If you use a digital platform to gather information or communicate with customers, you need to understand the GDPR.
The EU passed a privacy law giving all EU citizens more control over their personal data, called the General Data Protection Regulation (GDPR).
In this post, we break down what the GDPR is, what it aims to achieve, how you need to implement it, and what it means for tourism operators, specifically Wherewolf customers.
What is GDPR?
This significant EU privacy law gives European citizens more rights to direct how you manage their personal data, including:
- The right to be forgotten
- The right to data portability
- The right to object to profiling
- The right to restrict or object to how you process their data
Importantly, the GDPR regulates both how you collect data and how you store or process it. Any individual or organisation that captures or processes the personal data of EU individuals must abide by this law, regardless of whether you or your organisation is based in the EU.
In short, it’s about being transparent and letting individuals exercise choice and control over their personal data. On the Wherewolf platform, this means:
- Users can easily understand what T&Cs they’re agreeing to
- Guests can decide whether to opt in to mailing lists
- Guests can control their stored data, including the ability to review, update, or delete it
What is “personal data”?
Personal data is any information that can identify an individual, such as name, email, address, or telephone number. So the typical information you gather for a booking, like name, passport number, and birth date, all counts as personal data.
Who is affected?
In short, pretty much all of us. If you’ve ever had an EU citizen book with you, and therefore collected personal information from them, you need to comply with GDPR.
Four simple ways to become GDPR compliant
- Long-winded, confusing terms and conditions are a thing of the past. Customers should easily understand what they’re opting in for, so you need to be transparent. While you might collect an email address to send a booking confirmation or e-ticket, you must also collect specific consent before contacting them with an email campaign. Then, once you’re sending campaigns, make it easy for every guest to unsubscribe.
- Your customers have the right to access their own personal data at any time, and to easily request that you erase it.
- Collect data in an easily transferable format, so you can handle access requests quickly and easily. You also need to protect it adequately, both from unauthorised access and from disasters such as a data centre fire.
- Every service and tool your business uses to collect, store, and process guest data needs to comply with the legislation.
For points 2 through 4, that means us, Mailchimp, any booking reservation site you integrate with, and everybody else who stores, handles, or processes your clients’ data.
Your business must ensure it gathers data legally. In addition, any individuals, businesses, or organisations that collect or manage that data on your behalf must protect it from misuse and exploitation, or face penalties for failing to do so.
Wherewolf GDPR Compliance
As a Wherewolf customer, you’ve chosen us to be a data processor of your clients’ personal data. The good news: we’re GDPR compliant, and we ensure all our services comply with its provisions for every one of our clients. The GDPR is an important step in protecting the fundamental privacy rights of European citizens, and it also raises the bar for data protection, security, and compliance across the industry. You can read more about Wherewolf’s GDPR implementation here and the data processing agreement here.
To summarise
If a European citizen has ever booked on your trip, GDPR affects your company. But rather than treating this as another painful process, treat it as an opportunity to build a more trusting relationship with your guests. When users clearly understand what you’ll do with their data, they’re more likely to share it with you. So explain the benefits, such as the more personalised experience you can offer as a result.
Want to read more? Here are some sites we found helpful:
- How GDPR will impact the travel sector
- How to comply with GDPR: recommendations for the travel industry
- How does GDPR impact the tourism marketing industry?
- ICO guide to the General Data Protection Regulation
Got questions? Reach out to our team anytime.