SlideShare a Scribd company logo
INSERT INFORMATION CLASSIFICATION HERE
General
Data
Channels
UX / CRO
Consent or Legitimate
Interest?
The big question for marketing.
Public
INSERT INFORMATION CLASSIFICATION HERE
Lawful basis
To process personal data under GDPR, you require a legal basis:
• Consent
• To perform a contract
• Legal compliance
• Protection of vital interests of a person
• Public interest or official authority
And the big one for marketing!
6(1)(f ) – Necessary for the purposes of legitimate interests
pursued by the controller or a third party, except where such
interests are overridden by the interests, rights or freedoms of
the data subject
“the processing of personal data for direct marketing purposes
may be regarded as carried out for a legitimate interest.” Rec 47
Public
INSERT INFORMATION CLASSIFICATION HERE
GDPR ,
not E-privacy
(PECR)
Public
GDPR is not about permission to send electronic marketing
(that’s another law)!
GDPR is about all of the other processing you do behind the
scenes as well:
• Segmentation
• Targeting
• Profiling
• Data matching
• Screening
Example; Electronic marketing needs to be compliant with
GDPR and Privacy and Electronic Communication
Regulations.
Just because you’ve got a tick box for electronic marketing,
doesn’t make you GDPR ready.
INSERT INFORMATION CLASSIFICATION HERE
Consent
Public
“any freely given, specific, informed and unambiguous
indication of the data subject's wishes by which he or
she, by a statement or by a clear affirmative action,
signifies agreement to the processing of personal data
relating to him or her”
ICO “The GDPR sets a high standard for consent.”
“Remember – you don’t always need consent. If consent
is too difficult, look at whether another lawful basis is
more appropriate”.
You will need to be specific about any use you will be
putting the data to.
INSERT INFORMATION CLASSIFICATION HERE
Legitimate Interest (this is the way many
businesses have been doing it since 1998)
Public
• Is it the most appropriate lawful basis for processing?
• Explain how or why we need an individual’s personal data
• Use a layered privacy notice/policy
• Give individuals the option to refuse marketing
• This right is explicitly stated, prominently displayed and it’s easy to exercise that right
• Collect the minimum data necessary and delete records after use
• Ensure you have a valid reason to process an individual’s personal data using your
legal legitimate interests
The processing of personal data for direct marketing purposes may be regarded as
carried out for a legitimate interest. Rec 47
INSERT INFORMATION CLASSIFICATION HERE
The Balancing Test
Public
Marketing is a legitimate interest of the data controller, but:
• Is the processing necessary for the direct marketing?
• Is any third party processing necessary for the purpose of direct marketing?
• Is their another way of achieving your legitimate interest?
• Would the individual reasonably expect this processing?
• Is the processing relevant to your relationship with the individual?
• Are you processing the minimum personal data required to meet your needs?
• Is this processing likely to harm or disadvantage the individual (what type of
marketing are you doing??!!!)
And finally…
Public
Don't wait for further guidance, work with what you have.
This law won’t go away, act now while the current
regulations are in place.
If whatever route you have chosen becomes damaging to
your business or seems impossible, ask advice from the
ICO or DMA, a better route may be possible.
Get someone in your organisation trained to Data
Protection practitioner level.
The first step is the data audit, if you haven’t started yet,
start one tomorrow.
Good Luck!

More Related Content

PPTX
Consumer Law Seminar ABTA
PDF
Ai driven Predictive Analytics. Enough theory - let's talk about results!
PDF
Cookies, FLoC & GDPR: Marketing Impact
PPTX
The Customer Data Platform, the Future of the Marketing Database
PDF
Accelerate Revenue with a Customer Data Platform
PDF
Connecting the Customer Data Dots
PDF
Customer Data Platform 101
PDF
Social Marketing: Insight and Response
Consumer Law Seminar ABTA
Ai driven Predictive Analytics. Enough theory - let's talk about results!
Cookies, FLoC & GDPR: Marketing Impact
The Customer Data Platform, the Future of the Marketing Database
Accelerate Revenue with a Customer Data Platform
Connecting the Customer Data Dots
Customer Data Platform 101
Social Marketing: Insight and Response

What's hot (20)

PPTX
Elevating customer analytics - how to gain a 720 degree view of your customer
PDF
ListenLogic Unstructured & Structured Data Analytics
PDF
Big_data for marketing and sales
PDF
Bluekai Little Blue Book
PPTX
Big Data, customer analytics and loyalty marketing
PPTX
Teradata Integrated Web Intelligence
PDF
TechConnectr's Big Data Connection. Digital Marketing KPIs, Targeting, Analy...
PPTX
The Promise of First-Party Data: How the Top Brands Get the Strongest ROI for...
PPTX
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
PDF
Customer Data Platform ( CDP ) and Marketing Automation for FMCG
PDF
Big Data - How Marketing Has Revolutionised - by Sean Singleton
PPTX
Listening in Real-Time
DOCX
Enhanced auto shopping experience through analytics path
PDF
All Customers are Not Alike: Gaining a 360 Degree View
PPTX
What Marketers Need To Know About GDPR
PDF
Moving Forward with Big Data: The Future of Retail Analytics
PDF
Data collection, processing & organization with USPA framework
PDF
Big Data - New Insights Transform Industries
PDF
Right Message, Right Time: The Secrets to Scaling Email Success
PDF
360 degree customer view
Elevating customer analytics - how to gain a 720 degree view of your customer
ListenLogic Unstructured & Structured Data Analytics
Big_data for marketing and sales
Bluekai Little Blue Book
Big Data, customer analytics and loyalty marketing
Teradata Integrated Web Intelligence
TechConnectr's Big Data Connection. Digital Marketing KPIs, Targeting, Analy...
The Promise of First-Party Data: How the Top Brands Get the Strongest ROI for...
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
Customer Data Platform ( CDP ) and Marketing Automation for FMCG
Big Data - How Marketing Has Revolutionised - by Sean Singleton
Listening in Real-Time
Enhanced auto shopping experience through analytics path
All Customers are Not Alike: Gaining a 360 Degree View
What Marketers Need To Know About GDPR
Moving Forward with Big Data: The Future of Retail Analytics
Data collection, processing & organization with USPA framework
Big Data - New Insights Transform Industries
Right Message, Right Time: The Secrets to Scaling Email Success
360 degree customer view
Ad

Similar to How to get prepared for the GDPR (20)

PPTX
GDPR Briefing for marketers
PPTX
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
PPTX
BIMA Breakfast Briefing | GDPR & Why People Say YES to Marketing
PPTX
Webinar: What the Hell is Legitimate Interest?
PDF
GDPR Ready Presentation - Marc Michaels
PDF
CMR - GDPR - general introduction for marketeers
PDF
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
PDF
GDPR changes affect direct marketing
PPT
Data protection janine paterson - direct marketing association
PDF
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
PDF
Opportunity or burden
PDF
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
PDF
Gdpr ready reckoner for marketers
PDF
Sitecore 9 & GDPR: The Opportunity
PPTX
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
PDF
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
PDF
GDPR and Data Privacy in the EU - A Rhetorik Guide for B2B Technology Marketers
PPTX
GDPR Breakfast Briefing for Business Advisors
PPTX
GDPR - A Concise Treatise
PPTX
GDPR and email marketing: an opportunity for transformation?
GDPR Briefing for marketers
EU GDPR Changes: What do you need to know? - CommuniGator Seminar
BIMA Breakfast Briefing | GDPR & Why People Say YES to Marketing
Webinar: What the Hell is Legitimate Interest?
GDPR Ready Presentation - Marc Michaels
CMR - GDPR - general introduction for marketeers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
GDPR changes affect direct marketing
Data protection janine paterson - direct marketing association
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Opportunity or burden
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
Gdpr ready reckoner for marketers
Sitecore 9 & GDPR: The Opportunity
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR + Sales & Marketing A practical guide by Dan Smith Doogheno
GDPR and Data Privacy in the EU - A Rhetorik Guide for B2B Technology Marketers
GDPR Breakfast Briefing for Business Advisors
GDPR - A Concise Treatise
GDPR and email marketing: an opportunity for transformation?
Ad

Recently uploaded (20)

