9
13 Comments

How do you deal with GDPR when collecting email addresses?

I have a WordPress site and would like to ask visitors to leave their emails (if they want to) so that I can notify them when I either update my products or launch new products. But how can I do that while remaining complaint with GDPR? Which plugin can I use, for example..?

GDPR is by far the most complex and ambiguous rule I have ever seen. It feels like it is designed to kill the entrepreneurship in Europe.

on February 7, 2023
  1. 4

    Indeed GDPR is shit.

    Consent checkbox and subscription confirmation email should work

    1. 1

      What will that consent checkbox mean? Logically, the person who leaves his/her email address should also be giving his/her consent to receive emails later on. Or, do you mean that the consent checkbox should also link to a Privacy Policy? If yes, what should that Privacy Policy state? How can I know for sure that my Privacy Policy will be complained with GDPR? There are services out there claiming that they are able to generate Privacy Policy that is complained with GDPR but I cannot find any example that is related to email collection and then sending emails to such people later on.

      1. 1

        I'm not an expert but my impression is that there's no possibility of 100% full compliance with GDPR.

        The answer is paying thousands of euros to lawyers so they can draft privacy policy and check the process of how you manage your data, where you store it, who has access to it and whether you have data processing agreements with them.

        Involving lawyers can only bring your compliance to 99.9% but there's still no guarantee that you will be completely safe.

        It sucks big time because to stay fully compliant you need to shell out 2-4k euros for drafting all legal documents before you can even test your product idea. In practice I had seen that not many entrepreneurs actually do so, so its a matter of who gets caught next

        I don't think these GDPR policy generators are good enough. We don't know how thoroughly they actually worked on their templates and bullet proof policy has to be tailored to your exact business process.

  2. 2

    In my opinion it's deliberately complex to protect larger companies from competition.

    Quite simply, the time and cost for a startup is huge relative to initial revenue.

    A larger company would almost rather pay for a GDPR specialist just to keep you out the market.

    1. 2

      Startups are not welcome in Europe.

  3. 1

    Don't worry about it, seriously, not in 100 years they will come after a small business.

  4. 1

    Your users are actively giving you their email address for a specific purpose, so that makes it easier (no automatic collection of personalized data).
    You need to inform your users in your privacy policy what happens with their data , where it is stored, who gets access to it and what their rights are to e.g. delete the data again. There are a lot of GDPR privacy policy generators out there who can help you with that.
    double opt-in would be nice, but it seems that isn't required by GDPR.

    Most of the email newsletter tools offer guides and tools to comply with GDPR and if you than generate a good privacy policy, you are good to go :-)

    1. 1

      Thanks for your answer.

      What you suggest makes sense. But is it based on knowledge or is it just your interpretation?

      Also, do you know any email collector WordPress plugin that is surely inline with GDPR?

      1. 1

        Making my apps GDPR compliant since the start of GDPR, so it's based on some knowledge. GDPR is interpretation btw πŸ˜‰ That's the challenging thing, that courts still in the progress of interpreting GDPR and privacy shield so it's all still in progress.
        If you can you should prefer services within the EU (because of the whole privacy shield problem), e.g. sendinblue.com
        But I think you shouldn't worry too much about it. Nail the basics with imprint and privacy policy, avoid problematic services like Google Analytics and Google Web fonts and you are good to go ;-)

        1. 1

          "avoid problematic services like Google Analytics"

          Literally one of the most used and comprehensive free web analytics tools on the market. Dropping tools with such capacities makes your product less competitive than ones built by product teams in United States or Asian markets

          1. 1

            Depends on what you need. I use Plausible and Posthog, both self-hostable and with EU-cloud option. Offers me everything I need πŸ˜‰

            1. 1

              Totally agree with you that it depends on what you need.

              However Plausible's data is insufficient for actionable data insights. Last time I checked they didn't offer sales attribution, cart analysis, retention cohort building tools etc. Such lack of information might lead you to incorrect assumptions that lose time and money

              So basically you end up seeing the traffic and where its coming from but you don't get any details on what exactly is going when people use your app

  5. 0

    GDPR is not an issue. I do recommend having a completely separate "European" email address alongside your domestic email address. Check out a tool called Mailshake to help you keep up spam compliance.

    I use Apollo for reliable data enrichment especially for overseas pipeline engagement. The platform has an awesome rolodex of global email addresses and phone numbers.

    Here is a link
    https://apollo.grsm.io/plazasource