SlideShare a Scribd company logo
1 of 24
Presentation to
MediaPost Email Insider Summit
GDPR IS COMING –
ARE EMAILERS
READY?
Tuesday, April 24, 2018
Gary A. Kibel
Partner
Digital Media, Technology & Privacy
212.468.4918
gkibel@dglaw.com
@GaryKibel
© 2018 Davis & Gilbert LLP
AGENDA
1. U.S. vs. EU – Contrasting approaches to personal data
2. Key GDPR provisions applicable to ad tech and email
3. Pending Legislation
4. Q&A
GDPR is Coming – Are Emailers Ready?1
PRIVACY
Digital Marketing and Big Data4
QUOTES
You have zero privacy anyway.
Get over it.
Scott McNealy,
CEO, Sun Microsystems
1999 !
“ ”
“ ”
Men lie. Women lie. Children lie.
The only three things
that don't lie are data, pets,
and Spandex workout clothing.
Peter Shankman, PR/Author
5 GDPR & Ad Tech: Examining the IAB Europe Transparency & Consent Framework
U.S. VS EUROPE
6
FTC Section 5
“Unfair methods of competition in or
affecting commerce, and unfair or
deceptive acts or practices in or
affecting commerce, are hereby
declared unlawful.”
Regulation (EU) 2016/679 of the European
Parliament - General Data Protection
Regulation (GDPR)
Directive 2002/58/EC – (ePrivacy Directive)
PRIVACY ENFORCEMENT
GDPR is Coming – Are Emailers Ready?
FEDERAL TRADE COMMISSION ACT
SECTION 5
» “Unfair methods of competition in or affecting commerce, and unfair or
deceptive acts or practices in or affecting commerce, are hereby
declared unlawful.”
- Deception = Misrepresentations or omissions likely to mislead
consumers acting reasonably under the circumstances
- Unfairness = causes or is likely to cause substantial consumer injury,
not reasonably avoided by the consumer, and not outweighed by
countervailing benefits to consumers or competition
7 GDPR is Coming – Are Emailers Ready?
8
PII = Personally identifiable
information
» COPPA – “personal information”
» HIPAA – “protected health
information”
» GLB – “nonpublic personal
information”
» State security breach notification
laws
Personal Data = any information relating to an
identified or identifiable natural person (‘data
subject’); an identifiable natural person is one
who can be identified, directly or indirectly, in
particular by reference to an identifier such as a
name, an identification number, location data,
an online identifier or to one or more factors
specific to the physical, physiological, genetic,
mental, economic, cultural or social identity of
that natural person
GDPR is Coming – Are Emailers Ready?
EXPANDING SCOPE OF
PERSONAL INFORMATION
» FTC Consent orders – “Persistent identifiers”
» COPPA Amendments 2013 – Definition of personal information
expanded to include any “persistent identifier that can be used to
recognize a user over time and across different websites or online
services”
- Carve out for “support for internal operations”
• Certain internal activities would not be considered a collection of PI,
as long as the information collected is not used or disclosed to
contact a specific individual (e.g., site maintenance and analysis)
9 GDPR is Coming – Are Emailers Ready?
FTC – WHAT IS PII ?
Blog post – April 21, 2016
» “… we regard data as ‘personally identifiable,’ and thus warranting privacy
protections, when it can be reasonably linked to a particular person,
computer, or device. In many cases, persistent identifiers such as device
identifiers, MAC addresses, static IP addresses, or cookies meet this test.”
10 GDPR is Coming – Are Emailers Ready?
11 GDPR & Ad Tech: Examining the IAB Europe Transparency & Consent Framework
GDPR APPLICABILITY TO AD TECH
AND EMAIL
GDPR FOR AD TECH
» What is the GDPR?
» 173 Recitals. 99 Articles.
- Enforcement begins - May 25, 2018
