The General Data Protection Regulation (GDPR) is a law intended to strengthen the right to data protection of individuals in the European Union (EU) - Austria, Belgium, Bulgaria, Croatia, Republic of Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and the United Kingdom.
The regulation took effect on May 25, 2018 and applies to all companies and other organizations established anywhere in the world that offer goods and services to people in the EU, or collect and analyze personal data of EU residents.
The people whose personal data you collect, use, or process in any way are referred to in the GDPR as Data Subjects. This new complex set of rules aims to allow data subjects full control over their personal data by imposing strict obligations to which organizations that process their data will need to comply.
A breach of those obligations may incur a fine of up to 4% of annual global turnover or 20 million (whichever is greater).
Personal data must be, among other things:
What you need to do: Analyze the types of personal data that you collect and for what purposes. Ensure that the data are processed lawfully, fairly, and transparently. Determine how long you need to keep data and if you really do need all the various data elements. Verify with your vendors and your internal IT team that the data are securely handled.
What you need to do: You will want to adjust forms that prospects, members, event attendees, and other people fill out such that the end-user will understand why their data is being collected. Also, you may want to re-acquire consent from various contacts that you currently have. Our GDPR features will allow you to do this, for the contacts that you have within your instance of the MemberLeap system.
What you need to do: You will want to do an assessment of the personal data that you store in your system, to determine if any of the data falls into these special categories, and to acquire explicit consent as required by the GDPR.
What you need to do: You will need to be able to respond to various requests from data subjects for exercising their rights under the GDPR. Our system allows for most of this already, and the add-on GDPR center will make the rest easier, at least with respect to allowing data portability, and anonymizing data to satisfy the right to be forgotten.
For the most part, the controller is the association (you), while the processor is the vendor providing software for processing of those data,such as MemberLeap(us).
What you need to do: Understand your responsibilities as a controller and implement appropriate measures and security controls. Also, depending on your organization, you may need to appoint an EU-based representative as required by Article 27.
If you have need for storing EU citizen data, we would require you to sign an addendum to our online service agreement, and to pay an additional monthly charge. This charge offsets costs that we incur in order to comply to GDPR as a data processor. By paying this fee, you are also granted access to our Privacy/GDPR module, which includes features needed for compliance, as well as some additional materials and guidelines to help you get compliant. Below is the current schedule of additional fees.
Subject to change based on additional GDPR requirements.
The GDPR doesn't directly regulate the use of cookies, or the issue of cookie consent banners. Under EU law, cookies are regulated by the current ePrivacy Directive, which is set to be repealed and replaced by the ePrivacy Regulation. The new regulation is currently being negotiated in Brussels, and it's not possible to know if cookie banners will continue to be required after the new ePrivacy Regulation is finalized.
Even if you process the data of only a few EU citizens, it is highly likely that the GDPR will still apply to these particular processing operations. While under such circumstances you may be exempt from certain obligations, as described above, suchas maintaining records of processing activities or being required to appoint a Data Protection Officer, the majority of the GDPR requirements will still apply to your processing of EU data. If you are still in doubt, please feel free to contact us with inquiries.
It is a common misconception that the businesses will necessarily need to re-acquire consent from all the contacts in their database before May25, 2018. Making this determination should be subject to an analysis of the legal grounds that you may use,based on the specifics of your association, along with a number of other factors. In the "Using MemberLeap in the Context of the GDPR" guide available to our GDPR Module subscribers we have provided resources that will help you make this evaluation.
You can access the actual module in the Pastry Chefs of America - username: janeadmin9 and password: janeadmin9.
Please feel free to ask questions. As we get more questions, it will help us build this FAQ section. If you are a client, and have questions, please log into the system and submit a help ticket, so we can better coordinate our efforts to help you with compliance. If you are a prospective client and have questions about the GDPR module or other aspects of our product, please click here to contact us or email us at gdpr@memberleap.com.