{"id":1103,"date":"2018-05-21T14:27:06","date_gmt":"2018-05-21T14:27:06","guid":{"rendered":"https:\/\/www.getanewsletter.com\/en\/?p=1103"},"modified":"2023-09-29T09:44:15","modified_gmt":"2023-09-29T09:44:15","slug":"gdpr-final-checklist-for-email-marketers-free-gdpr-privacy-policy-templates","status":"publish","type":"post","link":"https:\/\/getanewsletter.com\/en\/blog\/gdpr-final-checklist-for-email-marketers-free-gdpr-privacy-policy-templates\/","title":{"rendered":"GDPR final checklist for email marketers + FREE GDPR privacy policy templates"},"content":{"rendered":"<p>Ok, so we\u2019re on the last lap now before GDPR comes into effect on 25 May! Relieved? Here\u2019s the <strong>final GDPR checklist<\/strong> of things you should have done to keep your email marketing on the right side of the new law:<\/p>\n<h6><img fetchpriority=\"high\" decoding=\"async\" class=\"size-full wp-image-1104 alignleft\" src=\"https:\/\/www.getanewsletter.com\/wp-content\/uploads\/sites\/2\/2018\/05\/1_blog.png\" alt=\"GDPR final checklist\" width=\"1200\" height=\"452\" srcset=\"https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/1_blog.png 1200w, https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/1_blog-300x113.png 300w, https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/1_blog-768x289.png 768w, https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/1_blog-1024x386.png 1024w, https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/1_blog-875x330.png 875w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/h6>\n<h4><\/h4>\n<h5><strong>1. Update<\/strong> your <strong>privacy policy<\/strong><\/h5>\n<p>You can find free <strong>templates <\/strong>for <strong>GDPR privacy policies<\/strong> <a href=\"https:\/\/seqlegal.com\/free-legal-documents\/privacy-policy\" target=\"_blank\" rel=\"noopener noreferrer\"><strong><u>here<\/u><\/strong><\/a> or <strong><a href=\"https:\/\/vinciworks.com\/blog\/free-data-protection-privacy-policy-template\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/strong>\u00a0and the <strong>privacy notice<\/strong> <a href=\"https:\/\/jamieking.co.uk\/blog\/cyber-security\/policies\/free-sample-privacy-policy.php\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n<h5><strong>2. Inform<\/strong> your subscribers about the policy update<\/h5>\n<p>Yes, send this annoying email\u00a0<em>now.\u00a0<\/em><\/p>\n<h5>3. <strong>Adjust<\/strong> your <strong>subscription forms<\/strong>, <strong>sign-up boxes,<\/strong> and <strong>pop-ups<\/strong><\/h5>\n<p>&#8230;on all your landing pages. <span style=\"text-decoration: underline;\"><strong>Remove<\/strong><\/span> any<strong> pre-ticked checkboxes<\/strong> and <strong>opt-outs<\/strong> and replace them with <strong>opt-ins (buttons or unticked checkboxes)<\/strong> to make sure that the new subscribers sign-up through \u2018<em>affirmative action<\/em>\u2019. Also, make sure your privacy policy is linked on the forms \u2013 you can read more about<a href=\"https:\/\/getanewsletter.com\/en\/blog\/gdpr-friendly-subscription-forms\/\" target=\"_blank\" rel=\"noopener noreferrer\"> <strong>GDPR-friendly subscription forms <em>here<\/em><\/strong><\/a>.<\/p>\n<h5><u><\/u>4.\u00a0 Make sure you have a <strong>process<\/strong> for how you <strong>store and protect<\/strong> <strong>user data <\/strong>in place<\/h5>\n<p>Have a clear description of the process (how the data is processed in your business and what for).<\/p>\n<h5>5. Make sure your business has a designated \u2018<strong>data processor<\/strong>\u2019 and \u2018<strong>data controller<\/strong>\u2019<\/h5>\n<p>\u2013 a natural or legal person who is responsible for processing personal data in your company and for controlling the process respectively.<\/p>\n<h5>6. Keep a <strong>clear record<\/strong> of how you obtained <strong>consent<\/strong> from your current subscribers<\/h5>\n<p>When, how, and why (what for) you obtained their data &#8211; timestamp, wording, source.