» Why is this important?
- Penalties = up to 4% of worldwide annual turnover or €20,000,000
12 GDPR is Coming – Are Emailers Ready?
GDPR FOR AD TECH
(1) Applicability / Extra-territorial scope
- Applies to controllers / processors not established
in the Union where:
• (i) the processing relates to the offering of goods/services in the EU or
(ii) monitoring of behavior of data subjects who are in the Union
(2) Lawfulness of Processing
- Consent
- Legitimate Interest (Interests and rights and freedoms of the user are not
overriding)
13 GDPR is Coming – Are Emailers Ready?
GDPR FOR AD TECH
(3) Personal Data
- Definition of personal data includes:
• Pseudonymous data
• Online identifiers (e.g. cookie IDs)
• Location data
• Child - <16 (vs. <13 in U.S.)
(4) Pseudonymization
- “the processing of personal data in such a way that the data can no longer be
attributed to a specific data subject without the use of additional information.”
(5) Anonymous Data – no connection of data with an individual
14 GDPR is Coming – Are Emailers Ready?
GDPR FOR AD TECH
(6) Data Subject Access Rights
- Transparency
- Access / rectification
- Restrict processing
- Right of erasure (a/k/a right to be forgotten)
- Right to restrict processing / Right to object
- Data portability
(7) Client / Vendor Relationships
- Data Processing Agreements
15 GDPR is Coming – Are Emailers Ready?
GDPR FOR AD TECH
(8) Lots of Internal / External policies
- Internal – Information Security;
- Privacy Notices
- User flow
(9) Breach notification
- 72 hours to regulatory authorities
(10) Record keeping
- processing activities
- More
16 GDPR is Coming – Are Emailers Ready?
HIERARCHY OF EPRIVACY AND GDPR
17 GDPR is Coming – Are Emailers Ready?
Processing
personal data
Consent GDPR Legal Basis
ePrivacy GDPR
 Collection of data over the
internet generally requires
under ePrivacy rules
 Processing of personal data
requires a
e.g. consent, or legitimate
interest
GDPR Legal Basis
Storing/accessing
data on device
Consent
GDPR
» Radically different approach to tracking than in the United States
GDPR is Coming – Are Emailers Ready?18
PENDING LEGISLATION
VERMONT – H.467
(DATA BROKER PROTECTION ACT)
» “Data Broker” means a commercial entity that collects, assembles, or maintains
personal information concerning individuals residing in Vermont who are not
customers or employees of that entity for the purpose of selling or offering for
sale, or other consideration, the personal information of a third party.
» “Personal Information” includes information that identifies, relates to, describes
or is capable of being associated with a particular individual. Includes internet
usage history; profile that includes personality / characteristics
» Data brokers must register with the state
» Data brokers must annually report to the state on its activities
» “Know your customer”
» Status: In committee
GDPR is Coming – Are Emailers Ready?20
“CONSENT ACT” (2018)
SENS. MARKEY (D-MA) & BLUMENTHAL (D-CT)
» Notice and choice for “personally identifiable information”
» Affirmative, express consent to use, disclose or access “sensitive customer
proprietary information”
- Includes web browsing history and application usage history
» Authorizes FTC to implement regulations
» No re-identification permitted
» Breach notification obligation
» Status: In committee
GDPR is Coming – Are Emailers Ready?21
don’t be creepy!
Q&A
To sign up and receive digital media alerts and
event invitations, email gkibel@dglaw.com
Gary A. Kibel
Partner
Digital Media, Technology & Privacy
212.468.4918
gkibel@dglaw.com
@GaryKibel
© 2018 Davis & Gilbert LLP

