SlideShare a Scribd company logo
1 of 27
10 GDPR myths,
scare tactics,
half truths and lies
Hello, I’m Howard
CEO @ VinciWorks
5 10 GDPR myths,
scare tactics,
half truths and lies
Fear
& Panic
Wetherspoons just deleted its entire
customer email database - on purpose
And said it will stop sending all email
newsletters
July 2017
Myth #1
You won’t be able to send
marketing emails anymore or will
have to delete your database
Wetherspoons just deleted its entire
customer email database - on purpose
And said it will stop sending all email
newsletters
July 2017
“We felt, on balance, that we would
rather not hold even email addresses
for customers.
The less customer information we
have, which now is almost none, then
the less risk associated with data.”
Source: Mailchimp
Wetherspoons just deleted its entire
customer email database - on purpose
And said it will stop sending all email
newsletters
July 2017
What we did at VinciWorks
● Verify your legal basis (consent, legitimate interest)
● Delete worst contacts
● Honor unsubscribes with your life
● Monitor unsubscribe rates
● Deliver phenomenal value
“Content is King”
Bill Gates, 1996
The content marketing lifecycle
Whatwe did at VinciWorks
Conditions for processing data
The person gave
explicit consent
To fulfil or prepare
a contract
There is a legal
obligation
(excluding a contract)
To save
someone’s life or
in a medical
situation
To carry out a
public function
There is some other legitimate
interest
(excluding public authorities)
1 2 3
4 5 6
Myth #3
Most staff don’t need to care
or worry about GDPR / It’s
something for your Data
Protection Officer to worry
about
What we did at VinciWorks
● Conduct a DPIA with all staff
● Update employment contracts
● Update internal rules and policies
● Train all staff on the basics of GDPR
● Create a culture of sensitivity to users
vinciworks.com/GDPR
Wetherspoons just deleted its entire
customer email database - on purpose
And said it will stop sending all email
newsletters
July 2017
Myth #4
You will be swamped with
data access request
Wetherspoons just deleted its entire
customer email database - on purpose
And said it will stop sending all email
newsletters
July 2017
VinciWorks and subject access requests
● Create a portal where people can fill out a form
● Stick to the timelines
● Automate what you can
● Build trust
● Create value
Myth #5
You’ll be fined 4% of global turnover for your first offence
It’s not about the regulation
It’s about the customer
Three pillars of GDPR
Trust RespectValue
www.vinciworks.com/GDPR

More Related Content

What's hot

ROI of Privacy: Building a Case for Investment [Webinar Slides]
ROI of Privacy: Building a Case for Investment [Webinar Slides]ROI of Privacy: Building a Case for Investment [Webinar Slides]
ROI of Privacy: Building a Case for Investment [Webinar Slides]TrustArc
 
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...TrustArc
 
10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPRNetApp
 
GDPR in the Digital World
GDPR in the Digital WorldGDPR in the Digital World
GDPR in the Digital WorldeZ Systems
 
Privacy Shield: What to expect by the end of 2021
Privacy Shield: What to expect by the end of 2021Privacy Shield: What to expect by the end of 2021
Privacy Shield: What to expect by the end of 2021TrustArc
 
Managing the Digital Shift in Privacy
Managing the Digital Shift in PrivacyManaging the Digital Shift in Privacy
Managing the Digital Shift in PrivacyTrustArc
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow MappingVISTA InfoSec
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowPiwik PRO
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...TrustArc
 
General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?Leigh Hill
 
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]TrustArc
 
CWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trustCWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trustCapgemini
 
GDPR non-compliance risks & GDPR365
GDPR non-compliance risks & GDPR365GDPR non-compliance risks & GDPR365
GDPR non-compliance risks & GDPR365Jaco Liebenberg
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]TrustArc
 

What's hot (19)

Swift guide to GDPR
Swift guide to GDPRSwift guide to GDPR
Swift guide to GDPR
 
ROI of Privacy: Building a Case for Investment [Webinar Slides]
ROI of Privacy: Building a Case for Investment [Webinar Slides]ROI of Privacy: Building a Case for Investment [Webinar Slides]
ROI of Privacy: Building a Case for Investment [Webinar Slides]
 
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
Benchmarking Your GDPR Compliance: Will You Make the Grade? [TrustArc Webinar...
 
