Email Marketing and UK Data Protection
Some time ago Digital Stationery took a big step to invest in Email Marketing.
We wanted a simple system for our customers to be able to log in to. Something that was branded to our company, looked like us and something that we didn’t need to do software maintenance on. Eventually we found a really cool company that supplied everything we wanted. We had done HTML email coding and email design for a long time and figured it was time to add some umph to our capabilities.
The big question was Data Protection. We knew that we would be responsible for holding and storing data for customers and fundamentally wanted the reassurance that we would not be breaking any Data Protection Laws with regards to “exporting”. Exporting meaning the transfer of data overseas, when clients upload their data to our seamless service.
UK Data Protection
We struggled to find a company that held data in the UK. Most service provders seemed to be in the US. Most Eurpoean and US services seemed quite happy to accept UK business and seem quite at ease with UK businesses uploading data to their services. Our question was simple – Are we breaking the law if we (or allow customers to) upload data to the US or Europe? The law seemed a gray area.
We found our answer…
Firstly, you, being “the person who holds that data” is responsible for it. Secondly, while the service provider is happy for you to upload data to their services, you are responsible for the data – meaning that it’s your responsibility for protecting the data.
Question 1
Are you protecting the personal data that you hold about your customers?
Question 2
Are you uploading this information abroad when you use email marketing services?
Uploading data to servers
Everytime you store or upload data about people (i.e. email addresses) to a server, you need reassurance that the data is going to be protected and safe-guarded. All the companies we looked at offered a high level of safe-guarding the information. This was reassuring. But how did we stand from a UK perspective?
Exporting Data from the UK
If the service provider you are using has servers outside the UK, then effectively you are exporting the data overseas. What’s the Law? We’ll in the UK you, as the data holder, you are responsible for protecting it. So can you export data to foreign countries?
The danger of storing data in the US.
Our service provider gives guidance on the issue:
In summary, it is a political minefield to store your data outside of the European Union. Even if your data is B2B, should you have anything stored which reflects the individual as a person then you could be breaching the laws of the DPA. This does not just apply to your Email Marketing data lists, but all of your company’s data storage, such as your CRM system.
They also go on to say:
Data Protection Principle 8 prohibits any export of personal data from the EEA (European Union, plus Iceland, Liechenstein and Norway), unless one of six complaint “gateways” is available:
The first principle is
The importing state has “adequate” data protection laws. The following countries outside the European area are listed:
Argentina
Canada |
Guernsey
Isle of Man |
Switzerland
Jersey |
What we found most interesting is that the United States is not listed.
It also states that:
The export is “necessary” for the fulfillment of contract between the data subject and data controller… Commercial convenience will NOT qualify.
We have posted this information for the benefit of anybody else considering using email marketing.
What this means for Small Businesses:
We understand this to mean:
Any UK business who is doing email marketing should not be uploading data to services in the US. If you do, you are breaking the Data Protection Act. For this there are very heavy fines. What we suggest is that you find a provider in the UK or the European Economic Area.
Alternatively, you may like to ask for permission to do so from each customer. We understand that if you upload customer data to the US (i.e. email addresses that include a persons’ name) – you should have a Data Protection Policy, Privacy Policy and also inform the customer how you are using their data. We believe that you need their expressed permission also.!! Shocked?
How we can help
We have an email marketing suite that is UK based, provided by a UK company who are registered with the ICO. We do not source, buy or collect data, but we have a UK based email marketing suite that our customers can use. Our only involvement is to design, build and install the templates for you to get on with running your own campaigns.
Would you like to discuss email marketing?
If you would like to discuss email marketing, or have believe you can benefit from email marketing, please get in touch via our Call Back facility.
This information is here as guidance and we believe it to be correct at the time of writing it.
Further Reading: