Keyboard with Data Protection Officer key

With GDPR (General Data Protection Regulation) day approaching, the number of vacancies in roles as a Data Protection Officer (DPO) has reportedly increased by over 700% in the last two years. Data protection professionals are finding that their skills and knowledge are suddenly invaluable and in high demand compared to a few years ago. VinciWorks’ guide to being a DPO will give you a clearer idea of what is required from a DPO, helping you appoint the right person for the role. The guide will also help those being promoted to the role of DPO gain an understanding of what is required of them under GDPR.

Free download

Continue reading

Social media screen on a smart phone

Often used as a free marketing tool, and with some staff having thousands of personal followers on social media platforms such as Twitter, Facebook and LinkedIn, social media is becoming an important cog in many companies’ marketing campaigns. Here is some guidance on what GDPR requires of us when using social media for marketing purposes.

Read: The digital marketing guide to GDPR

GDPR and social media

In recent years social media has become a central platform for communication between businesses and customers or clients. Since social media tools all work with personal data, those using them for business purposes must take data protection regulations into account. But this shouldn’t deter you from using these tools: used correctly, social media can be an excellent form of communication and marketing. The important thing is to make sure you keep your social media platforms secure and that you handle all customers’ data appropriately.

What does GDPR mean for social media marketing?

When considering how to best manage social media marketing, it’s important to keep data protection rules and best practice in mind. It is unlawful to collect more data than you need, and you need to be able to justify any information you collect. But social media marketing can actually be better for marketing and for GDPR compliance than older methods of email lists and marketing, which are not as effective as they once were. Connecting with potential leads through social media, sharing relevant content and contact details can be much more effective and targeted than blunt force direct marketing, and when done correctly, potentially less problematic on a GDPR front.

Who does the legislation apply to?

GDPR does not apply to individuals using social media for their own purposes, but does apply to individuals acting as sole traders or organisations who use social media in the following ways:

  • Posting personal data on a website
  • Downloading and using personal data from a website
  • Running a website which allows others to post comments or other content about people

Continue reading

This year has already been significant in terms of compliance breaches by some of the world’s largest companies. And it’s not just business who’ve seen major failings recently, as we review recent compliance scandals in this years’ Compliance Update: 1 April Special.

Easter bunny fined for sanctions breaches

The Easter Bunny has been fined a record £21m by the Office of Financial Sanctions

Implementation (OFSI) for illegally importing up to 40 million Easter eggs. The eggs were illegally imported from Never Never Land in violation of international sanctions against the rogue state, with The Easter Bunny allegedly committing serious acts of bribery during the import of the eggs to cover up their origins.

Never Never Land continues to remain under severe international sanctions due to its failure to adhere to data protection laws and the continued WMD programme of dictator Captain Hook. With recent EU legislation expanding the scope of sanctions compliance, all organisations are being reminded to ensure their compliance is up to speed and they are not doing business with designated persons such as Captain Hook.

Free sanctions policy template

Continue reading

Les utilisateurs peuvent changer la langue de leur cours en cliquant sur un bouton
Les utilisateurs peuvent changer la langue de leur cours en cliquant sur un bouton

Le cours en ligne Règlement Général sur la Protection des Données de VinciWorks, GDPR: Confidentialité au travail (GDPR: Privacy at Work), avec d’autres cours dans la suite de formation VinciWorks GDPR, est maintenant disponible en français. Le cours combine la dernière en matière de politique et de droit avec les lignes directrices des meilleures pratiques. Il fournit des scénarios du monde réel, des fonctions interactives et des questions de révision pour tester la compréhension des points clés. En complétant ce cours, les utilisateurs apprendront comment se conformer aux lois sur la protection des données pour leur rôle spécifique dans l’organisation. La formation en ligne est basée sur le Règlement général sur la protection des données (RGPD).

Alors que le GDPR entrera en vigueur dans toute l’Europe le 25 mai 2018, la France a déjà promulgué une législation pour préparer le nouveau régime de protection des données.

démo le cours

Continue reading

GDPR training in French
VinciWorks’ GDPR training can easily be viewed in multiple languages at the click of a button

VinciWorks’ online GDPR course, GDPR: Privacy at Work, together with the other courses in VinciWorks’ GDPR training suite, is now available in French. The course combines the latest in policy and law with best practice guidelines. It provides real-world scenarios, interactive features and review questions to test understanding of key points. By completing this course users will learn how to comply with data protection laws for their specific role in the organisation. The online training is based on the General Data Protection Regulations (GDPR).

While GDPR will be coming into force across Europe on 25 May 2018, France has already enacted some legislation to prepare for the new data protection regime.

