GDPR, why coorperation is key, Datastreams Blog!

The GDPR: why Cooperation is key

In our series of ‘GDPR Guide’ blogs, we briefly advise the Chief Data Officer (CDO), Data Protection Officer (DPO), Chief Marketing Officer (CMO) and Chief Revenue Officer (CRO) on how to approach the GDPR. While these guides offer a foothold for dealing with the GDPR, we believe that the true key to succeeding as a data-driven business under GDPR pressure is both simple and surprisingly difficult: cooperation.

Cooperation with the Data protection officer

Cooperation with your Data Protection Officer (DPO) across the company is a first important step to fostering a culture of compliance in your company. Your DPO needs to be able to provide everyone across the business with the knowledge they need to make compliant decisions. To fulfil this advisory role successfully, the DPO needs to have access to all departments, and people across the company need to be open to advice from the DPO. Additionally, employees in all departments should be pro-active in complying with the GDPR, asking the DPO for advice where necessary. Through this open communication, the DPO helps the other departments to keep doing their job in a way that is GDPR compliant.

Departments across the company should also take responsibilities in allowing the DPO to do their job. Employees across the company should provide the DPO with the software and information required for monitoring the company’s activities. Ideally, The Chief Data Officer builds a data stream map and grants the DPO access to monitoring software, while the Chief Marketing Officer provides the DPO with information on consent gathering procedures, and the Chief Revenue Officer responds to the DPO’s requests regarding SEPA numbers and employee ID numbers. It is this cooperation that allows the DPO to be as effective and efficient as possible.

Cooperation between departments

Of course, cooperation with the Data Protection Officer is important, but the GDPR presents the perfect reason to start breaking down all those silos inside your company. As your company implements new regulations and software in the move towards compliance, allowing input from employees across departments can prove instrumental in making the best choices for the business as a whole.

Ideally, if the CDO plans to implement a new data management system (as suggested by the DPO), he also asks the other departments for their input. The marketing department might inform him that a way to manage consent is required, while the CRO might express his wish for a system that ensures data quality. Because the CDO knows what is important in the software besides compliance, he can implement the solution that best suits the needs of everyone in the company. As a bonus, because the marketing department is more aware of the steps taken to ensure customer privacy, they might be able to leverage the CDO’s effort to use it as a competitive advantage.

Cooperation with outside help

While clever utilisation of the knowledge already present in your company will go a long way towards making GDPR compliance a reality, you shouldn’t be afraid to call upon outside help for compliance. Whether it’s knowledge that is not present in your company or a new piece of software that needs to be implemented, outside help can fill the gap of knowledge or resources present in your company. At Datastreams.io, we are happy to help you on the road towards compliance with one of our GDPR-proof solutions. Contact us to find out more or request a demo!

Chief Data Officer, brief guide for the GDPR, Datastreams

The GDPR: a brief guide for the Chief Data Officer

May 25th, 2018; the date the GDPR goes into effect. There is certainly plenty of information on the internet about what the GDPR is and what it requires from businesses. However, the impact the GDPR will have on your daily life might not be as apparent. In a series of blogs, we discuss the impact the GDPR will have on you and the changes you will have to make to continue working effectively under the new regulation. Today: The Chief Data Officer.

Realise your responsibilities

As Chief Data Officer, it’s your job to democratise the data: put the right data in the hands of the right people. While you certainly might be more hands-on with your data at times, it is your job to implement the rules and policies for regulating where data does (and doesn’t!) go. Besides managing the data infrastructure of your company, compliancy and security fall under your responsibility. No surprise, then, that the GDPR will certainly increase pressure as you move towards a compliancy-based data economy. Realising the responsibilities that come with the GDPR, is an important first step towards adapting to this new regulation.

