4 tips on getting up to speed with GDPR for U.S. companies

Four months in, the European Union’s GDPR privacy rule still reverberates through privacy and data use policies around the globe. Even the rock band Rage Against the Machine, which built a decades-long music career on being aggressively anti-establishment in both politics and sound, submitted to the machine by posting a GDPR compliance form to which fans must testify before signing up for the group’s newsletter.
GDPR for U.S. companies has its merits, one expert says, despite the compliance effort it requires.
“If Rage Against the Machine can buy into it, anyone can,” said Michael Piddock – founder and CEO of Glisser Ltd., a British-based slide-share and live audience-polling services vendor — in a presentation at HubSpot’s Inbound 2018 user conference where he offered advice on GDPR for U.S. companies. His company had to come up with compliance strategies to collect data at live events on behalf of its customers, each of which comprises its own large-scale data collection undertaking.
But not everyone has embraced GDPR with the same creative humor as Rage Against the Machine. Some organizations ask customers to sign off on every possible use of their data, creating terrible user experiences in the process.
GDPR for U.S. companies can mean pulling up a drawbridge and blocking all European users, as some companies have determined that European customers are not worth pursuing. Still others have stuck their head in the sand and are pretending the regulations don’t affect them — and have yet to design a compliance policy.
“Don’t think that just because you serve a primarily U.S. market that GDPR doesn’t affect you,” Piddock said. “It does affect you if you have any clients or prospects from Europe, or people with dual citizenships who would be affected by GDPR.”
However, that isn’t necessarily a bad thing for companies who use email and other online marketing channels, as it can not only make a company think out its privacy and customer data-handling policies, but it can also help build goodwill with customers by showing the company cares about protecting customer privacy.
Piddock offered four tips on getting up to speed with GDPR for U.S. companies that may not see how compliance could be beneficial.
“The first thing I think you need to do is to be working on the evidence that you are taking [GDPR] seriously,” Piddock said. “That way, if regulators do come knocking, you have this data in place to say, ‘look, we really are taking this seriously.'” Don’t think that just because you serve a primarily U.S. market that GDPR doesn’t affect you.
