GDPR: here are 4 letters that, combined, can give a headache to website developers and marketers, since its implementation on May 25, 2018! But many of these practices have now moved to the dark side of the force… at least if you don't inform your users beforehand, in your Privacy Policy. You may unsubscribe at any time. However, this is only a source of general information, which cannot be interpreted as a real legal advice. But the GDPR has reinforced the system of penalties already in place. Note that the GDPR also applies to internal company data: the data you collect on your employees, in personnel files, for example. A data mapping to show good faith, in short. Your register must answer three key questions about your data processing: This register must be kept up to date at all times. En vous inscrivant à la newsletter, vous consentez à ce que WPMarmite, en sa qualité de responsable de traitement, collecte vos données afin de vous envoyer des communications par voie électronique. Required fields are marked *. Get the last WPMarmite posts (and also exclusive resources). Use the GDPR Data Request Form plugin. In short, you are juggling with personal data. WPMarmite est un blog exclusivement consacré à WordPress. To write the initial version of this article, we called upon the advice of the law firm Langlais: thank you to them! To find out if your plugins are GDPR-compliant, you'll need to conduct your own little personal investigation. Let's move on! Hans is the founder and CEO of Pixabay - currently living abroad in Switzerland. The first key point of the GDPR is the need to place clear and transparent information on your website for users. For example, if you appoint your agency's marketing manager, it is highly likely that his/her opinion will be biased on the use of the data for his/her newsletters.. As WooCommerce indicates, once this page is selected, an additional box will appear when a user will land on your order page. Your email address will not be published. However, the GDPR also provides that you must inform any user, before they share their data with you, that they have the right to withdraw their consent at any time. So think about doing the same on your newsletters (normally, an unsubscribe link is present). On the other hand, if you plan to share this data with partners and prospecting, the user must give consent for each of these uses. All the APIs you have authorized (Facebook, Twitter, or Mailchimp, to take only these famous examples) are also concerned. A real work of art, which will allow you to set up a really clear process. I can hear you sighing: "It's not over yet, these consent and data issues"!? Turn your site into a rocket with the most powerful caching plugin recognized by WordPress experts. You must also ensure that you effectively guarantee the security of your users' personal data. He has always been interested in new technologies, studied computer science in Ulm (Germany), and has launched several web projects. And most importantly, if you are not GDPR compliant, you risk having some customers refuse to do business with you from now on! So it's a matter of planning how you address this use of data in your current and future customer contracts. Not easy, we concede… but absolutely necessary. I therefore invite you to take check on the use of the data you intend to collect and to create forms with the right mentions (and possible checkboxes if necessary). While this feature is handy, we still recommend that you hire a professional to design it. Your email address will not be published. And good news: Starting with WordPress 4.9.6, you can create your Privacy Policy page directly from the Settings > Privacy tab of your WordPress interface. Admittedly, in practice, these were rarely applied, or with relatively low fines. The General Data Protection Regulation is a European regulation that came into force on May 25, 2018. What should you include on your WordPress site? If you handle a large amount of data on a daily basis, we can only recommend that you call on professionals, such as those at Langlais, who can help you to comply. They can : It's simple: whether your visitor creates an account or not, they will have to enter information related to their order (delivery address, first and last name…) as well as their email address to allow them to track their order. My advice: redo yourself the user path of your visitor, to detect all the moments when they might want to exercise their right of withdrawal or deletion. to the part about marketing levers to eradicate from your practices. The problem, you can probably see it coming from far away, now that you are experts of the GDPR: yes, still the harvest of consent! Whether you delegate this task to a plugin, or whether you have built your forms yourself, you should in any case check that you can: Regarding the famous check boxes, it is not necessary to add them to obtain the users' consent in the case where there is only one reason for collection (in this case, to receive a newsletter). Meet the founder, Alex, and his team right here. Note: The mere mention of copyrighted material is no reason to conclude that a trademark is not protected by a third party! More. All you need for a great start. The elements that are most impacted by the GDPR on the web are the forms. On that note, let's see what we're going to talk about! That's good: WPMarmite had met with lawyers as early as 2018 to get a little more clarity. Because, when a user abandons their cart, plugins like YITH Recover Abandoned Cart, Jilt or AutomateWoo still collect data, and this without them having had the time to check the box on the Terms and Conditions. No legal jargon, no references to obscure parts of the law: only concrete things for WordPress and WooCommerce website creators! On WooCommerce websites, nothing is better to increase the credibility of your product than customer reviews. Simple and efficient! Here again, whatever the settings you choose, you will have to add a transparency note to your WooCommerce forms leading to your privacy policy. WPMarmite est un site édité par la SAS Alexandre B Média, au capital de 2.000 euros, immatriculée au Registre du commerce et des sociétés de TROYES sous le numéro 751 884 644 et ayant son siège social situé 3 Chemin de Saint-Martin, 10150 VOUE, Directeur de la publication : Monsieur Alexandre Bortolotti – Contact. It is more than ever the responsibility of the data owner to pamper data, notably by protecting it against any security flaws, but also by allowing individuals to have a right of control over it. But your contact form is quite suitable (you are not going to receive this kind of request every day after