Welcome to Episode 4 of “GDPR for dive centers”! In this episode we’ll go through some considerations related to the software that you use for your business. I’m sure that you already have an operations manual, the document containing a written description of how you handle things in your business, maybe the same that you use to train new staff members. At this point you need to update it including how you handle your customers and your staff members’ data from the point of collection to the point of destruction (or maintenance for your records). The following questions might help you understand what kind of information you need to add to your operations manual.
- Do you use an electronic or paper form (or both?) to collect your customers data?
- Do your forms contain GDPR-compliant consents? Read more here.
- If you use a paper form, do you or one of your staff members then input the data in your CRM software?
- If you use an electronic form, does it feed data into your CRM software or you need to copy data manually? Is the form encrypted?
- In case of electronic form, how do you receive it? E.g. Google Docs, email attachment, upload to a cloud drive, other.
- What happens to the paper or electronic forms once you’ve transferred the data into your software? Aka: who has access to the forms?
- Who has access to the locked file cabinets?
- Who has access to your computers/tablets/phones? Do you instruct your staff members to lock the screen in case they leave the devices unattended?
- Who has access to your software?
- Do you restrict access to sensitive data?
- How long do you keep the data?
- Is it possible and easy to modify or delete data if your customers request it?
- What kind of data do you need to safely store for your records even if your customers request the permanent deletion? E.g. invoices, consent forms, course forms…etc.
- CRM – that’s where you collect and manage your customers data
- Booking
- Accounting and payroll
- Marketing
- Website and blog
- Social media
- Dive agency software or web pages
- Communication (e.g. email, chat, messaging systems…etc.)
- Cloud storage
- Anything else that might contain your customers data?