18 September 2017

Is Your Website GDPR-Compliant?

Data protection is one of the most important aspects of running and maintaining a website, as failing to meet the basic standards of it will merit legal action, as well as it being a key focus of users and clients. Until recently, most UK website owners have had to mainly worry about the 1998 Data Protection Act, and the EU Data Protection Directive 1995, alongside a bunch of other EU and UK regulations on freedom of information and cybersecurity. But with the passing of the General Data Protection Regulation in the European Parliament, website owners have a whole new set of regulations to worry about.

Despite the Brexit vote undermining EU authority in the UK in the views of many, we are still expected to follow any rules and regulations passed down from the EP, with the GDPR voted on before the Brexit vote and the government expecting full compliance by UK businesses by 2018. Even if your website follows the 1998 act to the letter, the GDPR will supersede it by the May 2018 deadline. So what do you need to do?

One of the key focuses of the regulation is transparency in user data gathering. Much like how websites tell you that ‘cookies’ need to be enabled on a first visit, you will need to inform the user why you are gathering user data, how long the data will be kept and the user’s rights regarding personal data gathering and usage (i.e. reporting it to the Information Commissioner’s Office). Changes to your site’s Privacy Policy are recommended after receiving legal advice.

Your website needs a clearly-documented deletion process of old/junk data. Make sure that data can be compressed into a readable, common filetype (.CSV) when you need to display compliance with the GDPR. A process must in place to allow any personal data that an individual has provided to be moved, copied or transferred easily from one IT environment to another. This must be done in a safe and secure way, without affecting usability.

If your site uses ADM (Automated Decision Making), you need to show that the ADM is operating within fair and transparent limits, and demonstrate the logic and reasoning used by your ADM programs when it uses user data. If your website gathers data on users without their explicit consent, things like preticked boxes or general inactivity, these systems must be removed by the 2018 deadline.

Data breaches are also tackled in this regulation. Any data breaches that may affect the rights and livelihood of your users must be disclosed to the proper authorities (usually the ICO) and to affected individuals, as a breach may result in financial loss, defamation, discrimination and a loss of confidentiality for affected individuals. Your website’s security should already be a priority, but make sure that user data is secure, as the penalties for violating the regulations can be steep: up to 20 million EUR (18 million GBP) or 4% of your company’s annual turnover. Ensure that your website meets these regulations before May 2018, as these new regulations are no pushover. For WordPress users, a general site audit to see how your site tracks, monitors and stores user data wouldn’t be remiss. Check and see how your site handles:

  • user registrations,
  • comments,
  • contact form entries,
  • analytics and traffic log solutions,
  • any other logging tools and plugins,
  • security tools and plugins.

Chetaru is a UK SEO and website design agency based in Darlington that is excited about building a better future with the latest technological and IT solutions available. Chetaru has the IT know-how that your firm needs to succeed and thrive, from beautiful responsive websites to economical SEO services and useful mobile app designs..

Share this:

Leave a Reply

Your email address will not be published. Required fields are marked *

View All