SlideShare a Scribd company logo
GDPR, Data Privacy
and WordPress
Brendan Woods
Team Lead, XWP
@brendan_woods
brendan.woods@xwp.co
https://xwp.co/
not a lawyer
GDPR, WordPress and You.
GDPR, WordPress and You.
Ethical
Commercial
Legal
Ethical
Commercial
Legal
War is 90% information.
~Napoleon Bonaparte
Data = Power
WordPress is for a free internet
● WordPress is a bastion of the free internet
● Stands for equal opportunity, to allow anyone to bring a great idea to life
no matter where they are.
● We must stand for ethical data practice. To protect the vulnerable.
Ethical
Commercial
Legal
GDPR, WordPress and You.
GDPR, WordPress and You.
Data is Essential
● Understanding your market
● Cost saving / time reduction
● Product development
● Enhanced service
Being a Good Data Steward
● Data awareness is growing, and consumers are becoming far more
sceptical
● This is an opportunity to build consumer trust.
Ethical
Commercial
Legal
The General Data Protection Regulation (GDPR) is a new
regulation that acts as an addendum and overhaul of
the European Union's (EU) existing data privacy laws
Does GDPR apply to me?
- Any company processing the personal
data of subjects who are in the Union.
- It doesn’t matter where the
company is located.
Do I really need to follow?
● Previous fines under the DPD were much smaller, up to £500k in the UK.
● Now, failure to comply can result in fines up to €20 Million or 4% of global
revenue, whichever is more.
● Enforced Internationally.
GDPR, WordPress and You.
Major Changes
Data Types
Consent
Breaches
New Rights
Data Types
● IP address and mobile IDs now included as personal data.
● Geolocation data.
● Sensitive personal data
○ Health, sexual orientation, race, religion, political opinion.
○ Also includes biometric data - fingerprints, retina scans, genetic data.
Consent
● Explicit consent must be obtained, no more pre-ticked boxes and vague
statements.
● Revoking consent must be just as easy.
● GDPR applies to some data already collected.
○ Some companies will need to re-establish consent.
● Must be used only for the purpose it was collected.
Breaches
● Companies have a 72 hour deadline to report data breaches to their
relevant Data Protection Authority.
● Breach must be reported to users/customers without “undue delay”.
● Due to this difficult clause, companies will need reporting policies and
procedures, as well as breach templates.
I just want my phone call
My New Rights
● Data subjects are able to request to be forgotten. I.e. The right to erasure.
● The right to restrict processing
● Data Portability
● Knowledge of profiling
WordPress Core
● WP 4.9.6 Release implemented a set of changes to
help site owners with compliance
● Comment Consent (check language)
● Data export and erasure feature
● Privacy policy generator
● Gaps in localisation
Leo Postovoit
So what should I be doing?
Next Steps
● Check your plugins
■ Google Analytics
■ Email opt in
■ Cookie consent
● Create a Privacy Policy
● SSL and Encryption
The most important questions
● What data am I collecting?
● Where am I storing it?
● Why am I collecting it?
● Did I get proper permission to have it?
What kind of future do we want?
Questions & Comments
@brendan_woods

More Related Content

PPTX
GDPR - what you need to know
PDF
Piwik PRO The Real Cost of Data Privacy
PDF
Web Analytics and Privacy
PDF
Privacy Regulations and Your Digital Setup
PDF
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
PDF
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
PPTX
Gdpr presentation
GDPR - what you need to know
Piwik PRO The Real Cost of Data Privacy
Web Analytics and Privacy
Privacy Regulations and Your Digital Setup
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
Gdpr presentation

What's hot (20)

PDF
GDPR Data Subject Rights - What You Need to Know
PDF
GDPR and Hadoop
PPTX
A Brief Overview on GDPR
PPTX
GDPR
PPTX
GDPR: Your Journey to Compliance
PDF
DAMA Ireland - GDPR
PDF
Beginning your General Data Protection Regulation (GDPR) Journey
PPTX
An Overview of GDPR
PPTX
iKnow Solutions Laura Eisenhardt
PDF
Practical steps to GDPR compliance
PPTX
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
PPTX
Evolving international privacy regulations and cross border data transfer - g...
PPTX
Do You Have a Roadmap for EU GDPR Compliance?
PPTX
Webianr: GDPR: How to build a data protection framework
PPTX
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
PPTX
UBA legal changes in marketing automation
PDF
Your Worst GDPR Nightmare - Unstructured Data
PDF
Employee Training is Key to GDPR Compliance: GDPR
PDF
2018 Client Briefing GDPR
PPTX
IoT - Attacks and Solutions
GDPR Data Subject Rights - What You Need to Know
GDPR and Hadoop
A Brief Overview on GDPR
GDPR
GDPR: Your Journey to Compliance
DAMA Ireland - GDPR
Beginning your General Data Protection Regulation (GDPR) Journey
An Overview of GDPR
iKnow Solutions Laura Eisenhardt
Practical steps to GDPR compliance
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Evolving international privacy regulations and cross border data transfer - g...
Do You Have a Roadmap for EU GDPR Compliance?
Webianr: GDPR: How to build a data protection framework
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
UBA legal changes in marketing automation
Your Worst GDPR Nightmare - Unstructured Data
Employee Training is Key to GDPR Compliance: GDPR
2018 Client Briefing GDPR
IoT - Attacks and Solutions
Ad