Learn to work with your Data Protection Officer

Specifically, the GDPR means your company will often need to appoint a Data Protection Officer. This DPO will independently assess and audit the way data is managed in your company, meaning that it is crucial that you learn to work with your DPO instead of seeing him or her as a hindrance. Your DPO is independent and does not determine (or is concerned with) the purpose of the processing in your company. It will be your job to immediately address any concerns your DPO might raise, while still ensuring valuable data can be utilised optimally.

The GDPR also means you’ll have to ensure that you manage data in a responsible and well-documented way. Expect your DPO to ask you for an overview of what data is collected and who has access to specific parts of the data. To answer to these and other queries of your DPO, a wise step would be to start building your data stream map; an overview of the data that is collected, streamed and processed in your company.

See the opportunities in change

As a CDO it’s also important to realise that the GDPR is not just a challenge, it’s also an opportunity to finally implement all these changes you’ve been petitioning for years. The GDPR is the perfect opportunity to set up a new data infrastructure that is not only GDPR-compliant, but also more effective on all other aspects. The job of the CDO after the GDPR comes into effect, then, will not just be to conform to the required changes set by the DPO, but to ride the wave of change towards improvement on all aspects of data governance.

Use the right tool for the job

The tools you are currently using in your company might not comply with GDPR regulations, or allow you to perform your new duties under the GDPR. New tools designed for compliance might help turn that GDPR-pressure around. Our Data Stream Manager allows you to manage where the data in your company goes in a secure, GDPR-compliant way. The DSM enables you to easily manage and map where your data is collected and where it ends up, providing you with both the control and documentation you need. Security levels for sources and destinations means you’ll never accidentally send data to the wrong place, while comprehensive omnichannel-integration gives you an excellent 360-degree view of your customers to boot. Are you ready for the GDPR?

Chief Marketing Officer, brief guide for the GDPR, Datastreams

The GDPR: a brief guide for the Chief Marketing Officer

May 25th, 2018; the date the GDPR goes into effect. There is certainly plenty of information on the internet about what the GDPR is and what it requires from businesses. However, the impact the GDPR will have on your daily life might not be as apparent. In a series of blogs, we discuss the impact the GDPR will have on you and the changes you will have to make to continue working effectively under the new regulation. Today, the professional in a field that is highly impacted by the shift towards big data: The Chief Marketing officer.

Be unafraid & work together

As Chief Marketing Officer, you are probably familiar with how important data has become in the world of online marketing. Indeed, gathering data on customers is growing more and more important for developing 360-degree customer insight, adaptive real-time targeting, personalised content and improved customer experiences.

With the GDPR placing limitations on the collection and processing of personal data, you’d be forgiven for being hesitant in relying too much on data in your marketing. However, under the GDPR there is still plenty of room for data-driven marketing. While the GDPR certainly provides some challenges for marketers, it’s important to realise how valuable customer data continues to be. Work together with your Data Protection Officer to find ways to collect and process data in a GDPR-compliant way. The possibilities are greater than you might think!

Be transparent & honest

An important part of the GDPR is increased transparency. Customers need to be fully informed of where and why their data is collected, as well as being informed of their rights. This means you’ll likely need to rewrite your privacy statement and cookie-pop up to inform customers of your activities and their rights. This includes, but is not limited to, the right to be forgotten and the right to withdraw consent.

While being transparent is a central part of complying with the GDPR and avoiding fines, communicating honestly with customers is also crucial to forming a good relationship with customers. Customers are getting increasingly worried about their information and what happens with it. Unsurprisingly, they increasingly shy away from companies they feel they can’t trust. Your cookie pop-up and privacy policy could very well be one of the first things a customer encounters on your website, making them a great tool to communicate your dedication to keeping their data safe to your customers. Being honest and transparent, then, is not only a way to comply with the GDPR, but also a great move marketing-wise.

Be relevant & fun

The GDPR hands a lot of control over their data back to the customer. Under the GDPR, customers have more control over when and how they can be approached by companies. For instance, building an email list can no longer be done via opt-out measures or adding addresses collected for other purposes to your newsletter list. Instead, you have to collect fully informed, unambiguous consent before you can start sending newsletters.