More Related Content

What's hot

What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?Faidepro
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...Kenneth Riley
 
Personal Data Privacy and Information Security
Personal Data Privacy and Information SecurityPersonal Data Privacy and Information Security
Personal Data Privacy and Information SecurityCharles Mok
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingJes Breslaw
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesAmazon Web Services
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)Madhumita Mantri
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOUCliff Gibson
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 

What's hot (20)

What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
 
Personal Data Privacy and Information Security
Personal Data Privacy and Information SecurityPersonal Data Privacy and Information Security
Personal Data Privacy and Information Security
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-masking
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud Services
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
GDPR Awareness for YOU
GDPR Awareness for YOUGDPR Awareness for YOU
GDPR Awareness for YOU
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 

Similar to GDPR Is Coming – Are Emailers Ready?

GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.Matthias Dobbelaere-Welvaert
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Aoife Flynn
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18Fife Centre for Equalities
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationN N
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 

Similar to GDPR Is Coming – Are Emailers Ready? (20)

GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
GPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-RightGPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-Right
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017Payslip gdpr deck nov 2017
Payslip gdpr deck nov 2017
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
FCE Briefing GDPR and Equal Opportunities Monitoring MAY18
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016
 
GDPR
GDPRGDPR
GDPR
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 

More from MediaPost

Visible Wireless: Grass Roots Branding and Media Planning
Visible Wireless: Grass Roots Branding and Media PlanningVisible Wireless: Grass Roots Branding and Media Planning
Visible Wireless: Grass Roots Branding and Media PlanningMediaPost
 
MediaPost Data & Programmatic Insider Summit - Survey Results
MediaPost Data & Programmatic Insider Summit - Survey ResultsMediaPost Data & Programmatic Insider Summit - Survey Results
MediaPost Data & Programmatic Insider Summit - Survey ResultsMediaPost
 
Can the Past Predict the Future of CTV?
Can the Past Predict the Future of CTV?Can the Past Predict the Future of CTV?
Can the Past Predict the Future of CTV?MediaPost
 
First-Party Data Takes The Cake In A Post-Cookie World
First-Party Data Takes The Cake In A Post-Cookie WorldFirst-Party Data Takes The Cake In A Post-Cookie World
First-Party Data Takes The Cake In A Post-Cookie WorldMediaPost
 
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...MediaPost
 
The Right Audience for the Job: Cadillac’s First Party Data Engine
The Right Audience for the Job: Cadillac’s First Party Data Engine The Right Audience for the Job: Cadillac’s First Party Data Engine
The Right Audience for the Job: Cadillac’s First Party Data Engine MediaPost
 
Sustained Innovation Through Creativity, Technology & Data
Sustained Innovation Through Creativity, Technology & DataSustained Innovation Through Creativity, Technology & Data
Sustained Innovation Through Creativity, Technology & DataMediaPost
 
Search and Performance Insider Summit - Survey Results
Search and Performance Insider Summit - Survey ResultsSearch and Performance Insider Summit - Survey Results
Search and Performance Insider Summit - Survey ResultsMediaPost
 
Reaching Buyers Without Cookies
Reaching Buyers Without CookiesReaching Buyers Without Cookies
Reaching Buyers Without CookiesMediaPost
 
Cookie Apocalypse!!!
Cookie Apocalypse!!!Cookie Apocalypse!!!
Cookie Apocalypse!!!MediaPost
 
Leveraging Performance Video on Amazon
Leveraging Performance Video on AmazonLeveraging Performance Video on Amazon
Leveraging Performance Video on AmazonMediaPost
 
MediaPost Publishing Insider Summit Survey
MediaPost Publishing Insider Summit SurveyMediaPost Publishing Insider Summit Survey
MediaPost Publishing Insider Summit SurveyMediaPost
 
When Less is More: Building a Successful Advertising Business from a Subscrip...
When Less is More: Building a Successful Advertising Business from a Subscrip...When Less is More: Building a Successful Advertising Business from a Subscrip...
When Less is More: Building a Successful Advertising Business from a Subscrip...MediaPost
 
What Do First Party Data and Golf Have In Common?
What Do First Party Data and Golf Have In Common? What Do First Party Data and Golf Have In Common?
What Do First Party Data and Golf Have In Common? MediaPost
 
Turning Customers Into Fans: Church’s New Social Media Playbook
Turning Customers Into Fans: Church’s New Social Media PlaybookTurning Customers Into Fans: Church’s New Social Media Playbook
Turning Customers Into Fans: Church’s New Social Media PlaybookMediaPost
 
Restaurant Customer Engagement: The Path to Personalization
Restaurant Customer Engagement: The Path to PersonalizationRestaurant Customer Engagement: The Path to Personalization
Restaurant Customer Engagement: The Path to PersonalizationMediaPost
 