Bryan Lillie, CTO and Cyber Security - QinetiQ
Bryan Lillie, CTO and Cyber Security - QinetiQBryan Lillie, CTO and Cyber Security - QinetiQ
Bryan Lillie, CTO and Cyber Security - QinetiQ
 
10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR
 
GDPR in the Digital World
GDPR in the Digital WorldGDPR in the Digital World
GDPR in the Digital World
 
Privacy Shield: What to expect by the end of 2021
Privacy Shield: What to expect by the end of 2021Privacy Shield: What to expect by the end of 2021
Privacy Shield: What to expect by the end of 2021
 
Managing the Digital Shift in Privacy
Managing the Digital Shift in PrivacyManaging the Digital Shift in Privacy
Managing the Digital Shift in Privacy
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 
General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
CWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trustCWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trust
 
GDPR non-compliance risks & GDPR365
GDPR non-compliance risks & GDPR365GDPR non-compliance risks & GDPR365
GDPR non-compliance risks & GDPR365
 
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 

Similar to Gdpr myths

GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOUCliff Gibson
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongLouise Owens
 
Are You Ready for GDPR?
Are You Ready for GDPR?Are You Ready for GDPR?
Are You Ready for GDPR?Perkuto
 
Are You Ready For GDPR?
Are You Ready For GDPR?Are You Ready For GDPR?
Are You Ready For GDPR?Uberflip
 
Privacy and Big Data Overload!
Privacy and Big Data Overload!Privacy and Big Data Overload!
Privacy and Big Data Overload!SparkPost
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPRSrijan Technologies
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?Gareth Miller
 
The GDPR Is Only for Europe—Right?
The GDPR Is Only for Europe—Right?The GDPR Is Only for Europe—Right?
The GDPR Is Only for Europe—Right?Priyanka Aash
 
GDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationGDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationZero Point Development
 
The Event Marketer's Checklist for GDPR Compliance
The Event Marketer's Checklist for GDPR ComplianceThe Event Marketer's Checklist for GDPR Compliance
The Event Marketer's Checklist for GDPR ComplianceSplash
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Jim Kaplan CIA CFE
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantEsendex
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policytermsfeed
 
A Day in the Life of a GDPR Breach - September 2017: France
A Day in the Life of a GDPR Breach - September 2017: France A Day in the Life of a GDPR Breach - September 2017: France
A Day in the Life of a GDPR Breach - September 2017: France Splunk
 
Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy Piwik PRO
 

Similar to Gdpr myths (20)

GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOU
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
Are You Ready for GDPR?
Are You Ready for GDPR?Are You Ready for GDPR?
Are You Ready for GDPR?
 
Are You Ready For GDPR?
Are You Ready For GDPR?Are You Ready For GDPR?
Are You Ready For GDPR?
 
Privacy and Big Data Overload!
Privacy and Big Data Overload!Privacy and Big Data Overload!
Privacy and Big Data Overload!
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?
 
The GDPR Is Only for Europe—Right?
The GDPR Is Only for Europe—Right?The GDPR Is Only for Europe—Right?
The GDPR Is Only for Europe—Right?
 
GDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationGDPR - General Data Protection Regulation
GDPR - General Data Protection Regulation
 
The Event Marketer's Checklist for GDPR Compliance
The Event Marketer's Checklist for GDPR ComplianceThe Event Marketer's Checklist for GDPR Compliance
The Event Marketer's Checklist for GDPR Compliance
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policy
 
A Day in the Life of a GDPR Breach - September 2017: France
A Day in the Life of a GDPR Breach - September 2017: France A Day in the Life of a GDPR Breach - September 2017: France
A Day in the Life of a GDPR Breach - September 2017: France
 
Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy
 

Recently uploaded

Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book nowVadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book nowgargpaaro
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...nirzagarg
 
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Service
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts ServiceCall Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Service
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Servicenishakur201
 
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...Elaine Werffeli
 
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...gajnagarg
 
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...HyderabadDolls
 
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...HyderabadDolls
 
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...gajnagarg
 
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...nirzagarg
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Klinik kandungan
 
