Data protection (RGPD) on your real estate website
Few times has a European Regulation been discussed as much as Regulation (EU) 2016/679 at the opening of university town
and of the Council, on data protection.
Its effective application on May 25, 2018 , coincides with the scandal of the leakage of data from users of platforms such as Facebook and the improper use of the personal information of thousands of users in political campaigns.
However, this Law was prepared 2 years before the launch of park view city (it came into force on May 25, 2016), so its effective implementation should not mean major changes in companies, should it?
It depends on how the personal data information has been requested, both offline and online.
The fact that a large part of the contacts by ichs town islamabad
are generated through online channels does not mean that the Regulation is valid only on these supports.
In the last days / weeks, you will have seen messages on many web pages, social networks and emails, warning of changes in the privacy policy of the company that sent the message.
Google, Facebook, faisal hills islamabad , WordPress ,… even though they are companies from outside the European Union, they have had to modify their legal texts and the way to manage users' personal data.
The penalties for non-compliance include written warnings, audits and fines of up to 20 million euros or 4% of the turnover of the previous year
WHAT IS THE GENERAL DATA PROTECTION REGULATION
The RGPD is the General Data Protection Regulation, a European level regulation that applies to all companies that operate in the European Union and that handle personal data.
The regulations indicate that the data can only be processed if there is a legal basis for it, that is, when:
- the interested party expresses the consent to the processing of their personal data for one or more specific purposes.
- the processing is necessary to execute a contract to which the interested party is a party or to take prior measures at the request of the interested party.
- the processing is necessary for the controller to fulfill a legal obligation to which it is subject.
- the processing is necessary for the protection of the vital interests of the interested party or another natural person.
- the processing is necessary to perform a task in the public interest or by exercising the official authority held by the controller.
- the treatment is necessary to safeguard the purposes of the legitimate interests of the controller or a third party except when these interests are overridden by the fundamental rights or freedoms of the interested party.
THE CONSENT
It is the key term of this new regulation and what sets it apart from the LOPD.
Before a user sends personal data, responsible for the processing of data must ensure that the interested party has expressed consent.
This consent must be "freely given, specific, informed and unequivocal", expressed in "clear and simple" legal language. In addition, it must be proven that the processes comply with the standards and are respected in each case.
Previously, the LOPD allowed the use of the "unsubscribe" shortcut to make data collection legitimate.
Now, consent must be express, free and clear.
New rights for users
The regulation also integrates two new rights for interested parties:
- the right to be forgotten , which requires data controllers to alert subsequent recipients of requests to delete data and
- the right to data portability , which allows data subjects to request a copy of their data in a common format.
These two rights will make it easier for users to request that any stored information be removed or that the information collected be shared with them. Specific:
- Obtain details of the treatment of your data by an organization or company.
- Obtain copies of personal data.
- Request to correct incorrect or incomplete data, or even delete it.
- Obtain your data from one organization and request that it be transferred to another.
- Oppose the processing of your data.
- Do not undergo automated decision making, including profiling.
Differences between the Organic Data Protection Law and the Personal Data Protection Regulation, via J ose Facchin
Let us now look at the actions necessary to accommodate the business to the requirements of the GRPD:
GDPR AND REAL ESTATE WEBSITE
If you have a real estate website and want to adapt to the new European Data Protection Law, you just have to follow the next steps.
EXPOSE THE LEGAL TEXTS
The legal notice, the privacy policy, the customer data protection policy and the cookie policy must be accessible on the web, not necessarily separately, but with all the information on data processing.
A good place to put it is in the footer, so it will be visible on all pages.
INFORM DATABASE CONTACTS
To the people who appear in your databases and who have not expressly consented to the data processing, a statement must be sent with the request to obtain that consent.
Through an email, you must let them know that you have their personal data and what you will use them for:
- database creation,
- email marketing campaigns,
- supply and demand alerts,
- automated marketing ,
- share the information with third companies.
And in that communication request consent.
RECEIVE YOUR EXPLICIT CONSENT FOR EACH PURPOSE
Each user must give the go-ahead, explicitly and unequivocally for each specific purpose. If until now real estate agencies were satisfied with the tacit consent of clients to use their personal information, explicit confirmation is now mandatory.