Delivery & Streaming, the Ultimate Experience with Roku
Delivery & Streaming, the Ultimate Experience with RokuDelivery & Streaming, the Ultimate Experience with Roku
Delivery & Streaming, the Ultimate Experience with RokuMediaPost
 
Focus Brands’ Licensing Calculus
Focus Brands’ Licensing CalculusFocus Brands’ Licensing Calculus
Focus Brands’ Licensing CalculusMediaPost
 
Three Tips to Maximize Creative Asset Efficiency
Three Tips to Maximize Creative Asset EfficiencyThree Tips to Maximize Creative Asset Efficiency
Three Tips to Maximize Creative Asset EfficiencyMediaPost
 
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the NumbersThe QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the NumbersMediaPost
 

More from MediaPost (20)

Visible Wireless: Grass Roots Branding and Media Planning
Visible Wireless: Grass Roots Branding and Media PlanningVisible Wireless: Grass Roots Branding and Media Planning
Visible Wireless: Grass Roots Branding and Media Planning
 
MediaPost Data & Programmatic Insider Summit - Survey Results
MediaPost Data & Programmatic Insider Summit - Survey ResultsMediaPost Data & Programmatic Insider Summit - Survey Results
MediaPost Data & Programmatic Insider Summit - Survey Results
 
Can the Past Predict the Future of CTV?
Can the Past Predict the Future of CTV?Can the Past Predict the Future of CTV?
Can the Past Predict the Future of CTV?
 
First-Party Data Takes The Cake In A Post-Cookie World
First-Party Data Takes The Cake In A Post-Cookie WorldFirst-Party Data Takes The Cake In A Post-Cookie World
First-Party Data Takes The Cake In A Post-Cookie World
 
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
Real-time buying for real-time events: Leveraging Programmatic TV for Live Ev...
 
The Right Audience for the Job: Cadillac’s First Party Data Engine
The Right Audience for the Job: Cadillac’s First Party Data Engine The Right Audience for the Job: Cadillac’s First Party Data Engine
The Right Audience for the Job: Cadillac’s First Party Data Engine
 
Sustained Innovation Through Creativity, Technology & Data
Sustained Innovation Through Creativity, Technology & DataSustained Innovation Through Creativity, Technology & Data
Sustained Innovation Through Creativity, Technology & Data
 
Search and Performance Insider Summit - Survey Results
Search and Performance Insider Summit - Survey ResultsSearch and Performance Insider Summit - Survey Results
Search and Performance Insider Summit - Survey Results
 
Reaching Buyers Without Cookies
Reaching Buyers Without CookiesReaching Buyers Without Cookies
Reaching Buyers Without Cookies
 
Cookie Apocalypse!!!
Cookie Apocalypse!!!Cookie Apocalypse!!!
Cookie Apocalypse!!!
 
Leveraging Performance Video on Amazon
Leveraging Performance Video on AmazonLeveraging Performance Video on Amazon
Leveraging Performance Video on Amazon
 
MediaPost Publishing Insider Summit Survey
MediaPost Publishing Insider Summit SurveyMediaPost Publishing Insider Summit Survey
MediaPost Publishing Insider Summit Survey
 
When Less is More: Building a Successful Advertising Business from a Subscrip...
When Less is More: Building a Successful Advertising Business from a Subscrip...When Less is More: Building a Successful Advertising Business from a Subscrip...
When Less is More: Building a Successful Advertising Business from a Subscrip...
 
What Do First Party Data and Golf Have In Common?
What Do First Party Data and Golf Have In Common? What Do First Party Data and Golf Have In Common?
What Do First Party Data and Golf Have In Common?
 
