
The privacy policy and measures for the protection of personal data are not just a formal requirement, but a very serious and responsible matter, so it must be treated as seriously as possible.
If you have decided to create a website or online store, you need to take special care of creating a privacy policy to comply with the principles of legality and integrity. Any processing of personal data must have a legal basis.
In this article we will tell you what customer data is considered to be personal data, which is the processing of personal data and when your website should have a privacy policy.
The most common personal data are the given name, surname and personal identity number. However, this is not the only data that allows the identification of a person. An identifiable person shall be one who can be identified, directly or indirectly, in particular by reference to an identifier such as that person's name, personal identity number, location data, online identifier, one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity. It follows from the foregoing that personal data are different information, which, when collected, can identify a particular person.
It has to be said, however, that the same name and surname, which is common, for example, Anna Bērziņa, will not yet be personal data if there is no additional information about which Anna Bērziņš is talking about. However, if this particular given name and surname is linked to an additional identifier, such as a personal identity number, place of work or place of residence, then it is personal data, since the person in question thus becomes identifiable.
Individuals may also be associated with the online identifiers they use on their devices, applications, tools and protocols, such as IP addresses, cookie identifiers or other identifiers. This may leave traces that, in particular when combined with unique identifiers and other information received by servers, can be used to create profiles and identify profiles of individuals.
By definition, the processing of personal data is any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means. For example:
The Regulation does not apply to data processing concerning data relating to legal personality data, such as information on the name of the company, the form of business and contact details.
The requirements of data protection laws must be met by everyone who obtains and uses any personal data. As we have already found out, personal data is any information that allows to legally identify a particular person – name, surname, address, e-mail address, date of birth, etc. Personal data protection obligations shall apply to absolutely everyone who:
If you offer products or services on your website or you have customers, or your website has a statistical collection or contact form, even if you are simply communicating with website visitors, it is mandatory to have a privacy policy on your website.
The Privacy Policy is a section of the website or a document that informs the visitor or customer of the website about the principles of data processing on your website, online store and company.
The Privacy Policy must clearly describe the following:
The privacy policy should not be very long and complex, but it should contain answers to all the above questions. When creating a privacy policy, it is mandatory to inform the person about his or her rights.
If you use statistical collection or marketing tools on your website or online store, such as Facebook pixel, Google Analytics or any type of tracking codes, then the visitor of the site must be informed about the use of cookies because these tools use cookies. When creating a section on cookies, you must include the following:
The privacy policy strictly prohibits the inclusion of unauthorised practices, such as the right to send advertising emails to the customer if he or she has made a purchase but has not individually applied for advertising (prohibited by the EU's general data protection regulation).
When compiling a privacy policy, be sure to take into account that each company, website and online store is different, so you should not copy the privacy policy of any other company or website even if you feel that you are doing exactly the same thing or something similar. Take a look at the issues related to the drafting of the privacy policy and, if necessary, also attract a lawyer.
We hope that this article helped you understand why it is necessary to include a privacy policy on your website.