I made a search for "GDPR" in all the BHW forums, and didn't find many threads, which means most of the people are unaware that, in about 2 months, our business will change forever.
In particular, I'm trying to address the issues that affiliate marketers will face, that's why I decided to post in this forum in particular.
I hope this thread will open your eyes and will help all of us to find a solution to comply with this new regulation. Let's start with some info:
What is GDPR?
It is an European union regulation about privacy in general, which is going to affect, among other things, any website that is served to EU citizens, regardless of where it is located. The new regulation is imposing a very strict way to obtain "consent" and to treat the collected data.
Why should we worry?
Because, in case you are not respecting this regulation, you are subject to a fine of EUR 20 Millions or 4% of your turnover (whichever is higher!).
What does GDPR state that could affect an affiliate marketer?
In general, every website that collects data is affected. This means that even a non-profit blog with no affiliate links, even if just tracking traffic with Google Analytics, must comply with the law.
Now, a simple affiliate website usually does not collect any data about his customers (unless they have the possibility to register, or newsletter opt-ins). It's the affiliate network, or Amazon, or whoever is the e-shop, to collect data.
The law, though, specifies that if you facilitate the data collection by third parties (exactly the affiliate job) then you must comply with the law.
In particular, here is a short (and, for sure, incomplete) list of requirements (NOTE: this is taken from the official GDPR website (apparently I cannot post links yet), interpreted by various articles I was able to find online:
1. extra-territorial applicability: the law is applicable to every website which is visible to the EU citizens, regardless of where it is located.
2. clear and distinguishable consent: which means, apparently, that every cookie must be accepted (or refused) separately (example: Google Analytics, Amazon, Clickbank, etc) and, furthermore, that the content cannot be blocked for who is refusing cookies. In addition, the consent form must be clearly giving an option to refuse (no thing like "if you continue to use this site you accept..."), and explain, not in "legalese" but in common language, what happens if the consent is given. Finally, the user must have a way to withdraw consent at any time. Most likely, all this info must be provided in all the EU languages.
3. other obligations: the website owner must keep a record of consent given/withdrawn; must document the procedures used for data security; must grant access to the user, so that he can see his own data; must cancel in full (or in part) the data that are not strictly necessary anymore, even if not solicited to do so by the user; must communicate to his users, within 72 hours, if there has been a breach in data security. And must prove, if requested, that all these procedures are in place.
-------------------
As you can understand, this law was written by someone who doesn't know how internet works. It's a law that could potentially destroy 95%, if not more, of the EU websites (because I don't think website owners outside the EU will even care).
Here is another short (and incomplete) list of paradoxical situations that this law is going to create:
1st paradox: the way the law was created. It's the result, they say, of a survey where EU citizens were asked if they would like to have more privacy protection online. I wonder what law they would approve if they do a survey asking if EU citizens would like to pay less taxes...
2nd paradox: the amount of fines. With a "minimum" fine of 20 million for serving cookies without consent, they clearly show that they don't know the structure of internet. It seems a law made only for the giants (Google, Amazon, etc) but the internet is made of millions of small sites that, certainly, cannot afford to pay that fine. Moreso, they cannot afford to invest in the measures needed to comply with the law, so they will either not respect the law or disappear.
3rd paradox (linked to the 2nd): how do they think to check the more than one billion (I have no idea, probably many more) websites that are visible to the EU citizens? Will they wait for EU people to sue a website, to start checking? Or will they just hit casually?
4th paradox: it's clearly illegal and against the international laws to demand that websites which are not located in the EU and belong to individuals/companies outside of the EU, to comply with a foreign law.
5th paradox: they wrote a law which is very hard to interpret, without giving any specific procedure that makes you safe. Yet, they demand that we "translate" their obscure language in common language, easy to understand for the users
6th paradox: they say it's prohibited to block the content from the users that won't accept cookies, but then, what about the sites where you must register to see the content? Are they all criminals from now on? And, assuming we (the affiliates) comply: does it mean we need to have a double version of our website? One with affiliate links, one without? And what if you have 5 affiliate programs, with the user being able to accept/refuse 5 types of cookies? Do you need to have 32 versions of your website, to consider all the accept/refuse combinations?
7th paradox: we, the affiliates, that until now would not collect user's data, will be forced to collect user's data: a great result, in terms of privacy.
------------------
Who's gonna help us?
Certainly, not Amazon. They don't seem to care much about their affiliates. On the contrary: not complying to the law could be a reason to ban our accounts.
We can hope in the affiliate networks, like Tradetracker, Commission Junction, etc. Those, certainly, are the ones who have all to lose if the affiliate business disappears. Soliciting them to provide a solution, which I have done already, seems a good thing to do and I invite you to do the same to enforce the request.
Conclusions
I hope this post will raise your awareness of this problem. The deadline to comply (May 25th, 2018) is very close. Honestly, I have no idea of what to do. Close my activity? Risk to be fined and lose all I have? My hope is that an easy solution will come out.
Certainly, I cannot afford to pay lawyers or software houses to create a specific solution for me. I'm not a good coder either, and cannot help if an opensource solution comes out; but if we want to try a crowdfunding campaign together, I'm more than available to contribute.