The user must take conscious action to accept the privacy conditions set by the company receiving their data.
In web forms, such as:
- those that are placed in the real estate files,
- those aimed at buyers,
- those of recruitment of owners,
- the company's contact information,
- product and / or service landings,
- those of subscription to blog, newsletters, ..
The consent request box must be unchecked and clear information about the company's privacy policy must be displayed.
Example of a property information request form on a real estate website, in which the express consent of the user is requested, for each purpose of the communication.
MAKE COMMUNICATIONS TO OBTAIN SUCH CONFIRMATION
Real estate agents that do not obtain the unequivocal consent of their clients to continue using their personal data will be forced to carry out campaigns to promote such confirmation.
The aim is to obtain consent explicitly and specifically for each of the purposes.
CLEAN UP CONTACT DATABASES
If the consent is not obtained, the real estate agency will be forced to purify its databases, eliminating the contacts that have not explicitly shown their consent for the company to use their personal information.
FILE REGISTRATION
The Data Protection Agency recalls the obligation to notify files, it is replaced as of May 25, 2018 by preparing a record of treatment activities that must contain the information indicated in article 30 of the aforementioned Regulation.
GDPR AND EMAIL MARKETING
If you carry out email marketing campaigns , you will have to work with data, so there are some keys to keep in mind:
- The consent must be express and the checkboxes cannot be marked by default, but the user will have to mark them expressly (conscious action).
- The request for consent must be separated from other terms and conditions.
- Users must be provided and informed of the revocation of said consent.
- Systems must be maintained that allow the user to manage the preferences of the communications as well as the unsubscribe from them.
GDPR AND INFORMATION SYSTEMS
If you use a contact management program (CRM) and / or a database, whose information is stored in a place out of your reach, ask your provider to sign you a document that includes this circumstance.
It is necessary to regulate the contractual relationship between both parties regarding the treatment of personal data, between the service provider (Data Processing Manager) and the company (Data Holder), both recognizing the validity of the clause of Data Protection.
Hubspot study on the opinion of users towards companies and their personal data management
CONSEQUENCES OF THE RGPD FOR THE MARKETING OF REAL ESTATE
1 in 3 companies think that, when adding alerts in the contact generation channels, about data privacy, a percentage of users will not continue with the process of sending their personal data.
41% think that using user authentication systems, such as those of Facebook or Google, will be easier for them than directly requesting both data and consent from the user.
These external systems already have the express consent of the user, although in some cases, such as in payment campaigns, the advertiser must question their own privacy and data protection policy.
Half of the companies believe that their contact lists will be reduced, since not all users will respond or act to give their express consent.
Perception of the RGPD by business leaders, about the consequences on their marketing.
DOES YOUR COMPANY COMPLY WITH THE GDPR?
Real estate companies must have procedures that allow their clients and users to freely and unequivocally accept the use and treatment of their data.
Those procedures include the use of clear informative clauses to expressly express your consent, either by checking a box in the contract, order form, or on the web form.
As many different and independent consents must be requested as different purposes for the use of the data, and it must be explicit when making automated decisions, including profiling.
In the event that the real estate companies do not have express consent, they will be forced to carry out some action or campaign to achieve it, which in turn must respect the principles of the Regulations.
One of the most important consequences for companies in the sector is to analyze, legitimize and debug their databases: having a legal basis that justifies data processing and based on consent, which has been expressly provided by those interested.
QUESTIONNAIRE
This checklist makes it possible to clarify the situation in the company, although it is advisable to request a study from a specialized company, which, together with the company's security manager, can determine the degree of compliance with the regulations and the actions necessary for optimal adjustment:
- What personal data do we collect / store?
- Do we get them honestly?
- Do we have the necessary consents and are the interested parties duly informed about the specific purpose for which we will use their data?
- Were we clear and precise about that purpose and informed them of their right to withdraw consent at any time?
- Have we established these purposes clearly and unambiguously, and have we informed data subjects of their right to withdraw their consent at any time?
- Do we ensure that we do not retain data for longer than necessary and keep it updated?
- Do we protect data using an appropriate level of security based on risk?
DIAGNOSTIC TOOLS
- Self-Diagnosis Tool National Institute of Cyber Security
- Security Master Plan
- Evaluates Service (Data Protection Agency)
Replies