How is GDPR affecting affiliates? And how to solve the issue?

pecas

Newbie
Joined
May 22, 2014
Messages
30
Reaction score
7
I made a search for "GDPR" in all the BHW forums, and didn't find many threads, which means most of the people are unaware that, in about 2 months, our business will change forever.

In particular, I'm trying to address the issues that affiliate marketers will face, that's why I decided to post in this forum in particular.

I hope this thread will open your eyes and will help all of us to find a solution to comply with this new regulation. Let's start with some info:

What is GDPR?
It is an European union regulation about privacy in general, which is going to affect, among other things, any website that is served to EU citizens, regardless of where it is located. The new regulation is imposing a very strict way to obtain "consent" and to treat the collected data.

Why should we worry?
Because, in case you are not respecting this regulation, you are subject to a fine of EUR 20 Millions or 4% of your turnover (whichever is higher!).

What does GDPR state that could affect an affiliate marketer?

In general, every website that collects data is affected. This means that even a non-profit blog with no affiliate links, even if just tracking traffic with Google Analytics, must comply with the law.
Now, a simple affiliate website usually does not collect any data about his customers (unless they have the possibility to register, or newsletter opt-ins). It's the affiliate network, or Amazon, or whoever is the e-shop, to collect data.

The law, though, specifies that if you facilitate the data collection by third parties (exactly the affiliate job) then you must comply with the law.

In particular, here is a short (and, for sure, incomplete) list of requirements (NOTE: this is taken from the official GDPR website (apparently I cannot post links yet), interpreted by various articles I was able to find online:

1. extra-territorial applicability: the law is applicable to every website which is visible to the EU citizens, regardless of where it is located.
2. clear and distinguishable consent: which means, apparently, that every cookie must be accepted (or refused) separately (example: Google Analytics, Amazon, Clickbank, etc) and, furthermore, that the content cannot be blocked for who is refusing cookies. In addition, the consent form must be clearly giving an option to refuse (no thing like "if you continue to use this site you accept..."), and explain, not in "legalese" but in common language, what happens if the consent is given. Finally, the user must have a way to withdraw consent at any time. Most likely, all this info must be provided in all the EU languages.
3. other obligations: the website owner must keep a record of consent given/withdrawn; must document the procedures used for data security; must grant access to the user, so that he can see his own data; must cancel in full (or in part) the data that are not strictly necessary anymore, even if not solicited to do so by the user; must communicate to his users, within 72 hours, if there has been a breach in data security. And must prove, if requested, that all these procedures are in place.

-------------------

As you can understand, this law was written by someone who doesn't know how internet works. It's a law that could potentially destroy 95%, if not more, of the EU websites (because I don't think website owners outside the EU will even care).

Here is another short (and incomplete) list of paradoxical situations that this law is going to create:

1st paradox: the way the law was created. It's the result, they say, of a survey where EU citizens were asked if they would like to have more privacy protection online. I wonder what law they would approve if they do a survey asking if EU citizens would like to pay less taxes...

2nd paradox: the amount of fines. With a "minimum" fine of 20 million for serving cookies without consent, they clearly show that they don't know the structure of internet. It seems a law made only for the giants (Google, Amazon, etc) but the internet is made of millions of small sites that, certainly, cannot afford to pay that fine. Moreso, they cannot afford to invest in the measures needed to comply with the law, so they will either not respect the law or disappear.

3rd paradox (linked to the 2nd): how do they think to check the more than one billion (I have no idea, probably many more) websites that are visible to the EU citizens? Will they wait for EU people to sue a website, to start checking? Or will they just hit casually?

4th paradox: it's clearly illegal and against the international laws to demand that websites which are not located in the EU and belong to individuals/companies outside of the EU, to comply with a foreign law.

5th paradox: they wrote a law which is very hard to interpret, without giving any specific procedure that makes you safe. Yet, they demand that we "translate" their obscure language in common language, easy to understand for the users

6th paradox: they say it's prohibited to block the content from the users that won't accept cookies, but then, what about the sites where you must register to see the content? Are they all criminals from now on? And, assuming we (the affiliates) comply: does it mean we need to have a double version of our website? One with affiliate links, one without? And what if you have 5 affiliate programs, with the user being able to accept/refuse 5 types of cookies? Do you need to have 32 versions of your website, to consider all the accept/refuse combinations?

7th paradox: we, the affiliates, that until now would not collect user's data, will be forced to collect user's data: a great result, in terms of privacy.

------------------


Who's gonna help us?
Certainly, not Amazon. They don't seem to care much about their affiliates. On the contrary: not complying to the law could be a reason to ban our accounts.
We can hope in the affiliate networks, like Tradetracker, Commission Junction, etc. Those, certainly, are the ones who have all to lose if the affiliate business disappears. Soliciting them to provide a solution, which I have done already, seems a good thing to do and I invite you to do the same to enforce the request.

Conclusions
I hope this post will raise your awareness of this problem. The deadline to comply (May 25th, 2018) is very close. Honestly, I have no idea of what to do. Close my activity? Risk to be fined and lose all I have? My hope is that an easy solution will come out.

Certainly, I cannot afford to pay lawyers or software houses to create a specific solution for me. I'm not a good coder either, and cannot help if an opensource solution comes out; but if we want to try a crowdfunding campaign together, I'm more than available to contribute.

