If your business collects personal information through its website, such as through contact forms, newsletter sign-ups, downloadable resources or cookies, it’s important to understand your responsibilities for protecting that information.
The European Union’s General Data Protection Regulation (GDPR) establishes requirements for collecting, using, storing and protecting personal data belonging to individuals in the EU. While GDPR is an EU regulation, some U.S. businesses may fall under its requirements if they offer goods or services to individuals in the EU or monitor their behavior online.
GDPR violations can result in significant financial penalties, making data privacy and cybersecurity important considerations for businesses that collect personal information online.
What Does GDPR Protect?
GDPR broadly defines personal data as information that relates to an identified or identifiable individual. Depending on how your website and business operate, this may include:
- Names
- Email addresses
- Home or business addresses
- IP addresses
- Online identifiers and cookie data
- Photos
- Financial information
- Social media information
- Health or medical information
- Other information that can be used to identify an individual
The regulation is intended to give individuals greater control over how their personal information is collected and used.
For businesses, that means understanding what information your website collects, why it is collected, where it is stored and who has access to it.
What Does This Mean for Your Website?
GDPR can affect several common website functions, including contact forms, e-newsletter subscriptions, downloadable content and cookies.
For example, if visitors provide their email address to receive a newsletter or download a white paper, your business should clearly explain how that information will be used. Depending on the circumstances and applicable legal requirements, you may need to obtain consent before using the information for certain purposes.
Visitors should also have a clear way to unsubscribe from marketing communications. Your website should provide an appropriate privacy notice explaining what information is collected and how it is handled, along with access to your privacy policy.
Individuals may also have rights regarding the personal information a business holds about them, including requesting access to their data or, in certain circumstances, requesting that it be deleted.
Businesses should also understand their obligations if personal information is compromised in a data breach. Depending on the circumstances, GDPR may impose specific notification requirements and deadlines.
Key Principles for Collecting Personal Data
The European Commission emphasizes several important principles for organizations handling personal information.
Have a clear purpose for collecting information. Personal information should be collected for specific, legitimate purposes and should not be used in ways that are inconsistent with those purposes.
Collect only what you need. Businesses should avoid collecting unnecessary personal information. For example, if someone is signing up for an e-newsletter, you may need an email address, but additional personal information may not be necessary.
These principles can also serve as useful guidelines for businesses outside the scope of GDPR. Limiting the information you collect can reduce the amount of sensitive data your organization has to protect.
Seven Steps to Better Data Privacy Practices
The European Commission recommends that businesses take several steps to manage personal data responsibly:
- Understand what personal data you collect. Identify what information you collect, why you collect it and the legal basis for doing so.
- Inform individuals about your data practices. Provide appropriate privacy notices when collecting personal information.
- Keep information only as long as necessary. Establish retention practices and securely dispose of information that is no longer needed.
- Protect the information you collect. Use appropriate administrative, technical and physical safeguards to protect personal data.
- Document your data-processing activities. Maintain records that help demonstrate how personal information is collected and handled.
- Review third-party relationships. If another company processes personal information on your behalf, understand its responsibilities and address data privacy requirements contractually.
- Determine whether additional privacy responsibilities apply. Depending on your organization and its data-processing activities, you may need specific personnel or processes dedicated to data protection.
Not every business will need to appoint a data protection officer. Whether one is required depends on factors such as the nature, scale and risk associated with the organization’s data-processing activities.
Data Privacy Is Also a Cybersecurity Concern
GDPR compliance is only one part of protecting the personal information your business collects.
Consider how your organization handles information throughout its entire lifecycle. Do you have a data security plan? Who has access to customer information? How long is information retained? Do you have policies governing employee use of social media and company systems? If a cyber incident occurs, does your organization have an established response plan?
Businesses should also consider regularly reviewing their cybersecurity controls and working with qualified IT and security professionals to identify potential vulnerabilities.
The National Institute of Standards and Technology (NIST) provides the Cybersecurity Framework, which offers organizations guidance for identifying, protecting against, detecting, responding to and recovering from cybersecurity risks.
Where Does Insurance Fit In?
Strong privacy and cybersecurity practices can help reduce the likelihood and potential impact of a data breach, but no organization can eliminate cyber risk entirely.
Cyber incidents can result in costs associated with investigating a breach, notifying affected individuals, responding to regulatory requirements, restoring systems and managing related legal or business expenses. Depending on the policy, cyber insurance may provide coverage for certain first-party and third-party expenses arising from covered incidents.
Businesses should review their insurance program to understand how privacy and network security risks are addressed. A cyber liability or privacy and network security policy may provide coverage that is not available under a standard commercial insurance policy.
At Bender Insurance Solutions, we help businesses evaluate their insurance programs in the context of their broader risk management strategies. If your business collects personal information through its website, processes sensitive data or relies on third-party technology providers, talk with your Bender advisor about whether your current insurance program adequately addresses your cyber and privacy exposures.
Whether your organization needs to comply with GDPR or simply wants to strengthen its approach to protecting personal information, understanding what data you collect—and taking steps to safeguard it—is an important part of managing today’s business risks.
This article is intended for informational purposes only and should not be interpreted as insurance, legal, or risk management advice.