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteedamy56318795
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...HyderabadDolls
 
Predictive Precipitation: Advanced Rain Forecasting Techniques
Predictive Precipitation: Advanced Rain Forecasting TechniquesPredictive Precipitation: Advanced Rain Forecasting Techniques
Predictive Precipitation: Advanced Rain Forecasting TechniquesBoston Institute of Analytics
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNKTimothy Spann
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...gajnagarg
 
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...gajnagarg
 
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...kumargunjan9515
 

Recently uploaded (20)

Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book nowVadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
 
Abortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get CytotecAbortion pills in Jeddah | +966572737505 | Get Cytotec
Abortion pills in Jeddah | +966572737505 | Get Cytotec
 
Call Girls in G.T.B. Nagar (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in G.T.B. Nagar  (delhi) call me [🔝9953056974🔝] escort service 24X7Call Girls in G.T.B. Nagar  (delhi) call me [🔝9953056974🔝] escort service 24X7
Call Girls in G.T.B. Nagar (delhi) call me [🔝9953056974🔝] escort service 24X7
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
 
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Service
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts ServiceCall Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Service
Call Girls In GOA North Goa +91-8588052666 Direct Cash Escorts Service
 
Abortion pills in Doha {{ QATAR }} +966572737505) Get Cytotec
Abortion pills in Doha {{ QATAR }} +966572737505) Get CytotecAbortion pills in Doha {{ QATAR }} +966572737505) Get Cytotec
Abortion pills in Doha {{ QATAR }} +966572737505) Get Cytotec
 
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
SAC 25 Final National, Regional & Local Angel Group Investing Insights 2024 0...
 
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...
Top profile Call Girls In Chandrapur [ 7014168258 ] Call Me For Genuine Model...
 
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...
Lake Town / Independent Kolkata Call Girls Phone No 8005736733 Elite Escort S...
 
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
 
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...
Top profile Call Girls In Nandurbar [ 7014168258 ] Call Me For Genuine Models...
 
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
Top profile Call Girls In Bihar Sharif [ 7014168258 ] Call Me For Genuine Mod...
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
 
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
 
Predictive Precipitation: Advanced Rain Forecasting Techniques
Predictive Precipitation: Advanced Rain Forecasting TechniquesPredictive Precipitation: Advanced Rain Forecasting Techniques
Predictive Precipitation: Advanced Rain Forecasting Techniques
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
 
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
 
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
High Profile Call Girls Service in Jalore { 9332606886 } VVIP NISHA Call Girl...
 

Gdpr myths

  • 1. 10 GDPR myths, scare tactics, half truths and lies
  • 2. Hello, I’m Howard CEO @ VinciWorks 5 10 GDPR myths, scare tactics, half truths and lies
  • 4. Wetherspoons just deleted its entire customer email database - on purpose And said it will stop sending all email newsletters July 2017
  • 5. Myth #1 You won’t be able to send marketing emails anymore or will have to delete your database
  • 6. Wetherspoons just deleted its entire customer email database - on purpose And said it will stop sending all email newsletters July 2017
  • 7. “We felt, on balance, that we would rather not hold even email addresses for customers. The less customer information we have, which now is almost none, then the less risk associated with data.”
  • 9. Wetherspoons just deleted its entire customer email database - on purpose And said it will stop sending all email newsletters July 2017
  • 10. What we did at VinciWorks ● Verify your legal basis (consent, legitimate interest) ● Delete worst contacts ● Honor unsubscribes with your life ● Monitor unsubscribe rates ● Deliver phenomenal value
  • 12. The content marketing lifecycle Whatwe did at VinciWorks
  • 13.
  • 14. Conditions for processing data The person gave explicit consent To fulfil or prepare a contract There is a legal obligation (excluding a contract) To save someone’s life or in a medical situation To carry out a public function There is some other legitimate interest (excluding public authorities) 1 2 3 4 5 6
  • 15. Myth #3 Most staff don’t need to care or worry about GDPR / It’s something for your Data Protection Officer to worry about
  • 16. What we did at VinciWorks ● Conduct a DPIA with all staff ● Update employment contracts ● Update internal rules and policies ● Train all staff on the basics of GDPR ● Create a culture of sensitivity to users
  • 18. Wetherspoons just deleted its entire customer email database - on purpose And said it will stop sending all email newsletters July 2017
  • 19. Myth #4 You will be swamped with data access request
  • 20.
  • 21. Wetherspoons just deleted its entire customer email database - on purpose And said it will stop sending all email newsletters July 2017
  • 22. VinciWorks and subject access requests ● Create a portal where people can fill out a form ● Stick to the timelines ● Automate what you can ● Build trust ● Create value
  • 23. Myth #5 You’ll be fined 4% of global turnover for your first offence
  • 24. It’s not about the regulation It’s about the customer
  • 25.
  • 26. Three pillars of GDPR Trust RespectValue

