What companies need to know about new GDPR legislation

View in another language:
What companies need to know about new GDPR legislation
Categories
Resources
Author

Kwanruedee Sangkhep

Executive Manager
Date

On 25 May 2018, a new law comes into force, replacing the current and outdated Data Protection Act. This new law introduces tougher fines for non-compliance and gives individuals more influence over what businesses can do with their personal information.

Outsourcify helped a few of our client go through the necessary changes in their web apps to comply to these new regulations.

What is the GDPR law?

The GDPR means General Data Protection Regulation, it is a new regulation is a new European legislation governing the use and processing of personal data of individuals, it can be read in full on the CNIL website.

It has 3 objectives:

Harmonize European regulations on the protection of private data of individuals between European countries.

Give citizens control over how their personal data is used.

Ensure that companies are aware of their responsibilities for personal data.

Who is concerned?

If you have a company operating in the EU or if you sell to customers in the EU, this new legislation applies to you, especially if you have a website or applications retrieving information about their users. This regulation applies to companies established outside the European Union that target EU residents through profiling or offer goods and services to European residents.

The GDPR has also eliminated distinctions between different types of businesses – including B2B, B2C, for-profit and non-profit – which means that the law also applies to all organizations that handle the personal data of European citizens.

In which case to apply it?

Although these regulations are theoretical and in fact the legislation is generally inapplicable within the time limit imposed for the vast majority of existing websites, it should be taken into account for any new website development collecting user data.

All stakeholders should be in compliance with the GDPR by May 25, 2018. Although this date may seem too close and unrealistic, you should still familiarize yourself with this new legislation and prepare to apply it to your existing websites and applications as planned.

What is the amount of the fine?

Companies that do not comply with the GDPR could be fined 2-4% of their annual income, or up to $ 20 million, whichever is greater.

Here are eight things you need to know:

  1. “Personal data” now covers a much wider range of information, including photos, bank details, social media names, medical information, email addresses, and birth dates. The legislation only applies to the information of individuals, not companies.
  2. You must keep records of all data processed by your company, as well as the purpose of the processing, and they should only be kept for legitimate purposes before being destroyed. The processing of personal data is authorized when:
    – the consent is given by the individual to process his data (which must be recorded)
    – a contract requires data processing (in the case of employees, for example),
    – there is a legal obligation, a vital interest or public interest, or a legitimate interest – such as personal information collected for marketing purposes.
  1. When collecting personal data for a list of marketing email addresses, it was acceptable to have a pre-checked box in which individuals had to remove the check mark in order to unsubscribe. This is no longer acceptable, this box can no longer be precoched and there must be a process of “double opt-in”. This means that individuals will need to check a box to participate in marketing communications and will need to receive a confirmation email that will allow them to unsubscribe.
  2. If you determine the purpose for which personal data is collected and how it will be processed, you are referred to as the “Data Controller”. A Data Processor is another person or organization, other than an employee of the Data Controller, who processes the data on their behalf. An example of this might be if you outsource your payroll or human resources functions. You must ensure that you have an appropriate and sufficient contract with all data processors that you use, to ensure that the personal data you provide is protected against unauthorized access, loss, or destruction.
  1. The persons whose personal data you have collected have the “right to be forgotten”. If they request that their data be completely erased, you must comply with this request and notify all other organizations that hold the data, such as a data processor, to delete them as well. There may be certain exemptions where there is a legitimate interest in keeping certain records, such as employee information, which is usually kept for at least 40 years.

     

  2. The persons for whom you have personal data may request access to the information you hold about them. You are no longer able to charge an administration fee to comply with their application, and you have only 40 days to complete the application and disclose the information. Requests for information are very generic and you must provide all information relating to the individual. If the person is looking for specific information, you can reduce the time and expense required to comply with this request by asking if there is specific information that they need and providing this information.
  3. If you experience a data breach, such as if a security breach would have allowed a hacker to recover one of your databases, you must notify the Office of the Information Commissioner within 72 hours. Anyone affected or potentially affected by this data theft must also be notified.
  4. Failure to comply with these new rules could result in a significant penalty. If a violation is not reported within 72 hours, you may be fined 2% of your total turnover, whichever is higher.

How to prepare

  1. Use double opt-in confirmation for newsletters
    We recommend using dual membership forms to gather new subscribers to your newsletter and to make it clear to users how their personal data will be used.
    The GDPR also requires an easy way for your contacts to unsubscribe: all sent newsletters must contain an unsubscribe link.
  2. Learn how to correct and delete information from your contacts
    The right to access, modify and delete data is one of the key points of the GDPR
  3. Update your subscription forms
    We recommend that you review and update the wording of your newsletter subscription forms so that they are as explicit as possible about how the requested information will be used. Include an affirmative language that clearly indicates that the user agrees with the stated terms.
  4. Delete contacts and lists you no longer need
    One of the main objectives of the GDPR is to minimize the risk of leakage or data leakage and to prevent the misuse of the personal data of European residents.
    That’s why it’s best to delete all your inactive contacts or those who have already unsubscribed to your communications. If you do not use this information, it is best to ignore it.

