मार्केटिंग टीमों को भेजने से पहले दो अलग-अलग कानूनी सवालों का जवाब देना होता है। GDPR व्यक्तिगत डेटा को नियंत्रित करता है। ePrivacy Directive इलेक्ट्रॉनिक संचार को नियंत्रित करता है।
GDPR व्यक्तिगत डेटा को नियंत्रित करता है: प्रोसेसिंग को वैध क्या बनाता है, व्यक्ति के क्या अधिकार हैं, और आपको क्या दिखाने में सक्षम होना चाहिए। ePrivacy Directive, Directive 2002/58/EC, इलेक्ट्रॉनिक संचार को नियंत्रित करता है, और उस निर्देश का Article 13, जैसा कि प्रत्येक सदस्य राज्य के अपने कानून में लागू किया गया है, ईमेल और SMS द्वारा अनचाही मार्केटिंग के लिए पूर्व सहमति की आवश्यकता रखता है और प्रदाता के अपने मौजूदा ग्राहकों के लिए सीमित अपवाद प्रदान करता है।
इसलिए GDPR अकेला वह साधन नहीं है जो तय करता है कि मार्केटिंग ईमेल भेजा जा सकता है या नहीं। यह पेज Official Journal टेक्स्ट का अनुसरण करता है। यह कानूनी सलाह नहीं है। ePrivacy नियम सदस्य राज्य के अनुसार भिन्न होते हैं।
GDPR एक मार्केटिंग कार्यक्रम से क्या माँगता है?
प्रोसेसिंग के लिए एक वैध आधार, और उसका प्रमाण।
व्यक्तिगत डेटा की प्रोसेसिंग तब तक प्रतिबंधित है जब तक छह आधारों में से एक लागू न हो:
Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
...
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject
(a) और (f) दोनों मार्केटिंग के लिए उपयोग किए जाते हैं, और यह चुनाव दिखने से कहीं अधिक महत्वपूर्ण है। Legitimate interests के लिए आपको एक संतुलन अभ्यास करना और उसे दस्तावेज़ित करना होता है, और यह भेजने के लिए ePrivacy सहमति नियम से मुक्ति नहीं देता। इसे इसलिए चुनना क्योंकि सहमति कठिन लगती है, गलत समस्या को हल करता है।
सहमति क्या मानी जाती है?
एक सकारात्मक कार्य, और विनियम स्पष्ट रूप से शॉर्टकट को बंद करता है:
Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her ... Silence, pre-ticked boxes or inactivity should not therefore constitute consent.
Article 7 फिर चार शर्तें निर्धारित करता है, और हर एक एक सामान्य साइनअप पैटर्न को अमान्य करती है:
1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
तीन व्यावहारिक व्याख्याएँ:
- सेवा की शर्तों में छिपी मार्केटिंग सहमति पैराग्राफ 2 में विफल होती है, क्योंकि यह घोषणा में अन्य विषयों से स्पष्ट रूप से अलग पहचानने योग्य नहीं है।
- एक-क्लिक सब्सक्राइब और बहु-चरणीय अनसब्सक्राइब पैराग्राफ 3 में विफल होता है। सहमति वापस लेना उतना ही आसान होना चाहिए जितना देना था, जो एक समरूपता की आवश्यकता है, सामान्य उचितता की नहीं।
- उत्पाद का उपयोग करने के लिए मार्केटिंग सहमति की आवश्यकता पैराग्राफ 4 में विफल होती है, जब मार्केटिंग सेवा प्रदान करने के लिए आवश्यक नहीं है।
पैराग्राफ 1 वह है जो आपके फ़ॉर्म के बजाय आपके स्कीमा को आकार देता है। आपको सहमति प्रदर्शित करने में सक्षम होना चाहिए, जिसका मतलब है कि यह कब दी गई, उस समय क्या कहा गया था, और किस कार्य द्वारा दी गई, यह सब स्टोर करना, न कि केवल हाँ कहने वाला एक फ़्लैग।
जब कोई आपत्ति करता है तो क्या होता है?
मार्केटिंग रुक जाती है, बिना किसी संतुलन और बिना किसी अपवाद के।
अधिकांश GDPR अधिकार सशर्त हैं। डायरेक्ट मार्केटिंग पर आपत्ति का अधिकार सशर्त नहीं है:
2. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
3. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
इसकी तुलना पैराग्राफ 1 में आपत्ति के सामान्य अधिकार से करें, जहाँ कंट्रोलर जारी रख सकता है यदि वह "demonstrates compelling legitimate grounds"। पैराग्राफ 2 में ऐसा कोई प्रावधान नहीं है। इसीलिए legitimate interests पर निर्भर रहने से मार्केटिंग सूची सहमति की तुलना में अधिक टिकाऊ नहीं बनती: आपत्ति दोनों को समाप्त कर देती है।
इसके साथ एक प्रकटीकरण कर्तव्य भी जुड़ा है:
4. At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.
पहले संचार के समय, अलग से प्रस्तुत किया गया। केवल गोपनीयता नीति लिंक के माध्यम से उपलब्ध अधिकार सूचना स्पष्ट रूप से इसे संतुष्ट नहीं करती।
और क्या इसके दायरे में आता है?
दो चीज़ें जिन्हें कागज़ी कार्रवाई मानना आसान है, लेकिन वे नहीं हैं।
आपके भेजने वाले प्लेटफ़ॉर्म के साथ अनुबंध। कोई प्रदाता जो आपकी ओर से भेजता है वह प्रोसेसर है, और GDPR आपके बीच एक विशिष्ट लिखित अनुबंध की आवश्यकता रखता है। डेटा प्रोसेसिंग एग्रीमेंट क्या है में बताया गया है कि Article 28 उस अनुबंध में क्या शामिल करवाता है।
डेटा कहाँ रहता है। EU के बाहर स्थानांतरण के लिए अपना अलग आधार चाहिए, जिससे आपका डेटा जिस क्षेत्र में संग्रहीत और प्रोसेस होता है वह इन्फ्रास्ट्रक्चर प्राथमिकता के बजाय अनुपालन का सवाल बन जाता है। डेटा रेज़िडेंसी क्या है में बताया गया है कि यह Bird पर कैसे काम करता है।
संक्षेप में
GDPR वह नियम नहीं है जो भेजने के लिए सहमति की माँग करता है।
वह नियम ePrivacy Directive में है। GDPR आपके पास मौजूद और आपके द्वारा प्रोसेस किए जाने वाले व्यक्तिगत डेटा को नियंत्रित करता है, जो एक अलग सवाल है और जिसका उत्तर भी अलग है।
सहमति की एक परिभाषा है, और मौन उसे पूरा नहीं करता।
पहले से टिक किए गए बॉक्स और निष्क्रियता को बाहर रखा गया है, और सहमति वापस लेना उतना ही आसान होना चाहिए जितना देना था।
डायरेक्ट मार्केटिंग पर आपत्ति का अधिकार पूर्ण है।
कोई संतुलन परीक्षण नहीं है और कोई legitimate interest इससे नहीं बचता। जब कोई व्यक्ति आपत्ति करता है, तो मार्केटिंग के लिए प्रोसेसिंग रुक जाती है।
आपको सहमति प्रदर्शित करने में सक्षम होना चाहिए, केवल रखना पर्याप्त नहीं।
ज़िम्मेदारी कंट्रोलर पर है, जिसका मतलब है कि सहमति कब और कैसे दी गई इसका रिकॉर्ड आवश्यकता का हिस्सा है।