“GDPR very significantly increases the obligations and responsibilities for organisations and businesses in how they collect, use and protect personal data. At the centre of the new law is the requirement for organisations and businesses to be fully transparent about how they are using and safeguarding personal data, and to be able to demonstrate accountability for their data processing activities.”
The implementation of GDPR addresses the storage of customer data. Our position at In1 has always been that a processor should only store relevant information for as long as it is useful. Less form filling at the booking / purchase stage improves the conversion rate. Additionally, it reduces the obligations under GDPR as GDPR is about the protection of personally identifiable data. Less is better and there are many simple steps which can be taken to make sure such data is not Personally Identifiable.
There is no longer a need, for example, to retain the postal address of a customer. Why bother? Few use postal services to communicate and retaining this data would simply increase the obligation to protect it. In fact, keeping data for no good reason breaches GDPR. A processor is mandated to retain the data required to service a transaction. Nothing more. Similarly, with phone numbers, is there a need for them after the guest has departed? Perhaps for a short period, in the case of something being left behind in the room. There is no need, say, more than 30 days after departure. In addition, phone numbers (almost certainly in the case of mobile) makes the data more likely to be personally identifiable. GDPR is about the security of personally identifiable information, so we remove the personally identifiable attributes as soon as possible. Less is better.
Credit/Charge card data has long been subject to stringent control. All In1 technologies, both partner and guest facing, are SSL Secured and PCI DSS Compliant. We never store or supply Credit Card CVV’s as this would be in breach of the Credit Card Merchant agreement and result in serious fines. The moment a transaction is complete, we obfuscate Credit Card information. Where servers and services comply with PCI/DSS, they must comply with security of access, meeting with best technical practice, a significant part of the obligation under GDPR. When customer data is stored, it is kept safe and secure.
GDPR implemented correctly can enhance business and should be approached with that in mind.
Build customer trust
Improve brand image and reputation
Improve data governance
Improve information security
Improve competitive advantage
Although there has been a certain degree of scare mongering to date, the objective of GDPR is to advise and improve data security. Those that consciously and deliberately abuse the data security of their customers and fail to implement corrective actions, or cease their abuse once advised or warned, can rightly expect a degree of censure. Those who do not respect customer security and confidentiality endanger online commerce and customer trust and should rightly be brought to heel.
Those that work to comply with GDPR and follow guidance or advice to improve their processes should not expect to be punished or fined. This is what the Data Protection Commissioners across Europe have stated as their objective. They wish to advise, educate and improve data security, not penalise genuine businesses working toward GDPR compliance.