To any affiliate: we should act now, or our (small or big) extras are going to disappear.
In particular, I'm trying to address the issues that affiliate marketers will face, that's why I decided to post in this forum in particular.
I hope this thread will open your eyes and will help all of us to find a solution to comply with this new regulation. Let's start with some info:
What is GDPR?
It is an European union regulation about privacy in general, which is going to affect, among other things, any website that is served to EU citizens, regardless of where it is located. The new regulation is imposing a very strict way to obtain "consent" and to treat the collected data.
Why should we worry?
Because, in case you are not respecting this regulation, you are subject to a fine of EUR 20 Millions or 4% of your turnover (whichever is higher!).
What does GDPR state that could affect an affiliate marketer?
In general, every website that collects data is affected. This means that even a non-profit blog with no affiliate links, even if just tracking traffic with Google Analytics, must comply with the law.
Now, a simple affiliate website usually does not collect any data about his customers (unless they have the possibility to register, or newsletter opt-ins). It's the affiliate network, or Amazon, or whoever is the e-shop, to collect data.
The law, though, specifies that if you facilitate the data collection by third parties (exactly the affiliate job) then you must comply with the law.
In particular, here is a short (and, for sure, incomplete) list of requirements (NOTE: this is taken from the official GDPR website (apparently I cannot post links yet), interpreted by various articles I was able to find online:
1. extra-territorial applicability: the law is applicable to every website which is visible to the EU citizens, regardless of where it is located.
2. clear and distinguishable consent: which means, apparently, that every cookie must be accepted (or refused) separately (example: Google Analytics, Amazon, Clickbank, etc) and, furthermore, that the content cannot be blocked for who is refusing cookies. In addition, the consent form must be clearly giving an option to refuse (no thing like "if you continue to use this site you accept..."), and explain, not in "legalese" but in common language, what happens if the consent is given. Finally, the user must have a way to withdraw consent at any time. Most likely, all this info must be provided in all the EU languages.
3. other obligations: the website owner must keep a record of consent given/withdrawn; must document the procedures used for data security; must grant access to the user, so that he can see his own data; must cancel in full (or in part) the data that are not strictly necessary anymore, even if not solicited to do so by the user; must communicate to his users, within 72 hours, if there has been a breach in data security. And must prove, if requested, that all these procedures are in place.
-------------------
As you can understand, this law was written by someone who doesn't know how internet works. It's a law that could potentially destroy 95%, if not more, of the EU websites (because I don't think website owners outside the EU will even care).
Here is another short (and incomplete) list of paradoxical situations that this law is going to create:
1st paradox: the way the law was created. It's the result, they say, of a survey where EU citizens were asked if they would like to have more privacy protection online. I wonder what law they would approve if they do a survey asking if EU citizens would like to pay less taxes...
2nd paradox: the amount of fines. With a "minimum" fine of 20 million for serving cookies without consent, they clearly show that they don't know the structure of internet. It seems a law made only for the giants (Google, Amazon, etc) but the internet is made of millions of small sites that, certainly, cannot afford to pay that fine. Moreso, they cannot afford to invest in the measures needed to comply with the law, so they will either not respect the law or disappear.
3rd paradox (linked to the 2nd): how do they think to check the more than one billion (I have no idea, probably many more) websites that are visible to the EU citizens? Will they wait for EU people to sue a website, to start checking? Or will they just hit casually?
4th paradox: it's clearly illegal and against the international laws to demand that websites which are not located in the EU and belong to individuals/companies outside of the EU, to comply with a foreign law.
5th paradox: they wrote a law which is very hard to interpret, without giving any specific procedure that makes you safe. Yet, they demand that we "translate" their obscure language in common language, easy to understand for the users
6th paradox: they say it's prohibited to block the content from the users that won't accept cookies, but then, what about the sites where you must register to see the content? Are they all criminals from now on? And, assuming we (the affiliates) comply: does it mean we need to have a double version of our website? One with affiliate links, one without? And what if you have 5 affiliate programs, with the user being able to accept/refuse 5 types of cookies? Do you need to have 32 versions of your website, to consider all the accept/refuse combinations?
7th paradox: we, the affiliates, that until now would not collect user's data, will be forced to collect user's data: a great result, in terms of privacy.
------------------
Who's gonna help us?
Certainly, not Amazon. They don't seem to care much about their affiliates. On the contrary: not complying to the law could be a reason to ban our accounts.
We can hope in the affiliate networks, like Tradetracker, Commission Junction, etc. Those, certainly, are the ones who have all to lose if the affiliate business disappears. Soliciting them to provide a solution, which I have done already, seems a good thing to do and I invite you to do the same to enforce the request.
Conclusions
I hope this post will raise your awareness of this problem. The deadline to comply (May 25th, 2018) is very close. Honestly, I have no idea of what to do. Close my activity? Risk to be fined and lose all I have? My hope is that an easy solution will come out.
Certainly, I cannot afford to pay lawyers or software houses to create a specific solution for me. I'm not a good coder either, and cannot help if an opensource solution comes out; but if we want to try a crowdfunding campaign together, I'm more than available to contribute.
To any affiliate: we should act now, or our (small or big) extras are going to disappear.
Last edited:
