In keeping with our ongoing commitment to privacy and security, FeedOtter will be ready for the GDPR before May 25, 2018, when the law goes into effect.
What is GDPR?
The General Data Protection Act (GDPR) is being introduced by the European Union to regulate how personal data can be processed. The GDPR is an attempt to strengthen, harmonize, and modernize EU data protection law and enhance individual rights and freedoms, consistent with the European understanding of privacy as a fundamental human right. The GDPR regulates, among other things, how individuals and organizations may obtain, use, store, and eliminate personal data.
The GDPR will replace a prior European Union privacy directive known as Directive 95/46/EC (the "Directive"), which has been the basis of European data protection law since 1995.
When does it come into effect?
The GDPR was adopted in April 2016, but will officially be enforceable beginning on May 25, 2018.
Who does it affect?
The scope of the GDPR is very broad. The GDPR will affect (1) all organizations established in the EU, and (2) all organizations involved in processing personal data of EU citizens. The latter is the GDPR's introduction of the principle of “extraterritoriality”; meaning, the GDPR will apply to any organization processing personal data of EU citizens—regardless of where it is established, and regardless of where its processing activities take place. This means the GDPR could apply to any organization anywhere in the world, and all organizations should perform an analysis to determine whether or not they are processing the personal data of EU citizens. The GDPR also applies across all industries and sectors.
What is "Privacy Shield" and how is that related to GDPR?
The Privacy Shield, as stated at https://www.privacyshield.gov/welcome is a privacy framework "designed by the U.S. Department of Commerce and the European Commission and Swiss Administration to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States in support of transatlantic commerce."
It is important for third party data processors in the US to be Privacy Shield compliant. GDPR permits data transfers to countries that have been deemed to have adequate data protection laws. The US's privacy protection laws generally do not meet the standards; being certified under Privacy Shield is a means for a company to contractually agree to meet applicable privacy regulations.
FeedOtter has self-certified to both the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield regime, and lawfully transfers EU/EEA personal data to the U.S. pursuant to our Privacy Shield Certification. It should be noted that Privacy Shield certified companies like FeedOtter will automatically be agreeing to GDPR as of May 25, 2018 through such certification.
What is considered "personal data"?
Per the GDPR, personal data is any information relating to an identified or identifiable individual; meaning, information that could be used, on its own or in conjunction with other data, to identify an individual. Personal data will now include not only data that is commonly considered to be personal in nature (e.g., email addresses, names, physical addresses, social security numbers), but also data such as IP addresses, behavioral data, location data, biometric data, financial information, and much more. This means that, for FeedOtter customers, at least a majority of the information that you collect about your end-users will be considered personal data under the GDPR. It's also important to note that even personal data that has been "pseudonymized" can be considered personal data if the pseudonym can be linked to any particular individual.
Sensitive personal data, such as health information or information that reveals a person's racial or ethnic origin, will require even greater protection. You should not store data of this nature within your FeedOtter account.
What does it mean to "process" data?
Per the GDPR, processing is "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction." Basically, if you are collecting, managing, using or storing any personal data of EU citizens, you are processing EU personal data within the meaning prescribed by the GDPR. This means, for example, that if any of your FeedOtter projects contains the email address, name, or other personal data of any EU citizen, then you are processing EU personal data under the GDPR.
Who is the "controller" and who is the "processor"?
If you access personal data, you do so as either a controller or a processor, and there are different requirements and obligations depending on which category you are in.
Data controllers are companies that supply goods or services to EU residents, or that track or monitor EU residents and decide why and how data is collected and processed.
Data processors are vendors or businesses that process data on behalf of data controllers. As a customer data platform, FeedOtter is considered a data processor. We will be ready for the GDPR as both a data controller and when acting as a data processor on your behalf.
In the context of the FeedOtter application and our related services, in the majority of circumstances, as one of our customers, you are acting as the data controller. Our customers, for example, decide what information from their end-users is uploaded or transferred into their FeedOtter account and direct FeedOtter, through our application or API, to send emails to certain end-users. FeedOtter is acting as a processor by performing these and other services for our customers.
As a data controller, you retain primary responsibility for data protection (including, for example, the obligation to report data breaches to data protection authorities). Additionally, you are required to only work with compliant data processors.
How is the GDPR different from the Directive? How are obligations changing?
While the GDPR preserves many principles established by the Directive, it introduces several important and ambitious changes. Here are a few that we believe are particularly relevant to FeedOtter and our customers:
There are many other principles and requirements introduced by the GDPR, so it is important to review the GDPR in its entirety to ensure that you have a full understanding of its requirements and how they may apply to you.
Does the GDPR say anything about cross-border data transfers?
Yes, the GDPR contains provisions that address the transfer of personal data from EU member states to third-party countries, such as the United States. The GDPR's provisions regarding cross-border data transfers, however, do not radically differ from the provisions in place under the Directive. The GDPR, like the Directive, does not contain any specific requirement that the personal data of EU citizens be stored only in EU member states. Rather, the GDPR requires that certain conditions be met before personal data is transferred outside the EU, identifying a number of different legal grounds that organizations can rely on to perform cross-border data transfers.
One legal ground for transferring personal data set out in the GDPR is an "adequacy decision." An adequacy decision is a decision by the European Commission that an adequate level of protection exists for the personal data in the country, territory, or organization where it is being transferred. The Privacy Shield framework constitutes one such example of an adequacy decision. FeedOtter participates in and has certified its compliance to the Privacy Shield framework, and we are committed to treating all personal data received from EU member countries in accordance with the Privacy Shield framework's applicable principles.
What does this mean for you? Generally speaking, it means we expect that FeedOtter's EU customers will be able to continue to rely on FeedOtter's Privacy Shield certification in order to transfer their lawfully obtained personal data to FeedOtter under the GDPR.
Do you need to comply with the GDPR?
You should consult with legal and other professional counsel regarding the full scope of your compliance obligations. Generally speaking, however, if you are an organization that is organized in the EU or one that is processing the personal data of EU citizens, the GDPR will apply to you. Even if all that you are doing is collecting or storing email addresses, if those email addresses belong to EU citizens, the GDPR likely applies to you.
What happens if you do not comply?
Non-compliance with the GDPR can result in enormous financial penalties. Sanctions for non-compliance can be as high as 20 Million Euros or 4% of global annual turnover, whichever is higher.
Will FeedOtter comply with the GDPR?
FeedOtter is excited about the GDPR and the strong data privacy and security principles that it emphasizes, many of which FeedOtter instituted long before the GDPR was enacted. At FeedOtter, we believe that the GDPR is an important milestone in the data privacy landscape, and we are committed to achieving compliance with the GDPR on or before May 25, 2018.
As part of FeedOtter's GDPR preparation we are reviewing (and updating where necessary) all of our internal processes, procedures, data systems, and documentation to ensure that we are ready when the GDPR goes into effect. While much of our preparation is happening behind the scenes, we are also working on a number of initiatives that will be visible to our customers. We are, among other things:
In addition, we will be prepared to address any requests made by our customers related to their expanded individual rights under the GDPR:
If you have specific questions about the GDPR and your use of FeedOtter, you can email [email protected].
DISCLAIMER: The above FAQ is meant as a general set of questions and answers and is not advice and cannot be relied upon for any legal purpose. You must consult your own professional advisors for your specific facts and circumstances before taking, or refraining from taking, any particular course of conduct. The above FAQ is not an amendment or supplement to any agreement between FeedOtter and you.