For more information on the new GDPR legislation, please consult these links.

Wikipedia page about GDPR

https://www.cnil.fr/en/general-data-protection-regulation-guide-assist-processors
Kwanruedee Sangkhep · Executive Manager

With a degree in software engineering from the Mae Fah Luang University of Chiang Rai, Kwan has had experiences as a web developers working in Australia for 4 years before coming back to Thailand to found a web agency in 2013 which evolved into Outsourcify.

Have a project in mind?
Let's start your project today

Contact Us
Have a project in mind?
Let's start your project today

Related blog articles

Resources

Building a B2B Product: Laying the Right Foundations from Day One

September 29, 2025

Building a B2B Product: Laying the Right Foundations from Day One
Building a B2B Product: Laying the Right Foundations from Day One
Technologies

Recent Projects at Outsourcify: A Behind-the-Scenes Series

June 2, 2025

Recent Projects at Outsourcify: A Behind-the-Scenes Series
Recent Projects at Outsourcify: A Behind-the-Scenes Series
Technologies

A ResTech MVP in 1 Month

September 19, 2025

A ResTech MVP in 1 Month
A ResTech MVP in 1 Month
Technologies

Our Headless WordPress Journey with Astro.js and Vue.js

September 2, 2025

Our Headless WordPress Journey with Astro.js and Vue.js
Our Headless WordPress Journey with Astro.js and Vue.js
Resources

Why Taking Over a Development Project Is Always a Challenge

August 11, 2025

Why Taking Over a Development Project Is Always a Challenge
Why Taking Over a Development Project Is Always a Challenge
Technologies

From Vibe-Coded Prototype to Production-Ready: How Client Mockups Accelerate Our Work

August 5, 2025

From Vibe-Coded Prototype to Production-Ready: How Client Mockups Accelerate Our Work
From Vibe-Coded Prototype to Production-Ready: How Client Mockups Accelerate Our Work
Technologies

Outsourcify’s 2025 Tech Stack Driving Digital Excellence

August 4, 2025

Outsourcify’s 2025 Tech Stack Driving Digital Excellence
Outsourcify’s 2025 Tech Stack Driving Digital Excellence
Outsourcify Story

What Our Clients Say About Us: A Look at Outsourcify’s Google Reviews

July 30, 2025

What Our Clients Say About Us: A Look at Outsourcify’s Google Reviews
What Our Clients Say About Us: A Look at Outsourcify’s Google Reviews
Outsourcify Story

The Agency Developer: Beyond the Code

July 14, 2025

The Agency Developer: Beyond the Code
The Agency Developer: Beyond the Code
Resources

A Website Is Non-Negotiable in 2025 — But Its Content May Be Training AI

July 9, 2025

A Website Is Non-Negotiable in 2025 — But Its Content May Be Training AI
A Website Is Non-Negotiable in 2025 — But Its Content May Be Training AI
Resources

SaaS Tools Annual Cost Comparison for a 35-User Team – and What You Can Learn from Our Journey

June 11, 2025

SaaS Tools Annual Cost Comparison for a 35-User Team – and What You Can Learn from Our Journey
SaaS Tools Annual Cost Comparison for a 35-User Team – and What You Can Learn from Our Journey
Resources

A Guide to Thailand’s Online Payment Gateways

May 4, 2025

A Guide to Thailand’s Online Payment Gateways
A Guide to Thailand’s Online Payment Gateways
Technologies

10 Programming Practices Worth Rethinking

April 29, 2025

10 Programming Practices Worth Rethinking
10 Programming Practices Worth Rethinking
Outsourcify Story

The Outsourcify Story #1: Lessons from a decade in Web Development

March 23, 2025

The Outsourcify Story #1: Lessons from a decade in Web Development
The Outsourcify Story #1: Lessons from a decade in Web Development
Technologies

Outsourcify partners with Sisense: the Power of Business Intelligence

February 16, 2025

Outsourcify partners with Sisense: the Power of Business Intelligence
Outsourcify partners with Sisense: the Power of Business Intelligence
Technologies

The 8 Archetypes of Software Engineers Every Team Needs (And How to Harness Their Superpowers)

February 6, 2025

The 8 Archetypes of Software Engineers Every Team Needs (And How to Harness Their Superpowers)
The 8 Archetypes of Software Engineers Every Team Needs (And How to Harness Their Superpowers)
Outsourcify Website

