Setting up compliance requirements - Online Help | Zoho Campaigns

Setting up compliance requirements

GDPR  

The GDPR(General Data Protection Regulation) is a regulation that defines how personal data of individuals in EU (European Union) should be collected and processed. It came into effect on May 25, 2018, which replaces the older data privacy directive - Directive 95/46/EC of the European Parliament.

GDPR impacts any email marketer who has contacts in the EU. This law addresses how personal data of individuals is handled and transferred, and emphasizes that communication should be permission based. According to the GDPR and EU privacy regulations, it means sending emails only to users who have explicitly opted in, preferably through a double opt-in process. Non-compliance with GDPR requirements can result in huge penalties.

Zoho Campaigns recommends sending permission-based marketing emails and newsletters only to subscribers who have clearly given consent. It is also best to regularly clean your mailing lists by removing any old/inactive contacts (unresponsive for up to three months) and attempting re-engagement before doing so.

To enable GDPR compliance:  

  1. Click Settings icon in the top-right corner of the screen.
  2. Navigate to Compliance Settings under Consent and privacy.
  3. Enable the GDPR toggle.
Notes
Note:
Once GDPR is enabled, you'll need to specify a lawful basis for communication whenever you import contacts into Zoho Campaigns.

Similarly, to disable GDPR compliance settings:  

  1. Click Settings icon on the top-right corner of the screen.
  2. Click Compliance Settings under Consent and privacy.
  3. Disable the GDPR toggle.

Setting up GDPR correctly ensures you stay compliant while building trust with your audience through transparent and permission-based communication.

HIPAA Compliance  

The Health Insurance Portability and Accountability Act, HIPAA, which includes the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act, requires Covered Entities and Business Associates to take appropriate measures to protect health information that can identify an individual. It also grants certain rights to individuals regarding their data.

Zoho does not collect, use, store, or maintain health information protected by HIPAA for its own purposes. However, Zoho Campaigns provides features that help customers handle and secure health related data in line with HIPAA compliance requirement.

HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to legal@zohocorp.com.

 How to apply HIPAA compliance in Zoho Campaigns? 

Admins in Zoho Campaigns can secure and restrict the export of individuals' health information and stay compliant with the HIPAA guidelines by using the following options:

Marking fields that contain PHI: Marking fields containing personal health information allows the system to identify sensitive data and restrict access to these fields through APIs and prevent the export of these field values. For example, fields that contain surgical history, symptoms, or medication details can be marked as PHI.
Notes
Only Custom fields can be marked as fields with PHI ( Protected Health Information). Standard fields cannot be marked.
Setting restrictions for PHI data: Once fields are marked as PHI, you can restrict how this data is shared outside Zoho Campaigns. There are two options for restricting and any of these options can be enabled depending on the org's requirements:
  1. Restrict data access through API: Other applications can connect with Zoho Campaigns using API and data can be transferred. You can ensure that personal health data of your customers is not shared in the process, by restricting transfer of personal health data to other applications via API.
  2. Restrict data export: While exporting data from the Zoho Campaigns account you may want to withhold personal health information from being exported by checking this option.
Alert
The custom fields are not encrypted by default. You need to encrypt them manually if required.

 How to configure HIPAA compliance 

  1. Go to Settings > Consent and Privacy > Compliance Settings.
  2. Navigate to HIPAA Compliance.
  3. Toggle the HIPAA compliance settings Switch on. Once you toggle this on, switches that enable restriction of personal health data appear.
  4. Enable either or both of the following:
  5. Restrict data export
  6. Restrict data transfer through API.

These options help control how sensitive health data is shared or accessed.

How to mark a field as Containing personal data?  

When creating any Custom field, Check the "Contains Personal health data" check box after filling out the custom field details.

You can also edit an existing custom field and mark or unmark it as containing personal health data at any time.   

How to disable HIPAA compliance?  

To disable HIPAA compliance:

  1. Go to Settings > Consent and Privacy > Compliance Settings.

  2. Navigate to HIPAA Compliance.

  3. Turn off the HIPAA compliance toggle.

  4. Once you toggle this off, a confirmation dialog box appears. Click Yes, Disable HIPAA Compliance.

  5. Once disabled, restrictions on exporting and accessing PHI data will be removed.

Enabling HIPAA settings helps you handle sensitive health data responsibly while maintaining tighter control over how it is accessed and shared.