{"id":1235,"date":"2018-05-23T11:30:39","date_gmt":"2018-05-23T11:30:39","guid":{"rendered":"http:\/\/wishloop.com\/blog\/?p=1235"},"modified":"2021-09-01T09:48:00","modified_gmt":"2021-09-01T09:48:00","slug":"wishloop-and-gdpr","status":"publish","type":"post","link":"https:\/\/wishloop.com\/blog\/wishloop-and-gdpr\/","title":{"rendered":"Wishloop and the GDPR"},"content":{"rendered":"\n<p>To those that have been living under a rock for the past year, the <a href=\"http:\/\/www.eugdpr.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR<\/a> is Europe\u2019s new privacy law that regulates the processing of personal data relating to individuals in the European Union.<\/p>\n\n\n\n<p>It is designed to ensure that people understand what personal data we collect and how we use it \u2013 and gives them greater control over that use.<\/p>\n\n\n\n<p>While we are currently working to implement specific GDPR requirements before enforcement begins on May 25, 2018, we&#8217;d like to remind our users that we already build privacy into everything we do and will continue to do so under GDPR.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>What does GDPR entail?<\/h2>\n\n\n\n<p>Depending on who you speak to, you may get answers ranging from mild annoyance at having to comply with yet more regulations, to various expletives and even to &#8220;the end of marketing as we know it&#8221;.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" width=\"450\" height=\"253\" src=\"http:\/\/wishloop.com\/blogtest\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-argh.gif\" alt=\"\" class=\"wp-image-1264\"\/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Whatever the reply, its fair to say that GDPR has many website owners in a state of panic.<\/p>\n\n\n\n<p>There\u2019s been a lot of talk hefty fines awaiting those who fail to comply with the regulations.<\/p>\n\n\n\n<p>And over the past few weeks my inbox has been overflowing with privacy policy updates, requests to (re)consent to the use of my data and a fair share of general GDPR doom and gloom.<\/p>\n\n\n\n<p>In addition to this, our support desk has been inundated with queries about what we&#8217;re doing to make Wishloop&#8217;s optin forms GDPR compliant.<\/p>\n\n\n\n<p>Judging by the wording of these requests, most people are either:<\/p>\n\n\n\n<p>a) confused about what they actually should be doing in the face of GDPR<br>b) misinformed about what compliance entails<\/p>\n\n\n\n<p>Having surveyed hundreds of posts on the subject and the regulations themselves, its no wonder why.<\/p>\n\n\n\n<p>The regulations themselves are characteristically vague, no concrete case history is yet available and businesses are generally doing their best to interpret and respond to the regulations in varying different ways.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>Wishloop and the GDPR<\/h2>\n\n\n\n<p>In this post, we\u2019ll take a closer look at what GDPR actually means for small business entrepreneurs and email marketers.<\/p>\n\n\n\n<p>And you\u2019ll discover ways in which you can&nbsp;<strong>make your website and Wishloop campaigns compliant without sacrificing your conversion rates or your&nbsp;visitors\u2019 user experience<\/strong><\/p>\n\n\n\n<p><em><em>Disclaimer: I\u2019m not a lawyer and this post does not contain legal advice.&nbsp; Always work with your legal advisors to help you make the right decisions in relation to any regulations.<\/em><\/em><\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>Good News &#8211; The EU isn\u2019t After You!<\/h2>\n\n\n\n<p>Contrary to what some commentators may have you believe, the EU isn&#8217;t armed with an army of lawyers, gladly rubbing their hands together at the prospect of inflicting hundreds of thousands of massive fines upon unsuspecting small businesses as soon as the regulations come into effect.<\/p>\n\n\n\n<p><em>On this point its a useful reminder to always be mindful of the intentions behind what is written &#8211; some of the most incendiary content I&#8217;ve reviewed was written by so-called experts who have sprung up overnight to help small businesses through the &#8220;nightmare&#8221; of EU compliance.<\/em><\/p>\n\n\n\n<p><em>Of course, we live in a world where fake news often has more power to provoke reaction (and drive sales) than reality!<\/em><\/p>\n\n\n\n<p>The GDPR is about the processing of people\u2019s private data online and primarily aims to regulate businesses that do a lot of data processing &#8211; and especially businesses that make their money from selling or \u201cexploiting\u201d the data they collect about people.<\/p>\n\n\n\n<p>Think: data harvesting giants like Google or Facebook (Facebook&#8217;s recent scandal with Cambridge Analytica is a good example of the kind of misuse of data that the GDPR seeks to prevent)<\/p>\n\n\n\n<p>For the average Wishloop customer or small business owner at large, you&#8217;re unlikely to do any significant amount of data processing.