{"id":18206,"date":"2018-04-05T11:30:06","date_gmt":"2018-04-05T11:30:06","guid":{"rendered":"https:\/\/www.heartinternet.uk\/blog\/?p=18206"},"modified":"2018-04-05T11:30:06","modified_gmt":"2018-04-05T11:30:06","slug":"a-guide-to-gdpr-and-what-to-do-to-prepare","status":"publish","type":"post","link":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/","title":{"rendered":"A guide to GDPR and what to do to prepare"},"content":{"rendered":"<p>In May 2017, The Economist called personal data \u201c<a href=\"https:\/\/www.economist.com\/news\/leaders\/21721656-data-economy-demands-new-approach-antitrust-rules-worlds-most-valuable-resource\" target=\"_blank\">the world\u2019s most valuable resource<\/a>\u201d ahead of oil. That\u2019s not surprising. Personal information is an object of desire for any business that\u2019s looking to improve communication and boost customer experience.<\/p>\n<p>However, what\u2019s surprising and a big cause for concern is that most businesses don&#8217;t have an ethical approach to securing and protecting customer data. In fact, according to Symantec\u2019s State of European Privacy Report, <a href=\"https:\/\/www.symantec.com\/en\/uk\/about\/newsroom\/press-releases\/2016\/symantec_1018_01\" target=\"_blank\">90% of businesses believe it\u2019s too difficult to remove customer data<\/a> and\u00a060% do not have the processes in place\u00a0to do so.<\/p>\n<p>The stats get even more worrying. The study also revealed that businesses that use customer data don\u2019t fully understand <em>how<\/em> they should use it. 41% of marketers admit to not fully understanding both best practices, or the law, around the use of consumer\u2019s personal data.<\/p>\n<p>That is why the European Union is introducing the General Data Protection Regulation (GDPR) &#8211; a new set of laws designed to regulate the way businesses collect, store and use consumer data.<\/p>\n<p>This level of regulatory overview of personal data is unprecedented and will require businesses to ensure the highest level of user data privacy and security, or suffer dire financial consequences.<\/p>\n<p>With GDPR going into effect May 25, 2018, we\u2019ve put together this guide to help clarify not just what GDPR is, but also how it is being implemented and enforced, whether or not you or your clients will be impacted and how to prepare.<\/p>\n<h2>What is GDPR?<\/h2>\n<p>The General Data Protection Regulation (GDPR) consists of a set of regulations designed to put the highest levels of protection around personal data. Put simply, it&#8217;s meant to protect user data, giving the consumer ultimate control over what happens to it.<\/p>\n<p>GDPR defines personal data as any information related to an individual (data subject) that can be used to directly or indirectly identify that individual. It can be anything from a name, a photo, an email address, bank details, posts on social media channels, or even a computer IP address.<\/p>\n<p>So, to be GDPR-compliant, a business needs to handle consumer data carefully as well as provide users with myriad ways to control, monitor, check and delete any information pertaining to them.<\/p>\n<p>Businesses must also implement processes to ensure that data is always protected and kept safe and secure. They\u2019ll need to regularly conduct privacy impact assessments, strengthen the way they seek permission to use the data, document the ways in which they use personal data and improve the way they communicate data breaches. The idea is that businesses need to be as transparent as possible with all the actions connected with users\u2019 personal information.<\/p>\n<p>Failing to comply with GDPR could lead to fines of up \u20ac20 million or 4% of the company\u2019s total global revenue. Although fines of this size will not be commonplace, it&#8217;s a strong indication of how seriously you should take GDPR.<\/p>\n<h2>What businesses will it affect?<\/h2>\n<p>If you\u2019re collecting, storing or using personal data of EU citizens, you will be affected by GDPR, irrespective of where you are based.<\/p>\n<p>So if you\u2019re a freelance web designer or run a web design agency and you collect personal data from users within the EU via your website or blog, then you&#8217;re subject to the provisions of GDPR.<\/p>\n<p>And the coming of Brexit won&#8217;t impact GDPR either &#8211; the UK is introducing a new data protection law based on the regulation, and that means that UK businesses will still be bound by its rules in the future.<\/p>\n<p>Here are the areas that are most affected by GDPR:<\/p>\n<h3>Email marketing<\/h3>\n<p>You&#8217;re probably using your website to collect user data and generate leads. If you&#8217;re asking users for their names, email addresses or other information to sign up for your newsletter or to download a free template or an ebook, that&#8217;s known as &#8220;opt in&#8221;.<\/p>\n<p>Well, from now on, when users submit their email address in exchange for access to an ebook, you will be required to explicitly ask for their consent to be contacted, instead of automatically adding them to your mailing list and then waiting for them to opt out.