Turning Customers Into Fans: Church’s New Social Media Playbook
Turning Customers Into Fans: Church’s New Social Media PlaybookTurning Customers Into Fans: Church’s New Social Media Playbook
Turning Customers Into Fans: Church’s New Social Media Playbook
 
Restaurant Customer Engagement: The Path to Personalization
Restaurant Customer Engagement: The Path to PersonalizationRestaurant Customer Engagement: The Path to Personalization
Restaurant Customer Engagement: The Path to Personalization
 
Delivery & Streaming, the Ultimate Experience with Roku
Delivery & Streaming, the Ultimate Experience with RokuDelivery & Streaming, the Ultimate Experience with Roku
Delivery & Streaming, the Ultimate Experience with Roku
 
Focus Brands’ Licensing Calculus
Focus Brands’ Licensing CalculusFocus Brands’ Licensing Calculus
Focus Brands’ Licensing Calculus
 
Three Tips to Maximize Creative Asset Efficiency
Three Tips to Maximize Creative Asset EfficiencyThree Tips to Maximize Creative Asset Efficiency
Three Tips to Maximize Creative Asset Efficiency
 
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the NumbersThe QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
The QSR Media Dispersion: Pre, Mid & Post Pandemic – By the Numbers
 

Recently uploaded

Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guidekiva6
 
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...Benjamin Szturmaj
 
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDigital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDemandbase
 
pptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxpptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxarsathsahil
 
SORA AI: Will It Be the Future of Video Creation?
SORA AI: Will It Be the Future of Video Creation?SORA AI: Will It Be the Future of Video Creation?
SORA AI: Will It Be the Future of Video Creation?Searchable Design
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationAli Raza
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresLisa M. Masiello
 
BrightonSEO - Addressing SEO & CX - CMDL - Apr 24 .pptx
BrightonSEO -  Addressing SEO & CX - CMDL - Apr 24 .pptxBrightonSEO -  Addressing SEO & CX - CMDL - Apr 24 .pptx
BrightonSEO - Addressing SEO & CX - CMDL - Apr 24 .pptxcollette15
 
Best Persuasive selling skills presentation.pptx
Best Persuasive selling skills  presentation.pptxBest Persuasive selling skills  presentation.pptx
Best Persuasive selling skills presentation.pptxMasterPhil1
 
Influencer Marketing Power point presentation
Influencer Marketing  Power point presentationInfluencer Marketing  Power point presentation
Influencer Marketing Power point presentationdgtivemarketingagenc
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...Hugues Rey
 
Common Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityCommon Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityMonishka Adhikari
 
Forecast of Content Marketing through AI
Forecast of Content Marketing through AIForecast of Content Marketing through AI
Forecast of Content Marketing through AIRinky
 
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一s SS
 
Fueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfFueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfVWO
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfEastern Online-iSURVEY
 
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Search Engine Journal
 
marketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfmarketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfarsathsahil
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setupssuser4571da
 
Cost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesCost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesPushON Ltd
 

Recently uploaded (20)

Jai Institute for Parenting Program Guide
Jai Institute for Parenting Program GuideJai Institute for Parenting Program Guide
Jai Institute for Parenting Program Guide
 
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
How videos can elevate your Google rankings and improve your EEAT - Benjamin ...
 
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdfDigital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
Digital Marketing Spotlight: Lifecycle Advertising Strategies.pdf
 
pptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptxpptx.marketing strategy of tanishq. pptx
pptx.marketing strategy of tanishq. pptx
 
SORA AI: Will It Be the Future of Video Creation?
SORA AI: Will It Be the Future of Video Creation?SORA AI: Will It Be the Future of Video Creation?
SORA AI: Will It Be the Future of Video Creation?
 
ASO Process: What is App Store Optimization
ASO Process: What is App Store OptimizationASO Process: What is App Store Optimization
ASO Process: What is App Store Optimization
 
Word Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample GenresWord Count for Writers: Examples of Word Counts for Sample Genres
Word Count for Writers: Examples of Word Counts for Sample Genres
 
BrightonSEO - Addressing SEO & CX - CMDL - Apr 24 .pptx
BrightonSEO -  Addressing SEO & CX - CMDL - Apr 24 .pptxBrightonSEO -  Addressing SEO & CX - CMDL - Apr 24 .pptx
BrightonSEO - Addressing SEO & CX - CMDL - Apr 24 .pptx
 
Best Persuasive selling skills presentation.pptx
Best Persuasive selling skills  presentation.pptxBest Persuasive selling skills  presentation.pptx
Best Persuasive selling skills presentation.pptx
 
Influencer Marketing Power point presentation
Influencer Marketing  Power point presentationInfluencer Marketing  Power point presentation
Influencer Marketing Power point presentation
 
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
(Generative) AI & Marketing: - Out of the Hype - Empowering the Marketing M...
 
