Privacy at the heart of the data journey

26.11.2024

The data journey is the sequence of steps your customers’ data goes through, from collection to use. How can you ensure complete confidentiality and transparency throughout the process?

Data offers companies crucial added value, and a strategic framework is necessary to ensure you have a good data policy. The data journey provides just that. But efficient data protection is also essential. Since 2018, the General Data Protection Regulation (GDPR) has provided a framework for processing personal data.
 

GDPR and you

What data are we talking about?

A company can process both personal and professional data. The GDPR applies to personal data in a very broad sense: it covers all data on the basis of which you can trace the identity of an individual, even indirectly. That could be a surname, first name or email address, or technical data such as an IP address.
 

What changes did the GDPR bring?

The GDPR grants several rights. In addition to the right to protection of privacy through the security of their data, every individual also has the right to transparency. This means the explanation they must receive about how their data is processed – collection, use, retention, transfer, etc – must be clear and easy to understand. Privacy and transparency are not mutually exclusive; they complement each other. The right to transparency can be exercised through the right to access this data.

But the GDPR grants other rights, such as the right to modify your data, the right to transfer it, the right to withdraw your consent, the right to have your data erased, the right to oppose the processing of your data and the right to limit its processing.

In addition, the GDPR insists companies apply data protection by implementing appropriate technical and organisational measures. 
 

Do I have to comply with the GDPR?

It doesn’t matter if you’re a florist, accountant, event agency or scout leader: the GDPR comes into effect as soon as you process the personal data of EU residents, for purposes not limited to the private sphere. In the event of non-compliance, you risk a fine of up to 4% of your turnover. So good preparation is valuable too.
 

And in daily practice?

GDPR is always relevant. At every step of the data journey, you must ensure confidentiality and the highest level of data protection, while being as transparent as possible about how you process someone’s data.

Steps of the data journey

 

  1. Data collection. Are you collecting data to create a loyalty card, for example? Of course, your systems must be secure, but you must also inform the customer about the data you are collecting, why you are collecting it and their right to oppose the processing of their data for commercial purposes at any time.
     
  2. Transport over a secure network. This is the priority of the telecom company, but you can also secure data by transferring all data via secure solutions such as OneDrive, SFTP and S3.
     
  3. Storage. Where are you going to store the data? When asking yourself that question, remember that the data must be stored in a secure place, but also that your customer has the right to permanent access to their data. In addition, the retention period should be limited.
     
  4. Processing and analysis. Your customer must know how and for what purposes you will process their data. Those purposes must be specific and explicit. You may not use the data for purposes other than those for which it was given. Specify all those elements in detail in your privacy policy.
     
  5. Also important: if you use an analytics tool on your website, ask for permission to use cookies, but also offer the option to refuse them.

 

Fully transparent protection

The last step of the data journey is protection, which is actually present at every stage. All members of your company are involved. By properly protecting as well as informing the customer, you reassure them and create added value for your company. There are only benefits, in other words!

 
 

Want to explore this topic? Check out our webinar.

Hello, Interested
in our offer?
Welcome to
Orange Business.

Thanks for your interest in our offers, let's schedule a meeting.

Contact us

I have a question or a complaint