{"id":2610,"date":"2022-10-26T11:35:00","date_gmt":"2022-10-26T17:35:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2610"},"modified":"2024-10-10T13:18:33","modified_gmt":"2024-10-10T19:18:33","slug":"essential-guide-marketing-under-the-gdpr","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/","title":{"rendered":"Your Essential Guide to Marketing Under the GDPR"},"content":{"rendered":"\t\t<section id=\"block_33598005423f5825120bc60fcff7209a\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Your Essential Guide to Marketing Under the GDPR<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_53cb33152982eb52a5cca2f049d77b16\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<p>Although the GDPR is not new, its effects on business marketing activities continue to puzzle practitioners. Marketing under the GDPR with consumer information is still possible, but you\u2019ll need to understand the regulation thoroughly.<\/p>\n<h2>What is the GDPR?<\/h2>\n<p>Implemented in May 2018, the European Union\u2019s\u00a0<a href=\"\/regulations\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>\u00a0claims to be the\u00a0<em>toughest privacy and security law in the world.<\/em>\u00a0And you don\u2019t have to be based in Europe to be impacted by it.<\/p>\n<p>As long as your organization targets or collects data related to individuals in the EU, you must abide by the regulations. If you don\u2019t,\u00a0<strong>you can expect penalties reaching into the tens of millions of euros.<\/strong><\/p>\n<p>The GDPR is large and far-reaching and may impact many areas of your company, including your marketing strategies.<\/p>\n<h2>Consent and marketing under the GDPR<\/h2>\n<h3>Can my company capture consent in exchange for content? For example, can I collect an email address to download a white paper or register for a webinar?<\/h3>\n<p>Yes, but\u2026 to do this, you must be very clear on the specific uses of the information you collect. Businesses must clearly state the purpose at the time information is collected. It\u2019s unlikely any non-disclosed purposes will be consented to if challenged.<\/p>\n<p>For example, a company can\u2019t use email addresses obtained solely for contest entry purposes to then market to the individual or, for that matter, share that information with partners. The exception is, of course, if the consumer was asked and specifically and actively agreed to this.<\/p>\n<p>Essentially, businesses need to be very specific when it comes to the intended uses of information collected.<\/p>\n<h2>How should companies manage vendors?<\/h2>\n<h3>What are the key questions a marketer needs to ask email service providers (ESPs) to help them comply with GDPR requirements?<\/h3>\n<p>If you\u2019re just beginning your business dealings in the EU, you need to ensure your email service provider can comply. In short, ensure your ESP is aware of their obligations under\u00a0<a href=\"https:\/\/gdpr-text.com\/read\/article-28\/\" target=\"_blank\" rel=\"noopener\">Article 28 (3-f) of the GDPR<\/a>\u00a0and that they can help you demonstrate compliance.<\/p>\n<p>Setting up a comprehensive vendor assessment is also a good idea and it\u2019s recommended companies put in place a data protection agreement, incorporating standard contractual clauses.<\/p>\n<h2>Can companies still market to consumers with legitimate interests?<\/h2>\n<h3>Does \u201csoft opt-in\u201d still exist under the GDPR?<\/h3>\n<p>The term \u201csoft opt-in\u201d is often used to describe how a company can market to existing customers. Provided you have fulfilled certain criteria, under existing regulations you can market to customers without their explicit consent if:<\/p>\n<ol>\n<li>You have already sold your goods and services to that individual<\/li>\n<li>They gave you their details and did not opt out of marketing messages<\/li>\n<li>You are emailing them about goods or services that are the same or similar to previous goods or services<\/li>\n<li>You give them a clear chance to opt out with every message you send them. If individuals have unsubscribed, opted out, or otherwise indicated their desire that your organization stop using their personal information, your organization may not contact them to seek their consent to marketing.<\/li>\n<\/ol>\n<p><strong>The \u201csoft opt-in\u201d rule means you may be able to email or text your own customers.<\/strong><\/p>\n<p>However, it does not apply to prospective customers or new contacts, such as those from bought-in lists. It also does not apply to non-commercial promotions like charity fundraising or political campaigning.<\/p>\n<h2>Seeking GDPR-compliant consent<\/h2>\n<h3>What is \u201cstale\u201d consent, and how does it impact my business?<\/h3>\n<p>There\u2019s a lot of buzz around \u201cstale\u201d consent. Stale consent is consent that was previously obtained, but that may not meet the GDPR\u2019s new standards.<\/p>\n<p>For instance, let\u2019s say your marketing department had pre-ticked boxes for individuals to receive newsletter updates when they filled out a form to download a white paper. That previously obtained consent may no longer satisfy the clear, affirmative action requirement under the GDPR.<\/p>\n<p>For any instances that do not satisfy GDPR standards, companies should seek GDPR-compliant consent. Or, they should no longer use the earlier, acquired personal data.<\/p>\n<p>Requesting consent from individuals whose previously obtained consent doesn\u2019t meet GDPR standards is known as a \u201cre-permissioning\u201d or \u201cre-engagement\u201d campaign.<\/p>\n<h2>How does the GDPR impact data sharing between the EU and the U.S.?<\/h2>\n<h3>Are there any legal or other issues with accessing EU databases from the U.S.?