<\/p>\n<p>In addition, if required, you&#8217;ll need to be able to provide evidence that a user has elected to opt in receive emails from you.<\/p>\n<h3>Remarketing\u00a0<\/h3>\n<p>As GDPR classifies cookies used for remarketing as personal data, the same rules as email marketing apply. If you want to engage in remarketing, then you&#8217;ll need people to opt in.<\/p>\n<h3>Marketing automation<\/h3>\n<p>Marketing automation is a powerful, time-saving tool that many businesses rely on to communicate with customers. But if you don&#8217;t triple check to ensure it&#8217;s set up correctly, come May it may land you in trouble.<\/p>\n<p>For example, if an email is sent automatically to a user who has opted out that would count as misusing their data. That&#8217;s why it&#8217;s critical that you take the time to ensure that every name and email address in your database has given you permission to contact or to market to them.<\/p>\n<p>In addition, if someone opts out of an automated email, you need to make sure that that person is removed from all your mailing lists so they don&#8217;t receive further emails.<\/p>\n<h3>Third-party compliance<\/h3>\n<p>You&#8217;ll also need to pay attention if you&#8217;re using third-party tools and technology such as marketing automation platforms and CRMs. Check to make sure that any third party that you&#8217;re working with and holds data on behalf of your business is also GDPR-compliant.<\/p>\n<p>If you pass on personal data to a third party that doesn&#8217;t comply with GDPR, then that counts as a breach of the rules.<\/p>\n<h2>What do I need to do to prepare?<\/h2>\n<p>If you&#8217;re already complying with existing data protection laws, then you&#8217;re in a good position to adapt to GDPR. You will, however, still have to make some changes.<\/p>\n<p>The steps needed for GDPR compliance will vary from business to business, so it&#8217;s important to seek out expert advice that focuses on your particular needs. With that in mind, here is some general advice on what you&#8217;ll need to focus as you head towards GDPR compliance:<\/p>\n<h3>Get permission and \u2018repermission\u201d<\/h3>\n<p>When processing personal data, explicit consent from individuals is a requirement under GDPR. This means that after May 25 you can only email users who have actively, freely and willingly opted in to receive messages from you.<\/p>\n<p>This also applies retroactively to any subscriber in your current mailing list. Even if you\u2019ve followed best practices for mailing list signup, you may find that you don\u2019t have the level of consent required under GDPR to continue sending marketing emails to your list.<\/p>\n<p>Don\u2019t ignore this aspect as you may be asked at any time to provide this information. So it\u2019s best to act now to \u2018repermission\u2019 your list and collect affirmative consent so you can send confidently after May 25.<\/p>\n<p>Here are a few things you could cover in your \u2018repermission\u2019 email:<\/p>\n<ul>\n<li>How you got their personal details<\/li>\n<li>Why you are contacting them<\/li>\n<li>What sort of content you will send them in the future if they opt-in<\/li>\n<li>How they can update their communication preferences and opt-out<\/li>\n<\/ul>\n<p>Of course, if you\u2019ve previously collected sufficient proof of permission, you do not need to gain permission from subscribers again.<\/p>\n<h3>Make the task of \u201cgiving permission\u201d as easy, transparent and painless as possible<\/h3>\n<p>This means that you should clearly state why you want a user\u2019s information and how to intend to use it.<\/p>\n<p>For example, if you\u2019re collecting an email address within a webinar registration form, you should provide details on why you need that email address and how you\u2019re planning to use it. In this case, you need the email address to send the registration confirmation, the link to the webinar and a copy of the webinar once it ends.<\/p>\n<p>Here are a few design principles that might help you to better understand how to ask for permission:<\/p>\n<ul>\n<li><strong>Active opt-in<\/strong> &#8211; When asking for permission it&#8217;s imperative that you use an opt-in form and avoid any pre-ticked boxes as these are considered implied consent and not freely given. Explicit consent means that the user will need to tick a box to give you permission to send them further information.<\/li>\n<li><strong>Informed<\/strong> &#8211; Consent should be clear, concise and specific. So avoid jargon or ambiguous language.<\/li>\n<li><strong>Named<\/strong> &#8211; Permission should provide clear information about the processing organisation and information about any third-party involved in data processing.<\/li>\n<li><strong>Easy to withdraw<\/strong> \u2013 Make it simple for users to withdraw consent and opt out of your email lists, if they wish to do so. Also tell them how to do it.