Hi guys, i will be publishing a page that is needed to let users contact us with requests about specific information they are looking for. The idea is to use social authentication (via Firebase) to get their email and send us a mail telling something like "User X wants info about Y", as well as another one confirming him we have received the his request.
We will be not storing any information but definitely we will be using their email.
How does GDPR deals with this ? And how should we do as well?
Thanks!
Hi there Bruno, I'm partially copy-pasting from another thread that received the same information.
First of all, what one of the answers before me means to say is: check the ICO (https://ico.org.uk/ not co.co.uk). They're an absolutely excellent resource, to be more precise, they're the UK privacy authority.
Then, forget any generator that doesn't explicitly work under GDPR assumptions as another answer in here suggests, as the GDPR has completely changed the game and you're specifically asking about the GDPR.
So what to do? Here's the basis as it's explained by the British privacy authority, it's definitely helpful if you want to roll your own, or at least understand what's supposed to be inside a privacy policy: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed/ - check the great table.
At the contact form you'll add the privacy policy with an opt-in (pre-checked), if you collect this email also for a newsletter use a double opt-in and tell the user about the newsletter.
Those are the basics.
I'm also going to plug what I'm working on daily: privacy policies at https://www.iubenda.com - it is my job to keep the GDPR and other developments firmly in focus :) Hope this helps!
Thanks a lot ! It's all really appreciated ! I'll give a look at this laters.
Most of the time an email can uniquely identify a person. This means that its enough for it to fall under GDPR's definition of personal data.
First of all you should make sure you have a Privacy Policy available somewhere on your page. This should detail at a minimum who you are as an organisation and how somebody will be able to contact you in case of any issues with their personal data. The policy should explain why you are collecting your users' personal data, what personal data you are collecting( e.g. email, name, age,etc), how you are going to use it and if yoi are going to share it with any third parties (i.e. Google Analytics, Facebook pixel, etc) Be aware that if you are using things like Analytics or any other 3rd party tools on your website you are collecting more data than you think you are so check with those peoviders to make sure you understand what data they get from your users. The privacy policy should be transparent and honest. If you are going to use data in any way make sure users understand everithing about that. If you plan to market users make sure you get their consent.
There are a lot of resources for gdpr on www.co.co.uk.
Also there are a lot of GDPR privacy policy generators available online. Just google it.
Hope this helps!
I love IH community 😉
Well, i will have Google Analytics for sure, I won't be marketing users, and i don't explicitly save anything about the user in terms of cookies or other stuff. The page will not even be for authenticated users, just need a way to communicate with them.
The initial idea was to store users and their data, but i changed the architecture exactly because i don't need it and won't to minimize the GDPR impact.
Thanks for your answer.
This comment was deleted 8 years ago
Thanks !!