Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

11–20 of 82 posts

Re: GDPR and automated email marketing

#11

As someone who doesn't deal with Europe much... CASL here in Canada seems to have similar rules. Would following CASL automatically mean it follows GDPR?

The UK has had data protection laws for years, people aren't scared of GDPR because it finally provides laws, they're scared because they actually look enforceable.

Re: GDPR and automated email marketing

#12
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Sorry to break it to you, but having live both in EU, and now in the US, I still got more email spam from France.

Laws like this are broad and overreaching, but they are rarely enforced.

Re: GDPR and automated email marketing

#13

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

You can't prove it, but you can persuade a reasonable person that they probably did. You could do this by showing them your processes, the UI as the user would saw it, the code that ends up storing that in the database. Also, if your complaint rates are low, they will probably assume that the issue is not on your side.

Re: GDPR and automated email marketing

#14
I'm really curious whether or not this will have an effect and to what extent.

I have been using the last 6 months documenting all of our company's processes that handle customer interaction and data (which is basically all our processes), created flowcharts of how data moves between us, third part providers and customers as well as creating a document for each of these flowcharts that pinpoint exactly how we are complying with GDPR for every sub-process.

If for nothing else, we now have a total overview of what we do and how we do it - in an easily shareable collection of visualisations and documentational material.

Re: GDPR and automated email marketing

#15
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Sorry to break it to you, but having live both in EU, and now in the US, I still got more email spam from France. Laws like this are broad and overreaching, but they are rarely enforced.

The GDPR won't be implemented for another month and a half.

Re: GDPR and automated email marketing

#16

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Totally speculating, but "documented proof" seems to indicate that they would be satisfied by some sort of document? A screenshot would probably help? "Here is the screen where the user agreed to this" seems like it would be somewhat convincing. (If it's a screenshot then it will survive UI redesigns.)

Of course, from a security standpoint where the attacker is assumed to be totally untrustworthy, this is all nonsense since it would be trivial to fake. It does require a certain amount of trust that the company that will not stoop to faking documents.

I guess you could continue the charade by putting timestamped screenshots on a blockchain :-)

Re: GDPR and automated email marketing

#17

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Short of quizzing the user, you can't prove that they understood. But our lawyers and compliance officers seem to think it's enough to make it so that a decision not to understand is intentionally made by the user.

Like T&Cs, everybody knows that most people don't read them. Nobody's going to start quizzing their user, so what's a reasonable compromise? Forcing the user to at least scroll through some (or all) of it before agreeing. You make it clear that the intention is for you to read it, and that you're agreeing to something you should have read.

Re: GDPR and automated email marketing

#18
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Sorry to break it to you, but having live both in EU, and now in the US, I still got more email spam from France. Laws like this are broad and overreaching, but they are rarely enforced.

GDPR has much higher punishments for breaking it than previous EU privacy laws. Many companies are taking the legislation seriously due to this. I expect GDPR to be actually useful in moving the line for privacy.

Re: GDPR and automated email marketing

#19
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

The good news is there's going to be at least some echo effect here. I work for a US based company, although the vast majority of our users are in Asia. We're implementing GDPR for everyone. It won't affect the companies that exist solely to spam you much, but for most companies the technical issues of ONLY implementing this in the EU are simply too great.

So everyone will get at least some benefit. But ya, it'd be great if other governments took this as seriously.

Re: GDPR and automated email marketing

#20

Earlier quoted context omitted.

Sorry to break it to you, but having live both in EU, and now in the US, I still got more email spam from France. Laws like this are broad and overreaching, but they are rarely enforced.

The GDPR won't be implemented for another month and a half.

GDPR is active now. It has been for almost two years.

It is just now becoming enforced (with all its sanctions), after the two-year transition period.

Post reply on HN