GDPR Principles: Lawfulness, Fairness and Transparency

Lawfulness, Fairness, and Transparency
Home » Blog » GDPR Principles: Lawfulness, Fairness and Transparency
Free Web Marketing Consultations

Helping B2B Technology Companies Increase Their Lead Volume.
Serving: IT, MSP, Cybersecurity, Software Dev, SaaS, ISV, VARs & More.

Table of Contents
    Add a header to begin generating the table of contents

    This post represents part 1 of a series of posts covering principles of the General Data Protection Regulation (GDPR). The regulation sets out 7 keys principles that set the foundation for the directives to be enforced by the legislation. Today we will be covering lawfulness, fairness, and transparency.  Below are links to the full series of posts:

    Lawfulness

    Personal data must be processed in a lawful manner.  What this means for businesses is that you must have a valid legal reason for collecting personal data – it’s no longer valid to collect personal information from people for any purpose without a lawful basis for processing the data.  The GDPR has outlined six lawful bases for processing and the collecting and processing of personal information must be covered under one of these lawful bases and traceable back to that basis.

    The six covered lawful bases for processing are:

    • Consent
    • Contract
    • Legal Obligation
    • Vital Interests
    • Public Tasks
    • Legitimate Interests

    Consent – This forms a basis if an individual has given clear consent for you to process their personal data for a specific purpose.  Collecting consent is a topic on it’s own and one we will look to cover in a future post, but it’s both the most recommended approach for forming a lawful basis. This basis is also one that requires action on your part, your site will need to be updated to gather consent for you to collect PII.  This is an area where a lot of businesses are exposing themselves to liability by not collecting consent appropriately.  The most common mistake seen is not requiring an explicit consent.  Messages saying something to the extent of, “by continuing to use this site you are consenting to the collection of personal data” are not acceptable.  The GDPR is very clear on the need for an explicit opt-in mechanism such as an unchecked check box that your user has to check to opt-in to data collection.  Although it may take a little extra leg work to become compliant by collecting data using the lawful basis of consent, it becomes the easiest to demonstrate in the event of a regulatory investigation.

    Contract – The collection and processing of an individual’s personal data in the process of fulfilling a contractual obligation is considered a lawful basis for processing.  Here is a great example dealing with the implied contract of an online purchase.

    When a data subject makes an online purchase, a controller processes the address of the individual in order to deliver the goods. This is necessary in order to perform the contract.  However, the profiling of an individual’s interests and preferences based on items purchased is not necessary for the performance of the contract and the controller cannot rely on Article 6(1)(b) as the lawful basis for this processing. Even if this type of targeted advertising is a useful part of your customer relationship and is a necessary part of your business model, it is not necessary to perform the contract itself. 1

    Defending the collection of personal data under the contractual basis for lawful processing should be used as a last resort. It is much safer to build in consent mechanisms and develop a clear picture of the purposes for processing the personal data and incorporate them into your consent mechanisms.  In the example above, collection of consent to process personal data for the purposes of developing product recommendations would leave an organization protected.

    Legal Obligation – It is lawful to process personal data if it is done in accordance with a legal obligation.  Legal obligations can be compliance with another existing law or by court order for an ad-hoc purpose.  Processing of an individual’s personal data under this lawful basis is not recommended without clear reason for doing so.  It is recommended to consult an attorney if you intend to collect personal data as part of a legal obligation.  Be sure to take extra care in documenting the processing of personal data under the legal obligation lawful basis for processing.  Keep in mind that certain individuals rights such as right to erasure are forfeited when their data has been collected and processed as part of legal obligation.

    Vital Interests – It becomes lawful to collect and process personal data when it’s in the vital interest of preserving the individual or other natural persons life.  This will likely have the most applicability in the field of emergency medial care, when a person is indisposed and cannot give consent.  It is still recommend to give a best effort to obtain consent as lawful basis for processing instead of relying on protections from the vital interests basis.  Obtaining consent for personal data processing when a patient is admitted would be recommended.  If the patient’s health deteriorates while in your care and has a medical emergency that requires the processing of personal data it is better to have collected their consent upfront than to rely on the vital interests basis.

    Public Task – This lawful basis isn’t particularly new as far as data privacy is concerned.  Governments and other public entities have always had rules and regulations to follow with regard to the privacy of the citizens they serve.  The main changes in compliance requirement brought about for the public task bases is that the specific purpose for processing personal data must have a clear basis in law.  The requirements for documenting compliance have also been updated to be in line with the other bases.

