Did you know that data protection should be part of your communication activities?
No matter what activity we perform, we have the obligation to protect people’s fundamental right to privacy and their rights such as to access, rectify or delete their data. This has a legal basis, as personal data are protected under the EU General Data Protection Regulation (GDPR).
You may wish to use personal data in your communication, but there are some actions you must take to comply with data protection and protect people’s rights.
- Identify the communication activities or products (videos, photos, articles, events, etc.) for which you would use people’s personal data.
- List what data you need to collect. Personal data is an encompassing term, meaning any information relating to an identified or identifiable natural person (such as names, emails, images, gender, etc.). This must be done even if they are your colleagues.
- Prepare and publish a Data Protection Record for each specific communication activity (events, newsletters, videos, etc.) to describe why and how you are using the personal data (i.e. processing of data).
- Prepare a Data Protection Notice to inform people what data is being collected and for what end (e.g. a communication campaign, a video, and event, etc.).
- If you plan to process personal data based on an individual's agreement, prepare a consent form for the individual whose personal data you are seeking to process.
- Share with them the corresponding Data Protection Notice and the consent form. The individual can physically sign the consent form and return it or provide consent by clearing stating that they agree to their data being processed in accordance with the DP Record and DP Notice in a written communication.
- Keep track of all your Data Protection Records, Notices and consent forms signed during the entire lifecycle of the project.
- Establish the time limit to erase that data. Data must be stored for the shortest time necessary, and this time must be indicated in the DP Record and DP Notice. As a reminder, you may want to add in your calendar when you should delete the data you have collected.
- Keep the personal data safe: take appropriate technical and organisational measures to ensure the security of personal data and take immediate action in case of complaints or breaches.
- Do not save images to your personal devices, nor re-use images from external sources, where people are recognisable. You cannot be sure they comply with data protection rules. The same applies to any personal data.
You may want to get inspired by our Public Central Register and the guidance/checklist to comply with data protection rules.
You may also perform communication activities without collecting and processing people’s personal data. For example, taking and using photographs of an event without the attendees (i.e. photographs of the venue) or where they are not recognisable.
Disclaimer (important notice)
The information and guidance in these webpages are intended to contribute to a better understanding of EU data protection rules.
This is intended purely as a guidance tool – only the text of the General Data Protection Regulation (GDPR) has legal force. As a consequence, only the GDPR is liable to create rights and obligations for individuals. This guidance does not create any enforceable right or expectation.
The binding interpretation of EU legislation is the exclusive competence of the Court of Justice of the European Union. The views expressed in this guidance are without prejudice to the position that the Commission might take before the Court of Justice.
Neither the European Commission nor any person acting on behalf of the European Commission is responsible for the use which might be made of the following information.
As this guidance reflects the state of the art at the time of its drafting, it should be regarded as a 'living tool' open for improvement and its content may be subject to modifications without notice.