<\/h3>\n<p>In short, yes. The GDPR impacts data sharing between the EU and other parts of the world. As described in\u00a0<a href=\"https:\/\/gdpr-info.eu\/chapter-5\/\" target=\"_blank\" rel=\"noopener\">Chapter 5 of the GDPR<\/a>, companies in the U.S. and elsewhere outside the EU must have a legal transfer mechanism for receiving or accessing EU personal data.<\/p>\n<p>This means\u00a0<strong>companies must evaluate the methods they use for receiving, transferring and importing EU personal data<\/strong>. They also need to document their transfer basis.<\/p>\n<p>Many U.S. companies self-certify to the EU-U.S. Privacy Shield Framework. In fact,\u00a0<a href=\"https:\/\/trustarc.com\/truste-certifications\/privacy-shield\/\" target=\"_blank\" rel=\"noopener\">TRUSTe<\/a>\u00a0has verified thousands of them.<\/p>\n<h2>GDPR impact on lead generation and business cards<\/h2>\n<h3>How does the GDPR apply to attendee lists, either provided via email or business cards? Will trade show vendors need to change how they share attendee information?<\/h3>\n<p>Attendee lists and delegate lists such as those provided at conferences and trade shows, webinars, webcasts and workshops can be used if:<\/p>\n<ul>\n<li>The entity collecting the data has obtained the consent of the data subject<\/li>\n<li>The entity collecting the data has informed subjects how their data will be stored, used and shared.<\/li>\n<\/ul>\n<p><strong>It\u2019s important to remember that personal data does not just relate to email addresses<\/strong>. It\u2019s defined as any information that can be used to directly or indirectly identify someone.<\/p>\n<p>That can include their name, email address, photo, or computer IP address, but also information on medical conditions, dietary requirements and social media posts.<\/p>\n\t\t\t\t\t\t\t\t\t<div class=\"question-box-multiple\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Complexity_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Does the EU GDPR apply to my organization?<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>The reach of the EU GDPR extends quite broadly and extends outside the EU depending on certain factors.<\/p>\n<a href=\"https:\/\/trustarc.com\/regulations\/gdpr\/\" class=\"cta\">Learn more<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Update_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>GDPR Validation<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Get validated by an independent third party that attests your privacy and data protection practices.<\/p>\n<a href=\"https:\/\/trustarc.com\/products\/assurance-certifications\/gdpr-validation\/\" class=\"cta\">Get validated<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/gdpr\/\" class=\"badge\">GDPR<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>The implementation of the EU\u2019s General Data Protection Regulation (GDPR) in 2018 had major implications for business marketing around the world. Ensure your business is compliant when marketing under the GDPR.<\/p>\n","protected":false},"featured_media":1251,"template":"","topic-resource":[63],"type-resource":[6],"class_list":["post-2610","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-gdpr","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Your Essential Guide to Marketing Under the GDPR | TrustArc<\/title>\n<meta name=\"description\" content=\"The implementation of the EU\u2019s General Data Protection Regulation (GDPR) in 2018 had major implications for business marketing around the world. Ensure your business is compliant when marketing under the GDPR.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/\",\"name\":\"Your Essential Guide to Marketing Under the GDPR | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-purple-test.png\",\"datePublished\":\"2022-10-26T17:35:00+00:00\",\"dateModified\":\"2024-10-10T19:18:33+00:00\",\"description\":\"The implementation of the EU\u2019s General Data Protection Regulation (GDPR) in 2018 had major implications for business marketing around the world. Ensure your business is compliant when marketing under the GDPR.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/essential-guide-marketing-under-the-gdpr\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-purple-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-purple-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Your Essential Guide to Marketing Under the GDPR | TrustArc","description":"The implementation of the EU\u2019s General Data Protection Regulation (GDPR) in 2018 had major implications for business marketing around the world. Ensure your business is compliant when marketing under the GDPR.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/","url":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/","name":"Your Essential Guide to Marketing Under the GDPR | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-purple-test.png","datePublished":"2022-10-26T17:35:00+00:00","dateModified":"2024-10-10T19:18:33+00:00","description":"The implementation of the EU\u2019s General Data Protection Regulation (GDPR) in 2018 had major implications for business marketing around the world. Ensure your business is compliant when marketing under the GDPR.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/essential-guide-marketing-under-the-gdpr\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-purple-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-purple-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1251"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2610"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2610"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}