GDPR? The what, the why and the how

November 26, 2018
GDPR? The what, the why and the how

Webflow has gone through some major changes over the years. With the ongoing rollout of features like the visual CMS, Webflow Localization, and native ecommerce, the platform itself keeps getting more powerful for developers and designers alike.

Although most of the attention goes to these shiny new updates, the European Union released a regulation back in May 2018 called the General Data Protection Regulation (GDPR). This has pretty serious ramifications for website users, developers and designers. If there is even a small chance that a user from Europe will visit your site then you need to know exactly what this GDPR thing is all about.

What is GDPR?

GDPR is a set of rules designed to give EU citizens more control over their personal data — how it's collected, stored, and processed. These rules need to be complied with on any given website otherwise there are pretty substantial fines applicable. Cookies are one of the most common ways websites end up needing to think about GDPR, but the regulation covers personal data handling more broadly than just cookies.

What is GDPR Compliance?

In plain terms, compliance means following the rules the EU has set out in the GDPR. To be compliant, you will need to ensure the following:

  • Users viewing your site will have to have a choice whether they will allow you to use cookies
  • They will need to give consent to their information being captured on a contact form
  • They will need to have greater access to their data. They will need to be able to modify the info or delete it if needed.

Going forward - in order to do any business within the EU or with a company based in the EU, these above criteria will need to be met.

How Do I Get Compliant?

At Pathfind Media, we have placed a lot of emphasis on GDPR and have taken the time to ensure that our website is up to speed with all the GDPR regulations. We build all our websites in Webflow and it's really important we achieve compliance, as our client base isn't limited by country. Getting there usually comes down to a handful of trusted tools working together rather than one single fix. Here's what we typically reach for:

  • Elfsight - a cookie consent banner widget you can embed on your site, giving visitors the option to control whether you use cookies to enhance their experience
  • Iubenda - this scans your whole website and takes you through a step-by-step wizard to help you achieve compliance. It will help you set up a Privacy Notice (which is very important), a privacy tools page (where users can delete or modify their data if needed), and a terms and conditions page
  • For forms, the right tool depends on the build - we've used Webflow Forms, Jotform, Elfsight's form widget, and Zoho Forms across different sites. Whichever one you use, the important part is building in an explicit consent checkbox so visitors can choose to have their information stored

As you can see, the value of GDPR compliance cannot be overstated. What we need to stress is that this article is just a helpful guide to being compliant. It is not the complete guide and we cannot promise you that your site will be compliant if you follow the above steps.

To be completely compliant - you need to get legal advice. There are a lot of fantastic firms now offering GDPR compliance as a service, as it is a legal issue. CYBER1 Solutions (formerly DRS) is one such company offering GDPR compliance support in South Africa.

In saying that, we definitely hope this has helped and cleared up any confusion around the GDPR.

See you online!

Back to Blog