Common Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic CreativityCommon Culture: Paul Willis Symbolic Creativity
Common Culture: Paul Willis Symbolic Creativity
 
Forecast of Content Marketing through AI
Forecast of Content Marketing through AIForecast of Content Marketing through AI
Forecast of Content Marketing through AI
 
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一
定制(ULV毕业证书)拉文大学毕业证成绩单原版一比一
 
Fueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdfFueling A_B experiments with behavioral insights (1).pdf
Fueling A_B experiments with behavioral insights (1).pdf
 
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdfSnapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
Snapshot of Consumer Behaviors of March 2024-EOLiSurvey (EN).pdf
 
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
Do More with Less: Navigating Customer Acquisition Challenges for Today's Ent...
 
marketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdfmarketing strategy of tanishq word PPROJECT.pdf
marketing strategy of tanishq word PPROJECT.pdf
 
How To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot SetupHow To Utilize Calculated Properties in your HubSpot Setup
How To Utilize Calculated Properties in your HubSpot Setup
 
Cost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surgesCost-effective tactics for navigating CPC surges
Cost-effective tactics for navigating CPC surges
 

GDPR Is Coming – Are Emailers Ready?

  • 1. Presentation to MediaPost Email Insider Summit GDPR IS COMING – ARE EMAILERS READY? Tuesday, April 24, 2018 Gary A. Kibel Partner Digital Media, Technology & Privacy 212.468.4918 gkibel@dglaw.com @GaryKibel © 2018 Davis & Gilbert LLP
  • 2. AGENDA 1. U.S. vs. EU – Contrasting approaches to personal data 2. Key GDPR provisions applicable to ad tech and email 3. Pending Legislation 4. Q&A GDPR is Coming – Are Emailers Ready?1
  • 4.
  • 5. Digital Marketing and Big Data4 QUOTES You have zero privacy anyway. Get over it. Scott McNealy, CEO, Sun Microsystems 1999 ! “ ” “ ” Men lie. Women lie. Children lie. The only three things that don't lie are data, pets, and Spandex workout clothing. Peter Shankman, PR/Author
  • 6. 5 GDPR & Ad Tech: Examining the IAB Europe Transparency & Consent Framework U.S. VS EUROPE
  • 7. 6 FTC Section 5 “Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.” Regulation (EU) 2016/679 of the European Parliament - General Data Protection Regulation (GDPR) Directive 2002/58/EC – (ePrivacy Directive) PRIVACY ENFORCEMENT GDPR is Coming – Are Emailers Ready?
  • 8. FEDERAL TRADE COMMISSION ACT SECTION 5 » “Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.” - Deception = Misrepresentations or omissions likely to mislead consumers acting reasonably under the circumstances - Unfairness = causes or is likely to cause substantial consumer injury, not reasonably avoided by the consumer, and not outweighed by countervailing benefits to consumers or competition 7 GDPR is Coming – Are Emailers Ready?
  • 9. 8 PII = Personally identifiable information » COPPA – “personal information” » HIPAA – “protected health information” » GLB – “nonpublic personal information” » State security breach notification laws Personal Data = any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person GDPR is Coming – Are Emailers Ready?
  • 10. EXPANDING SCOPE OF PERSONAL INFORMATION » FTC Consent orders – “Persistent identifiers” » COPPA Amendments 2013 – Definition of personal information expanded to include any “persistent identifier that can be used to recognize a user over time and across different websites or online services” - Carve out for “support for internal operations” • Certain internal activities would not be considered a collection of PI, as long as the information collected is not used or disclosed to contact a specific individual (e.g., site maintenance and analysis) 9 GDPR is Coming – Are Emailers Ready?
