Need for GHL to be fully GDPR compliant for European agencies & clients
complete
I
Ian Tritschler
GDPR compliance has been raised many times by GHL members but I cant see an idea relating to it here. Issue: Companies managing data for European clients must provide a data processing agreement and process to demonstrate to clients on how they plan to handle personal data and breaches that is in line with GPDR. As far as I am aware GHL does not have this. The impact is that all European agencies using GHL are operating outside of EU law according to my understanding. Could we have a timeline on when this will be implemented please?
HIGHLVL-I-2209
Log In
R
RevEx Group
complete
Hello customers!
For GDPR compliance please head over to - https://app.gohighlevel.com/gdpr [you need to be logged-in as an agency admin]
Cheers!
D
David Ronka
As I understand GDPR, it applies to everyone who has clients or virtual visitors from the EU. That means a US-based company/website still has to comply with GDPR if people from the EU visit their website and/or buy their services/products. I could be wrong on this, but either way, I'm all for this feature!
D
Daniel Datsenko
We need this!!
M
Michel Smits
We need this
u
undefined undefined
I am all for this.
P
Patrick Kenney
Marla, here is the statute.Does the GDPR apply to EU citizens living or visiting the US?No. The GDPR specifically refers to “data subjects who are in the Union.” If an EU citizen is living or visiting in the US, the GDPR does not apply. This is an important distinction to be considered if all or nearly all of a company’s business takes place in brick-and-mortar locations on US soil.Territorial citation: https://gdpr-info.eu/art-3-gdpr/
M
Marla Harmon
One of the most common misunderstandings is that it's just for companies with clients in the EU. Every US-based company needs to understand and fully comply. Here's why:A person from the EU comes to the US on a trip and searches online for a dentist or a gym. Not only is the website owner, but the data processor is liable for compliance. There are very strict tracking and processing requirements, as well as opt-in and opt-out requirements. It doesn't matter if you intended to target the person who's researching from the EU about life in the US. They don't have to be in the US ever. If they visit your website, you can be held liable. You can't track it by IP address either because of VPNs.