&nbsp; If you have a website with some opt-in forms on it, the EU isn\u2019t coming straight for your jugular.<\/p>\n\n\n\n<p>To summarise, as a small business entrepreneur,&nbsp;<strong>you are not the GDPR\u2019s main target.<\/strong><\/p>\n\n\n\n<p>And on the point of &#8220;massive fines for non-compliance&#8221;, the UK&#8217;s Information Commissioner, Elizabeth Denham, has publicly stated that fines will always be a &#8220;<a href=\"http:\/\/iconewsblog.org.uk\/2017\/08\/09\/gdpr-sorting-the-fact-from-the-fiction\/\" target=\"_blank\" rel=\"noopener noreferrer\">last resort<\/a>&#8221; action, explaining that &#8220;Predictions of massive fines under the GDPR that simply scale up penalties we\u2019ve issued under the Data Protection Act are nonsense&#8221;.<\/p>\n\n\n\n<p>In practice, the expected process for non-compliant websites looks something like this:<\/p>\n\n\n\n<ol><li>Your users\/visitors take up the issue with you directly.&nbsp; For example, a user might ask you (the website owner) to see, change or remove their private data.<\/li><li>If you can\u2019t comply with that, the user can escalate this to a complaint, which would lead to a multi-step process by an EU data regulation agency, starting with an \u201cinformation notice\u201d.<\/li><li>Only if you are still not compliant after having received various notices and warnings will fines come into play.<\/li><\/ol>\n\n\n\n<p>In short: there\u2019s no reason to believe you\u2019ll face immediate punishment for a missing link to your privacy policy or a poorly worded optin form.<\/p>\n\n\n\n<p>That said, there&#8217;s never been a better time to put your house in order, update your privacy policy and, if applicable, amend you terms of service so they&#8217;re bang up to date.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>So what action should you take?<\/h2>\n\n\n\n<p>Hopefully you&#8217;re now a bit less worried about GDPR compliance than you may have been previously.&nbsp; Take a moment to smile again and breathe a sigh of relief.<\/p>\n\n\n\n<div class=\"wp-block-image aligncenter\"><figure class=\"aligncenter\"><img loading=\"lazy\" width=\"290\" height=\"226\" src=\"http:\/\/wishloop.com\/blogtest\/wp-content\/uploads\/sites\/6\/2018\/05\/relief.gif\" alt=\"\" class=\"wp-image-1256\"\/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>However that doesn&#8217;t mean you can simply ignore the regulations.<\/p>\n\n\n\n<p>Even as a small business you&#8217;re undoubtedly processing data in some ways.<\/p>\n\n\n\n<p>In their interactions with your business, your prospect and customers are sharing data with you and protecting people&#8217;s data and their privacy is important.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>GDPR and Email Marketing<\/h2>\n\n\n\n<p>GDPR isn\u2019t primarily about email marketing (which actually falls under separate Privacy and Eectronic Communications Regulations or <a href=\"http:\/\/ico.org.uk\/for-organisations\/guide-to-pecr\/what-are-pecr\/\" target=\"_blank\" rel=\"noopener noreferrer\">PECR<\/a>).<\/p>\n\n\n\n<p>However GDPR does change the meaning of the concept of consent and user rights which is then expanded upon by PECR.<\/p>\n\n\n\n<p>It\u2019s about how people\u2019s personal data is handled and email marketing contains such data (e.g. someone\u2019s email address).<\/p>\n\n\n\n<p>The main rights given to EU citizens under the regulation are as follows:<\/p>\n\n\n\n<ol><li class=\" class=\"><strong>The \u201ctell me what\u2019s going to happen\u201d right:<\/strong>&nbsp;Tell people what you will do with their email address&nbsp;<em>before<\/em>&nbsp;they sign up.<\/li><li class=\" class=\"><strong>The \u201cshow me my data\u201d right:<\/strong> Give people a view of the data you\u2019ve collected about them (probably only their name and email address).<\/li><li class=\" class=\"><strong>The \u201cI want to change that\u201d right:<\/strong> Give people a way to modify their data (e.g. get the emails sent to a different address) and unsubscribe.<\/li><li class=\" class=\"><strong>The \u201cforget about me\u201d right:<\/strong>&nbsp;Allow people to completely remove all data you have about them, if they request it.<\/li><\/ol>\n\n\n\n<p>As we&#8217;ll see below, for Wishloop customers we&#8217;re involved only with item 1 above.&nbsp; This is principally about making it possible for you to acquire the full consent from your subscribers and informing your visitors what will happen with personal data before it is submitted.&nbsp; Only by providing full disclosure of what kind of emails someone will receive if they opt into your form, can they give the proper consent for it.