{"id":2418,"date":"2020-12-31T18:54:16","date_gmt":"2020-12-31T13:24:16","guid":{"rendered":"https:\/\/www.lemnisk.co\/blog\/?p=2418"},"modified":"2021-03-30T20:49:40","modified_gmt":"2021-03-30T15:19:40","slug":"gdpr-compliance-cdp","status":"publish","type":"post","link":"https:\/\/www.lemnisk.co\/blog\/gdpr-compliance-cdp\/","title":{"rendered":"GDPR Compliance: Managing your Customer Data with Lemnisk CDP"},"content":{"rendered":"<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Data has become quite precious in today\u2019s digital business world. Most businesses thrive on the data they generate or collect from consumers. With an overwhelming dependence on all kinds of digital consumer data, consumers are increasingly concerned about their privacy and security. It\u2019s when their concerns reached a crescendo that governments all over the world decided to incorporate laws, policies, and regulations that safeguarded their data privacy.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">GDPR (General Data Protection Regulation) is one such regulation introduced by the European Union that aimed at protecting the privacy and personal data of their citizens. It provides guidelines and policies that companies must follow to protect the privacy and personal data of their EU customers. Non-compliance will result in heavy fines and penalties.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>CDP, Customer Data, and GDPR<\/b><\/h3>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2424 size-full\" src=\"https:\/\/www.lemnisk.co\/blog\/wp-content\/uploads\/2021\/01\/cdp.jpg\" alt=\"GDPR Compliance | CDP\" width=\"763\" height=\"475\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.lemnisk.co\/customer-data-platform\/\" target=\"_blank\" rel=\"noopener\">Customer Data Platform (CDP)<\/a> is a new and innovative martech tool that assists marketers in efficiently managing their customer data. It does this by aggregating and unifying data from various silos and sources to present a <a href=\"https:\/\/www.lemnisk.co\/blog\/single-customer-view\/\" target=\"_blank\" rel=\"noopener\">single view<\/a> for each individual user or customer. Using this view, marketers can easily discern valuable insights about each customer and use them to craft personalized campaigns that can help increase digital engagement and conversions.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The concerns that marketers have in a CDP is how does it comply with respect to privacy regulation laws such as GDPR.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">A CDP helps in supporting specific GDPR requirements. They are explained as follows:<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>1. Data Sources Identification<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">As per the GDPR requirements, all customer data caches must be identified and mapped. A CDP functions primarily by identifying the type of data and their data sources that need to be aggregated and unified.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>2. Data Accuracy<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">CDPs have the capability to create a single unified view of each customer that presents an accurate version of his\/her data. This data can be sent back to sources that may have errors. It ensures the downstream propagation of data subject access requests, which is part of the data governance requirements of GDPR.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>3. Data Privacy<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">GDPR requirements state that systems need to be designed with privacy in mind. A CDP adheres to this by centralizing access to the customer\u2019s personal data. It denies systems to directly access each other\u2019s data and only allows them to share it. A CDP can be designed to handle data in such a way that its authorized use and tracking is managed only in the CDP.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>4. Data Authority<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Marketers can use a CDP to track the authority of how customer data is collected and used. They can assess details such as consents, contracts, legal opinions, authority expiration dates, etc. As the information is readily assembled and available, it can be used to answer questions about how the data is used. CDPs can also be used to make consent adherence simple for downstream systems that receive data that are only GDPR compliant.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>How Lemnisk CDP Complies with GDPR<\/b><\/h3>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2425\" src=\"https:\/\/www.lemnisk.co\/blog\/wp-content\/uploads\/2021\/01\/Lemnisk_CDP_diagram.jpg\" alt=\"GDPR Compliance | Lemnisk CDP\" width=\"900\" height=\"409\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Lemnisk CDP provides an easy to use interface and APIs to Delete and Suppress user data. This is a key requirement to achieve compliance with privacy regulations like <a href=\"https:\/\/www.lemnisk.co\/data-privacy-and-gdpr\/\" target=\"_blank\" rel=\"noopener\">GDPR<\/a>. As part of GDPR, the following rights are available to Data Subjects (end users) with regards to their data stored and managed by Data Controllers (Clients) and Data Processors (Lemnisk):<\/span><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Right to erase<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Right to Modify\/Rectify<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Right to Access<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Right to Data Suppress (Opt-out)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Opt-in (Unsuppress)<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h4><b>Use Cases<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">a) A user can request to Suppress any further data collection from the client&#8217;s website. Lemnisk CDP has the capability to receive such suppression requests and process these requests within a stipulated time and provide the status of the request to the client.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">b) A user can request to Delete the entire data about this user that is stored on the Lemnisk platform. It can receive such deletion requests and process these requests within 24 hours and provide the status of the request to the client.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Suppress<\/b><\/h4>\n<p>&nbsp;<\/p>\n<h4><b>1. Suppress new data without deleting existing customer data<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The data here includes profile as well as events data. Once a suppression request is received for a user, the same can be applied to all the sources. This means that no data (event) about this user is received (processed) at Lemnisk servers across different sources.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>2. Suppress new data and delete existing data<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">All data about the user is deleted from Lemnisk\u2019s managed servers including profile, events, etc. Once the profile is deleted, the platform remembers the identifier and prevents any data from this user across sources to be stored at Lemnisk\u2019s servers.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>Delete<\/b><\/h4>\n<p>&nbsp;<\/p>\n<h4><b>Delete existing data without suppressing any new data<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">All data about the user is deleted from Lemnisk\u2019s managed servers including profile, events, and backup data. The Lemnisk platform is able to receive suppression requests from the client through the Lemnisk GDPR API endpoint.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4><b>User Interface to raise and track GDPR requests<\/b><\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Lemnisk CDP can receive suppression requests from the client either through Lemnisk UI or through Lemnisk GDPR Data Suppression API. A suppression request is processed within 24 hours. And once it has been completed, the completion status along with a timestamp is displayed on the UI.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>In Conclusion<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">A CDP&#8217;s single unified user view can solve various challenges posed by privacy regulations such as GDPR. Hence, enterprise marketers can definitely proceed with implementing a CDP in their organizations. If they are still concerned, they can ask <a href=\"https:\/\/www.lemnisk.co\/blog\/choosing-cdp-vendor\/\" target=\"_blank\" rel=\"noopener\">CDP vendors<\/a> to present to them their compliance adherence to GDPR and other privacy regulations. This will help them in evaluating each vendor and choose the right one that meets their business goals and objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h5>By Bijoy K.B | Marketing Manager at Lemnisk<\/h5>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data has become quite precious in today\u2019s digital business world. Most businesses thrive on the data they generate or collect from consumers. With an overwhelming dependence on all kinds of digital consumer data, consumers are increasingly concerned about their privacy and security. It\u2019s when their concerns reached a crescendo that governments all over the world [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":2431,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,58,156,126,177],"tags":[19,157,8,178],"class_list":["post-2418","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-all-blogs","category-customer-data-platform","category-data-privacy","category-digital-marketing","category-gdpr","tag-customer-data-platform","tag-data-privacy","tag-digital-marketing","tag-gdpr"],"_links":{"self":[{"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/posts\/2418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/comments?post=2418"}],"version-history":[{"count":18,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/posts\/2418\/revisions"}],"predecessor-version":[{"id":2545,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/posts\/2418\/revisions\/2545"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/media\/2431"}],"wp:attachment":[{"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/media?parent=2418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/categories?post=2418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lemnisk.co\/blog\/wp-json\/wp\/v2\/tags?post=2418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}