Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

51–60 of 82 posts

Re: GDPR and automated email marketing

#51
VERIFIED OPT-IN parts opens up beautiful opportunity to destroy your competitor for $5.

1. Open DigitalOcean hosting for $5. With prepaid card they will let you do it, however port 25 will be blocked.

2. You don't need port 25 anyways. Download few lists of emails from online search and setup php_curl every 30 seconds to your competitor's landing page subscription ajax call.

3. Wait few months for them being slammed with $4MM fines as there will be unable to prove how they got that traffic in the first place :)

Re: GDPR and automated email marketing

#52
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Spammers don’t tend to operate from first-world jurisdictions. (When they do, CAN-SPAM is decent about requiring working unsubscribe buttons). Spam is not a problem you can solve with regulation.

If the spammers are pushing some product that is sold online or sold in the "first world," they certainly could be attacked with regulation.

Re: GDPR and automated email marketing

#53
This is a frustrating article.

The regulation in GDPR is not new! It's a refinement of long existing law (in England this is the DPA, and PECR).

If it's illegal under GDPR it was probably already illegal under PECR.

All this stuff about "ZOMG we need informed consent before we send email"? You already need that.

Re: GDPR and automated email marketing

#54

Earlier quoted context omitted.

Today, I requested assistance from the authority for the first time. And I’m eager to see how my request will be handled. Do you have any suggestion? You seem pretty accustomed to it.

Which authority specifically? My experience is with two Portuguese regulators (one of Data Protection, other of Telecommunications). The first was pretty good, the second required a bit of insistence to prevent them from closing the matter after the company sent a reply that said nothing, but both worked out with nothing more than a few emails.

With the Italian Data Protection authority. http://gpdp.it

I wanted to know if emails are enough, but you already answered that. I'll need to test how numerically "a few" is.

My fear is that the process will take too much effort, it would be useless if rules were not enforced.

Re: GDPR and automated email marketing

#55

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

This regulation is aimed at stopping the hidden checkbox, or the hidden clause in a ToS.

All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted.

Things like proper confirmed opt-in help.

Re: GDPR and automated email marketing

#56

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Would something like a verification email asking them to double verify answer that? They click the box, then they have to open an email and click a link also verifying it?

But is that sufficient under GDPR? Although a double opt-in has generally been considered good practice for a long time, it only demonstrates that a recipient has agreed to receive mail for some purpose, not for any specific purpose.

Even if you've been building up your mailing list for years, following generally accepted good practices, and only signing up genuinely interested recipients, it seems you could now to be in a position where either:

(a) when you signed people up, you provided sufficient information about what you would be sending to them and you can still produce evidence of that today;

(b) you need to contact everyone on your list to obtain explicit, specific consent for whatever you actually send to your list; or

(c) you have to remove anyone who isn't covered by (a) or (b) above (or delete your whole list).

As with so much about the GDPR, what will be accepted as reasonable evidence of informed consent for earlier subscribers to a mailing list is ambiguous, and the consequences of either doing too much or not doing enough are undesirable.

Re: GDPR and automated email marketing

#57
Unclear regulation? I am encountering this over and over again. Lets clear the unclearity...

If you have my data, you will handle them in same manner as you would handle yours. You are not selling yours to get higher prices when buying something online? You are not selling your email account to spammers to get a lot of worthless emails to your email account each day? ... Now you wont do it withy my data either. It is so simple, you don't need any clarification. No special law or directive, no studying of GDPR... it just works. Oh you want me to receive unsolicited emails for your profit? You want me to get tracked? ... I will personally take care you will get a punishment and/or sue you personally.

What is so complicated here? Act in best interest of you customers, regarding the personal data, and you are safe, over whole EU. I don't understand what is the problem unless you are NOT ACTING IN THEIR BEST INTEREST, then it becomes vague (you need a way to circumvent GDPR, but you can't as it is not an IRS list but a conceptual law). Anyone having a problem with GDPR already knows the answer that solves the "problem". But wants to continue his habits.

Just state your problem and I will answer to you with advice where you wont get punished for breaking GDPR, just ask. But you wont, right? You know the answer, but you need a way to avoid it. Wont work.

Re: GDPR and automated email marketing

#58
post #55

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

This regulation is aimed at stopping the hidden checkbox, or the hidden clause in a ToS. All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted. Things like proper confirmed opt-in help.

All you have to do to comply with it is be clear and direct when collecting personal data, and make a record of the permission granted.

It appears that you also need to have been all of those things, as far back as you've been collecting personal data, even if no such requirements existed at the time. Organisations might not be in that position even if they followed accepted good practices when signing people up to their lists, so the GDPR may have unintended consequences here.

Re: GDPR and automated email marketing

#59
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Spammers don’t tend to operate from first-world jurisdictions. (When they do, CAN-SPAM is decent about requiring working unsubscribe buttons). Spam is not a problem you can solve with regulation.

Oh, I wouldn't expect it to solve the spam problem. But as I said, there are a lot of US-based companies that are at best sloppy with address management. Those are also the ones most likely to make it past my existing filters, because they are semi-legitimate. Being able to turn up the heat on them would be a pleasure.

Re: GDPR and automated email marketing

#60
post #8

As somebody who has hated spam for years, I can only wish that I were in the EU. There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Spammers don’t tend to operate from first-world jurisdictions. (When they do, CAN-SPAM is decent about requiring working unsubscribe buttons). Spam is not a problem you can solve with regulation.

There are 2 kinds of spam:

* Nigerian scam type spam

* ads/commercial spam

The first is already illegal, and yes, it's difficult to fight and comes from first world jurisdictions.

But the second is operated by well known companies, most of the time through well known service providers (Salesforce, Adobe...). And these companies do put a lot of personal information in their databases (what did you buy, did you click on a specific link, did you open a specific email, etc).

Post reply on HN