<\/p>\n\n\n\n<p>Unfortunately, in terms of its relation to email marketing, most \u201chow to be GDPR compliant\u201d content seems to suggest that you have to add multiple checkboxes, disclaimers and extra steps all over your website.<\/p>\n\n\n\n<div class=\"wp-block-image aligncenter\"><figure class=\"aligncenter\"><img loading=\"lazy\" width=\"346\" height=\"314\" src=\"http:\/\/wishloop.com\/blogtest\/wp-content\/uploads\/sites\/6\/2018\/05\/horrified.gif\" alt=\"\" class=\"wp-image-1261\"\/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Thankfully, while this is one way of addressing GDPR, its&nbsp;<strong>not the only way<\/strong>, and seldom is it the way that&#8217;s likely to impact least on your all important conversion rates.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"class=\">The Checkbox Myth<\/h2>\n\n\n\n<p>So how do you make your opt-in forms GDPR compliant?<\/p>\n\n\n\n<p>Well judging by the support tickets we&#8217;ve received and much of the literature online I think 90% of marketers would answer:&nbsp;<em>\u201cby adding checkboxes!\u201d<\/em><\/p>\n\n\n\n<p>I don\u2019t know where this idea came from, but&nbsp;<strong>GDPR doesn\u2019t mean adding checkboxes.<\/strong><\/p>\n\n\n\n<p>Yes, you need the subscriber\u2019s explicit consent to send them emails, but a checkbox is not the only way (and definitely not the best way) to get this consent.<\/p>\n\n\n\n<p>Think about it, nobody likes to read small print, and that&#8217;s what your typical checkbox amounts to.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" width=\"1024\" height=\"903\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/GDPR-Landing-Page-Example.png\" alt=\"\" class=\"wp-image-1242\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/GDPR-Landing-Page-Example.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/GDPR-Landing-Page-Example-300x265.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/GDPR-Landing-Page-Example-768x677.png 768w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/GDPR-Landing-Page-Example-20x18.png 20w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Yuck!<\/figcaption><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>As you know, at Wishloop we&#8217;ve put a lot of emphasis on conversion optimisation.<\/p>\n\n\n\n<p>We&#8217;ve made it easy for you to split test email signup forms so the last thing we (and you) want is to have to throw those high converting signup forms out of the window by covering them in checkboxes and disclaimers.<\/p>\n\n\n\n<p>That&#8217;s bad for you, bad for the customer and even bad for the EU (where they take a share of your profits in the form of value added tax).<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>What other options are there then?<\/h2>\n\n\n\n<p>There are two approaches you can use to make your opt-in forms GDPR compliant without adding checkboxes or extra hoops for your visitors to jump through:<\/p>\n\n\n\n<ol><li>Change the copy in your opt-in forms<\/li><li>Change from single to double optin<\/li><\/ol>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3>Fix 1: Change the Copy<\/h3>\n\n\n\n<p>Let\u2019s look at an example of a typical opt-in form, pre-GDPR:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" width=\"1024\" height=\"769\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/non-gdpr-compliant.png\" alt=\"\" class=\"wp-image-1249\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/non-gdpr-compliant.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/non-gdpr-compliant-300x225.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/non-gdpr-compliant-768x577.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>If someone signs up through this form and you then start sending them emails,&nbsp;<strong>that\u2019s not GDPR compliant.<\/strong><\/p>\n\n\n\n<p>Why not?<\/p>\n\n\n\n<p>Because&nbsp;<strong>there was no indication in this form that you\u2019d be sending emails<\/strong>&nbsp;(and visitors can\u2019t consent to something you haven\u2019t told them about).<\/p>\n\n\n\n<p>The entire form is about getting a 30% discount for today only.&nbsp; The visitor who signs up agrees to receiving a discount, but nothing else.<\/p>\n\n\n\n<p>Here\u2019s what the form could look like, with modified copy:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" width=\"1024\" height=\"767\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliant-1.png\" alt=\"\" class=\"wp-image-1266\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliant-1.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliant-1-300x225.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliant-1-768x575.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Here\u2019s exactly what we changed, to make this form GDPR compliant:<\/p>\n\n\n\n<ul><li class=\"\">We are still providing a 30% discount.