What Does a £20 million GDPR Fine Have To Do With Customer Segmentation?
What this covers
In a world where insights propel marketing and data continues to serve as leverage to attaining a competitive advantage, it’s no surprise that the majority of the world’s businesses have developed mechanisms to actively harvest data. Everything from user web search histories, places visited, calls made, email sent, and even photos taken is tracked, measured and then used to formulate a unique digital footprint. When paired with footprints from a diverse range of users these blocks of data are a prized digital assets, so valuable and sensitive that they’re sometimes subject to exploitation and theft (at the expense of the user).
*So, what protects the user?*
The security of the typical web user, consumer or business client has been a major talking point in the analytics field. One survey conducted by TRUSTe/NCSA showed that no less than 92% of web users think the privacy of their data and overall security is a major concern. 57% of all consumers go on to outrightly state that they don’t believe the modern-day business brand handles their data responsibly, not surprising to say the least. It’s on the record that an alarming 90% of businesses find it rather difficult to delete user data. 60% of these businesses don’t even have a mechanism to do this in the first place!
Data misuse is a prevalent practice in the analytics and marketing space, and before now there was very little protection (by way of often lax federal laws) protecting the rights of the internet user, consumer or customer. In 2018 however, the EU signed the GDPR, an extensive set of digital privacy laws, drafted to intimately protect the privacy and security of the EU citizens.
**The Implications of the GDPR****
While data-oriented organizations would have gotten away with consumer privacy violations in the past, GDPR debuts as a regulatory cuff that holds companies wholly responsible for the privacy and security implications of their digital products. It’s legally binding as all its provisions are enforceable and tenable in a court of law. This means that for the data-oriented firm, business or marketer, negligence, exploitation or misuse of user data will no longer attract just the customary slap on the wrist from regulatory authorities. GDPR ushers in a new wave of stricter sanctions, steeper fines and tougher restrictions for privacy and security violations, one that every data-oriented firm would be prudent to avoid.
**Compliance with GDPR****
It’s important to note that GDPR doesn’t just apply to marketers, online businesses, or other enterprises chiefly concerned with storing customer data. More than that, it’s an all-encompassing string of laws intentionally crafted to account for all forms of data use within and outside the business analytics ecosphere. So, even if you were a traditional firm or organization attempting to orchestrate a customer segmentation analysis, you would still need to comply with the GDPR since the latter involves the handling of user data.
The good news, however, is that the seemingly extensive provisions of GDPR can be condensed into three essential rules, all of which are relatively easy to understand and appreciate.
- Data access: GDPR mandates that all users (users, in this case, referring to every entity implicated in a data capture) be accorded the right to specify how they want their data collected with the additional ability to access and if the need is, remove this data.
- Data focus: Businesses must also provide a justifiable basis for collecting data sets captured in their marketing and analytics platform, i.e., they must prove that data collected from users is essential to the propagation of their organizational goals. This regulation aims to limit just how much user information organizations and marketers have at their disposal – you’re only allowed to keep data if you have a proven (and relatable) need for it.
- Data permission: Data permission is concerned with the level of access an organization has to specific components of user data. While in the past a simple user opt-in for promotional offers could be treated as consent to send marketing offers, tailored leads or outrightly sign them up for other extras, the new GDPR laws mandates that users must freely provide express, unambiguous, and specific consent with distinct affirmative actions.
Like we’ve already emphasized, compliance with GDPR is critical for any organization handling user data, and even more so for global organizations intent on performing customer segmentation analysis. In trying to segregate the ideal customer from the everyday consumer, a customer segmentation analysis leverages AI and big data, both of which utilize immense computing resources to comb through vast pools of user data. Conforming to GDPR regulations on a micro level (mailing lists, data permissions, etc.) is pretty much a straightforward process. However, the extent and inclusiveness of big data and AI significantly raises the risk of flouting its provisions on a macro level.
Invariably, orchestrating a successful consumer segmentation requires that global organizations take proactive steps to conform to the new requirements of GDPR, especially considering the steep fines that accompany violations. In August of 2016, for instance, Flybe one of Europe’s regional airlines was fined £70,000 for sending a promotional email to 3.3 million people who had unsubscribed from its mailing list. I wouldn’t want to have been part of that marketing snafu. And if that sounds steep, then the new GDPR fines in the range of £20 million or 4% of overall global profits (whichever turns out to be greater) should highlight the dire consequence of noncompliance.
Is your organization GDPR compliant?
Do you have a customer segmentation strategy that accounts for GDPR? Let’s start a conversation today to discuss tested data strategies for performing GDPR friendly customer segmentation analysis.