PPTX
PRINCIPLES OF MANAGEMENT and functions (1).pptx
PDF
exceptionalinsights.group visitor traffic statistics 08-08-25
PDF
Modernizing IT for the age of AI - Jason Aloia, Freshworks
PPTX
The evolution of the internet - its impacts on consumers
DOCX
AL-ahly Sabbour un official strategic plan.docx
PPTX
Assignment 2 Task 1 - How Consumers Use Technology and Its Impact on Their Lives
PPTX
Your score increases as you pick a category, fill out a long description and ...
PDF
Digital Marketing in the Age of AI: What CEOs Need to Know - Jennifer Apy, Ch...
PDF
Fly Emirates SEO case study by Rakesh pathak.pdf
PPTX
Fixing-AI-Hallucinations-The-NeuroRanktm-Approach.pptx
PPTX
Sumit Saxena IIM J Project Market segmentation.pptx
PDF
Building a strong social media presence.
PDF
PDF
E_Book_Customer_Relation_Management_0.pdf
PDF
Future Retail Disruption Trends and Observations
PDF
Hidden gems in Microsoft ads with Navah Hopkins
PPTX
Amazon - STRATEGIC.......................pptx
PPTX
Kimberly Crossland Storytelling Marketing Class 5stars.pptx
PDF
NeuroRank™: The Future of AI-First SEO..
PDF
Is Kanav Kesar Legit or a Scam? Uncovering the Truth Behind the Hype
PRINCIPLES OF MANAGEMENT and functions (1).pptx
exceptionalinsights.group visitor traffic statistics 08-08-25
Modernizing IT for the age of AI - Jason Aloia, Freshworks
The evolution of the internet - its impacts on consumers
AL-ahly Sabbour un official strategic plan.docx
Assignment 2 Task 1 - How Consumers Use Technology and Its Impact on Their Lives
Your score increases as you pick a category, fill out a long description and ...
Digital Marketing in the Age of AI: What CEOs Need to Know - Jennifer Apy, Ch...
Fly Emirates SEO case study by Rakesh pathak.pdf
Fixing-AI-Hallucinations-The-NeuroRanktm-Approach.pptx
Sumit Saxena IIM J Project Market segmentation.pptx
Building a strong social media presence.
E_Book_Customer_Relation_Management_0.pdf
Future Retail Disruption Trends and Observations
Hidden gems in Microsoft ads with Navah Hopkins
Amazon - STRATEGIC.......................pptx
Kimberly Crossland Storytelling Marketing Class 5stars.pptx
NeuroRank™: The Future of AI-First SEO..
Is Kanav Kesar Legit or a Scam? Uncovering the Truth Behind the Hype

How to get prepared for the GDPR

  • 1. INSERT INFORMATION CLASSIFICATION HERE General Data Channels UX / CRO Consent or Legitimate Interest? The big question for marketing. Public
  • 2. INSERT INFORMATION CLASSIFICATION HERE Lawful basis To process personal data under GDPR, you require a legal basis: • Consent • To perform a contract • Legal compliance • Protection of vital interests of a person • Public interest or official authority And the big one for marketing! 6(1)(f ) – Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject “the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” Rec 47 Public
  • 3. INSERT INFORMATION CLASSIFICATION HERE GDPR , not E-privacy (PECR) Public GDPR is not about permission to send electronic marketing (that’s another law)! GDPR is about all of the other processing you do behind the scenes as well: • Segmentation • Targeting • Profiling • Data matching • Screening Example; Electronic marketing needs to be compliant with GDPR and Privacy and Electronic Communication Regulations. Just because you’ve got a tick box for electronic marketing, doesn’t make you GDPR ready.
  • 4. INSERT INFORMATION CLASSIFICATION HERE Consent Public “any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her” ICO “The GDPR sets a high standard for consent.” “Remember – you don’t always need consent. If consent is too difficult, look at whether another lawful basis is more appropriate”. You will need to be specific about any use you will be putting the data to.
  • 5. INSERT INFORMATION CLASSIFICATION HERE Legitimate Interest (this is the way many businesses have been doing it since 1998) Public • Is it the most appropriate lawful basis for processing? • Explain how or why we need an individual’s personal data • Use a layered privacy notice/policy • Give individuals the option to refuse marketing • This right is explicitly stated, prominently displayed and it’s easy to exercise that right • Collect the minimum data necessary and delete records after use • Ensure you have a valid reason to process an individual’s personal data using your legal legitimate interests The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. Rec 47
  • 6. INSERT INFORMATION CLASSIFICATION HERE The Balancing Test Public Marketing is a legitimate interest of the data controller, but: • Is the processing necessary for the direct marketing? • Is any third party processing necessary for the purpose of direct marketing? • Is their another way of achieving your legitimate interest? • Would the individual reasonably expect this processing? • Is the processing relevant to your relationship with the individual? • Are you processing the minimum personal data required to meet your needs? • Is this processing likely to harm or disadvantage the individual (what type of marketing are you doing??!!!)
  • 7. And finally… Public Don't wait for further guidance, work with what you have. This law won’t go away, act now while the current regulations are in place. If whatever route you have chosen becomes damaging to your business or seems impossible, ask advice from the ICO or DMA, a better route may be possible. Get someone in your organisation trained to Data Protection practitioner level. The first step is the data audit, if you haven’t started yet, start one tomorrow. Good Luck!