1. Get a list of all personal data
To get an overview of the company's starting point in relation to GDPR, it is important to know where the company has personal data. A online store may have customer data in the online store, the customer service system, marketing lists and the like. Remember that an important part of GDPR gives consumers the right to know how their personal data are used and where it is located – then you have to be ready to respond.
- List the enterprise's systems and databases
- Find out which of these are customer data
2. Update Privacy Statement
“In don’t think the average user read full terms of service” said Mark Zuckerberg in the congressional hearing in the light of personal data scandal to FacebookSo let's say that this is the same thing as that. Many privacy statements and “terms of service” are camouflaged in highly advanced languages with difficult words. This is one of the things that the new regulation will end. Update the Privacy Statement with the correct information about how you use your personal data – in an understandable language.
Three. Denominate Privacy Agent and Set of Rules
If you process your personal data to a large extent, you should appoint a privacy representative.
A data protection representative is a dedicated person who shall ensure the safe processing of personal data and that the company complies with the law accordingly. Some of the Ombudsman's first tasks may be:
- Get a list of the company's personal data
- Establish safe practices and train the enterprise – Example: An employee sends an Excel file with the entire customer database by email, this will be an example of very risky and uncertain processing of personal data.
- Notify any data breaches – If any in the company leaks personal data, the affected persons shall be notified by the Ombudsman.
4. Allow active consent
One of the things that is crystal clear in GDPR is that the customer should be able to give active consent to marketing. This means that the customer should be able to say yes or no for marketing. It no longer keeps “return” the acceptance to the customer into the terms and automatically add them to the mailing list when they press the “registrer” button. Here is an example of good practice:

A good rule of thumb is that there should be “a pressure” with consent to be an active consent. Here it is a matter of being creative and trying out, to get as many as possible to accept that you can send them marketing.
5. Let the customer sign up for marketing
Another central part of GDPR is the right to be forgotten. Do you send out newsletters and other content to your customers? Make sure you can easily sign up and get it stopped at any time. Here are some examples of that:

Bottom of Marketing E-Mail
“Do you not want to receive SMS? Send STOP until 2031’ At the end of the marketing SMS
6. Notify customers of GDPR and your changes
The probability is high for you to have made big changes to how the company processes personal data. Notify customers of the measures – you will gain trust from your customers and show them that you take privacy seriously.
Summary
At the time of writing, it's 15 days to GDPR. If you do these 6 actions, your company is well on its way to being GDPR-compatible. Do you think GDPR is difficult and don't know exactly how to proceed? Contact us today, we have been involved in the legislation and have helped more customers to get readySo let's say that this is the same thing as that.
Good luck!