The increasing control customers have over which company they interact with, means it’s important to be relevant and fun for customers. Produce valuable content and give your customers a reason to want to read your website or subscribe to your newsletter. Additionally, inform your customers that the data you collect will be used to provide them with personalised offers. Since customers like being approached in a personalised way, this will only cause your marketing efforts to be more focused and effective, but will also make customers more likely to give their consent. Summarising: don’t try to break down the door unannounced: work on being invited in.

Use the right tool for the job

The GDPR will certainly be a challenge for marketers, and an important part of tackling that challenge is using the right tools for the job. Consider implementing a data management platform to manage your tracking scripts and your customers’ content settings. Our Data Stream Manager is an easy and comprehensive way of managing the customer data you collect and process. Additionally, our consent management solution allows you to create modular consent pop-ups to collect informed consent for different processing purposes. Additionally, it allows you to manage the collected consent in a dynamic way.

Data Protection Officer, brief guide for the GDPR, Datastreams

The GDPR: a brief guide for the Data Protection Officer

May 25th, 2018; the date the GDPR goes into effect. There is certainly plenty of information on the internet about what the GDPR is and what it requires from businesses. However, the impact the GDPR will have on your daily life might not be as apparent. In a series of blogs, we discuss the impact the GDPR will have on you and the changes you will have to make to continue working effectively under the new regulation. Today, the newest addition to many companies: The Data Protection officer.

Establish your role

As Data Protection Officer, you occupy an interesting position in your company. Your presence in your company is likely mandated by the GDPR, but your exact role and duties might be unclear to your colleagues, or even to yourself. As DPO, it is important that your colleagues (and more importantly: managers) know what your role entails, especially if you were appointed as DPO on top of your regular occupation. They must understand that you must have the freedom to act independently, that you cannot be instructed on how to investigate your company’s processing, that you cannot be penalised for performing your duty and that you can’t be personally held accountable for (non)compliance.

On the other hand, it is important your colleagues realise you can be approached for questions regarding GDPR and compliance, as you are as much an advisor as you are an officer. Establishing who you are, what you do and which access you are entitled to, helps you work together with your colleagues and management in an effective and efficient way.

Know your company’s data infrastructure

There’s many reasons why one of the first priorities when starting your work as a DPO, is to gain a clear overview of the data infrastructure of your company. If you have no idea where and how data is transported in your company, it is difficult to locate problems in data processing or collection activities. Furthermore, keeping records of data processing activities (as required by article 30) requires a clear overview of the data infrastructure of your company. In most cases, you won’t actually have to start mapping the data yourself, but work with your Chief Data Officer to build a data stream map as fast as possible, so you have a strong foundation to build future activities on.

Don’t forget about people

With a lot of processing activities to audit and evaluate, it might be easy to focus on the processing and forget about the people. However, training and educating your colleagues is an important part of your job. It’s your job to inform your colleagues about the GDPR and advise them on ways to perform their jobs while complying with the GDPR. Fostering a culture of GDPR compliance and privacy by design and default is an effective way of making sure everyone does their part in helping the company become GDPR compliant, which also makes you are more efficient employee.

Use the right tool for the job

Since the DPO is a new position in many companies, it makes sense that not all the tools you need to do your job are present in your company. Like any professional, it’s important you have the right tools for the job. Our Data Stream Manager helps you and the CDO to gain an overview of the data collection, streaming and processing activities in your company, making auditing and reporting activities much simpler. Additionally, the DPO has been designed to keep your data streams secure and provide you with an easy way of managing who has access to the data collected in your company, making it an excellent tool for any DPO to have.

Chief Revenue Officer, brief guide for the GDPR, Datastreams

The GDPR: a brief guide for the Chief Revenue Officer

May 25th, 2018; the date the GDPR goes into effect. There is certainly plenty of information on the internet about what the GDPR is and what it requires from businesses. However, the impact the GDPR will have on your daily life might not be as apparent. In a series of blogs, we discuss the impact the GDPR will have on you and the changes you will have to make to continue working effectively under the new regulation. This time, we discuss some important GDPR guidelines for the Chief Revenue Officer.

Strike a balance

As Chief Revenue Officer, you are likely used to performing a balancing act: balancing marketing versus sales or direct conversions versus long-term content strategies. The GDPR will bring an extra challenge: striking a balance between GDPR demands and financial results. As your Data Protection Officer is not concerned with the financial impacts of GDPR-guidelines, you might find yourself at odds with him or her at times. Working together with your DPO to comply with the GDPR while still being able to perform valuable analytics, is crucial.

Break down silos

An issue in companies that is growing in magnitude as the GDPR approaches, is the silos that might still be present in your company. As Chief Revenue Officer is it vital you break down silos in your company to allow marketing, sales and customer relations to work together towards a single goal. Open communication with the data protection officer and even the IT department is also growing in importance, as clarity on where data is processed for with purpose is vital for complying with the GDPR.

Continue to be data driven

The best Chief Revenue Officers are data-driven, and this will not change under the GDPR. Collecting omnichannel customer data and using it to proactively address customer issues, is still one of the most effective ways of ensuring more (and more predictable) revenue. While collecting customer data will be more difficult under the GDPR, doing it will be more important than ever to identify market opportunities.

For the data-driven revenue officer, the GDPR might actually turn out to be a blessing in disguise. The GDPR will force many companies to adopt a more structured approach towards gathering and processing data. Companies will likely turn to data management platforms and the like to map and manage the data they collect. A smart CRO will be able to use this data management platform, along with other technologies, to collect and process a wide variety of data in a more comprehensive way. Work together with your data protection officer and higher management to ensure you can reap the benefits from any new technology that is being brought in. In other words…

Use the right tools for the job

The ideal data management tool does not only ensure GDPR-compliant processing, but also provides you with constant access to comprehensive, complete, quality data. Our Data Stream Manager has been developed not only with the GDPR in mind, but also with a dedication to ensuring quality data across the company. Whether you are interested in optimising conversion rates or analysing customer behaviour, the Data Stream Manager enables you to perform analytics on complete, integrated datasets. This way, we aim to help you improve your current revenue and discover valuable new business opportunities in a GDPR-compliant way.

Combining Consent Management and the DPO Controller Portal

Combining the DPO Controller Portal with Consent Management

The General Data Protection Regulation (GDPR) influences all organisations that do business within the European Union or processes any kind of personal data that belong to European citizens. Complying with the GDPR rules should not be underestimated, as it takes a lot of time and effort from all each department within an organisation. The complexity has to do with, among other things, the differences between the preferences, processes and permissions of all departments. But taking the next steps is necessary to prevent any type of fines and – even more important – to preserve customers trust.

The marketing department
The risk for the marketing department concerns the complexity of the data they collect and that it might be used for purposes a user didn’t approve. The cookie request for overall marketing purposes that is used by most companies at the moment does not meet the requirements of the regulation. The GDPR provides a much-needed, updated definition of consent, defining it as:  “Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”. This means companies need to specify their requirements and the marketing department can only use the collected data for that purpose.

The right of the users
Before an organisation can collect any kind of information about a visitor, they need to ask for consent. And as the GDPR states, each individual has the right to change their preferred setting at any time. Organisations should adapt to this feature by implementing privacy by design principles in their processes. One of biggest concerns is that there are a lot of companies that use Google Analytics (GA). GA will gather the data of the users before they can decline anything and the result is that a company is not compliant – before the regulatory authorities even checks their other processes. With a solution such as our consent manager, individuals can change their preferred settings at any time. This way the user does not only think they have control over their settings, they actually do. Every time an individual uses the consent manager, it will change instantly.

