GDPR is built on a handful of principles rather than a checklist. You need a lawful reason to process someone's personal data, you should collect only what you actually need, you should keep it only as long as you need it, you must keep it secure, and you must be able to explain what you hold and why. People have rights over their own data too, including the right to see it, correct it and ask for it to be deleted.
For a small business the practical version is simpler than the legal text suggests. Tell people what you are collecting and why, in plain language and at the point of collection. Do not gather fields you have no use for. Keep a record of which suppliers process data on your behalf and have a written agreement with each of them. Know how you would find and delete one person's records if they asked.
A website chat widget touches all of this because it collects names, email addresses and phone numbers. Clerkzo is GDPR compliant, and the design supports the principles directly: you choose which fields the lead capture form collects, the leads inbox gives you one place to find and remove a person's record, and you can be explicit in the widget about why you are asking for contact details in the first place.
Related terms
Browse all 142 terms- CCPACCPA (the California Consumer Privacy Act, as amended by the CPRA) is a California law that gives state residents rights over the personal information businesses collect about them, including the right to know what is held, to delete it, and to opt out of its sale or sharing.
- HIPAAHIPAA (the Health Insurance Portability and Accountability Act) is US law that sets standards for protecting individually identifiable health information held by healthcare providers, health plans and the vendors that work with them.
- SOC 2SOC 2 is an independent examination of how a service provider protects customer data, carried out by an accredited auditor against criteria covering security, availability, processing integrity, confidentiality and privacy.
- Personally Identifiable Information (PII)Personally identifiable information (PII) is any data that can identify a specific individual on its own or when combined with other information — names, email addresses, phone numbers, account identifiers and more.