• #

Privacy Policy: processing of personal data and GDPR compliance

The Privacy Policy is a mandatory document for websites that indicates the method of processing personal data. Do not underestimate the provided sanctions and, above all, pay attention to the GDPR updates since May 25, 2018.

Mattia Chimini
Mattia Chimini · 28 2023
Do you also, like me, have an email inbox flooded with newsletters about updates/courses/training/whoever-has-more-to-say regarding the privacy policy? And this blessed GDPR (for many GPDR or DGPR, basically whatever they feel like) that seems to have become a real nightmare? Let's say the web public is divided into two parts: those who are too scared, who ask for signed consents even just to look the customer in the eye... and those who are too unconcerned, somewhat reckless even regarding the hefty fines provided for. In short, let's clear things up and organize the information regarding this thorny subject.

What is a privacy policy?

It is a document that describes in the most detailed and clear way possible the methods of management and processing of the personal data of users and visitors of the website by the company. Personal data does not only mean name, surname or email address but also Cookies used by Google Analytics, therefore for tracking user behavior on the website.
The document is divided into several paragraphs, in which the following are indicated: the DATA CONTROLLER, the RIGHTS of users, the PLACE and PURPOSE of the processing, the TYPE of data processed, the COOKIES released by the website, the RETENTION of data, LINKS to external content and also the methods for modifying settings.

Privacy Policy: fines and penalties

It is mandatory by law; a website without one could incur sanctions and very heavy fines, starting from a minimum of 3,000 Euros to a maximum of 50,000 Euros. And who checks? The Privacy Guarantor. How? They can act upon a report from a user, so if a friendly "friend" of yours decides to report your currently lacking website, it triggers an immediate mechanism of checks (and sanctions); or through other types of checks such as those carried out by the Guardia di Finanza.
In your opinion, is it worth the risk? Mmmh, in our opinion, no!

Who writes the Privacy Policy document?

We recommend two possible paths to our clients. The first, more expensive but certainly more attentive and precise (perhaps also useful for organizing all the appointments of the data processing supervisors within the company, not just regarding the website), is to contact an expert lawyer in the sector and have it written directly by them. The other, more economical, is to turn to dedicated websites (for example Iubenda.com) that generate the document based on the information provided, after obviously contacting the site's technical reference to understand its behavior 100%.
Please Note: Privacy Policies are not standard texts; they must be drafted by examining the actual method of data processing within the company. Therefore, "copy-pasting" (which many websites do) is often counterproductive if it does not actually correspond 100% to your corporate reality.

And what is this new GDPR?


GDPR is the acronym for General Data Protection Regulation, namely the European regulation regarding Privacy, operational since May 25, 2018. It is a text that attempts to harmonize all European laws on the processing of personal data and, therefore, on the control of our information. But is it really a revolution compared to previous rules? Yes, absolutely yes. It has had a great impact even on small companies. Among the main obligations of the GDPR are:
*     request for consent in a clear and explicit form
*     establishment of an activity register
*     notification of breaches within 72 hours


But let's get to the interesting part, the fines (so we can further worry the catastrophists and perhaps tickle the peaceful ones): depending on the severity, the sanction is triggered, first tier up to a maximum of 10 million euros (or 2% of turnover if higher), second tier up to a maximum of 20 million (or 4% of turnover if higher).
We have provided you with one more reason not to underestimate the subject, that's for sure! For further information or clarification, do not hesitate to contact us; we are at your disposal.

Since May 25, 2018, therefore, the GDPR (General Data Protection Regulation) has become fully applicable in Italy, which we remind you relates to the protection of natural persons with regard to the processing and free movement of personal data, not only in the web environment, but also in the normal management of data within a company. However, to date, many companies have still not implemented the minimum measures necessary to guarantee the protection of personal data and consequently many websites are still non-compliant with the regulation.

It must always be remembered that the GDPR applies to all businesses, small or large, including those located outside the European Union that offer services or products within the EU market. All companies must therefore respect the rules, regardless of their geographical position, under penalty of heavy sanctions from the competent supervisory bodies (for Italy, the Guarantor for the Protection of Personal Data GPDP).