The influence of the DPO
According to the GDPR, many companies require assigning a DPO along with their name and contact details. The most important role of the DPO is managing the data streams that take place within the company and control the data agreements with third parties. When there is the need for a new connection between a data source (of any kind) and a destination, it needs to be requested to the DPO of the organisation. Firstly, the DPO checks the purpose and estimates whether this is legally permitted. After that, the DPO informs the requester if the data stream is approved or not. The Datastream portal makes it possible for the DPO to control all the data streams that exist within a company and its trusted parties. It also shows the DPO insights of which data is collected, what settings the user chose and for what purposes the user gave opt-in.

The complexity of technology
Luckily Datastreams.io understands the complexity of technology and that it might be difficult for companies to comply data streams between systems and with the different roles of sources and destinations. Not only might the complexity of technology be a burden, but to adapt to the GDPR in all processes, it demands a lot of effort from the IT department. This is why Datastreams.io provides a GDPR compliant solution that only requires a Single Line Of Code, the SLOC. It is not designed to replace any kind of technology or tool an organisation currently has, but it is meant to provide the controller portal for the DPO and to provide secure, privacy by design transport between internal and external systems. Why not start today?

Collecting data on a colaboration data platform Datastreams

Data loves to speak, we just need to listen

We humans, by our very nature, are storytellers. The hundreds of myths and legends spread throughout history are a poignant indicator of the human drive to create and share stories. Stories have always been closely interwoven with data. Data provides the start for every story, the wellspring for tales both real and fictitious. From the moment, we are born and commit our date of birth to the world, we leave behind trails of data in everything we do, until we finally close out our story with the date we die. An autobiography, in a way, written in the data we leave behind.

Data speaks to those willing to listen. “Where do you get your inspiration from?” Is a common question to writers and innovators of other types. The answer, often, is something we have all observed: an idea we’re all familiar with, an event we have all witnessed or a fact we all know. The question “Why didn’t I think of that?” often rises when we see innovations or hear stories. When the stories are told to us and we look at the data they are based on, it seems to clear what the data had been telling us all along. Why, then, didn’t we hear it talk before? The answer is simple: we weren’t listening.

Companies have realized the potential in data for quite a while. As companies, we love collecting data from our customers, running analytics and crunching data until it churns out results. We know the percentages, the uptakes in sales, the averages. When we see data (and we see a lot of data) we are prone to asking ourselves: “What can we do with this data?” when we should be asking “What is this data telling me?”

Professor of Economics Robert Coase was right when he said: “If you torture the data long enough, it will confess.” Indeed, if we analyze the enormous amounts of data available, we will find the cold, analytic information we are looking for. But as is the question with all information obtained through torture: how truthful is the story we are told? It is time we stop torturing our data and start listing to it, start looking at it through the eyes of an artist. Only then will we come to ideas that will make our competitors scratch their heads and think: “Why didn’t I think of that?”.

CRO, GDPR and e-privacy regulations optimisation with a risk

CRO – Optimisation with a risk

In the world of marketing, CRO stands for ‘Conversion Ratio Optimisation’. A quick search on Wikipedia for the definition of CRO, yields a different result. Here, the abbreviation CRO is also explained as standing for ‘Chief Risk Officer’. That same Wikipedia explains the main task of a CRO as: “To ensure that the organisation is in full compliance with applicable regulations and to analyse all risk related issues”.

Considering the impending GDPR and e-privacy regulation, each marketer looking to improve his conversation ratio, should first look to that other CRO. Similarly, each CRO should pay a visit to the marketing department to see what happens there. Time for a short introduction for both.

What is CRO?
Conversion Ratio Optimisation is a generic term for a combination of processes and techniques that aim to optimise the conversion ratio. Often, improving the customer experience is named as the target for these processes, but eventually this improved CX is supposed to lead to a higher conversion ratio.

Coen Huijsmans, strategist at TamTam, gave a good explanation (Dutch) of what CRO entails and what it takes to get the best results. Google Analytics is hailed as ‘your best friend in CRO’.