To any affiliate: we should act now, or our (small or big) extras are going to disappear.
 
Last edited:
Dude, why spreading panic for nothing?

First of all the fine is not minimum 4% or 20 millions, but UP to this: "This is the maximum fine that can be imposed for the most serious infringements".... "There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order ..."
Second: Its not about cookies but PERSONAL DATA. Even now you need special permission to operate with personal data (ID documents and such). I am pretty sure that this is not something 99.999% of the affiliate businesses care about.
Third: None of the above have anything to do with affiliate businesses.
 
I sincerely hope you're the one to tell me "I told you so", but that's not what I found online.
 
Ha, I was just looking for info like this!

I think I am in the same boat as TS is. To be honest: I don't think GDPR is only about dealing with "ID documents and such", it is about ANY information collected (by you or 3rd parties you facilitate the collection of data for, like GA, Adsense, affiliate networks, etc.) on your sites/blogs/etc.

Information comes in 3 forms, according to the GDPR:
1. Personal data (device-ID's, name/address, IP-address)
2. Psudo-personal data (like encrypted user-id, encrypted e-mail address, etc. Data that is anonymous but that can be linked to a user if more information is connected)
3. Anonymous data.

Also, you are forced to check if any of these 3rd parties that you allow to collect data on your site(s) do comply with the laws. If you allow a 3rd party to collect data on your site(s) and you claim that you comply to all the rules, and this 3rd party turns out not to comply, it is you who gets fined, for you are the facilitator for this infringement to occur.

Furthermore, you are forced to collect, for any visitor, if he accepted your cookies/tracking or not, and if so what he accepted. You need to commect this data and keep it available for an inquest by authorities. Then, you cannot tell a visitor to just accept/not accept cookies, you need him to accept all types of cookies individually. And to top it off, you cannot have a popup with all your types of tracking listed and a checkmark next to it already checked, you need to have the visitor check all the boxes himself.

I am looking for an install-and-go ready tool to do all that is needed to comply, as I don't want to deal with any EU regulator in my life - ever.
 
This whole thread deserve just a freaking:

upload_2018-3-19_13-18-44.png

The whole shit (https://www.eugdpr.org/key-changes.html) is about information YOU keep about the user. Cookies are information that is SEND to the users. If you did not see the difference - go and panic.
 
I'm not too worried. The EU is a joke! Every year they come up with BS rules but they can barely enforce their own rules and laws.

Like this cookie popup. Officially your website has to show a cookie warning when sending/collecting any data.

None of my sites ever had this plus they now find those messages annoying themselves.

You shouldn't be too worried about it unless you will become a really big player.

Until then, fuck em.
 
Last edited:
This whole thread deserve just a freaking:

View attachment 101673

The whole shit (https://www.eugdpr.org/key-changes.html) is about information YOU keep about the user. Cookies are information that is SEND to the users. If you did not see the difference - go and panic.

Haha, first of all I agree on the "whole shit".

I beg to differ on your interpretation of cookies. The law mentions cookies specifically in the premises (#30):

Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.

and later on, at article 4, here is the definition of personal data:

‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
 
Of course it's a completely stupid law which they will be unable to enforce, just like the current law, that nobody takes seriously and is highly annoying (all those freekin' popups/walls all the time).

But saying it won't apply to cookies because a cookie is not collected but placed on the visitors' machine is, in my humble opinion, incorrect. If a cookie is placed but can never be 'collected' for tracking etc., it is useless, no?

Anyway; I agree with AWK: let's just use a plugin to take care of stuff and be done with it, or, in the wise words of Billy Batts: fuck em.
 
You can get around a bunch of it by defining specific elements as necessary for the user experience.

Take for example a shopping cart on an ecommerce site. It is not reasonable for a customer to disallow cookies that maintain their shopping cart as it is required for the site to perform functions that are beneficial to and in the best interests of the customer.

There are a whole load of other places where this is the case. You will need to have an updated privacy policy clearly declaring what information you take from customers and what cookies are used on the site etc, but don’t be too worried about this.

There was an article (I will try and find the link) from someone working on this, stating that they are not just out to fine people. It’s about supporting sites and businesses in improving their data protection.

Aside from that, it will be ridiculously hard to police and I have no idea how they intend to do it. If your sites or business is under a certain size, you will likely only come onto the radar if a number of your site visitors make a complaint.
 
so will this crap GDPR affect us affiliate marketers at the end or not and if affects us what we need to do?
 
so will this crap GDPR affect us affiliate marketers at the end or not and if affects us what we need to do?
Depending on who you ask, the answer is either "won't affect anyone, really" or "prepare for a sh*tload of reading, legal mumbo jumbo, lawyer bills and code implementations".

Really, the interpretations for GDPR are all over the place. Even spokespersons for the different affiliate networks are on both ends of the spectrum. And then there is the big G, of course.

I wish there was a solid answer, but so far, I have found nothing to really go on. So I'm going to wait it out 'till May, then go with the most likely scenario and look for resolutions to be on the safe side of things. So I'm sorry for not being of any help.
 
The things to be careful with on affiliate sites are cookie policies and newsletter signups primarily.

In its most basic sense, GDPR is about getting user consent to obtain and use personal data. Most affiliate sites won’t really be dealing with much personal data.
 
This is too big and they cant enforce it, a small cookie popup was another story but this one is impossible for them to enforce, It will make many people angry
 
Back
Top