#29 General Data Protection Regulation (GDPR) with Rosemary Smith episode artwork

EPISODE · Jul 29, 2016 · 50 MIN

#29 General Data Protection Regulation (GDPR) with Rosemary Smith

from The Next 100 Days Podcast

Rosemary Smith talks to us about the new EU data protection rules – General Data Protection Regulation (GDPR) What should you do about data protection and GDPR now the UK has voted to exit the EU? We asked one of the UK’s leading experts in data protection, Rosemary Smith. Rosemary’s background Rosemary became involved in the lobby against restrictive data protection in Europe whilst working at the Periodical Publishers Association in the late eighties. She wrote the first guide to the 1984 Act for magazine publishers and served on the Advertising Association Data Protection Committee and the CAP Committee. Rosemary was later active in the British List Brokers Association and wrote guidance for members on privacy issues.  She served on the working party which drafted the list and database rules in the CAP code. She served on DMA's Governance Committee for eight years and was Chairman until 2008 overseeing lobbying activity, the Mailing, Telephone and Fax preference Services and the DMA Code of Practice. Rosemary was also a member of the DMA Board for 7 years and was DMA Chairman until October 2008. She is an active member of the FEDMA List Council. She has given presentations covering privacy, data protection and self-regulation to audiences in the UK, Europe, USA and Australia. Rosemary is co-author (with fellow Opt-4 Director, Jenny Moseley) of the book "New Data Protection Liabilities & Risks for Direct Marketers" published in September 2004. Rosemary is also Managing Director of data consultancy RSA Direct. What next for Data Protection, post Brexit? Will GDPR still apply? What advice can Rosemary give? It affects you if you handle any data from which an individual can be identified. So that includes B2B data too! Our existing Data Protection Act was created in ’95 and enacted in ’98, so the latest changes are all about bringing the law up to date. GDPR – General Data Protection Regulation – it was all going smoothly until the Brexit vote. The plan was for the GDPR to be implemented on 25 May 2018. The ICO, Information Commissioners Officer believe the UK needs to prove adequacy to trade with the EU. So UK data protection standards need to be equivalent to EU legislation. Rosemary suggests we could get a GDPR ‘lite’. The UK was a dove in the EU discussions. As opposed to Germany and Spain who were far more stringent. If you process data on people in the EU, then the EU data protection regulations will apply to you as the legislation has the extra territorial reach. So what are the BIG changes? GDPR has 2 overarching principles Transparency – all about making sure individuals know if you are collecting their data what you’ll do with their data, how long you’ll hold it. This places an emphasis on making your intentions clear on point of capture – Rosemary suggested that previous data protect statements were true examples of obfuscation by nature, they did not make it clear at all. Accountability – you have to account for what you are and aren’t doing with the data. How will you secure it, who has access it, will it be shared? Record keeping stuff. For marketing, the big issue is the definition of consent. Under the current legislation that can be done on implied consent, that is opt out. Consent to send communications. However, the new legislation makes the definition, it needs to be UNAMBIGUOUS? Rosemary says you need to be opting in customers. A shock to the system. The time is right to test statements. Opt-4, Rosemary’s company has done a lot of testing. She observes that although accept wisdom is that 70% of consumers will not opt-out, but only 30% of consumers will actively opt-in, by tweaking the wording, getting lots of reassurance into the statement, see our privacy policy, you can always unsubscribe, she can get MUCH higher rates than 30%. Balance of interest – is it in the legitimate interest of the organisation to send a communication?

Episode metadata supplied by the publisher feed · Published Jul 29, 2016

Embed this episode

NOW PLAYING

#29 General Data Protection Regulation (GDPR) with Rosemary Smith

0:00 50:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Next 100 Days Podcast?

This episode is 50 minutes long.

When was this The Next 100 Days Podcast episode published?

This episode was published on July 29, 2016.

Can I download this The Next 100 Days Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!