Similar to GDPR, WordPress and You. (20)

PDF
Understanding gdpr compliance gdpr analytics tools
PPTX
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
PDF
Everything B2B Tech Marketers Need to Know About Privacy + Consent
PDF
Flash Friday: Data Quality & GDPR
PDF
GDPR - General Data Protection Regulation
PPTX
Ritz 4th-july-gdpr
PDF
GDPR - Sink or Swim
PDF
GDPR changes affect direct marketing
PPT
13687562.ppt
PDF
MMV Webinar 1. GDPR Perspectives. November 2017
PPTX
CRMCS GDPR - Why it matters and how to make it Easy
PDF
PDF
Beyond Cookies Preparing for a Privacy-First Future - Steve Krull
PPTX
12th July GDPR event slides
PPTX
Gdpr action plan
PDF
Is your business GDPR ready?
PDF
GDPR: Time to Act
PPTX
General Data Protection Regulation (GDPR) Implications for Canadian Firms
PDF
Data Quality-Driven GDPR: Compliance with Confidence
PDF
2016 11-17-gdpr-integro-webinar
Understanding gdpr compliance gdpr analytics tools
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Everything B2B Tech Marketers Need to Know About Privacy + Consent
Flash Friday: Data Quality & GDPR
GDPR - General Data Protection Regulation
Ritz 4th-july-gdpr
GDPR - Sink or Swim
GDPR changes affect direct marketing
13687562.ppt
MMV Webinar 1. GDPR Perspectives. November 2017
CRMCS GDPR - Why it matters and how to make it Easy
Beyond Cookies Preparing for a Privacy-First Future - Steve Krull
12th July GDPR event slides
Gdpr action plan
Is your business GDPR ready?
GDPR: Time to Act
General Data Protection Regulation (GDPR) Implications for Canadian Firms
Data Quality-Driven GDPR: Compliance with Confidence
2016 11-17-gdpr-integro-webinar
Ad

More from WordCamp Sydney (20)

PDF
Don’t Panic: How To Troubleshoot Your WordPress Site
PDF
WordPress Hosting Survival Guide
PDF
Preparing For The Flood. How Do You Conduct Load Testing To Ready Your WordPr...
PDF
Goodbye Themes, Hello Elementor – Beyond Creating Basic Websites
PDF
Divi 4.x and WooCommerce Changes
PDF
Why No One Is Reading Your Blog Posts (And How To Change That)
PDF
Our Wild Journey Implementing A Headless WordPress Blog
PDF
Escaping Client Hell: 6 Practical Tips To Make Freelancing Fun Again
PDF
Planning Your Website Roadmap: Why Every Website Project Needs One To Save It...
PDF
Website Delivered – It’s The START Of The Relationship!
PDF
5 Steps To Avoiding Burnout: Creating A Healthy Work/Life Balance
PDF
The Healthy Baker - Flipping the Brief
PDF
Gutenberg Block Editor Tips & Tricks
PDF
Let's Get Engaged
PDF
The Science Of WordPress
PDF
Basics of Search Engine Optimisation
PDF
The Future of Web Content (an introduction to the new WordPress editor)
PDF
Beyond the Theme: Affirming the role of the designer in the WordPress ecosystem
PDF
5 Ecommerce Trends to Implement Now
PDF
Modern Local Environment for WordPress in 2018
Don’t Panic: How To Troubleshoot Your WordPress Site
WordPress Hosting Survival Guide
Preparing For The Flood. How Do You Conduct Load Testing To Ready Your WordPr...
Goodbye Themes, Hello Elementor – Beyond Creating Basic Websites
Divi 4.x and WooCommerce Changes
Why No One Is Reading Your Blog Posts (And How To Change That)
Our Wild Journey Implementing A Headless WordPress Blog
Escaping Client Hell: 6 Practical Tips To Make Freelancing Fun Again
Planning Your Website Roadmap: Why Every Website Project Needs One To Save It...
Website Delivered – It’s The START Of The Relationship!
5 Steps To Avoiding Burnout: Creating A Healthy Work/Life Balance
The Healthy Baker - Flipping the Brief
Gutenberg Block Editor Tips & Tricks
Let's Get Engaged
The Science Of WordPress
Basics of Search Engine Optimisation
The Future of Web Content (an introduction to the new WordPress editor)
Beyond the Theme: Affirming the role of the designer in the WordPress ecosystem
5 Ecommerce Trends to Implement Now
Modern Local Environment for WordPress in 2018

