy Impact Assessment) Specific information Profiling Requirements
  • 13. « Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her » • Unambiguous • Freely Given • Separate from other declarations • Informed • Capacity to provide consent • Burden of proof Declaration of Consent For E-Mail Marketing
  • 14. Quality of Data Lawfullness of Data Processing Sustainability Reducing Data Data Process Register Specific information to prospects Secure People Rights DPO A facilitator to exercice people rights Data conservation Data Update Opt-In Portability Modification & Suppression Opposition & Opt-out About Your Databases …
  • 15. • Identity and contact details of the Data Processor • Identity and contact details of the DPO • To what end the data is collected and the legal basis for it ( for instance : legitimate interest, consent, etc.) • Third parties • Duration for data conservation / date of deletion • Mention of applicable rights for the data owner giving consent - art. 15/20 (opt-out, etc.) • Mention of any automated process resulting in decision making Focus on Consent
  • 16. CRITICAL DATA • Article 9 about « critical data » ‣ Political, religious, philosophical opinions ‣ Race, sexuality, health… • Principle : critical data processing is forbidden • Exceptions ‣ Health / Public / Research interests ‣ Processing by a NGO ‣ When the data was made public by its owner
  • 18. LEGAL FRAMEWORK DOESN’T MATTER SO MUCH ! • Spam is all about perception • Auto-regulation mechanisms in France (IP, domains, and lists reputation) and Germany (whitelisting) • Best practices & code of ethics
  • 20. Reputation Reports Spamtraps E-Mail Content IP Identification Domain From Identification Brand/Content Identification
  • 22. Other FBL & IP aggregated Stats SNDS Sender Score Return Path Connections Up Connections Up • Image Display • Default links activated • No limit to hourly sendings • Connecti ons Up • Improved Inbox Deliverab ility
  • 23. • No false-positives at 0.6% of reports on a campaign • Blacklisting at 1% or 2 000 reports • Campaigns/Domains fragmentation is dangerous • Learning to work with ISPs and their messaging security editors • Watch out for bad customers DELIVERABILITY ISSUES
  • 24. • Full ARF reports • IP level aggregated data from ISPs • Spamtrap data on Orange recycled addresses SUBSCRIBING TO FBL AND REPUTATION DATA Ask for data sample on your IP setup (thomas.fontvielle@signal-spam.net)