What is the GDPR?

What is the GDPR?

The GDPR (General Data Protection Regulation) is the European Union's (EU) most awaited step to protect the fundamental right to privacy of EU citizens. It is effective since May 25, 2018

Does the GDPR require the EU data to stay with the borders of the EU?  

No, the GDPR does not require EU personal data to stay in the EU, nor does it place any new restrictions on transfers of personal data outside the EU.

Is Zoho Campaigns GDPR compliant?  

Yes, Zoho Campaigns is completely compliant with GDPR. We honor the right to data privacy and protection. Zoho Campaigns strongly recommends that our customers send permission-based marketing emails and newsletters to their subscribers. It is best to remove any old (unresponsive for up to three months) contacts from their mailing lists and send re-engagement emails.

What should marketers do to stay GDPR compliant?  

Here's what marketers are recommended to do to stay GDPR compliant.
  1. Maintain filtered mailing lists
  2. Obtain clear and explicit permission
  3. Maintain plain and simple language while seeking consent
  4. Allow users to view their information in a readable format
  5. Let users conveniently export their data
  6. Allow for rectification of users' data
  7. Conduct periodic reviews to verify the veracity of the data
  8. Avoiding misleading email headers
  9. Promptly honor opt-out requests
  10. Only collect necessary and relevant data
  11. Preserve data in an encrypted format
  12. Don't hold unprocessed subscriber data
  13. Erase consented subscriber data if unused for more than 6 months (with consent)

What are the benefits of GDPR?  

GDPR is a good movement for both marketers and individuals. Some of the benefits are
User empowerment
Improved data security
Improved data processing and storage

Is it applicable for data controllers from the UK?  

Yes, it is applicable for every data controller who is handling the data of EU residents.

What rights will data subjects (individuals) have under GDPR?  

Data subjects (individuals) have some important rights with the advent of GDPR. They are
Right to Consent
Right to Access
Right to Rectification
Right to be Forgotten/Erase data

What will happen if you are not compliant with GDPR?  

Non-compliance with GDPR leads to costly consequences. It's a fine that can go up to as much as 20 million euros or 4% of the company's annual global turnover of the preceding financial year, whichever is higher.

What's GDPR's stance on offline opt-ins?  

GDPR requires clear and explicit consent from data subjects, be it online opt-ins or offline opt-ins from events and roadshows. Double opt-in is the standard recommendation.

What's the difference between data controllers and data processors?  

Data Controller- A data controller can be a person or a body with the authority to determine the purposes and means of processing personal data. As a Zoho Campaigns user, you would feed in all your data and Zoho Campaigns acts as the controller of your data. Your data consists of your personal and business information.
 
Data Processor- A data processor is the entity that processes the data on behalf of the controller or under controller's instruction. The controller and processor can be one entity as well. Zoho Campaigns acts as the processor while handling the data related to your subscribers.

What constitutes personal data?  

Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Who will be affected by GDPR?  

Any organization around the world that works with the personal data of EU citizens will be affected and is now obliged to protect their users' data.