    Legitimate Interests – The legitimate interests basis for processing can be thought of as a catch all basis.  It is the most flexible of the bases and the most prone to interpretation. In order to rely on this basis you must:

    1. Identity the legitimate interest that warrants collection and processing
    2. Show that collection and processing is necessary to achieve it
    3. Consider the impacts and interests of the individuals and balance collection and processing methods against them

    Note that a legitimate interest for the collecting business or organization alone is not enough to make this a basis for processing.  Legitimate interests must benefit the individual or serve another public purpose, profit motivated interests alone are not sufficient to qualify.  What’s important under the GDPR is that you document the process of relying on the legitimate interests basis and keep a record of it.  You must also inform consumers of your intent to collect and process the data in your privacy policy and comply with any other applicable provisions such as the right to object. We still recommend collecting explicit consent when feasible as it will leave your company more protected and compliant.

    Fairness

    Once you’ve established a lawful basis for collecting and processing personal data, you still have to document that process and collection was done in the spirit of fairness. One of the best ways to determine if the principle of fairness is being violated is to look for an injury to an individual or group of individuals.  Be especially careful when collecting personal information that relates to a protected class such as race or gender. For instance say you are running a resume aggregating service and collect consent from your users to obtain their gender as part of the completion of their profile.  A female data subject submits a right to object request after not being granted an interview for a position she felt qualified for and it is determined that the algorithm your aggregation service uses to match applicants to employers is biasing against women inadvertently.  This presence of an injury to a group of individuals would violate the principle of fairness in the collection of that data.  It could also be determined not to be fairness in collection in processing if you led the individual to believe their gender was only being collected for informational purposes and was not intended to be fed as a parameter to a resume matching algorithm.  Even if no injury was present, this would violate the principle of fairness since deceptive methods were used to collect the information, which cloaked the true intent for its use.  Keep in mind that although an injury may be present, that does not necessarily form the basis for a violation of the fairness principle.  Turbo Tax is a great example.  Considerable amounts of personal information are collected as part of the tax filing process, and at the end an estimate of taxes due is provided to the system’s user.  Although there is sometimes a monetary loss associated with using the system, the use of the personal information to assist the user in filing their taxes would be considered fair.

    Transparency

    The principle of transparency is a mainstay in the collection and processing of personal information for government agencies, but now transparency requirements are extending to businesses.  Organizations must be clear, concise, and honest about why they are collecting personal data, and how they will process and use the personal data.  These communications must be done in a plain language manner that a user could reasonably expect to be communicated to in that manner.  Legalese and lengthy, over-complicated explanations designed to confuse or distract a user, are not acceptable under the GDPR.  Accessibility is also a key concern in regards to the transparency principle, it’s a great idea to have your consent mechanisms, privacy policy, and terms of use pages reviewed for accessibility using a scanner such as wave.  An element of salesmanship will become valuable when communicating to users about why you would like to collect their data and how you would like to process it, especially in ways that the value may not be immediately apparent such as using profile data to recommend purchases.

    Conclusion

    The first principle of the GDPR:  Lawfulness, Fairness and Transparency focuses mostly on the underlying reasons for collecting and processing personal information and how it will be used.  It outlines the need for a lawful basis for processing and discusses the 6 bases for processing that have been identified. The bases of consent is the most recommend basis and organizations would do well to ensure they establish proper consent collection mechanisms.  It ensures that data is collected fairly and that the collection does not present unjust injury to an individual or group of individuals, regardless of how many other individuals are unaffected.  It ensures that organizations are being transparent in the way they inform their users on the type of information that is collected and the way it will be processed and used.  The responsibility lies within the collecting organization to document compliance with principles of the GDPR.  Establishing a process for documenting a lawful basis for processing, fairness, and transparency in collection will leave organizations prepared for regulatory scrutiny, help avoid lawsuits and fines.

    Share This Article
    Posted in:
    Tagged:

    Hunter Nelson

    Hunter is the founder and president of Tortoise and Hare Software, a digital marketing agency for the technology sector and other lead generation oriented businesses. Hunter has more than 10 years’ experience building web applications and crafting digital strategies for companies ranging from scrappy startups to Fortune 50 household names. When not on the clock, you'll find him spending time with his family and pups, relaxing on the beach, or playing competitive online video games. See for more.