Editor's Notes

  1. Good Morning everyone. Today I was going to dispel 10 GDPR myths but VinciWorks ran a GDPR webinar yesterday and we had over 800 registrations and over 500 attendees and we captured some great data that I really want to share with you today. So I am going to brighten your day and dispel only 4 or 5 key myths, share what we learned yesterday and probably commit professional suicide by telling you why I think GDPR is actually good for business. And even if you think I have gone nuts this presentation might at least give some of you sound bytes to help you better sell GDPR to the Board and get a bigger budget or help you get some buy in from Marketing and Sales to do what you ask of them. Like others here this morning, I’ve been in the compliance business for a long time and I’ve seen the cycle before: Anti money laundering, anti-bribery, sanctions, diversity, tax evasion, modern slavery and now GDPR. A new regulations are announced and what happens?
  2. The scaremongering begins, the ambulance chasers come out and a whole new breed of consultants start telling us to take action, spend money and do stuff they don’t really know we need to do. Well if you are still in panic - Relax
  3. This is a result poll from our Webinar yesterday. Only 2% said they were Fully Prepared and almost 40% said they hadn’t prepared at all. So feel proud or relieved – whatever works for you.
  4. So let's get right to it with Myth number 1.You won't be able to send marketing emails anymore or you will have to delete your entire database. Rubbish Right? Well it seems that someone gave JD Wetherspoons this advice and they followed it. Wetherspoons is a UK national chain of pubs that is publicly listed with over £1.6 billion in revenue. Now have some sympathy for Wetherspoon because in June 2015 they got hacked and had over 650,000 customers records stolen. So once bitten twice shy – right.
  5. Well in July 2017 Wetherspoon deleted its entire user database including around 500,000 email addresses and said it will no longer send email newsletters to anyone. What was their rational?
  6. A Wetherspoons spokesman said: “We felt, on balance, that we would rather not hold even email addresses for customers. The less customer information we have, which now is almost none, then the less risk associated with data.” Well its true that the best way to take no risk is to do nothing - but for most of us communicating with our clients and prospects via email is a critical part of our marketing strategy and its justified.
  7. The ROI per dollar spent on email marketing is nearly double the next best option - SEO. So if Wetherspoon is going to stop all email marketing but still market online they are going to have to double their marketing budget to achieve that same ROI. Now I am not saying Wetherspoon were wrong – they are a successful company that knows their business. As I am sure are all of you.
  8. So this is an interesting poll result from yesterday’s webinar – half the people haven’t decided and around 25% are going to ask for consent – and yes around 4% intend deleting what they have. The truth is that no one will have a complete understanding of the regulations until they are tested and that’s going to take some time. We at VinciWorks have no greater insight that the rest of you but I thought it might give you food for thought if shared with you how we at VinciWorks responded to these myths remembering that every business is different. You may have well have valid bases for processing personal data and take a very different approach to us.
  9. First, which you all must do. We took advice. Then we started with a Data Audit. It took time and effort to look at all the personal data we hold including both internal employee data and external prospect and client data. 1. With the external data we did an assessment and started deleting the worst or ‘weakest contacts’. These were contacts that had never opened any of our emails, never clicked on a link or had never engaged directly with us. We determined that by their inaction they had clearly signaled that they were not receiving value from us, they hadn’t consented and when we got real we recognized that there was almost zero likelihood that they would ever actually buy anything from us – so why keep this personal data . We also assumed that they were the most likely to report us for data breaches, whether we committed one or not. So we did a Witherspoon and dumped it. Interestingly we found that many of these weakest contacts had gmail.com or hotmail.com addresses. 2. Next we made sure we had an iron-clad process for managing unsubscribe requests. We absolutely didn't want to be sending emails to anyone that didn’t want to receive them – why would we? For sure THEY WILL NEVER BUY. 3. Another thing we started to more closely was to monitor our unsubscribe rates. Our typical unsubscribe rate is less than 0.5% and we learned that an increase to over 1.5% meant there was a problem and it was probably us who was doing something wrong. 4. And finally and most importantly we re-focused on delivering exceptional value from our marketing
