GDPR, In Plain English
The UK General Data Protection Regulation and the Data Protection Act 2018 govern how any organisation collects, stores and uses information about living people. Most of the questions we are asked are not really legal questions at all — they are practical marketing questions wearing a legal hat. The answers below are the ones we give clients most often. They are general guidance, not legal advice, and if your situation is complex you should take advice from a solicitor or speak to the Information Commissioner's Office directly.
What actually counts as personal data?
Anything that can identify a living person, on its own or when combined with something else you hold. Names and email addresses are obvious. Less obvious are IP addresses, mobile advertising identifiers, cookie IDs, photographs, CCTV footage, vehicle registrations and even a job title at a small company where only one person holds it. If you could work out who someone is from it, treat it as personal data.
Do we need consent for everything?
No, and this is the single most common misunderstanding we come across. Consent is one of six lawful bases. The others are contract, legal obligation, vital interests, public task and legitimate interests. If someone buys from you, you do not need their consent to process their order — you are performing a contract. If you are keeping accounting records, you are meeting a legal obligation. Consent matters most for electronic marketing, non-essential cookies and anything a person would not reasonably expect.
What makes consent valid?
It has to be freely given, specific, informed and unambiguous, and given by a clear affirmative action. Pre-ticked boxes do not work. Bundling marketing consent into your terms and conditions does not work. Burying it in a privacy policy nobody reads does not work. You also have to keep a record of who consented, when, and to what, and withdrawing consent must be as easy as giving it.
Can we email businesses without consent?
Corporate subscribers — limited companies, LLPs and public bodies — can be emailed under the soft opt-in and legitimate interests route, provided the message is relevant to their role, you identify yourself clearly and you give an unsubscribe option in every message. Sole traders and partnerships are treated as individuals, so the rules are stricter. Either way, the moment someone opts out you must stop.
What is the soft opt-in?
If somebody bought from you, or negotiated to buy from you, you may market similar products and services to them without fresh consent, as long as you offered an opt-out at the point of collection and you offer one in every message afterwards. It does not cover lists you have bought, scraped or been passed by a third party.
How long can we keep data?
For as long as you have a genuine reason, and no longer. There is no single number in the legislation. Set a retention period for each category of data, write it down, and actually delete things when the period expires. Customer transaction records typically follow the six-year accounting requirement. A cold marketing list that has not been opened in three years is doing you no good and is a liability.
What rights do people have?
Access to a copy of their data, rectification of anything inaccurate, erasure in certain circumstances, restriction of processing, data portability, objection to processing including profiling, and an absolute right to object to direct marketing. You normally have one calendar month to respond, free of charge.
What about our website, analytics and ads?
Non-essential cookies, including analytics and advertising tags, require consent before they fire. That is why a compliant banner has to block those scripts until the visitor agrees rather than simply announcing that cookies are in use. Mobile advertising identifiers used in geo-fencing campaigns are also personal data, which is why device-level opt-out matters.
Who is the controller and who is the processor?
You decide why and how the data is used, so you are the controller. Suppliers acting on your instructions — an email platform, a hosting provider, an agency running your campaigns — are processors. Every processor relationship needs a written agreement setting out scope, duration, security and deletion.
What happens if there is a breach?
Assess it immediately. If it is likely to result in a risk to people's rights and freedoms, report it to the Information Commissioner's Office within 72 hours of becoming aware. If the risk is high, tell the affected individuals too. Record every breach internally, even the ones you decide not to report.
How we handle this at Corrie D Marketing
We act as a processor for the campaign, website and email work we deliver, we sign a data processing agreement with every client who needs one, and we build consent handling into the websites we produce rather than bolting it on afterwards.