On the contrary, for the CRO, Google Analytics is the biggest enemy. When you use Google Analytics, you share personal information with Google and where personal information is used, consent needs to be obtained. When you just use Google Analytics for Analytics and don’t collect Personally Identifying Information (PII), you can do this before asking consent, though you’ll still need to pay close attention to the settings in Google Analytics. However, Google Analytics is fairly easily integrated with marketing tools like Google Doubleclick and Google Optimze. As soon as you start doing this, Google Analytics will have to be used only after asking users’ consent. If you fail to obtain this consent and continue to measure using Google Analytics, you are in violation of the GDPR and risk being sanctioned.

GDPR and e-Privacy Regulations
By now, nearly everyone in our sector knows that the GDPR comes into effect May 2018. At that same moment, the e-Privacy Regulation will also come into force. For the e-Privacy Regulation might be accompanied by a two-year transitional period, but that is by no means a guarantee.

The e-Privacy Regulation complements the GDPR and mostly concerns the things a marketer seeks to do online. According to the GDPR, direct marketing is allowed without consent, but the e-Privacy Regulation clearly states that so called ‘unsolicited marketing’ without consent isn’t allowed. A direct mailing per post is therefore allowed, but for a DM using e-mail you will need to ask consent first.

Sanctions
The sanctions for violating both laws are the same. They can be enforced per violation, so when you continue to violate one or both of the laws, you can encounter the same sanction again. When we talk about GDPR sanctions, fines may seem like the biggest threat. In relation to CRO, you could make a business case: how high is the fine and what does the optimisation bring us? However, in this case, don’t forget to take damage to your reputation into account for this business case. How many clients leave the company and how difficult will it be to find (and bind) new clients, after you’ve been caught breaching regulations. This impact, of course, depends on what kind of business you are. A big dating-site will suffer more reputational damage than a fairly small web shop.

Of course, we would never advise anyone to purposefully violate the law. If you decide to this, any decent CRO will prevent you from giving in to this temptation! A good thing, because one of the most dangerous sanctions is rarely discussed, but will most definitely still be enforced: a ban on the collection and processing of personal information.

Let that sink in. A complete ban on processing personal information. What can you do if you are no longer allowed to process personal information. Does your company even have a ground for existing in that case, or would you need to close shop immediately?

CRO and GDPR
It is viable to optimise conversion ratios, improve customer experiences and (re)target your campaigns under the GDPR. A lot is still possible, but not without a concerted effort. Only after obtaining consent in a valid way, are you allowed to use data for this purpose. Do you tell your customers in your consent pop-up that you use Google Analytics for analytics purposes? Then you’re not allowed to use the data for targeting and can not link your Google Analytics to Doubleclick or Optimize. Did you tell your customers that you measure your customer’s behavior to increase your conversion ratio and have customers consented to this? Then nothing is stopping you in optimising your conversion ratio.

A final word: if you link your Google Analytics to Google Optimize, you are only allowed to use Google Analytics after a visitor has given consent for the tracking of his behavior for marketing purposes. This is because when you send ID’s from Google Analytics to Optimize, Google assumes that all ID’s have already given their consent.

Data dreams of: American Express, data-driven company

Data dreams of: American Express

It is sometimes said that everything starts with a dream. To help you kickstart your own dreams, we are sharing the dreams of some of our clients. Today we are looking at the dreams of American Express, who leveraged the power of visualized data to gain improved insights into their marketing campaigns.

From ambitious data-dreams
American Express dreams of a way to gain better insight into their key touchpoints within the approval process for credit card applications. This would allow Amex Acquisition teams around the world to improve their marketing campaigns at any time based on data that is up to date, trusted and easy to understand.

For their data-driven challenge

  • Collect data from master sources and configure them into new data models.
  • Speed up the collection, collation and reporting of data from different sources
  • Configure data models and visualize them in an understandable manner.
  • Allow the end user to easily segment and filter data themselves.
  • Provide a high-level overview of campaign tracking data, allowing the detection of trends that require deeper analysis.
  • Be flexible and scalable across Amex in different countries
  • Enable compliance with the impending GDPR demands.