  10. We only communicate information that is of significant value to our customers. Its expensive to create great content and it takes time to get your head around giving away such high quality content away - for free. But it works. Give it away and get rich! Most importantly it works in terms of generating great leads, up-sales and renewals and what is really cool is that from a GDPR perspective no one ever complains about receiving amazing value.
  11. We don't do any telemarketing nor any cold calls. All of our growth today is driven by delivering a constant flow of high value content. The internet shifted the power in the buying decision from Seller to the Buyer. We never know when the buyer is actually ready to buy But by constantly delivering relevant high value content we hope to retain some level of ‘mindshare’, create a level of trust and by so doing, hope be asked to sit at the table when the buyer is ready to buy. GDPR has helped us purify our policies and impose processes that drive our growth.
  12. You can’t store personal data. There are lawyers and others in the room who can discuss this with much more authority than me but rest assured it is more than a myth, it is a lie.
  13. Touching on just 3 conditions - what is true is that in order to process personal data, the data controller must have a lawful basis on which he can rely. The most obvious is contractual - we provide compliance and risk management software to companies but we also offer compliance training to around 100,000 individual lawyers and accountants including some of you here is Cyprus – thank you! We have a contract with agreed Terms & Conditions and that contract gives us a lawful basis to process the related personal data. Next is Consent. It’s common sense. Did the consent to you sending him stuff? We were nervous about asking for consent but then we realised we were more afraid of creating a detractor as opposed to a promotor. And so if people are not engaging with us we should assume they don’t consent - its safe and it’s right. It honours the individual and his or her rights. . I think the legitimate interest condition is most interesting because it allows for a lot of discretion particularly as to what is reasonable. Bottom line we don’t want to fight with anyone. If we end up going to court no one wins and either way we lose the customer.
  14. Your DPO may be the person you have “tasked” with achieving GDPR compliance. But GDPR is about people, it is about your customers and out your employees. And in many organisations the DPO has never actually spoken to a customer And unless your DPO is also your head of HR, do you want them having sensitive conversations about personal data with your staff? I didn’t. Think about who in your organisation has access to or deals with ‘information’ relating to an identifiable person. This includes a person’s name, identification number, location or online identifier such as email address. In our company it was the HR Team, Office Manager, Finance Team, Marketing Team and yes, the Sales Team – everyone dealing with our prospects or customers. That is almost everyone. So we decided all these people needed to take ownership and responsibility for the protection of data. They will be the ones that cause us to breach the regulations, negatively impact the reputation of our business and ultimately lose our clients.
  15. Our first step, was to complete a limited Data Protection Impact Analysis – we didn’t feel we were obligated to do this. We don’t believe there is a high risk of us impacting on the rights and freedoms of a large number of individuals but we are in the Risk and Compliance Management business. So we undertook a Risk Identification process. We looked at the data we had and assessed if there was low, medium or high risk of a breach occurring. We learned what most companies are learning: We needed to review all staff employment contracts: we needed to reference the employees GDPR rights in their contracts and at the same time tell them what their obligations are as employees We needed to and review and update our Terms & Conditions and many of our other policies and internal rules. We also needed to ensure that some time would be taken at the launch of every new project to evaluate the project in the context of GDPR. However what we really needed to do was to make data sensitivity an integrated part of the VinciWorks corporate culture Same was as we are doing around harassment, diversity, bribery and risk in general. This requires behavioural change and that requires good governance, great communication and consistent and ongoing training.
  16. We were lucky because VinciWorks creates great online compliance training So we deployed GDPR training to all staff Training doesn’t have to be long, boring or difficult but it does need to be tailored to an individual’s role Your team need to understand what GDPR is from their perspective within the context of their specific job role.