&nbsp; However, instead of the discount and the newsletter being totally separate,&nbsp;<strong>the \u201cmain action\u201d on the form is signing up for the newsletter&nbsp;<\/strong>and getting the discount is a bonus provided to newsletter subscribers.&nbsp; This means the user is giving consent to subscribing to a newsletter<\/li><li>We add&nbsp;<strong>\u201cSubscribe to save\u2026\u201d<\/strong>&nbsp;to the button copy.&nbsp; This way, it\u2019s clear that the user is consenting to a newsletter by signing up.<\/li><li class=\"\">We\u2019ve added a link to our privacy policy below the form.<\/li><\/ul>\n\n\n\n<p>As you&#8217;ll see, not a checkbox in sight, yet its still allowing the subscriber to consent to receiving daily emails from you and giving the link to your privacy policy where you should make them aware of how you will treat their data, and how they can view, edit or request to be forgotten.<\/p>\n\n\n\n<p>As you&#8217;ll see in a moment we&#8217;ve made it really easy to add this extra link to your existing Wishloop forms.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>So what does GDPR mean for Wishloop?<\/h2>\n\n\n\n<p>We&#8217;re reviewing our procedures and investing in our infrastructure to help you take advantage of the changes under GDPR.<\/p>\n\n\n\n<p>Our approach to GDPR breaks into two sections:<\/p>\n\n\n\n<ol><li>What we&#8217;re doing as a company to make sure that we&#8217;re GDPR compliant<\/li><li>What we&#8217;re doing to ensure that our customers are GDPR compliant when using Wishloop<\/li><\/ol>\n\n\n\n<p>Lets start with the first point:<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3>What we&#8217;re doing as a company to make sure that we&#8217;re GDPR compliant<\/h3>\n\n\n\n<p>If you&#8217;re in the EU you will be able to:<\/p>\n\n\n\n<ul><li>Ask for a copy of the personal data we\u2019ve collected about you.<\/li><li>Request that we stop sending you direct marketing messages.<\/li><li>Ask that we stop using your personal data for certain purposes.<\/li><li>Ask that we amend or delete your personal data.<\/li><li>If we ask for consent to process your personal data, you can later withdraw your consent (please note that in some cases this may mean that we are unable to continue providing you with our software service)<\/li><\/ul>\n\n\n\n<p>To help comply with these new demands we&#8217;ve appointed a Data Protection Officer (that&#8217;s myself!) to handle any related data and privacy requests.<\/p>\n\n\n\n<p>We&#8217;ve also made some small adjustments to our <a href=\"http:\/\/wishloop.com\/terms\" target=\"_blank\" rel=\"noopener noreferrer\"><em><strong>Terms of Service<\/strong><\/em><\/a> and <em><strong><a href=\"http:\/\/wishloop.com\/privacy\/\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy Policy<\/a><\/strong><\/em>&nbsp;and added a new <a href=\"http:\/\/wishloop.com\/wishloop-data-protection-goals.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Data Protection Goals<\/strong><\/a> document.<\/p>\n\n\n\n<p>Finally we&#8217;ve completed an exhaustive review of our data processing practices and policies and prepared a <a href=\"http:\/\/wishloop.com\/wishloop-data-protection-activities.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em><strong>Statement of Data Processing Activities<\/strong><\/em><\/a>.<\/p>\n\n\n\n<p>This document contains a list of all our data processing activities, the data being processed, a clear explanation of why we process this data, the legal basis for the processing activity and the names and addresses of any third party services we use to process the data.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3>What we&#8217;re doing to ensure that our customers are GDPR compliant when using Wishloop<\/h3>\n\n\n\n<p>If you&#8217;re reading this post then this is the part you&#8217;re most likely interested in.<\/p>\n\n\n\n<p>The first thing to note is that, apart from an important distinction mentioned below, we don&#8217;t actually store personally identifying information about <em>your<\/em> customers.<\/p>\n\n\n\n<p>When you collect personal information e.g. name and email address using a Wishloop optin form <strong>we don&#8217;t store that information for more than a few seconds<\/strong>.<\/p>\n\n\n\n<ul><li>Where your webforms use the API method of integration we store the user data only <em>temporarily<\/em> whilst it is safely passed directly to one of our integration partners (e.g. Mailchimp or Active Campaign) over a secure connection.&nbsp; This typically happens in the time it takes to redirect the user to your thank you page.&nbsp; As soon as the integration partner responds that they have received the data, it is deleted from our system.