See how text campaigns can increase your conversion rates, in 5 minutes
Book a DemoGDPR, the European Union's General Data Protection Regulation, sets the standard for how personal data must be collected, processed, and protected in the EU and for anyone messaging EU residents. It replaced the previous EU Data Protection Directive and has been enforceable since May 25, 2018. As a messaging platform that helps businesses reach their customers via SMS, WhatsApp, and other channels, ShoutOUT takes GDPR compliance seriously, both in how we handle data ourselves and in how we support customers who send messages to EU-based recipients.
If you use ShoutOUT to message customers in the EU, your responsibilities will depend on the nature of your business and the personal data you process. Broadly, GDPR requires that personal data be:
GDPR also places obligations on companies to document their processing activities and be able to demonstrate compliance with these principles, and it codifies the requirement to apply data protection by design and by default when building products and processes.
Where you use a service provider like ShoutOUT to process personal data on your behalf, you'll need an appropriate data processing agreement in place obligating that provider to meet GDPR's standards, which is exactly what our GDPR Addendum below is designed for. If you transfer EU personal data outside the EU, that transfer must go to a jurisdiction the EU Commission recognizes as having adequate data protection, or be covered by appropriate safeguards such as standard contractual clauses.
Depending on your business and the data you process, other GDPR obligations may apply. We recommend consulting a qualified privacy professional to understand exactly how GDPR applies to your specific business.
Personal data means data relating to an identified or identifiable natural person (a "data subject"). Someone is identifiable if they can be recognized, directly or indirectly, through an identifier such as a name, ID number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
This is a broad definition and can include things like IP addresses, device IDs, or phone numbers. It doesn't matter that an identifier could change over time (for example, a user changing their phone number) — what matters is whether the information can be used to single that person out, even if you don't know exactly who they are.
The definition of personal data under GDPR is also broader than "personally identifiable information" (PII) under many US data breach laws. Even data that seems low-risk on its own, such as an IP address, still counts as personal data under GDPR, though it may not require the same level of protection as more sensitive data like payment card numbers.
It depends. Article 37 of GDPR requires entities to designate a data protection officer if:
EU data protection regulators have published additional guidance to help you determine whether your business fits within one of these categories.
GDPR has broad scope and reach, but it isn't unlimited. If you have no establishment in the EU and don't process personal data belonging to EU individuals, GDPR won't apply to your activities. If you're not sure whether you process EU personal data, consider whether you offer goods or services (even free ones) to individuals in the EU, or monitor the behavior of individuals in the EU — if either applies, GDPR likely covers you. GDPR is not intended to apply to entities that inadvertently process EU personal data without trying to offer goods or services to people in the EU.
Compliance with standards like ISO 27001 can help with GDPR, particularly around security of processing, but the two aren't interchangeable. Being ISO 27001 compliant doesn't automatically mean you're GDPR compliant.
Depending on the nature of the violation, data protection authorities may issue fines of up to €20 million or 4% of global annual revenue, whichever is higher.
A lot has been written about GDPR, and a simple web search will surface plenty of information. The most authoritative resources will always be those produced by data protection regulators or the EU itself, including guidance published by the European Data Protection Board on how enforcement is likely to be interpreted.
The information on this page is ShoutOUT's interpretation of GDPR and its requirements as of the date of publication. Not all interpretations or requirements of GDPR are fully settled, and how it applies is fact- and context-specific. This information should not be relied upon as legal advice or used to determine how GDPR applies to your business. We encourage you to seek guidance from a qualified professional regarding how GDPR applies specifically to your organization and how to ensure compliance. This information is provided "as-is" and may be updated without notice. You may refer to our Privacy Policy for details on how ShoutOUT itself handles personal data.