What does the GDPR mean for your website?

01 May 2018

As of May 25, 2018, the GDPR applies in the Netherlands for the processing of personal data. The GDPR also applies to all companies and organizations that collect, process, and use personal data.

What does the GDPR mean for your website?

Thanks to this regulation, uniform personal data protection is created within the EU. The main goal is that the privacy rights of individuals are respected. This also applies to people visiting your website. What can you do yourself?

AVG = Algemene Verordening Gegevensbescherming
GDPR = General Data Protection Regulation is the English name for the AVG.

 

7 points you definitely need to think about from May 25, 2018


1. Privacy Statement
Put a clear privacy statement on your website. State what personal data is stored and processed via the website, what you are going to do with it, and which parties have access to this data (you become a data processor very quickly, even if you just store data from a contact form).

2. SSL Certificate
You will soon be obliged to ensure optimal protection of personal data. If forms, orders, or (newsletter) registrations are filled in via the site, an SSL certificate (HTTPS) is mandatory. Read more about SSL. But even if you don't use forms, SSL is recommended to secure all traffic via the website.

3. (Input) forms
You may only ask for the visitor data that you actually need. If you want more data, you must explicitly state what you are going to do with it. Also note that you should no longer pre-check boxes; the visitor must do this actively themselves.

4. Store personal data securely!
Make sure you know where the data is located, as you are responsible for this data. Don't know where your data is stored? Then contact us to clear this up, because if you have been negligent, you will get very high fines! Do not keep the data longer than necessary.

5. Google Analytics
You can use Google Analytics, but only if you set it up correctly. You are obliged to enter into a processor agreement with Google. Google is a data processor whom you give permission to process the personal data of your company and visitors (every computer has an IP address, which is personal data. You may only use the IP address if you have informed the visitors in advance).

6. Website administrators (CMS users)
Everyone who has access to the CMS must have a valid reason, and this must be recorded separately so that it is clearly visible why this person has access to personal data. Unnecessary accounts must be deleted.

7. Management and security
You are responsible for the security of your website! It is important that you use the latest technologies to ensure that the chance of hacking and leaks is minimal.

 

Updates, patches, and backups are important!

Find a good internet partner who has web hosting well organized. There are many "underwater" entrances that you as a "non-system administrator" are often unaware of, which means you may unknowingly not comply with the law. Multimove and Infracom are ready for you!

Share page: