June 1, 2018 byJamie Lords

Why should you care about GDPR?

Everywhere you look in ecommerce, you will see someone discussing EU GDPR or the European Union General Data Protection Regulation. There is a variety of information, from technical articles to speculation on social media. We all want to know how it will affect us. What changes, if any, will I need to make? What does it really mean?

In this article, we will take a quick look at EU GDPR - what it is, how can we prepare, and how it might impact an online business.

Who does GDPR impact? 

The EU GDPR not only applies to organizations in Europe but any organization that will process and hold personal data for individuals in the European Union as well as EU citizens living abroad. In other words, if you plan to have customers from Europe, you will need to pay attention.

What happens if you do not comply? 

The GDPR will be enforced beginning May 25, 2018. Non-compliance penalties are significant.

  • Fines can be assessed up to 4% of annual global revenue or 20 Million Euro, whichever is greater.
  • Individuals will have the right to seek compensation for damages, including loss of control over personal data or limitation of rights, discrimination, financial loss, damage to reputation, or loss of confidentiality of personal data protected by professional secrecy.
  • Individuals can choose to seek action against either the data controller, the processor, or both, and possibly anyone in the supply chain.

What are your options? 

If you own or operate an ecommerce business, your options are insufficient. There are really only two options.

Option 1 - Embrace it (Good Idea!)

A friend once told me: “if you don’t know what direction you are going, you are already lost.” I think this is especially true with EU GDPR. There is a great deal to learn and still more that needs to be clarified. But achieving EU GDPR readiness begins with a decision to comply. Assess your situation and identify areas where you are not compliant. You can then establish a strategy for minimizing your liability.

Option 2 - Don’t sell to Europe or their citizens (Bad Idea!)

If you don’t wish to comply with the EU GDPR, we highly recommend that you don’t plan to do business with anyone from Europe. Please remember, those European individuals can live abroad. Limiting your ecommerce business to U.S. borders does not ensure your compliance. The risk of non-compliance is significant and can be described as “by pain of penalty.” Non-compliance is an option, but it is not recommended.

5 key areas of the regulation 

EU GDPR readiness involves becoming familiar with five key areas of the regulation - consent, individual rights, policies, and accountability.

Zonos, the leader in cross-border ecommerce technology, will continue to lead out and guide merchants through the challenge of selling their products to the world. We will continue to provide FAQs and document examples displaying internal privacy policies and processes that you can adopt. We will share internal training documents for you to use with your team. Zonos takes data privacy seriously and is committed to EU GDPR readiness. More details will be coming on a regular basis.

Author
Jamie Lords
Published: June 1, 2018
Share