What does the GDPR mean for your Loopia Sitebuilder website and how do you prepare?

The GDPR (General Data Protection Regulation) is a European privacy law that came into force on 25 May 2018. If your Loopia Sitebuilder website collects or stores information that can be linked to an individual, you need to comply with it – for example by getting clear consent, publishing a privacy policy and handling data requests. This article gives a general overview of GDPR compliance and the most common requirements.

The GDPR doesn’t only apply to European businesses. It covers every business that may process personal data about EU citizens, wherever the business is based and wherever it stores or processes the data.

The GDPR gives people more control over their personal data. It gives them the right to access, correct, erase and restrict the processing of their data, and sets strict requirements for user consent. You can read the full text of the GDPR to learn more.

Preparing for the GDPR

Your website collects and processes personal data in a compliant way. However, it’s your responsibility to meet the GDPR requirements when you collect and process personal data from your customers in the EU.

What counts as personal data

Personal data is any information that can be used, directly or indirectly, to identify a person. This includes names, photos, email addresses, IP addresses, bank details, social media posts, medical information, and even random codes assigned to users to collect analytics data or run A/B tests.

The GDPR significantly broadens the definition of personal data to cover any information that can be linked to a known person – for example browsing history and social media activity. There are also special rules for data about a person’s physical and mental health, such as genetic and biometric data.

Consent is the cornerstone of the GDPR. Unless there’s a legitimate interest, consent from customers must be explicit, written in plain language and clearly state what it’s for. Users need to know exactly what their personal data will be used for and by whom.

In its strictest interpretation, using an EU citizen’s personal data requires consent that is freely given, specific, informed and unambiguous. It requires an active action – it can’t be inferred from silence, pre-ticked boxes or inactivity.

Legitimate interest isn’t the same as consent, since data collected on that basis may not be used for purposes other than those the interest covers.

Once you’ve obtained consent, you must record it, keep it and be able to produce it on request.

Loopia Sitebuilder and the GDPR

Loopia Sitebuilder helps you collect user consent by providing a consent request form, adding clear consent boxes to forms, reminding you of the consequences of pre-ticked boxes, and encouraging you to update your terms.

You must obtain consent to process your customers’ personal data. Prepare a clear privacy policy stating why you collect personal data, what data is stored and how customers can withdraw their consent.

Loopia Sitebuilder gives you two free options for asking visitors’ consent to cookies on your site:

  • Setting up a CookieBot consent banner
  • Turning on the Loopia Sitebuilder cookie consent banner

Giving customers access to their data

You must be able to give customers a copy of their personal data in a readable, portable format. You can access customers’ personal data in your control panel. Also consider any third-party services you use that may have access to your customers’ personal data.

Giving customers the right to erase, edit and restrict use of their data

Basic requests (for example a customer asking you to delete their order) can be handled quickly in your control panel. Again, consider any third-party services that may have access to the data.

We recommend storing data digitally. Encrypted data protected by a strong password – or one created with a password generator – is safer than printed invoices.

Reporting a personal data breach

Your online store acts as a data processor, while you as the merchant are the data controller. If your site suffers a personal data breach, Article 33 of the GDPR requires you to report it to your national data protection authority within 72 hours of becoming aware of it. If the breach poses a high risk to the rights and freedoms of the people affected, Article 34 also requires you to inform them without undue delay. Data processors must in turn inform the data controller without undue delay after becoming aware of a breach.

Changes in your team

You may need to appoint a data protection officer (DPO) – this is required if you regularly process personal data. The DPO advises the business on GDPR compliance and acts as the main point of contact with supervisory authorities.

Train your team too. Giving everyone with access to data enough training on what the GDPR means and its consequences helps prevent incidents – a small investment in keeping staff informed is time well spent.

Key points to remember

  1. Websites need SSL/TLS certificates.
  2. Your website needs a privacy policy.
  3. Subscribers and customers must be able to have their data erased.
  4. Subscribers must also be able to request a copy of their data.
  5. Clear consent is needed if someone signs up for a free download and at the same time agrees to be added to your general mailing list.
  6. Go through your existing email list for subscribers from EU countries and ask for their consent to stay on the list – a good opportunity to resend your privacy policy too.
Was this article helpful?

Related Articles