all). So you will need to set up a simple procedure that will allow your users to: You could create a specific page dedicated to this procedure on your site, containing a precise request form. To do so, you'll use a small code snippet, adapted from the WooCommerce documentation. Ready to boil your mailbox? More than 40,000 people have done it, why not you? You can also subscribe without comment. Easy-peasy! For example, Google Analytics had quickly integrated this into its solution after the regulation was implemented, without making its users lose their visit history. Here again, WooCommerce thinks of everything for you, in the Settings > Accounts & Privacy tab. Many of the most popular ones have been compliant since 2018. In this case, a form should be accompanied by the mention of transparency as well as two checkboxes (one for each additional consent). All you need for a great start. And on a site, there are forms! By subscribing to the newsletter, you consent to WPMarmite, in its capacity as data controller, collecting your data in order to send you communications electronically. Because a showcase site or a blog and an ecommerce site don't mix the same type of data, it is essential to make a special point on what happens to sites using WooCommerce. The General Terms and Conditions of Sale are similar to the General Conditions of Use, except that they assume a commercial relationship between the user and the website. We can directly identify an Internet user thanks to their name, first name, but also their email address or phone number, and any type of demographic data (job function, gender, age, …) or geographical data (location, workplace, …). Another very important point: even if you or your company are based, or store your data, outside the European Union, the GDPR applies to your business. In the case of an ecommerce site, your Privacy Policy must appear clearly in the order forms. Want to let your users manage the deletion or modification of their data independently? Putting these elements in place on your WordPress site is first and foremost to save you trouble with them (reports and other threats…), and to install an aura of trust. Therefore, this article will guide you but make sure you double check with the law of your own country and with the help of professionals in this field. It can be an internal person (technical, legal position…) or an external person (lawyers, consultants…). If the GDPR seems to be a binding regulation, I wanted to finish this article on a critical, and above all positive tone. Don't subscribe The Jilt abandoned cart plugin is one of the good students in its category by adding a transparency message and a link to oppose this practice. WPMarmite helps beginners get the best out of WordPress with in-depth tutorials and honest reviews. Crédits : wpmarmite Le modèle de mentions légales est offert par Mentions légales. This is indeed a key point of contact between you and your visitors, where they share their personal data with you. That's good: WPMarmite had met with lawyers as early as 2018 to get a little more clarity. But don't get too worked up: as long as you know what APIs your site uses, what data they process, and you keep a record of all this (see the section dedicated to this point): there's no need to eliminate them from your WordPress site. So tell us in a comment what this regulation inspires you, and if you have found good practices to be GDPR-compliant! The method you use to collect, store and use your data; Your possible relationships with other subcontractors, who would use the same data; Your method of notification of a security breach, and possibly your process for correcting or deleting data at the request of users. Also note that you cannot ask a client to leave you data that is not related to what they are registering for. Totally not GDPR-friendly. In this case, a form should be accompanied by the mention of transparency as well as two checkboxes (one for each additional consent). Your best WordPress projects need the best host! Then go to the "Settings" tab of your WooCommerce plugin, then to "Order". Here are some elements to mention in your contracts, in a specific part about the use you make of your data, to be right on course: Even before the GDPR, the law already applied penalties in case of offences involving personal data. A veritable conductor of personal data, the DPO has the mission, in particular, of monitoring the entity's compliance with the GDPR and cooperating with the supervisory authority of each country. Let's get started: let's look at the best practices you should apply to your WordPress site. L'utilisation du site implique l'acceptation pleine et entière des conditions générales d'utilisation ci-après décrites. The purpose of this regulation, which has shaken the practices of professionals and individuals on the web: to ensure that all individuals control and protect the personal data they disseminate during their browsing on the web. And on top of that, the regulation specifies that this must be done easily for the user! Search for GDPR directly on their site or do a Google search of this type: GDPR. If you don't have this page yet, it's high time to create it! Since May 25, 2018, this procedure is no longer necessary, and is replaced by another obligation: that of keeping a data processing register. So here is a quick checklist of marketing levers for which you need to collect the consent of your users: Well, when it comes to profiling and retargeting, as a marketer, I'm scratching my head about the consent requirement…, For the moment, the first goal is to show the supervisory authority your goodwill towards the GDPR, despite the confusion that still reigns around these practices. Yes: since all this time, the GDPR, acronym for General Data Protection Regulation, has become well established in the minds of web users! Many sites use forms, for example, to offer newsletter subscriptions or to download documents. WPMarmite recommends Bluehost: great performance, great support. WordPress site creators generally manage these forms, known as "opt-in" forms, via plugins such as OptinMonster coupled with a MailChimp or MailPoet (there are many others). They are expected to reach 4% of the revenue of the person or company concerned, and up to 20 million euros for the most serious violations. Easy: go to Tools > Export Personal Data, and proceed in the same way. But if you have followed everything so far, you know that this is personal data! You will then be able to manually delete the data of the user who has asked you to do so, by entering their email address. Stay tuned, you'll see that there's some good in all this legislative mess!