<\/li><li>And where your webform is using a HTML form integration, that information never actually touches our servers, it is passed straight to the integration partner.<\/li><\/ul>\n\n\n\n<p>When we do collect information it is only to enable the correct display or functionality of your campaigns.<\/p>\n\n\n\n<ul><li>For example we use different cookies to help determine if a user is a new or a returning visitor or if they have viewed any specific campaign in the last X days.<\/li><li>We also use cookies to ensure the correct functioning of our evergreen countdown widget or to enable conversion tracking and to ensure your users don&#8217;t keep seeing the same form if they have already opted in to it.<\/li><\/ul>\n\n\n\n<p>As such, the burden of complying with regulations around allowing a user to view or change the data you&#8217;ve collected on them or their right to be forgotten (items 2-4 in the list above) doesn&#8217;t lie with us, but instead with your autoresponder or similar integration partner.<\/p>\n\n\n\n<p>In short, this makes compliance for us relatively straightforward as we haven&#8217;t needed to build too much extra functionality.&nbsp; (And fortunately most users are familiar with how to clear cookies from their browsers)<\/p>\n\n\n\n<p>So the main area where we do have a responsibility relates only to the area of&nbsp;<strong>telling users what\u2019s going to happen after their data is collected, or more generally around acquiring consent.<\/strong><\/p>\n\n\n\n<p>There is however one exception to this and its a feature of Wishloop that we&#8217;re going to simply discontinue.<\/p>\n\n\n\n<p>Lets move on to discuss each change we&#8217;re making in turn:<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>1. Discontinue our internal lead storage function. <\/h2>\n\n\n\n<p>We currently provide a little-used function to store your customer&#8217;s personal details within Wishloop&#8217;s Internal Database.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" width=\"528\" height=\"526\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage.png\" alt=\"\" class=\"wp-image-1268\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage.png 528w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage-300x300.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage-150x150.png 150w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage-80x80.png 80w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage-70x70.png 70w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/local-storage-100x100.png 100w\" sizes=\"(max-width: 528px) 100vw, 528px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>As GDPR means that providing this feature entails extra layers of compliance on our part (again, I&#8217;m referring to items 2-4 listed above), and based on the fact that this feature is barely used by anyone, we have simply taken the decision to discontinue this function.<\/p>\n\n\n\n<p>If you are using the Internal Database storage then you should export your leads from there before the 25th May using the yellow button on the campaigns table:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" width=\"1024\" height=\"168\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/internal-db.png\" alt=\"\" class=\"wp-image-1269\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/internal-db.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/internal-db-300x49.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/internal-db-768x126.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>2. Adding an option to enable GDPR\/privacy consent checkboxes<\/h2>\n\n\n\n<p>Remember I said above that a checkbox is almost always not the best corrective action you can make to a non-compliant form.<\/p>\n\n\n\n<p>Well&#8230; I still hold that this is true.<\/p>\n\n\n\n<p>Nevertheless there are some use cases where a checkbox can be useful, e.g.:<\/p>\n\n\n\n<ul><li>to allow additional copy to be added to a form without substantively altering its design,<\/li><li>or where you may want to be able to collect additional permissions without changing the copy.<\/li><\/ul>\n\n\n\n<p>You could use it like this for example:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" width=\"1024\" height=\"767\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-over-compliant.png\" alt=\"\" class=\"wp-image-1251\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-over-compliant.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-over-compliant-300x225.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-over-compliant-768x575.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Naturally, there will also always be those people who don&#8217;t read this post and think that a checkbox is the only way to stay compliant.