  • 11. FTC – WHAT IS PII ? Blog post – April 21, 2016 » “… we regard data as ‘personally identifiable,’ and thus warranting privacy protections, when it can be reasonably linked to a particular person, computer, or device. In many cases, persistent identifiers such as device identifiers, MAC addresses, static IP addresses, or cookies meet this test.” 10 GDPR is Coming – Are Emailers Ready?
  • 12. 11 GDPR & Ad Tech: Examining the IAB Europe Transparency & Consent Framework GDPR APPLICABILITY TO AD TECH AND EMAIL
  • 13. GDPR FOR AD TECH » What is the GDPR? » 173 Recitals. 99 Articles. - Enforcement begins - May 25, 2018 » Why is this important? - Penalties = up to 4% of worldwide annual turnover or €20,000,000 12 GDPR is Coming – Are Emailers Ready?
  • 14. GDPR FOR AD TECH (1) Applicability / Extra-territorial scope - Applies to controllers / processors not established in the Union where: • (i) the processing relates to the offering of goods/services in the EU or (ii) monitoring of behavior of data subjects who are in the Union (2) Lawfulness of Processing - Consent - Legitimate Interest (Interests and rights and freedoms of the user are not overriding) 13 GDPR is Coming – Are Emailers Ready?
  • 15. GDPR FOR AD TECH (3) Personal Data - Definition of personal data includes: • Pseudonymous data • Online identifiers (e.g. cookie IDs) • Location data • Child - <16 (vs. <13 in U.S.) (4) Pseudonymization - “the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information.” (5) Anonymous Data – no connection of data with an individual 14 GDPR is Coming – Are Emailers Ready?
  • 16. GDPR FOR AD TECH (6) Data Subject Access Rights - Transparency - Access / rectification - Restrict processing - Right of erasure (a/k/a right to be forgotten) - Right to restrict processing / Right to object - Data portability (7) Client / Vendor Relationships - Data Processing Agreements 15 GDPR is Coming – Are Emailers Ready?
  • 17. GDPR FOR AD TECH (8) Lots of Internal / External policies - Internal – Information Security; - Privacy Notices - User flow (9) Breach notification - 72 hours to regulatory authorities (10) Record keeping - processing activities - More 16 GDPR is Coming – Are Emailers Ready?
  • 18. HIERARCHY OF EPRIVACY AND GDPR 17 GDPR is Coming – Are Emailers Ready? Processing personal data Consent GDPR Legal Basis ePrivacy GDPR  Collection of data over the internet generally requires under ePrivacy rules  Processing of personal data requires a e.g. consent, or legitimate interest GDPR Legal Basis Storing/accessing data on device Consent
  • 19. GDPR » Radically different approach to tracking than in the United States GDPR is Coming – Are Emailers Ready?18
  • 21. VERMONT – H.467 (DATA BROKER PROTECTION ACT) » “Data Broker” means a commercial entity that collects, assembles, or maintains personal information concerning individuals residing in Vermont who are not customers or employees of that entity for the purpose of selling or offering for sale, or other consideration, the personal information of a third party. » “Personal Information” includes information that identifies, relates to, describes or is capable of being associated with a particular individual. Includes internet usage history; profile that includes personality / characteristics » Data brokers must register with the state » Data brokers must annually report to the state on its activities » “Know your customer” » Status: In committee GDPR is Coming – Are Emailers Ready?20
  • 22. “CONSENT ACT” (2018) SENS. MARKEY (D-MA) & BLUMENTHAL (D-CT) » Notice and choice for “personally identifiable information” » Affirmative, express consent to use, disclose or access “sensitive customer proprietary information” - Includes web browsing history and application usage history » Authorizes FTC to implement regulations » No re-identification permitted » Breach notification obligation » Status: In committee GDPR is Coming – Are Emailers Ready?21
  • 24. Q&A To sign up and receive digital media alerts and event invitations, email gkibel@dglaw.com Gary A. Kibel Partner Digital Media, Technology & Privacy 212.468.4918 gkibel@dglaw.com @GaryKibel © 2018 Davis & Gilbert LLP