GDPR - Practical Application for Your Website

  • Share on Facebook
  • Email to a friend

Just to caveat, we’re not lawyers, nor are we GDPR experts. If your business holds sensitive, personal information, we would strongly recommend speaking to an expert to ensure everything you’re doing is compliant – let us know if this is the case and we would be delighted to put you in touch with someone who can help.

As we see it, from a website perspective, there are three areas you need to be aware of. These are where your website is hosted, how your data is collected and how you ensure all those on your database want to hear from you.

To cover each of these in turn:

Where your website is hosted

The ‘data processor’ who hosts your website will hopefully have taken steps to ensure their service is GDPR compliant. As a result, the onus is on you as the website owner to check with your hosting provider that they have this covered.

Studio44 clients who host with us can rest safe in the knowledge that we have this very much under control! We have spoken before about how we host, and why we have chosen Pulsant as our hosting partner and they have shown again why we trust them with our hosting infrastructure. They’re well ahead of the game when it comes to GDPR, and have updated their terms and conditions to take GDPR into account – feel free to have a look  at section 17 of their terms and conditions which focusses on data protection.

It’s also worth noting here that you should ensure your website host uses an SSL certificate for encryption. This protects the data being collected via contact forms and any other personal data being stored on your hosting account. For the benefit of Studio44 clients, all websites launched from 2018 have been launched with SSL by default. Please contact us if you'd like this enabled on an older website and we can advise.

How you collect data

Collecting data on your website to be GDPR compliant is all about ensuring you have the right consent from whoever you are receiving the information from. You need to explicitly tell the user what you’re signing them up for, and ensure they’re opting in, as opposed to the traditional confusing tick box you see on pre-GDPR consent forms!

Every website is different, and businesses collect data on their website for a myriad of reasons but if you have a website that collects personal data, it’s worth speaking to a GDPR consultant to ensure your means of collecting data via your website is correct. As a generic sample, wording like this could work… “We’d love you to join our community so we can send you news and exclusive promotions from us and carefully selected partner organisations. We always treat your details with the utmost care and will never sell them to other companies for marketing purposes. And you’re free to unsubscribe at any time!” You could then have a tickbox which says “Yes please, I’d love to hear about offers and services.”

It may be worth speaking to a GDPR expert to tailor the wording for your exact situation and audience, but hopefully that at least gives you an idea about wording you could use!

Your current database

Ensuring all those in your current database want to hear from you is hugely important. This essentially means getting all those on your current database to opt in to receiving communications from you. In a way, it’s a positive. You can cleanse your data, and those who you’re emailing actually want to hear from you!

So how do you go about this? Well this one is quite straightforward if, like us you use a good email marketing platform (we use Campaign Monitor). Campaign Monitor actually give a great breakdown on GDPR and how they’re preparing for it which is well worth a read.

When re-gaining consent, we think you want to keep things simple and transparent. Send out an email to your current database explaining the situation with GDPR, and that you’re obliged to give current subscribers advanced warning about continuing to receive communications about special offers, events or whatever you’re promoting. Use this as an opportunity to sell them on the benefits of re-subscribing with you, and then provide them with a link to sign-up/re-subscribe. Simple!

Subscribers will be getting used to this as they get more and more re-subscribe requests to their inbox, so they will sign-up if they want to hear from you. We would also recommend doing this periodically down the line to ensure your data is as clean as it possibly can be, and that your subscriber list really do want to hear from you.

So there you have it, hopefully a practical guide to how GDPR will impact your web presence, and for our clients, reassurance that we’re taking steps to ensure your presence is GDPR compliant. If there’s anything specific you want to discuss then we would love to hear from you.


Suggested Articles