Ready for GDPR? Get your website prepared for May 25th!

by Sam Davis
In less than two months, the EU is introducing a new regulation entitled GDPR – which stands for General Data Protection Regulation. This will affect every website owner in Europe and beyond – as it requires the website owner to reveal exactly how visitors data is being processed as well as detailing the servers or third party services where the information is being stored. It is requires that the information must be clear to visitor of their website, giving the user greater peace of mind when visiting a website.
You may mistakenly think that because we’re exactly one year into Article 50 and the UK is heading for Brexit, that this EU regulation isn’t going to apply to you – you’re wrong, as it will be adopted by Britain regardless. The new rulings are, in the Union’s own words “designed to harmonise data privacy laws across Europe, to give citizens of the EU control over their personal data and to change the approach of organisations across the world towards data privacy.”
You’ll need to give your pages a security audit, and you’ll need to re-explore the ways that YOU already collect data from your website from your users.
What does this mean for a website owner? Well, your website will need to be “GDPR compliant”, meaning that you’ll need to give your pages a security audit, and you’ll need to re-explore the ways that YOU already collect data from your website from your users – ensuring that you yourself are fully aware of what you collect, where you store it, and how you intend to use it. Personal data is any information related to an individual. Such information includes:
- name;
- location;
- online identifier;
- IP addresses;
- email;
- address, etc.
Now, if you have a WordPress website, there are different ways that your pages will be capturing information without you possibly even realising it, which include:
- User Registration — users usually should provide an email, set up a password, and give some specific information;
- Comments — users usually have to specify the name and email;
- Contact forms — users provide an email or a name;
- Analytics and traffic log systems — they collect and analyse the visitor’s behaviour;
- Various logging plugins and tools, collecting and storing the information about the activity on the resource;
- Instruments and plugins responsible for the website security – like Wordfence.
There are a number of plugins which are available already which are designed to minimise the amount of auditing that a WordPress site owner needs to do, including WP GDPR Compliance, which integrate with a number of existing plugins like Contact Form 7, Thrive Leads, Formidable Forms, and WPForms – to ensure they comply with regulations. However, you should not rely on plugins like this alone, and you should go through the following checks to make sure your site is ready for May 25th!
Steps to Comply with GDPR
Make a personal data audit
Check what personal data you collect and how you process it. Analyse whether you still need some data, what kind of data it is, where it is stored, whether third parties can access and handle it. Also, check what plugins access the personal data and make sure they don’t do something illegal. Delete the data you don’t need anymore.
Correct all the documents
They include a privacy policy, terms of service and disclaimer. Show the visitors all the details what exactly you will collect and store, how you will collect it, and where are going to store it. Tell them how they can request their data, modify it or even completely erase them.
Inform users
Tell them about any security issues that may happen to your site. It can be, for example, a data leak. The user must know what happened to their data.
Provide a legal basis for all personal information collecting and processing
Make sure that all the agreements are created according to the GDPR norms. If you are not sure, consult a lawyer.
Does it REALLY matter if I am compliant?
Implementing the GDPR can be really challenging, especially for the owners of small sites, however protecting your site will ensure that you avoid having to pay fines – the severity of which will vary depending on your company size and turnover. The new EU regulation will make the Internet safer, and give users much more confidence when using a website – as they are within their rights to ask for how the data they have submitted is processed and stored (right to access), to ask for their data to be removed (right to be forgotten), and to be able to access a download of all personal data (data portability).