<\/li>\n<li><strong>Separate<\/strong> \u2013 Keep consent requests separate from other terms and conditions or privacy notices. For example, when someone downloads an ebook from your website, you&#8217;ll need to have a separate box that users need to tick to subscribe to your emails. Signing up for emails is <em>optional<\/em> &#8211; they can always download the ebook without subscribing to your emails.<\/li>\n<\/ul>\n<p>Don\u2019t forget \u2013 all of this will apply to all forms of marketing, including cookie-based remarketing. So make sure you apply these principles to all forms of data gathered for marketing purposes.<\/p>\n<h3>Update your Privacy Policy<\/h3>\n<p>GDPR says that your privacy information must be \u201c<em>concise, transparent, intelligible and easily accessible; written in clear and plain language, particularly if addressed to a child; and free of charge<\/em>.\u201d<\/p>\n<p>The Information Commissioner\u2019s Office (ICO) provides more useful information on <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/privacy-notices-transparency-and-control\/privacy-notices-under-the-eu-general-data-protection-regulation\/\" target=\"_blank\">what should be included in a privacy policy<\/a> so make sure you read it carefully. Then revisit and edit your policy accordingly. The idea is to use language that is simple and easy to understand, as jargon will not be acceptable under GDPR rules.<\/p>\n<h3>Centralise your personal data collection into a CRM system<\/h3>\n<p>Make sure users can access their data, review its proposed usage, and make any changes they wish to.<\/p>\n<h3>Keep evidence of consent<\/h3>\n<p>GDPR not only sets the rules for how to collect consent but also requires businesses to keep a record of these consents. So make sure you can always provide evidence of who consented, when and how.<\/p>\n<h3>Store data securely<\/h3>\n<p>To protect personal data, GDPR states that you\u2019ll need to \u201c<em>implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk<\/em>.\u201d<\/p>\n<p>This starts with encrypting any data that is submitted to your website, which is what GDPR recommends in Article 32. This will stop people from hijacking the data. An SSL certificate should be fitted to your site to encrypt the data.<\/p>\n<p>In addition, make sure you have strict rules in place for data access and to track security access.<\/p>\n<p>It&#8217;s also important to remember that this includes any physical storage devices that hold customer data &#8211; a list of unencrypted customer data on a USB stick is a data breach waiting to happen. Don&#8217;t let all your hard work on GDPR compliance be undone by a simple slip up like this.<\/p>\n<h3>Speak to a GDPR expert<\/h3>\n<p>GDPR is a complex topic. If you want specialised advice on GDPR compliance so you can also avoid any potential damage to your company\u2019s bottom line, it might be worth speaking to a GDPR expert. An expert can check to see whether your procedures are compliant and take you through the steps to follow to become GDPR-compliant.<\/p>\n<h2>Where can I find more information about GDPR and its impact?<\/h2>\n<p>Use the following resources for guidance and start your preparations as soon as possible.<\/p>\n<p>Perhaps the most immediately useful resource is the <a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1624219\/preparing-for-the-gdpr-12-steps.pdf\" target=\"_blank\">ICO&#8217;s 12 steps to take now to prepare for GDPR<\/a>. The <a href=\"https:\/\/ico.org.uk\/global\/contact-us\/helpline\/\" target=\"_blank\">ICO also has a helpline<\/a> you can contact.<\/p>\n<p>Here are some other useful GDPR resources.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.dpnetwork.org.uk\/gdpr-category\/general\/\" target=\"_blank\">Data Protection Network<\/a><\/li>\n<li><a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-the-general-data-protection-regulation-gdpr\" target=\"_blank\">ICO: Data protection reform<\/a><\/li>\n<li><a href=\"https:\/\/www.inforights.im\/document-library\/general-data-protection-regulation\/\" target=\"_blank\">All guidance on the General Data Protection Regulation issued by the Information Commissioner<\/a><\/li>\n<li><a href=\"https:\/\/www.rsaconference.com\/videos\/virtual-session-gdpr-without-the-hype\" target=\"_blank\">Virtual Session: GDPR without the Hype<\/a><\/li>\n<li><a href=\"https:\/\/techblog.bozho.net\/gdpr-practical-guide-developers\/\" target=\"_blank\">GDPR &#8211; A practical guide for developers<\/a><\/li>\n<li><a href=\"https:\/\/www.econsultancy.com\/blog\/69256-gdpr-how-to-create-best-practice-privacy-notices-with-examples\" target=\"_blank\">How to create best practice privacy notices (with examples)<\/a><\/li>\n<li><a href=\"http:\/\/www.gamingtechlaw.com\/2016\/04\/privacy-impact-assessment-gdpr.html\" target=\"_blank\">When and how shall a privacy impact assessment be run?<\/a><\/li>\n<\/ul>\n<h2>In conclusion<\/h2>\n<p>Here&#8217;s the thing: GDPR isn&#8217;t designed to stop businesses from communicating with customers. Not at all.<\/p>\n<p>The idea is simple:<\/p>\n<ul>\n<li>Don\u2019t assume people want to hear from you just because they downloaded an ebook from your website.