The Right Way to Use Data

The Marketing Dilemma

The 'Goldmine' Scenario

You have a list of 500 emails from a 'Remote Work Tips' webinar. You want to use them for a new 'Project Management' software launch.

Is this allowed? Having access to data doesn't mean you have the right to use it for anything you want.

Imagine you’re a Marketing Manager who just found a goldmine: a list of 500 email addresses from a webinar your company hosted last year on 'Remote Work Tips.' You’re now launching a new software product for 'Project Management.' It’s tempting to just copy those emails into your new campaign, right? After all, they’ve already interacted with the brand. But wait—under GDPR, having access to data doesn't automatically mean you have the right to use it for whatever you want.

The 'Permission Slip'

Lawful Basis

You need a valid reason to handle data. Think of it as a permission slip. Most daily tasks fall into three categories:

In the world of GDPR, you can't just handle personal data because it's convenient. You need a valid reason. Think of this as a 'Permission Slip.' First is Consent: The person explicitly said 'Yes'—like ticking a box for a newsletter. Second is Contract: You need the data to do what the customer paid for, like an address for shipping. Finally, Legitimate Interest: This is for things like fraud prevention that protect the business without harming the individual.

The 'No-Surprises' Rule

Purpose Limitation

Only use data for the specific reason it was collected. If a use would surprise the customer, it's likely a violation.

This rule is simple: you should only use data for the specific reason it was collected in the first place. If a customer gives you their phone number so you can call them about a delivery delay, that is the 'Expected' use. It’s a 'surprise'—and a violation—if you then use that number to send them SMS marketing for a summer sale. If they'd be annoyed or surprised to hear from you, you're likely breaking the rule.

What Would You Do?

A customer, Alex, submits a support ticket for a login issue. A Sales rep sees the info and wants to call Alex to pitch an upgrade. Is this okay?

Explain your reasoning below.

Let's look at a real-world case. Alex submits a support ticket because their login isn't working. While fixing the issue, a Sales rep sees Alex’s contact info and wants to call them for a pitch. Use the text box to explain if this is allowed and why, based on the 'No-Surprises' rule.

Your Daily Checklist

The GDPR 'Safety Check'

Before handling data, ask yourself:

Before you start any new task involving data, run through this quick checklist. First, Check the Source: Why do we have this data? Was it for a newsletter or a purchase? Second, the Expectation Test: Would the person be surprised or annoyed to hear from me for this reason? And finally, the 'Need vs. Want' Test: Do I really need this specific data, or do I just want it? If you're ever unsure, escalate it to your manager or the Data Protection Officer.