<\/p>\n\n\n\n<p>We can only do so much to educate people, but the checkbox will be available for you to make use of as you see fit.<\/p>\n\n\n\n<p>It will be easy to add checkboxes to your existing forms (provided you&#8217;re using an up to date template), simply open the campaign in the Wishloop builder and edit the form settings as shown in the right settings panel here:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" width=\"1024\" height=\"525\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-settings.png\" alt=\"\" class=\"wp-image-1252\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-settings.png 1024w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-settings-300x154.png 300w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-settings-768x394.png 768w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-settings-370x190.png 370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>3. Re-agreeing to our Terms of Service and Privacy Policy<\/h2>\n\n\n\n<p>When you next log in to Wishloop you will also be asked to accept our updated terms of service and privacy policy.<\/p>\n\n\n\n<p>This step is mandatory to be able to continue using our service and you won&#8217;t be able to edit or create any new campaigns without this consent being recorded.<\/p>\n\n\n\n<p>You&#8217;ll see the following splash page when you login and only need to click the consent button to access your dashboard.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" width=\"777\" height=\"1024\" src=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-777x1024.png\" alt=\"\" class=\"wp-image-1277\" srcset=\"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-777x1024.png 777w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-228x300.png 228w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-768x1013.png 768w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-1165x1536.png 1165w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance-1200x1582.png 1200w, https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/gdpr-compliance.png 1262w\" sizes=\"(max-width: 777px) 100vw, 777px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2>What you need to do next?<\/h2>\n\n\n\n<p>Every business is unique, and your requirements under GDPR may differ from other businesses &#8211; including our own obligations.<\/p>\n\n\n\n<p>Heres what we suggest you do next:<\/p>\n\n\n\n<ol><li><strong><a href=\"http:\/\/app.wishloop.com\/auth\/login\" target=\"_blank\" rel=\"noopener noreferrer\">Login to your Wishloop account<\/a><\/strong> and accept our new terms of service and privacy policy<\/li><li>Review existing campaigns and adjust the copy or add checkboxes as required.&nbsp; Alternatively, something as simple as enabling double optin on your forms may be sufficient<\/li><li>If you were using our Internal Database lead storage option then export the leads before we remove the option at midnight on the 25th May<\/li><\/ol>\n\n\n\n<p>Speaking more broadly, there are many resources available to help you determine how the new changes may affect your business.&nbsp; This includes the official EU GDPR website, and information published by regulators in the individual EU Member States.<\/p>\n\n\n\n<p>I hope you found this information useful and don&#8217;t hesitate to get in touch via our <a href=\"http:\/\/wishloop.zendesk.com\" target=\"_blank\" rel=\"noopener noreferrer\">support desk<\/a> if you have any questions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Discover ways in which you can make your website and Wishloop campaigns compliant without sacrificing your conversion rates or your visitors\u2019 user experience<\/p>\n","protected":false},"author":5,"featured_media":1244,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ub_ctt_via":""},"categories":[5],"tags":[],"featured_image_src":"https:\/\/wishloop.com\/blog\/wp-content\/uploads\/sites\/6\/2018\/05\/eu.jpg","author_info":{"display_name":"Stuart Frank","author_link":"https:\/\/wishloop.com\/blog\/author\/stuwl9783\/"},"_links":{"self":[{"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/posts\/1235"}],"collection":[{"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/comments?post=1235"}],"version-history":[{"count":1,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/posts\/1235\/revisions"}],"predecessor-version":[{"id":3301,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/posts\/1235\/revisions\/3301"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/media\/1244"}],"wp:attachment":[{"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/media?parent=1235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/categories?post=1235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wishloop.com\/blog\/wp-json\/wp\/v2\/tags?post=1235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}