<\/li>\n<li>Don\u2019t email users about your business unless they opted in and gave you permission to do so.<\/li>\n<li>Don\u2019t send them irrelevant information that they didn\u2019t ask for.<\/li>\n<li>Make sure all data-driven marketing you do complies with GDPR<\/li>\n<\/ul>\n<p>In fact, GDPR is an opportunity to grow your marketing list with quality leads.<\/p>\n<p>Think about it this way: when users land on your website and they like what they see, then they\u2019ll gladly opt-in to receive further information from you. And then you\u2019ll have a marketing list of qualified leads \u2013 people who are genuinely interested in your business, your products and services, and your content. Isn\u2019t that what makes a marketing list valuable?<\/p>\n<p>Heart Internet is in the process of implementing GDPR across our platforms.  You&#8217;ll start seeing changes in the coming months.  For more information, <a href=\"https:\/\/www.heartinternet.uk\/blog\/gdpr-and-heart-internet-frequently-asked-questions\/\" target=\"_blank\">GDPR and Heart Internet: Frequently Asked Questions<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.<\/p>\n","protected":false},"author":2,"featured_media":18210,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28,29],"tags":[],"class_list":{"0":"post-18206","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-your-business","8":"category-your-website"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A guide to GDPR and what to do to prepare - Heart Internet<\/title>\n<meta name=\"description\" content=\"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A guide to GDPR and what to do to prepare - Heart Internet\" \/>\n<meta property=\"og:description\" content=\"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\" \/>\n<meta property=\"og:site_name\" content=\"Heart Internet\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/heartinternet\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-04-05T11:30:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"533\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Eliot Chambers-Ostler\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@heartinternet\" \/>\n<meta name=\"twitter:site\" content=\"@heartinternet\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Eliot Chambers-Ostler\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\"},\"author\":{\"name\":\"Eliot Chambers-Ostler\",\"@id\":\"https:\/\/heartblog.victory.digital\/#\/schema\/person\/58ed7f27cc0f3ab6e69135742a5eee28\"},\"headline\":\"A guide to GDPR and what to do to prepare\",\"datePublished\":\"2018-04-05T11:30:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\"},\"wordCount\":2202,\"commentCount\":11,\"publisher\":{\"@id\":\"https:\/\/heartblog.victory.digital\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg\",\"articleSection\":[\"Your Business\",\"Your Website\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\",\"url\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\",\"name\":\"A guide to GDPR and what to do to prepare - Heart Internet\",\"isPartOf\":{\"@id\":\"https:\/\/heartblog.victory.digital\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg\",\"datePublished\":\"2018-04-05T11:30:06+00:00\",\"description\":\"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage\",\"url\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg\",\"contentUrl\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg\",\"width\":800,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.heartinternet.uk\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A guide to GDPR and what to do to prepare\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/heartblog.victory.digital\/#website\",\"url\":\"https:\/\/heartblog.victory.digital\/\",\"name\":\"Heart Internet\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/heartblog.victory.digital\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/heartblog.victory.digital\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/heartblog.victory.digital\/#organization\",\"name\":\"Heart Internet\",\"url\":\"https:\/\/heartblog.victory.digital\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/heartblog.victory.digital\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/02\/HeartInternet_Logo_Colour.webp\",\"contentUrl\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/02\/HeartInternet_Logo_Colour.webp\",\"width\":992,\"height\":252,\"caption\":\"Heart Internet\"},\"image\":{\"@id\":\"https:\/\/heartblog.victory.digital\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/heartinternet\/\",\"https:\/\/x.com\/heartinternet\",\"https:\/\/www.linkedin.com\/company\/heart-internet-ltd\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/heartblog.victory.digital\/#\/schema\/person\/58ed7f27cc0f3ab6e69135742a5eee28\",\"name\":\"Eliot Chambers-Ostler\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/heartblog.victory.digital\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/08\/cropped-Eliot-96x96.jpg\",\"contentUrl\":\"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/08\/cropped-Eliot-96x96.jpg\",\"caption\":\"Eliot Chambers-Ostler\"},\"url\":\"https:\/\/www.heartinternet.uk\/blog\/author\/eliot-chambers-ostler\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A guide to GDPR and what to do to prepare - Heart Internet","description":"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/","og_locale":"en_GB","og_type":"article","og_title":"A guide to GDPR and what to do to prepare - Heart Internet","og_description":"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.","og_url":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/","og_site_name":"Heart Internet","article_publisher":"https:\/\/www.facebook.com\/heartinternet\/","article_published_time":"2018-04-05T11:30:06+00:00","og_image":[{"width":800,"height":533,"url":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg","type":"image\/jpeg"}],"author":"Eliot Chambers-Ostler","twitter_card":"summary_large_image","twitter_creator":"@heartinternet","twitter_site":"@heartinternet","twitter_misc":{"Written by":"Eliot Chambers-Ostler","Estimated reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#article","isPartOf":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/"},"author":{"name":"Eliot Chambers-Ostler","@id":"https:\/\/heartblog.victory.digital\/#\/schema\/person\/58ed7f27cc0f3ab6e69135742a5eee28"},"headline":"A guide to GDPR and what to do to prepare","datePublished":"2018-04-05T11:30:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/"},"wordCount":2202,"commentCount":11,"publisher":{"@id":"https:\/\/heartblog.victory.digital\/#organization"},"image":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg","articleSection":["Your Business","Your Website"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/","url":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/","name":"A guide to GDPR and what to do to prepare - Heart Internet","isPartOf":{"@id":"https:\/\/heartblog.victory.digital\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage"},"image":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg","datePublished":"2018-04-05T11:30:06+00:00","description":"GDPR is the biggest shake up in data protection for decades. Discover what GDPR will change, what you will need to do, and how you can start preparing for its impact.","breadcrumb":{"@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#primaryimage","url":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg","contentUrl":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2018\/03\/tomasz-frankowski-198764-unsplash.jpg","width":800,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.heartinternet.uk\/blog\/a-guide-to-gdpr-and-what-to-do-to-prepare\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.heartinternet.uk\/blog\/"},{"@type":"ListItem","position":2,"name":"A guide to GDPR and what to do to prepare"}]},{"@type":"WebSite","@id":"https:\/\/heartblog.victory.digital\/#website","url":"https:\/\/heartblog.victory.digital\/","name":"Heart Internet","description":"","publisher":{"@id":"https:\/\/heartblog.victory.digital\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/heartblog.victory.digital\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/heartblog.victory.digital\/#organization","name":"Heart Internet","url":"https:\/\/heartblog.victory.digital\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/heartblog.victory.digital\/#\/schema\/logo\/image\/","url":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/02\/HeartInternet_Logo_Colour.webp","contentUrl":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/02\/HeartInternet_Logo_Colour.webp","width":992,"height":252,"caption":"Heart Internet"},"image":{"@id":"https:\/\/heartblog.victory.digital\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/heartinternet\/","https:\/\/x.com\/heartinternet","https:\/\/www.linkedin.com\/company\/heart-internet-ltd"]},{"@type":"Person","@id":"https:\/\/heartblog.victory.digital\/#\/schema\/person\/58ed7f27cc0f3ab6e69135742a5eee28","name":"Eliot Chambers-Ostler","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/heartblog.victory.digital\/#\/schema\/person\/image\/","url":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/08\/cropped-Eliot-96x96.jpg","contentUrl":"https:\/\/www.heartinternet.uk\/blog\/wp-content\/uploads\/2025\/08\/cropped-Eliot-96x96.jpg","caption":"Eliot Chambers-Ostler"},"url":"https:\/\/www.heartinternet.uk\/blog\/author\/eliot-chambers-ostler\/"}]}},"_links":{"self":[{"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/posts\/18206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/comments?post=18206"}],"version-history":[{"count":0,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/posts\/18206\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/media\/18210"}],"wp:attachment":[{"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/media?parent=18206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/categories?post=18206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.heartinternet.uk\/blog\/wp-json\/wp\/v2\/tags?post=18206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}