Recently uploaded (20)

PDF
Alethe Consulting Corporate Profile and Solution Aproach
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PDF
Understand the Gitlab_presentation_task.pdf
PPTX
newyork.pptxirantrafgshenepalchinachinane
PDF
si manuel quezon at mga nagawa sa bansang pilipinas
PDF
The Evolution of Traditional to New Media .pdf
PPT
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
PDF
Lean-Manufacturing-Tools-Techniques-and-How-To-Use-Them.pdf
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
PPTX
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
Slides PDF: The World Game (s) Eco Economic Epochs.pdf
PPTX
Internet Safety for Seniors presentation
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
PPTX
E -tech empowerment technologies PowerPoint
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PPT
Ethics in Information System - Management Information System
PPT
12 Things That Make People Trust a Website Instantly
PDF
Introduction to the IoT system, how the IoT system works
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
Alethe Consulting Corporate Profile and Solution Aproach
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Understand the Gitlab_presentation_task.pdf
newyork.pptxirantrafgshenepalchinachinane
si manuel quezon at mga nagawa sa bansang pilipinas
The Evolution of Traditional to New Media .pdf
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
Lean-Manufacturing-Tools-Techniques-and-How-To-Use-Them.pdf
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
Slides PDF: The World Game (s) Eco Economic Epochs.pdf
Internet Safety for Seniors presentation
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
E -tech empowerment technologies PowerPoint
Exploring VPS Hosting Trends for SMBs in 2025
Ethics in Information System - Management Information System
12 Things That Make People Trust a Website Instantly
Introduction to the IoT system, how the IoT system works
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟

GDPR, WordPress and You.

  • 2. Brendan Woods Team Lead, XWP @brendan_woods brendan.woods@xwp.co https://xwp.co/ not a lawyer
  • 7. War is 90% information. ~Napoleon Bonaparte
  • 9. WordPress is for a free internet ● WordPress is a bastion of the free internet ● Stands for equal opportunity, to allow anyone to bring a great idea to life no matter where they are. ● We must stand for ethical data practice. To protect the vulnerable.
  • 13. Data is Essential ● Understanding your market ● Cost saving / time reduction ● Product development ● Enhanced service
  • 14. Being a Good Data Steward ● Data awareness is growing, and consumers are becoming far more sceptical ● This is an opportunity to build consumer trust.
  • 16. The General Data Protection Regulation (GDPR) is a new regulation that acts as an addendum and overhaul of the European Union's (EU) existing data privacy laws
  • 17. Does GDPR apply to me? - Any company processing the personal data of subjects who are in the Union. - It doesn’t matter where the company is located.
  • 18. Do I really need to follow? ● Previous fines under the DPD were much smaller, up to £500k in the UK. ● Now, failure to comply can result in fines up to €20 Million or 4% of global revenue, whichever is more. ● Enforced Internationally.
  • 21. Data Types ● IP address and mobile IDs now included as personal data. ● Geolocation data. ● Sensitive personal data ○ Health, sexual orientation, race, religion, political opinion. ○ Also includes biometric data - fingerprints, retina scans, genetic data.
  • 22. Consent ● Explicit consent must be obtained, no more pre-ticked boxes and vague statements. ● Revoking consent must be just as easy. ● GDPR applies to some data already collected. ○ Some companies will need to re-establish consent. ● Must be used only for the purpose it was collected.
  • 23. Breaches ● Companies have a 72 hour deadline to report data breaches to their relevant Data Protection Authority. ● Breach must be reported to users/customers without “undue delay”. ● Due to this difficult clause, companies will need reporting policies and procedures, as well as breach templates.
  • 24. I just want my phone call
  • 25. My New Rights ● Data subjects are able to request to be forgotten. I.e. The right to erasure. ● The right to restrict processing ● Data Portability ● Knowledge of profiling
  • 26. WordPress Core ● WP 4.9.6 Release implemented a set of changes to help site owners with compliance ● Comment Consent (check language) ● Data export and erasure feature ● Privacy policy generator ● Gaps in localisation Leo Postovoit
  • 27. So what should I be doing?
  • 28. Next Steps ● Check your plugins ■ Google Analytics ■ Email opt in ■ Cookie consent ● Create a Privacy Policy ● SSL and Encryption
  • 29. The most important questions ● What data am I collecting? ● Where am I storing it? ● Why am I collecting it? ● Did I get proper permission to have it?
  • 30. What kind of future do we want?