Speaking specifically about the adaptation of a website, given that these are not simple modifications or "copy-pasting" of texts from other sites (which in fact could prove to be counterproductive), it is always best to rely on experts who know how to make changes in accordance with EU Regulation 2016/679 and know how to identify the correct tools to use to comply with the obligations imposed by law (such as iubenda.com, which offers the service of generating privacy and cookie policies in addition to other services for the processing of personal data).

But what are the necessary actions to have a GDPR-compliant website?

1)    Have a compliant privacy policy
The first rule is to have a complete privacy policy document compliant with EU Regulation 2016/679.

The privacy policy must contain the following information:
●    the data controller and, if appointed, the data protection officer;
●    the personal data subject to processing;
●    the purposes of the processing;
●    the legal basis for the processing;
●    who the recipients are;
●    any data transfers;
●    the methods and period of data retention;
●    all the rights of the data subject.

The privacy policy must then be available to all site users and reachable from any page.

2)    Have a compliant cookie policy
As with the privacy policy, having a cookie policy is also fundamental to comply with the Regulation. This document must contain the following information:
●    provide users with clear information on the use of cookies;
●    specify the types of cookies used (technical, analytics, profiling, etc)
●    list any other recipients of personal data
●    the timing and methods of information retention
●    the possibility and methods for users to exercise their rights regarding the protection of personal data.

3)    Have an updated and compliant banner
After drafting the cookie policy, the informative banner necessary to acquire user consent for the installation of cookies follows. It is necessary to ensure that:
●    the request for cookie installation is differentiated between technical, profiling, and analytical cookies and that different types are not grouped together (granular consent);
●    scrolling the page is not considered a positive action of consent;
●    ensure that in the absence of consent, only technical cookies are activated;
●    the revocation of cookie acceptance must be as easy as the acceptance;
●    consent must always be demonstrable by keeping a certified register.

4)    Update contact forms
The basic rule remains transparency, so to use the data provided by the user, it is necessary that the latter provides explicit consent to the use and that the purposes of the processing are clear.
With 2 examples, both key points can be clarified.
●    explicit consent is achieved by avoiding pre-selected checkboxes; in this way, by taking the action of accepting the data processing, the user provides informed and explicit consent
●    regarding the purposes of the processing explicitly stated in a clear way, taking the example of a contact form in which the collected email address is also intended to be used to send newsletters and commercial communications, it will be necessary to provide two different checkboxes: one relating to the processing of data to respond to the contact request (which will obviously be mandatory) and a second checkbox in which the purpose of the processing for sending newsletters will be explicitly stated, which cannot be mandatory and will remain the user's choice

We remind you that, as with the cookie policy, for contact forms as well, the consent after being collected must be archived in a specific register, which can be in paper or digital format and will contain the following information:
- who provided the consent,
- when it was provided,
- what are the conditions that the user explicitly accepted,
- who has access to the data.

The information provided previously cannot be considered as the instructions to follow to make any website GDPR-compliant, as every website or application has its own history and characteristics; it is therefore necessary, before proceeding with implementations, to carry out an analysis to understand what personal data is collected, how it is processed, and what types of cookies are used. Only in this way can you then intervene to have your website compliant with EU Regulation 2016/679.
 

We have selected some articles that may be of interest to you.

27/06/2024

Copywriter: what it is, what they do and how they can be useful to you

Copywriter: but who are they? And above all, what do they do? I have been dealing with web writing for about 15 years, and I will tell you (in my opinion) what the skills and qualities are that are essential to carry out this profession... but above all, how beautiful and stimulating this job is!

  • #
26/04/2023

Differences between Blog, Forum and Glacom's corporate Blog

What are the differences between a Corporate Blog and a Forum? What is a corporate blog used for? We answer all these questions, adding a further differentiation: the Blog VS the Forum VS Glacom's Corporate Blog.

  • #
22/02/2024

Subsidized finance: the 2023 ISI-INAIL call for 2024

What is the INAIL ISI 2023 call for applications? Who is it aimed at and which projects are eligible? Our Finance consultant answers all your questions.

  • #
🚀We are hiring!

We are hiring!

Glacom