Eco-friendly and Accessible Websites: Building a Sustainable Digital Future

December 10, 2024

Eco-friendly and Accessible Websites: Building a Sustainable Digital Future
Eco-friendly and Accessible Websites: Building a Sustainable Digital Future
Technologies

The impact of API-centric approaches on software development

November 27, 2024

The impact of API-centric approaches on software development
The impact of API-centric approaches on software development
Technologies

How to know you can trust a web agency: A practical guide

November 15, 2024

How to know you can trust a web agency: A practical guide
How to know you can trust a web agency: A practical guide
Technologies

Who’s watching? A guide to privacy on websites and protecting your data

November 14, 2024

Who’s watching? A guide to privacy on websites and protecting your data
Who’s watching? A guide to privacy on websites and protecting your data
Technologies

Understanding the differences between MVP and MMP for smarter product development

November 13, 2024

Understanding the differences between MVP and MMP for smarter product development
Understanding the differences between MVP and MMP for smarter product development
Technologies

The top 3 strategic pitfalls that can derail a tech startup

November 8, 2024

The top 3 strategic pitfalls that can derail a tech startup
The top 3 strategic pitfalls that can derail a tech startup
Technologies

How to avoid AI project failures: lessons from automation

November 7, 2024

How to avoid AI project failures: lessons from automation
How to avoid AI project failures: lessons from automation
Technologies

The top 3 pitfalls facing CTOs and how to overcome them

October 31, 2024

The top 3 pitfalls facing CTOs and how to overcome them
The top 3 pitfalls facing CTOs and how to overcome them
Technologies

How do we extract the needs of a startup in the context of a Define Scope – Requirements Workshop?

October 29, 2024

How do we extract the needs of a startup in the context of a Define Scope – Requirements Workshop?
How do we extract the needs of a startup in the context of a Define Scope – Requirements Workshop?
Technologies

The vital role of a product owner in your web project

October 25, 2024

The vital role of a product owner in your web project
The vital role of a product owner in your web project
Technologies

How to choose a web agency: Top platforms to help you find a reliable partner

October 15, 2024

How to choose a web agency: Top platforms to help you find a reliable partner
How to choose a web agency: Top platforms to help you find a reliable partner
Technologies

The breadth of expertise required for Web Development

October 9, 2024

The breadth of expertise required for Web Development
The breadth of expertise required for Web Development
Technologies

Running daily, a day early: cron jobs for everyone

October 7, 2024

Running daily, a day early: cron jobs for everyone
Running daily, a day early: cron jobs for everyone
Company Activities

Behind the scenes: Triple baby party & reflecting on our company’s sociology

October 4, 2024

Behind the scenes: Triple baby party & reflecting on our company’s sociology
Behind the scenes: Triple baby party & reflecting on our company’s sociology
Technologies

Caching: Our number one suspect

August 9, 2024

Caching: Our number one suspect
Caching: Our number one suspect
Technologies

What is a database and how do you choose one for your web application project?

June 18, 2024

What is a database and how do you choose one for your web application project?
What is a database and how do you choose one for your web application project?
Technologies

Outsourcify’s expertise with the Astro framework

June 11, 2024

Outsourcify’s expertise with the Astro framework
Outsourcify’s expertise with the Astro framework
Technologies

What is an API and how does Outsourcify use them?

May 22, 2024

What is an API and how does Outsourcify use them?
What is an API and how does Outsourcify use them?
Technologies

Which LLMs are we using to facilitate the development at Outsourcify?

May 10, 2024

Which LLMs are we using to facilitate the development at Outsourcify?
Which LLMs are we using to facilitate the development at Outsourcify?
Technologies

Integrating an AI service for Real Estate

January 19, 2024

Integrating an AI service for Real Estate
Integrating an AI service for Real Estate
Technologies

Top 10 Reasons to Outsource SaaS Application Design and Development

December 16, 2024

Top 10 Reasons to Outsource SaaS Application Design and Development
Top 10 Reasons to Outsource SaaS Application Design and Development
Company Activities

How to answer a Request for Proposal and prepare a pitch

March 31, 2020

How to answer a Request for Proposal and prepare a pitch
How to answer a Request for Proposal and prepare a pitch
Technologies

Developing web apps with no design requirements

March 4, 2019

Developing web apps with no design requirements
Developing web apps with no design requirements
Resources

Weekly/monthly web tech focused articles to follow

August 21, 2018

Weekly/monthly web tech focused articles to follow
Weekly/monthly web tech focused articles to follow
Technologies

The main reasons we use Symfony for web application developments

April 1, 2018

The main reasons we use Symfony for web application developments
The main reasons we use Symfony for web application developments
Resources

Why we chose TeamWork to manage our projects?

November 16, 2017

Why we chose TeamWork to manage our projects?
Why we chose TeamWork to manage our projects?