Demo GDPR training in French

Continue reading

GDPR webinar banner

Should we be deleting our whole email marketing list? How much can you actually be fined for a GDPR offence? In this webinar, Director of Course Development Nick Henderson and Yehuda Solomont explored the myths surrounding GDPR and helped separate the facts from the fiction. The webinar is based on our GDPR Mythbusters blog series that we are publishing in the lead up to GDPR day.

The webinar focused on the following GDPR myths

  • You’ll be fined 4% of global turnover for your first GDPR offence
  • GDPR requires you to delete all of a person’s data if they ask
  • You can’t send marketing emails anymore
  • HR policies and practices won’t be affected
  • No one will know if I don’t comply with GDPR
  • Compliance will cost you business

Watch now

Continue reading

Calendar showing when GDPR is in force
The EU wide General Data Protection Regulation comes into full force on 25 May

VinciWorks GDPR Training Course

With so much GDPR compliance to get done, figuring out a training schedule for staff can seem like an impossible nut to crack. That’s why VinciWorks have made it as easy as possible to figure out what staff need trained on what, when and how often.

VinciWorks’ flagship online training course, GDPR: Privacy at Work does the hard work for you with a unique course builder and training modules specifically tailored to every role in an organisation. With thousands of possible course combinations available, it’s the sure-fire way to get the right training in front of the right staff at the right time. Our GDPR training suite provides further GDPR courses and knowledge checks.

VinciWorks has developed an entire suite of helpful GDPR resources to guide your organisation on its way to compliance. For a more in-depth look at training requirements for different departments and job roles, review our suggested schedule below that includes what resources to roll out post-GDPR to assess comprehension and understanding.

Continue reading

People receiving marketing emails from their smart phones

How to make your digital marketing GDPR compliant:

Due to the requirements under GDPR for obtaining consent to collect and process data, one of the departments in your organisation most likely to be affected by the reguations are marketing professionals. 

Four years into GDPR, GDPR fines are bigger than ever before and always growing: there was a 113% increase in GDPR fines between July 2020 to July 2021, and penalties have grown as well, from 130.69 million in July 2020 to 293.96 million in July 20201. Many of the biggest fines were marketing related, including a €746m fine doled out to Amazon for compiling data on customers and a €225m fine to WhatsApp for failing to provide information in clear and plain language. 

Using information that is publicly available doesn’t mean you’re off the hook: agricultural conglomerate Monsanto were fined €4,000,000 for maintaining records of activists, since they were essentially tracking them in an ongoing way without informing them.

As a marketer who collects information, whether it’s information that’s publicly available or not, it’s more important than ever to make sure you’re doing so in a GDPR-compliant way. The guidance given in this blog will help your marketing team fully comply with GDPR.

Read: GDPR: 10 things to do now

Assessment: how ready are you for GDPR?

Marketing lists

In June 2017, JD Weatherspoons felt the best way for its digital marketing to become compliant with GDPR was to delete its entire marketing list. While this may be the favourable approach for the pub chain, GDPR certainly does not require businesses to delete their entire marketing list.

Organisations can provide customer details to third parties only if they made this clear when the information was being collected. Records of how consent was obtained must be clear if the list is being used for making marketing calls, texts, or emails.

Continue reading

Ringbinder full of donations
Charitable donations are often used as a conduit for making bribes

Corporate Giving Policy

While many large corporations strive to support worthy charitable causes across the world as well as the local community, it is important that staff are aware of the types of donations that are acceptable. It is also important that charitable donations made go directly to the charity and are not benefited by a political party or campaign. Charitable donations are often used to make bribes. Therefore, having a charitable and political donations policy in place will help ensure that donations to charities are made appropriately and don’t fall into the wrong hands.

Company Charity & Political Donations Policy Template<

VinciWorks’ charitable and political donations policy can be downloaded for free by clicking the button below. The template can easily be edited to suit your organisation’s industry and procedures. As well as creating a policy, it is also important staff undergo the appropriate anti-bribery training to allow them to identify suspicions of bribery.

Download policy template

Continue reading

GDPR countdown
Failure to comply with GDPR, coming into force on 25 May, can bring about huge fines, making compliance a must

How many days are there until the General Data Protection Regulation?

VinciWorks is counting down the days until GDPR comes into force, providing a host of resources such as online GDPR training, policy templates and helpful guides. We have also created a GDPR countdown to help you keep track of how long your business has to prepare.

Countdown to GDPR

The GDPR resource page

VinciWorks has created a GDPR resources page that includes all the tools and resources you will need to prepare for GDPR.

The GDPR resource page includes: