'Permission to personalise' - privacy policy and data acquisition for the purposes of personalisation

Privacy has been a hot topic recently. With the formal adoption of the General Data Protection Regulation (GDPR) and the revision of the e-Privacy Directive (‘the Cookie law’), there has never been a better time to talk ‘privacy’ and compliance.
In essence the new legislation considers all data now ‘personal’ whether it directly identifies an individual or not. Whilst the legislation aims to strengthen the individual’s control over their personal data by introducing new rights (such as the right to data portability and the right to be forgotten), it presents challenges to organisations, which will need to introduce new ‘privacy-centered’ policies and processes in order to comply with their obligations.
All EU companies have two years to prepare and fully comply but there are steps you can take now, especially if you are one of the 30%, who stated in a study done by E-Consultancy and Adobe, that Personalisation is their top priority for 2016.
Personalisation initiatives and your Privacy policy
Indeed, clients often ask us about the compliance implications when they consider adoption of sophisticated analytics in the pursuit of improved customer experience through personalisation.
Below are our guiding principles when writing a Privacy Policy for your personalised application or website.
The bundled consent in your Ts&Cs won’t cut it
Context is very important. Studies suggest that customers are relatively comfortable about anonymised data collection and they are relatively happy for companies to utilise their data if they can see service benefits to themselves. However, collection of potentially more sensitive information like location data has much lower acceptance rates.
To gain consent and properly comply with the upcoming legislation you should adopt an opt-in approach, instead of asking people to agree to the generic Terms and Conditions, which are usually difficult to read, poorly understood and hard to find on most websites.
Permission to personalise
A better approach to gaining consent would be to summarise your Tracking, Data collection and Personalisation activities in a separate, specific and easy to read policy.
Allowing individuals to opt-in and agree to personalisation could have a positive impact for both you and your customers. We call this approach ‘Permission to Personalise’.
On one hand, it allows organisations to obtain more accurate data and to be open and transparent about their initiatives; on the other, it puts the customer in the driver's seat to gain better understanding about the trade-offs between personal data and the value they are getting in return, thus making an informed decision about their choice.

Language and presentation
Make your policy statements ‘human’ and easy to understand. Write in a way that is compliant but also friendly to the user. Explain, clearly, what data you collect, how it works and what are the benefits of opting in. Provide an area on the website where people can manage their data consent settings and explain how to opt-out and request their data from your organisation.
Don’t underestimate the language and design of the page. If customers can see and understand the benefits of data collection and personalisation they are more likely to give you their consent and help to ensure that the data in their profile is accurate and useful.
A side note on third parties & privacy
One aspect often overlooked when dealing with data and Privacy is the involvement of third parties - partners, suppliers, marketing and creative agencies. Infringements made by a vendor is the responsibility of the ‘data owner’ and penalties would be applied to the organisation that released the data in the first place, regardless of how robust its internal processes are. This means that organisations must be confident that such third party vendors have the required knowledge and procedures in place to work with data and comply to relevant standards.
You may wish to include a section in your policy about third-party data handling, covering what kind of information you may share with third parties and how is that being used.



