If you are communicating with your prospects or customers via SMS to individuals in the European Union, compliance with the General Data Protection Regulation (GDPR) is essential. The GDPR, effective since May 2018, is designed to safeguard the privacy and personal data of individuals within the EU and the European Economic Area, establishing rules and processes for businesses to follow in order to protect the interests of European citizens.
Understanding GDPR
The GDPR centralizes regulations related to data protection and privacy, imposing guidelines for businesses operating within its jurisdiction.
Steps to Ensure GDPR Compliance
When engaging in SMS communication targeted at EU citizens, it is crucial to:
Obtain Explicit Consent
According to the GDPR, explicit consent must be obtained from individuals who wish to receive text messages. When collecting phone numbers, it is essential to clearly communicate that the individual agrees to receive text messages.
When using GReminders Public Scheduling pages there is an automatic checkbox to get consent. If you are not using Scheduling and only using GReminders for SMS Client Notifications you must get consent prior through other form collection systems of your terms of service.
Consent should not be a condition of purchase or providing of services, and links to Terms of Service and Privacy Policy must be provided. Read More here
Provide an Opt-out Mechanism
Honor the “right to be forgotten” by offering customers a clear opt-out mechanism, such as an opt-out link in your text messages. Opting-out should be free and available at all times.
Typically adding “Reply STOP to opt out” for SMS is recommended. Read More here
Maintain an Updated Privacy Policy
Ensure that your Privacy Policy is explicitly stated on your website page and all subscriber collection methods. Your Privacy Policy should cover:
- How your organization collects and uses customers’ data.
- Security measures for protecting customer data, both by your brand and any data processors involved.
- Support for customers’ rights to understand and control their personal data.
By following these steps, you can navigate GDPR compliance seamlessly in your SMS communication channels.
If you have any questions please reach out to [email protected]
FAQs
What is required to comply with GDPR when sending SMS to individuals in the EU?
To comply with GDPR when sending SMS to EU individuals, you must obtain explicit consent from recipients before sending messages, provide a clear opt-out mechanism such as a 'Reply STOP to opt out' option, and maintain an updated Privacy Policy that explains data collection, usage, security measures, and customers' rights.
How can I obtain explicit consent for SMS communication under GDPR?
Explicit consent can be obtained by clearly informing individuals when collecting their phone numbers that they agree to receive text messages. For example, GReminders Public Scheduling pages include an automatic checkbox for consent. If not using Scheduling, consent must be collected through other forms before sending SMS.
What should be included in my Privacy Policy to ensure GDPR compliance?
Your Privacy Policy should explicitly state how your organization collects and uses customer data, the security measures in place to protect that data (both by your brand and any data processors), and how customers can understand and control their personal data, including their rights under GDPR.