Live data from Hacker News

GDPR and automated email marketing

gdprhq.io

1–10 of 82 posts

Re: GDPR and automated email marketing

#2
> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to.

Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Re: GDPR and automated email marketing

#3

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Usually you'd save the users opt in time, and tie it back to their user account. You would need to make sure the opt in clearly explains what it's for. You would also save the context of the opt in - was it during account registration, when they visited a blog post, etc.

Obviously make sure to otherwise comply with the GDPR as you do this.

Re: GDPR and automated email marketing

#4

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

The article uses "beyond reasonable doubt" which is obviously a misapplication of the legal term of art. This being civil law, not criminal, the 50:50 proof, i. e. "preponderance of the evidence" should suffice.

In reality, I doubt there will be a practical difference to how it has been handled in the past here in Germany, where similar law has long been practice.

That means: your sign-up page needs a checkbox, that cannot be pre-checked, and that clearly states that it's an opt-in to receive these mails. This needs to be separate from any acceptance of ToS or anything else that is necessary for the transaction in question.

To verify the form submitter's identity, send a verification to their e-mail address (if you haven't already). Make sure the verification email does not already contain any advertisement itself.

Re: GDPR and automated email marketing

#5

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

The hard part here is not recording the check on the box--any email service provider will handle that. The hard part is the "full understanding." Historically lots of us have

a) been willfully unclear about what it means to subscribe to a list

b) changed what our mailings are like over time.

We can stop doing (a), with effort, but I don't see how (b) will ever go away. So this is going to be continuous, active effort with subscribers. I would like to think that very easy, reliable, one-click unsubscribe will be sufficient.

Re: GDPR and automated email marketing

#6

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Would something like a verification email asking them to double verify answer that? They click the box, then they have to open an email and click a link also verifying it?

Re: GDPR and automated email marketing

#8
As somebody who has hated spam for years, I can only wish that I were in the EU.

There is a whole swathe of companies that is somewhere between casual and negligent with email addresses, and it would be my distinct pleasure to have a stick like GDPR to beat them with.

Re: GDPR and automated email marketing

#9

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

The hard part here is not recording the check on the box--any email service provider will handle that. The hard part is the "full understanding." Historically lots of us have a) been willfully unclear about what it means to subscribe to a list b) changed what our mailings are like over time. We can stop doing (a), with effort, but I don't see how (b) will ever go away. So this is going to be continuous, active effort…

Make them take a quiz! That will help opt-in rates.

Re: GDPR and automated email marketing

#10

> Part of this opt-in verification process must include clear documented proof that the person opted in with a full understanding of what they were signing up to. Does anyone have any idea how to actually do that? How do I prove that a given user actively checked a box?

Would something like a verification email asking them to double verify answer that? They click the box, then they have to open an email and click a link also verifying it?

Yes, this is the way that is recommended the most.
Post reply on HN