GDPR Practices For The Online Fashion Industry | LG
What is GDPR?
The EU General Data Protection Regulation (GDPR) was
approved on April 14th, 2016 and has been in effect since May 25th, 2018
(Nabbosa and Iftikhar, 2019). GDPR sets out a list of guidelines that must be
adhered to when collecting and storing personal information from EU citizens.
Personal data is any information that is collected both directly and indirectly
that may identify an individual. Online identifiers are used to collect
information relating to the technical device that an individual is using. These
may include cookies, IP addresses, and locational data that must be considered
carefully when collecting identifiable information that can identify a person
(Goddard, 2017).
GDPR compliance for Online Fashion Retailers
The Continuous implementation of GDPR compliance will continue to be a challenge for Digital Retailers as there is a high dependency on data used in business processes like marketing (profiling consumers, personalised promotions) and collecting and analysing data after sales (Nabbosa and Iftikhar, 2019). Online fashion retailers are faced with the responsibility of ensuring that their brands are complying with the terms set by GDPR, resulting in marketing limitations. Retailers like ASOS and PrettyLittleThing must find alternative methods of advertising without requiring legal consent from their consumers. The term ‘Consent’ is often built into cookies and users will accept this when asked to read the terms and conditions.
GDPR has forced marketers to re-think their efforts
when conducting any activities that involve the use of personal data. The
obligation for all organisations to comply with the GDPR when collecting
personal data from EU residents is mandatory worldwide. Failure to comply with
this regulation may result in a fee of up to €20 million or 4% of annual global
turnover in fines, depending on which figure is highest (Governance, 2019).
One of the initial steps in becoming compliant with the
GDPR is a stricter approach in getting consent from consumers before gaining
access to their personal information.
Beckett (2017) explains that in order to be compliant
with the GDPR, companies are obliged to show why they have the right to process
the information in the first place. They must ensure that there is a legal
basis to process the personal information in the beginning so these
organisations go on to record this information.
At Group Fashion Agency our mission is to ensure that our clients are fully compliant with the necessary guidelines required by GDPR to avoid large penalties or fines.
Group Fashion Agency will ensure that:
- Data
Permission is clear and unambiguous with clear ‘opting in’ sections.
- Data Access can be removed when outdated or incorrect
- Data Focus is specific information as to what is required without the process of personal information.
#Compliant #GDPRconsent
References
·
Beckett, P., 2017. GDPR compliance: your tech
department's next big opportunity. Computer Fraud & Security,
2017(5), pp.9-13.
· Governance, I.
2019, EU General Data Protection Regulation (GDPR): an implementation
and compliance guide, ITGP.
·
Goddard, M., 2017. The EU General Data Protection
Regulation (GDPR): European regulation that has a global impact. International
Journal of Market Research, 59(6), pp.703-705.
·
Nabbosa, V. and Iftikhar, R., 2019. Digital Retail
Challenges within the EU. Proceedings of the 2019 3rd International
Conference on E-Education, E-Business and E-Technology - ICEBT 2019,.


Objectives for GDPR Framework | RM
ReplyDeleteGDPR exists to provide a set of standardised data protection laws across all member countries. The purpose is to make it easier for EU citizens to understand how their data is being used, allowing them to complain whether they are in the country that it’s located. The number one objective should be to comply with the regulation to avoid fines up to 20 Million and punitive measures. SMART Objectives should be set out to help enable performance for tracking and measurement. The key performance objectives outlined by the EU General Data Protection Regulation (GDPR) are as follows:
1. The capability of responding to subject access requests within the new prescribed time frame (now one month),
2. The capability of identifying and reporting data breaches to super-
visory authorities within 72 hours;
3. Retention periods of personal data;
4. Staff awareness training.
Reference
Zorzino, G., G., (2017), EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide
GDPR: RK
ReplyDeleteThe implementation of GDPR in May 2018 has led to increased awareness amongst consumers of how their personal data is used and processed by corporations. Apple has recently announced that they will roll out key privacy changes with their next update, expected to be released in Q2 or Q3 2021. Newly empowered iPhone users will be able to choose whether to opt in or opt out of being tracked by each app on their phone. (Taylor, 2021). This has led to a public outcry by Facebook who have stated that these changes will damage small businesses around the globe as their advertising will be less targeted (Taylor, 2021). In response, Facebook has recommended that advertisers implement the Facebook Conversions API. The API will allow businesses to track the performance on their websites through the website server, rather than solely relying on the Facebook Pixel which will be able to gather significantly less data due to the Apple update (Popolizio, 2021).
Popolizio, A. (2021) “Facebook Conversions API: What Marketers Need to Know” [Online Article] Available at: https://www.socialmediaexaminer.com/facebook-conversions-api-what-marketers-need-to-know/ [Accessed 5th April 2021]
Taylor, J. (2021) “Facebook v Apple: The Looming Showdown Over Data Tracking and Privacy” [Online] Available at: https://www.theguardian.com/technology/2021/feb/14/facebook-v-apple-the-looming-showdown-over-data-tracking-and-privacy [Accessed 5th April 2021]