The General Data Fortification Regulation is a new
regulation that regulates the protection of personal data of citizens residing
in the European Union. It is aimed at any person, natural or legal, who handles
user and / or customer data that are within the EU. Therefore, a China-based
online store whose customers are French or Spanish, for example, must also
comply with the GDPR. Thanks to the new regulations, users' guarantees on the
handling and security of personal data are increased.

General Data Protection Regulation
The General Data Protection Regulation introduces a series
of significant changes with respect to the Organic Law on Data Protection.
These are the most relevant.
First, the need to obtain explicit consent from users.
Consent must be informed and verifiable in order to manage your data, so that
as the owner of the website you must make available to users the necessary
tools to obtain and accredit it.
Of course, you have to inform them in advance what you are
going to use their data for. It is necessary to rigorously specify and specify
everything that includes the personal information of web users, whether in a
subscription or in a comment, for example.
The RGPD sets the accessibility and transparency of
information as new requirements. Therefore, users must be able to access the
information that concerns them. To all this, we must add that there is the
right to be forgotten in relation to the use of personal data.
As is logical, you have to prove the compliance of all
collaborators with whom you share personal information. And finally, you have
to have a well-defined protocol to detect and report any type of security
breach.
Tips to adapt your
website to the RGPD
So far the theory,
but what do you have to do to put all these points into practice?
The first step is to update all the legal policies of the
web. This is, privacy policy, legal notice and cookie policy. Write them
clearly and concisely so that users who share their personal data with you have
no doubt about what you are going to use them for and how you are going to
manage them. Legal texts must appear at the bottom of the page. It is highly
recommended that you make a record of treatment activities to analyze all the
security measures to be applied according to the risk of each treatment.
If you have a form on the website, you must add a legal
clause in it so that users explicitly accept it before submitting their data.
If the form is for sending the newsletter via email, remember that the consent
must be revocable. In each of the communications you have to allow users to
unsubscribe.
The consent to be able to process the data must be free and
specific. In addition, you must offer users a clear and detailed explanation
about what you are asking them for. According to the GDPR, consent must be
verifiable, so you must keep records to show what users consented to.
To all this, we must add the position of developing a record
of all the consents and personal data of the users of the web. And, finally, do
not forget to implement the security measures that are necessary according to
the type of personal data you collect.