The Right Way to Use Data
The Marketing Dilemma
The 'Goldmine' Scenario
You have a list of 500 emails from a 'Remote Work Tips' webinar. You want to use them for a new 'Project Management' software launch.
Is this allowed? Having access to data doesn't mean you have the right to use it for anything you want.
Imagine you’re a Marketing Manager who just found a goldmine: a list of 500 email addresses from a webinar your company hosted last year on 'Remote Work Tips.' You’re now launching a new software product for 'Project Management.' It’s tempting to just copy those emails into your new campaign, right? After all, they’ve already interacted with the brand. But wait—under GDPR, having access to data doesn't automatically mean you have the right to use it for whatever you want.
- Data access ≠ Data usage rights
- Context matters in data handling
- GDPR requires a specific plan for data
The 'Permission Slip'
Lawful Basis
You need a valid reason to handle data. Think of it as a permission slip. Most daily tasks fall into three categories:
- Consent: Explicit 'Yes'.
- Contract: Necessary for the service.
- Legitimate Interest: Necessary for business (e.g., fraud prevention).
In the world of GDPR, you can't just handle personal data because it's convenient. You need a valid reason. Think of this as a 'Permission Slip.' First is Consent: The person explicitly said 'Yes'—like ticking a box for a newsletter. Second is Contract: You need the data to do what the customer paid for, like an address for shipping. Finally, Legitimate Interest: This is for things like fraud prevention that protect the business without harming the individual.
- Consent must be explicit
- Contractual necessity covers shipping/billing
- Legitimate interest covers basic security
The 'No-Surprises' Rule
Purpose Limitation
Only use data for the specific reason it was collected. If a use would surprise the customer, it's likely a violation.
This rule is simple: you should only use data for the specific reason it was collected in the first place. If a customer gives you their phone number so you can call them about a delivery delay, that is the 'Expected' use. It’s a 'surprise'—and a violation—if you then use that number to send them SMS marketing for a summer sale. If they'd be annoyed or surprised to hear from you, you're likely breaking the rule.
- Stick to the original plan
- Avoid 'surprising' the customer
- New purposes require new permission
What Would You Do?
A customer, Alex, submits a support ticket for a login issue. A Sales rep sees the info and wants to call Alex to pitch an upgrade. Is this okay?
Explain your reasoning below.
Let's look at a real-world case. Alex submits a support ticket because their login isn't working. While fixing the issue, a Sales rep sees Alex’s contact info and wants to call them for a pitch. Use the text box to explain if this is allowed and why, based on the 'No-Surprises' rule.
- Support data is for support only
- Sales requires a separate basis
- Avoid 'Function Creep'
Your Daily Checklist
The GDPR 'Safety Check'
Before handling data, ask yourself:
- Check the Source: Why do we have this?
- The Expectation Test: Would they be surprised?
- The 'Need vs. Want' Test: Is this data necessary?
Before you start any new task involving data, run through this quick checklist. First, Check the Source: Why do we have this data? Was it for a newsletter or a purchase? Second, the Expectation Test: Would the person be surprised or annoyed to hear from me for this reason? And finally, the 'Need vs. Want' Test: Do I really need this specific data, or do I just want it? If you're ever unsure, escalate it to your manager or the Data Protection Officer.
- Always verify the data source
- Perform a mental 'Expectation Test'
- Distinguish between 'Need' and 'Want'