Operating a travel booking platform: simple intermediary or travel agency?
You own or develop an online platform for travel services that can be booked by tourists, and you have at least once …
Do you own a platform, an online shop or a mobile app? Or even a simple showcase site/blog where various articles are posted?
Without making an exhaustive analysis of all the legal provisions, in this article, you will see the main aspects provided by the GDPR that you should take into account when you own/operate a platform as a service (PaaS), an online shop, a mobile app or even a simple showcase site/blog (which we will generally call " site/mobile app").
The phrase “GDPR compliance” is increasingly used in discussions about technology and personal data protection. If you are developing or have already developed a site/mobile app, you have probably “run into” the “GDPR issue”.
But what does this GDPR mean and what should you do?
GDPR is a European regulation that regulates how personal data can be processed.
Specifically, the GDPR sets out several obligations on those who process personal data, such as the obligation to inform users, the obligation to obtain consent to send marketing messages etc.
A first step in complying with GDPR is to publish a personal data processing policy (i.e., privacy policy) on the site/mobile app. The role of this policy is to inform users about how you collect and further process their data.
This policy must contain a series of mandatory information according to the GDPR, including:
The privacy policy should be easily accessible to users:
The privacy policy is intended to inform users. Thus, being only an information on data processing, it is not necessary for the user to agree to the privacy policy, but only to confirm that they have read and understood it.
Example: with a check-box (which users must tick) and with a text such as “I have read and understood the privacy policy”.
Note: do not confuse the privacy policy tick with the user consent tick when used as a basis for processing - they are different.
Apart from ticking the privacy policy box, you should note that in order to send marketing messages you need the user’s express prior consent - the so-called subscribe.
How do you do that? With a tick and a text like “I agree to receive messages with promotions and other useful information”.
Good to know:
When you use cookies, you should inform the user about this, which in practice is done through the cookie policy.
Typically, the cookie policy contains the following information:
Similar to the privacy policy, the cookie policy should also be easily accessible to users - for example, you can include a link to it in the footer.
A distinction must be made between cookies that are strictly necessary for the proper functioning of the platform and other cookies that are not strictly necessary (such as analytics or marketing cookies).
For strictly necessary cookies you do NOT need to obtain user consent.
For the other categories of cookies you need to obtain prior consent. Usually, obtaining consent is done by implementing a pop-up banner, which must have both an “accept” and “decline” button.
Here’s what you should consider when using a pop-up banner:
Until the user accepts cookies that are not strictly necessary, you should not use such cookies. Likewise, you cannot use these cookies if the user refuses them.
Also, you should not make the use of the platform conditional on accepting cookies that are not strictly necessary.
Okay, now that you’ve seen the main documents you need to publish on your site/mobile app, you should bear in mind that GDPR also sets out several other equally important obligations. Thus, you should also pay attention to the following aspects:
Personal data protection is one of the main issues you need to consider if you operate a site/ mobile app.
Another equally important aspect is the regulation of the relationship with the users of the site/mobile app, which is usually done through the terms and conditions of the site/mobile app. Find out what to look out for in the terms and conditions in our article here .
We can help you implement GDPR for your product:
You own or develop an online platform for travel services that can be booked by tourists, and you have at least once …
Developing a software product is a complex process that involves much more than coding and design. It is important not …