Blog » 5 TIPS TO OPERATE A GDPR-COMPLIANT E-SHOP IN HUNGARY
5 TIPS TO OPERATE A GDPR-COMPLIANT E-SHOP IN HUNGARY
26 February 2018
Do you operate a small e-shop and think that GDPR and data protection concerns only giants like Amazon? Let’s just face it: you could not be more wrong. Think of the mere fact that your customers are private persons and you process at least their name, e-mail address and address. Before totally panicking from the realisation that GDPR applies to your e-shop, too, take a deep breath and read our 5 tips how your e-shop can be GDPR-compliant.
Among others you shall inform your customers for which purpose you process their data, who will possibly receive this data, how long you retain the data and what are their rights in relation with your processing activity.
2. Do you send newsletters?
Do you send newsletter to your customers? Excellent marketing tool but bear in mind that there are only few things that can annoy your customers more than unwanted messages. And we all know that pissed-off customers tend to make complaints before the Data Protection Authority.
Therefore, always ensure that your newsletter addressee list is up-to-date. If you rely on the customer’s consent (subscription) make sure that it is freely given, so please forget the pre-checked consent boxes.
Also, you have to provide the possibility to your customer to withdraw his consent to receiving newsletters from you, for example by having an “unsubscribe” button.
3. Do you use profiling?
Do you send 10 % discount offer to your customer for premium coffee if he ordered a coffee machine 2 weeks ago? Or do you send an e-mail reminder to the customer that he added some products the cart but has not bought them? How nice of you. But do not forget that this is called profiling and you have to inform your customers about it.
You also need to inform your customer about the basic logic of such profiling based on automated decision-making and its consequences. To return to the first example you have to clearly tell your customer that you will send customized offers to him based on his last orders.
Your customer may always object to the processing of his personal data for profiling for direct marketing purposes and you have to inform them about this possibility.
4. Do you have subcontractors?
Do you ship the purchased products to the customers’ home? This is exactly one of the benefits of an e-shop. Nevertheless, you have to remember that you transfer your customers’ certain personal data to the haulier who delivers the goods.
The haulier in this context will be considered as a data processor and you as a data controller have to conclude a precise contract with him dealing with certain specialities of the data processing.
Same applies for your IT service provider, your external accountant or direct marketing agency, in short for every third party who processes the personal data of your customers in accordance with your instructions.
5. Do you record phone calls?
Do you operate a customer helpdesk with a hotline number that customers can call? It is very customer-friendly but remember that if you record the calls this will have GDPR-related consequences.
Indeed, people often forget that the voice is also considered as personal data and for the processing the same rules shall apply when you would process the data subject name, birth date or address.
Thus, for instance, before starting to record the call, you clearly have to inform your customer that his call will be recorded and what is the purpose of the recording. Such meaningless information like ‘we record the call for quality assurance reasons’ won’t be precise enough under the GDPR.
To sum up to above, even if you only operate a small e-shop you will face several GDPR-related questions. Achieving GDPR-compliance is not rocket science but as you can see certain things simply cannot be ignored and you have to deal with them until May 2018.
LAWFUL DISMISSAL IN HUNGARY - PART VI: TERMINATION WITHOUT NOTICE
In the last two articles of our series on “lawful dismissal” we present the most severe sanction that can be applied to an employee, the immediate (formerly: extraordinary) termination. This measure is applied in serious incidents only, so many employers believe that they will not need to use the sanction. But, as we know, the devil does not sleep and it is in the details, so the employer needs to be prepared for this scenario as well to avoid further inconvenience.Read more »
5 CURRENT GDPR-FINES ACROSS EUROPE – LEARN FROM OTHERS’ MISTAKES
The supervisory authorities in Europe controlling compliance with the GDPR have not sat on their hands in the last couple of months. In this short article we collected five interesting cases from the recent past. The wide discretionary powers of the data protection authority is well illustrated by the fact that sometimes the GDPR fine was only EUR 2000, but in another case a company has been fined for EUR 11,5 Million! Continue reading if you would like to avoid the same or similar expensive errors.Read more »
LAWFUL DISMISSAL IN HUNGARY - PART V: PROTECTION AGAINST DISMISSAL
In the previous articles on the lawful dismissal, we discussed that, ranging from the employee’s behaviour to the employer’s reorganization, there can be many legitimate reasons for dismissal by the employer. However, irrespective of the legitimate reason, the employment relationship cannot be terminated if the employee is protected against dismissal by law (i.e. the Labour Code). From our article, you can learn about these protections.Read more »