Understanding the GDPR in 7 Questions


What lies behind this acronym? Which channels will be most affected? What business opportunities does it create?
To gain a clearer understanding, we are taking advantage of the arrival of consulting firm M13h within Labelium Group (of which Feed Manager is also a part) to ask a few questions to Mickaël Avoledo, Managing Director in charge of the regulatory offering.
What is the GDPR?
GDPR stands for the General Data Protection Regulation. It is a European regulation that will apply to all organizations that, as part of their activities, use the personal data of individuals residing within the EU.
What is its purpose?
Lawmakers have three main objectives with this regulation:
- Harmonize the rules governing personal data protection at European level. As this is a regulation rather than a directive, it applies immediately and uniformly across all member countries
- Provide greater protection for the personal data of EU citizens and introduce greater transparency regarding how companies collect and process this data
- Facilitate the free movement of data in exchange for greater accountability from the parties processing it (they must be able to prove their compliance at any time)
When will it be applied?
The effective date is set for May 25, 2018. According to an EY study published on January 31, only half of the companies surveyed stated that they were GDPR-compliant. The other half therefore has only a few weeks left to address the issue!
However, May 25 will not be a strict final deadline. Authorities are well aware of the scale of the task facing companies, and certain aspects may initially be subject to a degree of “tolerance”. Above all, the CNIL wants to ensure that serious compliance initiatives have been launched and that certain key principles of the regulation are being respected.
What penalties can be imposed?
Organizations that fail to comply with the regulation risk a substantial fine: this can reach either 4% of global revenue or €20 million, whichever amount is higher.
What is going to change?
In addition to the increased severity of penalties, several points change compared with the French Data Protection Act currently in force.
In terms of scope, the regulation has extraterritorial application: companies outside the EU that process the data of European citizens are also concerned. In addition, companies and their subcontractors become jointly responsible for compliance with the regulation.
The approach is also changing. First, the system is moving from prior declarations of data processing activities to a logic of “demonstrability” (accountability), which requires stronger documentation. Companies will therefore need, for example, to formally document their processing activities in a record of processing activities, indicating where the data comes from, where it is stored and which third parties within the organization have access to it. Second, the regulation introduces the concept of “privacy by design”: the strictest privacy settings are applied by default (for example, no more opt-out), and only data strictly necessary for the intended processing purposes may be collected (the principle of data minimization).
Individual rights are also strengthened. In addition to the rights of access and modification, the regulation introduces new rights such as the right to be forgotten, the right to data portability, and the right to object to profiling, among others. Companies must inform individuals of these rights before collecting their data.
Another important topic for marketers is the legal basis for collecting data. Companies may rely on several legal grounds to justify collecting personal data, such as legitimate interest or the performance of a contract. However, the strongest basis remains user consent. This consent must be expressed through a clear affirmative action. This concept continues to be debated, particularly regarding consent for placing cookies and collecting cookie-related information, which is a key input for digital marketing.
Finally, in terms of organization, a Data Protection Officer – or DPO – must be appointed within the company. This person will be responsible for overseeing the use and security of data within the organization. The DPO will also serve as the main point of contact for discussions with stakeholders regarding personal data management.
Which channels will be affected?
First of all, all pure acquisition channels used to acquire new customers and prospects will need to be rigorously controlled. If external data providers are used (3rd party data, email databases, etc.), companies will need to verify that these providers have collected valid consent under the GDPR and require this contractually.
Regarding web retargeting, regardless of the channel (search, display, social, etc.), the main impact could be on reach. As mentioned above, several legal bases may be used for placing cookies for advertising targeting purposes. The chosen basis (legitimate interest or, more likely, consent) will have a significant impact on retargeting reach, as will the way consent is implemented if this basis is selected, particularly the much-debated requirement for a “clear affirmative action”.
Finally, advertising and customer retention email campaigns are also directly targeted by the regulation and will be closely monitored. Opt-in is the key principle. Although the practice remains widespread today, it will be prohibited to pre-check a box subscribing users to a mailing list: users themselves must actively take this action. In addition, purposes must be clearly separated when collecting consent, potentially resulting in multiple checkboxes and putting an end to overly broad, generic consent. Finally, the legal information listed in Articles 13 & 14 of the regulation must clearly appear at the time consent is collected, and of course unsubscribe links (= “withdrawal of consent”) must remain in emails and may even become more sophisticated, providing access to a genuine privacy center that allows users to withdraw consent for each specific purpose.
Are there any opportunities?
Although the GDPR may appear relatively restrictive, it offers several advantages for companies.
If we had to highlight two of them:
- Improving overall data quality. The GDPR encourages organizations to collect and retain only what is genuinely necessary, allowing them to remain focused on what matters most: data that can actually be used.
- Building trust. The regulation provides a good opportunity to promote transparency and build trust. In the same way, companies that move from “push” marketing to a “pull” approach will clearly benefit from the regulation and its consent requirements, while also limiting wasted advertising spend on poorly engaged audiences.
In conclusion, while the GDPR may initially be perceived as a new constraint for marketers, it is also a genuine source of opportunities and deserves strategic consideration along two lines: how can I limit the impact on my marketing operations while remaining compliant? What competitive advantage can I gain from compliance?
What is going to change?
Are there any opportunities?




