Go to main content Go to main navigation Go to footer
Back to overview

GDPR : Have you written your statements?

Many people still think that GDPR only applies if you collect a Facebook load of personal data, but nothing could be further from the truth. If you haven't already made preparations, quickly check out our previous blog post where we recount the scope and consequences of the new regulation. Here, among other things, we talk about what preparations need to be made, one of which we will cover today.

Bob ten Vergert - Security officer bij Cube - Oldenzaal
Author Test Engineer | Security & Privacy
Reading time
3 min
Image without description

The privacy statement.

A good start to your GDPR preparation is an accessible privacy notice that immediately sets the tone for trusted processing of personal data. For this, in fact, you need to have a clear picture of the different categories of personal data being processed.

Having a privacy notice has long been mandatory under the Data Protection Act but the requirements it must meet are changing. This is because the new regulation brings better influence and protection to the citizen, who then needs to know what can be influenced, how and where.

Hence, this information should soon be easy to find, for instance via a fixed link in the footer. It should be as concise and transparent as possible, meaning that legally written tomes will soon be prohibited. Even the not-so-well-discussed stakeholder must understand what is meant, with the result that the text must be written at language level B1.

Throughout this blog, I refer to some examples of privacy statements:

  • The small statement, from ourself;

  • The medium statement, from web shop CoolBlue;

  • The big statement, from employment agency Yacht.

With 3 companies doing quite varied processing, I suspect most cases are covered.

*Some information in these statements may have been changed or updated after this blog was published.

Image without description

Step 1 : Collection inventory.

Try to get clear on how much, and what, personal data is collected on your website and/or within your CRM/ CMS.

Second, for each individual collection, look for the following information:

  • Where/when you are asking for the personal data;

  • Why you are asking for this personal data (purpose limitation);

  • The legal basis for processing the personal data;

  • The retention period, or criteria for this;

  • The categories of recipients (e.g. sub-processors);

  • Where applicable : does it use automated decision-making? (e.g. automated granting or rejection of online credit applications without human intervention);

  • Where applicable : whether there are any legal obligations, contractual obligations or conditions of contract performance attached to the collection;

  • Where applicable : whether personal data is sent to a third country (outside the EU) and how this is secured;

You only need to raise the last three points when the statements apply to a processing operation you carry out. For example, you read in Yacht's statement that "some of this data is mandatory in order to use our services", this indicates that conditions for performance of a contract are attached to the collection.

When you have all the information for each personal data, you look at the amount of information and choose the right way to communicate. In our statement, I choose a short story to name all obligations, thanks to the minimum amount of information. If, like CoolBlue or Yacht, you have a lot more data to declare, choose enumeration and/or segmentation.

CoolBlue currently has no retention period or criterion for this in its privacy statement and does not inform enough about automatic decision-making in the form of fraud prevention checks. Not quite GDPR-proof yet, in other words! There are also a number of other, new, obligations.

Step 2 : Serving stakeholders.

Indeed, the identified or identifiable natural person should be able to read and exercise all his/her new rights through the information in your privacy statement.

This means that the following information is mandatory to find :

  • they are entitled to see all personal data related to him/her in your possession. (Right to access);

  • they have the right to amend any personal data related to him/her in your possession. (Right to rectification);

  • they have the right to the deletion of any personal data related to him/her in your possession. (Right to erasure);

  • they have the right to receive all personal data related to him/her in your possession. (Right to data portability);

  • they have the right to withdraw previously granted consent for processing;

  • they have the right to complain to the Personal Data Authority.

In doing so, the information needed to exercise these rights should also be available. Yacht's privacy page received a facelift early this year in preparation for GDPR. However, some things are missing to approve this statement as fully compliant. Indeed, nowhere does Yacht offer its visitors the option to complain directly to the AP, but refers to an internal legal affairs department.

By contrast, Yacht would most likely get away with this as they are largely compliant. Should the AP approach Yacht about this, it would probably involve a call, warning or order under administrative order.

It seems like a tall order but the rights can be summed up well in a few short sentences, as in our own copy. It need not be difficult.

Step 3 : Any extras.

Our privacy statement contains a number of unnecessary extras that can add to your transparency and build trust with the data subject. For example, when I talk about our personal data, I talk about encrypted transmission plus secure server, and at the bottom I talk about our interest in privacy and security as well as training for staff.

Linking to additional and/or in-depth information on certain topics adds clarity to your story without adding chunks of text.

We also chose to place the cookie policy in the privacy statement. Since our privacy statement is not a huge chunk of text, we felt it was more informative together than separately. Partly because of the content interface. This section is mainly offered separately from the privacy statement and also does not belong to the mandatory entries for a good statement.

The current cookie law is still based on an EU directive but it too will soon be converted into a regulation. The desire is to introduce this legislation this year, which is unlikely to happen. By time of implementation, I will write a special story for the cookie rookie.

Step 4 : Finalise everything.

We have collected and reviewed a lot of information, now we need to present it neatly. Starting with your company's identity. Do you need an FG for your organisation according to the GDPR? Then you should also introduce him/her here with the necessary contact details.

Next, add all collection of personal data, with all associated information. Remember to keep your story easy to read, something CoolBlue thought was a good idea even before the GDPR came along.

Finally, inform data subjects about both the several rights they have and how these rights can be exercised. Complete this story with some additional information as desired and post it on the website!

Step 5 : Next story.

We have now written a nice statement for outside data subjects. However, within your company, you also have some data subjects with data that needs protection. Especially since this employee data is often of a sensitive nature.

The arrival of the GDPR also introduces an "accountability" obligation, i.e. the need to demonstrate that privacy obligations have been met. An established, implemented and complied privacy policy helps demonstrate compliance with these obligations.

The next lesson puts the magnifying glass inside your company, on policies that achieve the best protection of personal data.

See you soon!

Bob ten Vergert - Security officer bij Cube - Oldenzaal

Ready for the next step? We are too.

Want to know what your organisation needs to do to comply with GDPR? Bob will be happy to help you!

Worth reading next...