    Leave a Comment





    Recent Blog Posts

    SEO Not Working: Here’s Why

    Lately I’ve been getting on more and more calls lately with people saying something along the lines of “we’ve been doing SEO or inbound for 6 months, 12 months, or…

    Why SEO Investments Help Your MSP Weather a Recession and Keep the Door Open for New Opportunities

    What happens to your pipeline when the phones go quiet, inboxes stay cold, and paid ads stop converting? That’s not a hypothetical. It’s what happens in a recession. Budgets freeze.…

    MSP Marketing – How to Build a Strategy That Works

    Let’s be honest—most MSP marketing doesn’t work.Not because the tactics are bad, but because they’re unaligned. What looks like a marketing problem is often a strategy problem in disguise. Most…

    The 10 Best MSP SEO Agencies To Help You Grow Organic Traffic

    If you’re searching for SEO agencies for MSPs, the list of generalists can feel endless—and underwhelming. Most SEO providers don’t understand the managed services space, much less the buyer behavior,…

    Why Your MSP’s Online Marketing Efforts Are Failing

    If you’re leading an MSP and investing in online marketing, you’re probably feeling a growing sense of frustration. You’ve put money into websites, content, ads—even hired an agency or two…

    What Makes a Great MSP Website? 5 Examples You Should Follow

    Your MSP website is more than just an online brochure—it’s a powerful tool for attracting and converting potential clients. But what makes a website truly effective in the competitive managed…

    Related Blog Posts

    CMMC Presents New Marketing And Sales Opportunity for MSPs

    Have you heard about the Cybersecurity Maturity Model Certification (CMMC)? It’s a universal standard meant to enhance and normalize cybersecurity throughout the Defense Industrial Base (DIB). Released on January 31,…

    Why do I need a Privacy Policy?

    Data privacy is a topic that is of growing concern to many consumers around the U.S. and you may have heard the term privacy policy a time or two in…

    One Way Hash Functions and Data Privacy Compliance.

    This article will discuss how a one way hash function can be used in the context of privacy compliance for regulations like the GDPR. Storing customer’s personal data is an…

    GDPR Principles: Accuracy

    The accuracy principle states that controllers and processor should make reasonable efforts to ensure personal data is accurate.  They must allow citizens to challenge the accuracy of data and take steps to rectify or erase the data associated with the challenge.  Verification is sometimes needed to ensure data is accurate.  Controllers and processors should consider the impact to the individual and whether they collected the data or the user provided it when determining appropriate verification steps.  Organizations should document challenges and their responses thoroughly and in a timely manner. They should also document the thought process for determining whether personal data needs to be verified and the verification steps taken if necessary.

    SAR Portal – Privacy Definitions

    The GDPR and subsequent chain of privacy laws passed in countries around the world have resulted in a slough of new lingo for privacy professionals and IT professionals to learn.  One of these new terms is the SAR portal.  SAR portal stands for Subject Access Request portal.  Many of the new privacy laws grants certain rights to the citizens of their countries that allow them to make certain requests to businesses and other organizations that collect and process personal data.  The types of rights that are granted to citizens varies from country to country.  Some example requests that can be made are….

    GDPR Principles: Data Minimization

    Data minimization is the concept of collecting the minimum amount of data needed to carry out the stated purpose and no more.  When conducting a data minimization evaluation you must ensure that the data collected is adequate and relevant to your stated purpose as well as limited. The onus is on the organization to document compliance with this principle.  We recommend documenting a review of this principle each time new personal data is collected or processed.  Conduct at least an annual audit of personal data that has been collected or processed to ensure that changes in the business have not impacted compliance with the data minimization principle.

    Top Blog Content

    The Ultimate Guide To MSP SEO

    Search Engine Optimization (SEO) is one of the most important ways to attract new business for mid-market managed service providers (MSP). If you look at MSPs that have achieved any…

    The Ultimate Guide To Paid Search On Google Ads For Managed Service Providers

    Generating leads for your MSP can be a challenge. You spend so much time managing employees, making sure customer support tickets are answered, procuring hardware, and defending against cyber threats,…

    The Ultimate Guide To MSP Website Optimization

    A well-optimized website is essential for Managed Service Providers (MSPs) looking to scale their business, attract more leads, and achieve a lucrative exit. A lot of MSPs check a few…

    The Ultimate Guide to Hiring an MSP Marketing Agency

    Are you one of the many MSPs struggling to attract new clients consistently? According to research conducted by MSP Dojo, a leading MSP sales consulting firm, approximately 85% of MSPs…

    The Ultimate Guide To Setting A Marketing Budget For IT Companies

    Many IT companies get their start as a one-man operation and rely almost exclusively on word of mouth, referrals, and other organic offline means to get past their initial growth…

    Featured Review of Tortoise and Hare

    ryan drake president nettech consultants
    R.D.
    President Florida Based MSP

    Tortoise and Hare has been a key partner in our MSP's growth. Over the year's we've worked together they've helped our MSP dramatically increase our website traffic, and build a steady stream of leads sourced from our website and advertising efforts. Over that time, we've been able to raise our base customer size, build economies of scale to more efficiently service customers, and expand into new markets.