  17. Another poll from yesterday’s seminar…A much more even spread around DPIA Data Protection Impact Analysis
  18. Myth #3 You will swamped with data access request
  19. Very quick on this. Subject access requests are not new. They have been around in the UK since the Data Protection Act in 1998 and in Cyprus since 2001. The only difference is that now they are free instead of costing £10. I would like a show of hands, how many people have ever processed a subject access request? Well you are in good company:
  20. Swamped? I don’t think so
  21. That said, we really liked the Guidelines on Transparency issued by the Data Protection Working Party. So we thought it would be important for businesses to demonstrate our transparency and availability to our own staff and to our broader community of customers and prospects. At VinciWorks we sell workflow tools that make it really easy to create online forms, approval workflows and registers. And so we are using this tool to create a simple online portal that is accessible internally and externally to our entire community. It contains one page or form which is a Subject Access Request form. If someone submits a request it alerts the DPO by email and sends the request into a mailbox which is supported by a workflow that helps ensure the appropriate person responds to the request within the required timelines. Is this essential? Is it regulated? Probably not. But it relieves the DPO from some of the more arduous tasks and we see this as an opportunity to demonstrate to our community that we care, that we are open and available - and we are not doing the same thing in regard to whistleblowing, harassment, complaints, gifts and GDPR breaches.
  22. It’s a headline grabbing threat designed to leave you shaking at your keyboard, fearful that one wrong keystroke will siphon off €20m, or 4% of turnover, whichever hurts the most. Typical maximum fines that can be levied under current data protection laws in Europe is peanuts in comparison, £500,000. If the Regulators applied the maximum fines then some of the biggest fines would balloon under GDPR rules. TalkTalk’s 2016 fine of £400,000 would become nearly £60m However GDPR is not about fines. The ICO has made clear that maximum fines will not become the norm, nor will examples be made of big brands for minor infringements. As they’ve said, they prefer the carrot to the stick. The UK ICO’s record stands to reason. In 2016/17, the regulator dealt with over 17,000 cases. Only 16 resulted in a fine. I am not certain but from the research I did do it seems the ratio and certainly number and amount of the fines have been much lower here in Cyprus. There seems nothing to suggest that this will change under GDPR. The regulator has a range of tools available on a tiered basis, starting with ordering audits, issuing warnings and reprimands, demanding compliance and launching investigations. GDPR, is focused on getting data protection right for citizens, not fining businesses to within an inch of their profit margin.
  23. So my time is almost up. Let’s summarise: Of course GDPR is about the regulations but I hope I have made the point that GDPR can also be seen as an outcome of the shift in focus to Customer Success and Customer Care. As customers we know that. As customers we all get massively upset when we gets spammed, we get angry when we unsubscribe and then keep getting emailed and then we go ballistic when those telemarketing guys call us during dinner. Well if we as businesses want to create customer loyalty then surely GDPR simply becomes the benchmark minimum standard for caring about our customers’ data.
  24. In today’s global networked marketplace the Customer is constantly asking themselves why they should buy from us. And so attracting and keeping a client is only partially derived from the quality of the products and services we sell but is probably equally if not more derived from the relationship they feel they have with the company. And like all relationships it is built on trust, value and respect.
  25. Clearly we all need to achieve regulatory compliance and all the people presenting here today are here to help. VinciWorks can help in many ways around training and data collation, analysis and reporting but it is my belief and experience that if you apply common sense and focus on the three pillars of customer success - trust, value and respect then GDPR compliance becomes easy and obvious – GDPR compliance will actually enhance the quality of your offering, your relationships and ultimately your bottom line. We have set up a portal with a comprehensive GDPR resources at vinciworks.com/GDPR including links to training, policies, templates, guides, assessments and bunch of other stuff all freely available to you. Take our your phones and take a quick look now. Enjoy and thank you. Have a great day.
  26. We have set up a portal with a comprehensive GDPR resources at vinciworks.com/GDPR including links to training, policies, templates, guides, assessments and bunch of other stuff all freely available to you. Thank you and have a great day.