Influencer Marketing

GDPR – The Ins and Outs

By Angelica Rojas · · 6 min read

What Is GDPR and Why Does It Matter for Your Business?

GDPR (General Data Protection Regulation) is EU legislation, in force since May 2018, that requires companies to obtain explicit consent before processing personal data and to uphold the data privacy rights of EU citizens online. It applies to all businesses operating in the EU and to non-EU organisations that process data belonging to EU citizens. Failure to comply results in significant fines.

GDPR is a binding legal framework that strengthens data privacy rights. It is not a voluntary standard or a set of best-practice guidelines. All companies that process personal information are subject to its requirements, regardless of where they are based.

GDPR is not simply an update to cookie notices — it fundamentally changes how consent is collected, how data breaches are reported, and how businesses must document their data processing activities.

How Does GDPR Work in Practice?

GDPR changes the way companies handle personal data across marketing, operations, and third-party relationships. Under GDPR, companies must appoint a Data Protection Officer (DPO) for all main data processing activities. DPOs are responsible for fostering a data protection culture within their organisation.

The regulation also makes Privacy Impact Assessments mandatory. These are tools companies use to evaluate how personal data is collected and managed. Any company that processes personal information must have these assessments in place.

For marketing specifically, GDPR requires an active opt-in from individuals before they can be contacted. Companies can no longer assume consent or automatically add visitors to email lists when they complete a web form.

GDPR Requirement What It Means for Your Business
Explicit consent Individuals must actively opt in; pre-ticked boxes are not permitted
Data Protection Officer (DPO) Must be appointed for all main data processing activities
Privacy Impact Assessments Mandatory tool for evaluating how personal data is collected
Breach notification Data breaches must be reported within 72 hours of discovery
Right to erasure Individuals can request their data be deleted; a procedure must exist
Unbundled consent Consent requests must be separate from other terms and conditions

Consent under GDPR must be obvious, unbundled, and user-friendly. The customer must understand exactly what they have consented to, with no hidden details. Companies must also inform individuals of their right to withdraw consent at any time, and consent requests must be separated from other terms and conditions.

How Do You Prepare Your Business for GDPR Compliance?

Preparing your business for GDPR starts with understanding what personal data you hold and where it came from. The steps below set out the core actions required.

  1. Conduct an information audit to assess what personal data your company holds and where it originated.
  2. Review and update all internal procedures to ensure they comply with GDPR requirements.
  3. Review all contracts with third parties to confirm they meet GDPR standards.
  4. Put a clear procedure in place to handle right-to-erasure requests from both employees and customers.
  5. Implement the right tools to detect and report data breaches within the required 72-hour window.
  6. Appoint a Data Protection Officer (DPO) to oversee compliance across the organisation.
  7. Train all key figures in the business on correct data processing procedures.

One area where businesses frequently make mistakes is in seeking consent via email. According to the ICO (Information Commissioner’s Office), sending an email to ask customers for consent is itself a marketing communication and therefore a breach of the rules. Flybe was fined £70,000 in August 2016 by the ICO for doing exactly that. Penalties under GDPR are considerably heavier, reaching up to €20 million or four per cent of a company’s global annual turnover, whichever is higher.

Key GDPR Rules on Consent

Consent is one of the most important elements of GDPR compliance. The following principles define what valid consent looks like under the regulation.

  • Consent must be freely given, specific, informed, and unambiguous.
  • An individual must take a positive, active action to opt in — silence or inactivity does not count as consent.
  • Consent requests must be clearly separated from other terms and conditions.
  • Individuals must be told they have the right to withdraw their consent at any time.
  • Companies must be able to demonstrate that consent was properly obtained.

According to the ICO, ongoing choice over how personal data is managed is central to the spirit of GDPR. This means that consent is not a one-time action — it must be an ongoing relationship between the individual and the organisation handling their data.

Frequently Asked Questions About GDPR

What does GDPR stand for?

GDPR stands for General Data Protection Regulation. It is an EU regulation that came into force in May 2018 and governs how companies must collect, store, and process the personal data of EU citizens.

Who does GDPR apply to?

GDPR applies to all businesses operating within the EU, as well as non-EU organisations that process personal data belonging to EU citizens. It covers both employees and customers whose data is handled by the organisation.

What are the fines for GDPR non-compliance?

Fines for GDPR non-compliance can reach up to €20 million or four per cent of a company’s global annual turnover, whichever figure is higher. Smaller penalties also apply for less serious infringements.

Do I need a Data Protection Officer under GDPR?

Any company that processes personal information as a main activity is required to appoint or delegate a Data Protection Officer (DPO). The DPO is responsible for overseeing data protection practices and fostering a data protection culture within the organisation.

Can I email customers to ask for their GDPR consent?

No. Sending an email to request consent is itself considered a marketing communication, which means it requires consent that you do not yet have. According to the ICO, this approach breaches the rules — Flybe was fined £70,000 by the ICO for doing exactly this before GDPR came into force.

Ready to grow your brand?

Take the first step towards improving your digital presence.

Build Your Campaign Today

Latest Influencer Marketing Articles

The Seven Step Pathway to Video Virality

The Seven Step Pathway to Video Virality

Relatability and Relevancy Popular events such as big football matches or live festivals constantly generate copious amounts of trending topics …