To a data-driven solution
Datastreams.io teamed up with Adversitement to make the dreams of Amex come true. Datastreams.io provided the Data Stream Manager (DSM), which allowed Adversitement to collect data from different sources and build new data models. By connecting these data models to Tableau, Adversitement can create and maintain clear, insightful dashboards of clearly visualized, valuable and timely information.

For a data-driven future
With our solution being implemented in Amex companies in different countries, American Express can look forward to a future of easily accessible insights in key touchpoints with their clients. Amex acquisition teams no longer have to wait for reports put together by hand at the end of each month. Instead, they can rely on data that is batched on a near daily basis, meaning that they can monitor and implement changes in campaigns based on reliable data at any time. Users can also enjoy insightful dashboards that allow broader and deeper segmentation than before. They can clearly understand channel and campaign data without spending hours building their own reports. Finally, Amex is for the privacy standards of the future, as our data governance layer makes worries about the GDPR a thing of the past.

Consent, transparency, security, protection of data, Datastreams

Dear Santa, we need to talk about the GDPR

Dear Santa Claus, it has come to our attention that you are among the biggest collectors of personal data in the world. By our calculations, you collect personal information on more than 30% of young children in families around the world. Information gathered concerns whether subjects have been ‘naughty’ or ‘nice’, the geographic location of the bedrooms of children, knowledge about wishes and dreams and most peculiarly: sleeping patterns.

We can only assume that this information has been gathered through extensive data-gathering operations, rumored to be accomplished via a program termed ‘Elv3s’, distributed through the Rud01PF platform. With the GDPR fast approaching, we are concerned about whether your data collecting and processing activities are being conducted in a way that complies with the GDPR-regulation that comes into effect May 25, 2018. Because at Datastreams.io we are big fans of your charitable behavior, we would hate to see you fined up to 4% of your annual turnover. To avoid this, you might want to take a hard look at the following elements of your data processing:

• Consumers consent. While at Datastreams.io we know that you have nothing but good intentions, we also know that it is important to establish the lawfulness of your data processing activities. We believe that the lawful processing basis for your activities should be consent. We therefore advice to look at your consent policies, which are no longer up to date. Under the GDPR you will also be required to ask consent from parents before gathering information on their children. We’ve already written a guide on GDPR consent that may be useful to you.

• Transparency and disclosure. We understand you are a very secretive person, but it’s time to disclose some of your secrets. Specifically, which data you collect and how this data is collected and stored. You have clearly attempted to disclose some of this behavior in songs like ‘Santa Claus is coming to town’, but we believe this disclosure of information is not sufficiently written in a “concise, transparent, intelligible and easily accessible form, using clear and plain language” as the GDPR prescribes. Furthermore, data subjects will need to know where to contact you if they want personal data deleted or lodge a complaint. It’s time to reveal where on the North Pole your company is, exactly. 

• Security and protection. Because you are, as far as we know, the only data processor working with the Elv3s software, we hope that you have taken possible privacy concerns into consideration when implementing your data solutions. Encrypting data and regularly testing your cybersecurity solutions will be integral to keep operating in a compliant way. Make sure you don’t forget to inform your data subjects in the event of a data breach. Because you regularly monitor data subjects on a large scale, you will also be required by law to appoint a Data Protection Officer. You can appoint one of your current employees as a DPO, or bring in help from outside. We’re sure many ‘little helpers’ will be happy to take on the role.

These are just a few concerns we have with your data processing policies, Mr. Claus. The Data Protection Officer you will hopefully appoint will likely point out more issues, such as the profiling of children as ‘naughty’ or ‘nice’ and the reliability of kept records. You might find your current data architecture incapable of dealing with GDPR demands, but no fear: our data stream manager & consent manager solutions will help you comply with GDPR demands in time, so you can work on getting us those presents we asked for…

Merry Christmas, Santa!