The GDPR – Are you hellbent, on consent?

We receive many calls and messages stating that businesses need consent before they can carry out marketing. Does the UK GDPR demand this? Do you need it? Or is there a better way? As data protection practitioners, we don’t just help business comply with the GDPR. We help the business function as it wants to whilst complying with the law.

Consent under the GDPR

We all know the rules on gaining consent. You do, don’t you? Just in case you don’t then it must be freely given, without duress, specific about use of the data and without ambiguity. Finally, an affirmative action is needed. In other words, no pre-ticked boxes. We still see this today!

We were asked this week, do we have consent for…various activities. Do you? Well, it depends on your business. If you want to market to a client of course you have consent…don’t you? No! It is a myth that just because a business is a client you can market to them. You do need permission to do this unless you can claim legitimate interest. For example, helping the client to get the best from their purchase. Communicating with your client about their order or service is covered under ‘performance of a contract’.

Membership Organisations

Membership organisations are slightly different in how they market. This will depend on the terms and conditions agreed for new members. The organisation will want to keep members informed of membership benefits and will market to them accordingly. However, can the organisation market third party services to their members? If they are taking third party data and passing it on to members, then yes. The membership terms will cover this.

However, the member data cannot be passed to third party organisations for the purpose of marketing without explicit consent. Passing data in this manner requires explicit consent as once passed, you have lost control over the data. The UK GDPR requires this to be reported on your privacy notice, as transparency is important.

Privacy Notices

Better known as fair processing notices, your privacy notice is a legal requirement of the GDPR.

We are often asked whether we need differing privacy notices for events, webinars or networking meetings. The simple answer is no. If your privacy notice has taken into account your business activities, then it will cover all the processing you do. If you have ‘borrowed’ a privacy notice or bought yourself a cheap template, then it won’t be adequate to meet the requirements of the GDPR.

If you pass data to third parties, you must state this in your privacy policy. You must have consent.

If you would like to understand more about consent and the use of privacy notices, please contact us.