<\/p>\n<h5>7. Send a <strong>re-permission<\/strong> emails<\/h5>\n<p>If you don\u2019t have clear <strong>evidence of consent<\/strong> obtained through subscribers\u2019 affirmative action for all your contacts on your mailing list, send a <strong>re-permissioning<\/strong> email asking them to re-subscribe. You can find <strong>templates <\/strong>for GDPR <strong>re-permissioning<\/strong> emails <a href=\"https:\/\/getanewsletter.com\/en\/blog\/gdpr-re-permissioning-email-templates\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong><u>here<\/u><\/strong>.<\/a><\/p>\n<h5>8. Give people an opportunity to <strong>unsubscribe<\/strong><\/h5>\n<p>&#8230;that can be easily found in each newsletter.<\/p>\n<h5>9. Ask your subscribers to <strong>update their preferences<\/strong><\/h5>\n<p>If you are sending newsletters with <strong>multiple types of content<\/strong> (e.g. editorials, promotions, affiliate links) then ask your subscribers to <strong>update their preferences.\u00a0 <\/strong>They should opt into receiving each type of content through separate affirmative actions (ticking separate checkboxes etc.) to comply with the \u2018one purpose, one consent\u2019 rule.<\/p>\n<h5>10. Make sure that the <strong>sender <\/strong>of the newsletter is always clear<\/h5>\n<p>&#8230;and is the same as the subscribers have given their consent to \u2013 i.e. if you have subsidiary companies or lateral businesses to yours, you will not be able to send emails from them to the subscribers in your existing business without their separate consent.<\/p>\n<h4>Good practice (although not required by law per se) \u2013 introduce <strong>double opt-in<\/strong> for your subscriptions.<\/h4>\n<p>In conclusion, GDPR is not as scary as it seems for email marketers. Even if you lose some of the subscribers that never open your newsletters in the first place (and hence lower your email marketing ROI) \u2013 it will be only good riddance.\u00a0\ud83d\ude0a As Neil Patel said \u2018<em>If you are chasing quantity over quality when it comes to your email newsletter list, then you are wasting your time.\u2019\u00a0<\/em><\/p>\n<p>GDPR puts an end to (at least legal) the nuisance of having your email sold to third parties, and being surreptitiously subscribed to several mailing lists while doing online shopping just because you overlooked the option to opt out.<\/p>\n<p>It promotes good, engaging content that people actually *want* to read. Engagement is everything \u2013 it doesn\u2019t matter how many subscribers you have if 95% don\u2019t even open your emails.<\/p>\n<p>So, keep calm &amp; love GDPR \ud83d\ude09<\/p>\n<p><img decoding=\"async\" class=\"size-full wp-image-1106 aligncenter\" src=\"https:\/\/www.getanewsletter.com\/wp-content\/uploads\/sites\/2\/2018\/05\/keep-calm-.png\" alt=\"Keep Calm and Love GDPR \" width=\"423\" height=\"519\" srcset=\"https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/keep-calm-.png 423w, https:\/\/getanewsletter.com\/wp-content\/uploads\/2018\/05\/keep-calm--245x300.png 245w\" sizes=\"(max-width: 423px) 100vw, 423px\" \/><\/p>\n<p><em>\u00a0<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ok, so we\u2019re on the last lap now before GDPR comes into effect on 25 May! Relieved? Here\u2019s the final GDPR checklist of things you should have done to keep your email marketing on the right side of the new law: 1. Update your privacy policy You can find free templates for GDPR privacy policies [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":18316,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[10],"tags":[3,55,64,65,30],"class_list":{"0":"post-1103","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-email-marketing","8":"tag-email-marketing","9":"tag-gdpr","10":"tag-gdpr-email-marketing","11":"tag-gdpr-privacy-policy","12":"tag-get-a-newsletter","13":"entry"},"_links":{"self":[{"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/posts\/1103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/comments?post=1103"}],"version-history":[{"count":0,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/posts\/1103\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/media\/18316"}],"wp:attachment":[{"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/media?parent=1103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/categories?post=1103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getanewsletter.com\/en\/wp-json\/wp\/v2\/tags?post=1103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}