OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

GDPR Basics

What is the GDPR?

The European Union’s General Data Protection Regulation (GDPR) lays out a new set of rules for how the personal data of people living within the EU (“EU-local individuals”) should be handled. The policy comes into full effect on May 25, 2018, and we recommend that you start preparing now by speaking with a lawyer and familiarizing yourself with the information we’ve provided here.

Though it’s complex and far-reaching, at a high level, the GDPR can be understood in terms of three fundamental concepts:

1. Consent and control

Clear, informed consent and individual control over the use of personal data are basic rights in the GDPR. Any business collecting and processing personal data must not only obtain consent to do so, but must also explain what they need the information for. What’s more, they’re only allowed to collect the minimum amount of information required to get the job done, and can’t use the info for any purpose other than that to which the individual initially agreed. This puts the individual in charge of how their info is used from the very start.

2. Transparency

The GDPR imposes requirements around how companies should address security breaches that expose sensitive personal information. In the event of a breach, anyone whose information may have been exposed must be notified as soon as possible, and that notice should include an explanation of what happened, what’s being done to fix it, and what those affected should do to protect themselves. This type of information empowers each person to respond in the way they think is best in each circumstance in order to protect their own privacy.

3. The right to be forgotten

Under these new rules, EU-local individuals have the right to revoke consent for a service provider to use their data. When this happens, the provider must essentially erase all record of the individual, giving them a fresh start. This requirement is not without consequences or limitations: some services can’t be provided without personal information, and sometimes personal information has to be kept for reasons of public interest or relating to legal claims.

What is the purpose of GDPR?

The GDPR helps protect privacy in the digital age. The European Union views the protection of personal data as nothing less than a fundamental human right, alongside other rights such as freedom of expression, freedom of thought, and the right to a fair trial. Although there are other existing privacy laws in effect already, the GDPR is different in its scope of applicability and because significant fines may be levied for non-compliance. The GDPR replaces the 1995 EU Data Privacy Directive, harmonizing privacy laws across the EU. Once it comes into effect on May 25, 2018, it will be law in all EU member states.

Will GDPR impact your business?

The GDPR impacts all OpenSRS clients, as the changes we are making in response to the GDPR will be applied platform-wide. It also affects you if your business processes, or has the potential to process, the personal data of individuals living in the EU, regardless of whether you actively sell services in the EU. You now need to ensure that you’re obtaining permission from these customers to use their personal data, and meeting the updated requirements surrounding its handling. Before the GDPR comes into effect in May 2018, you’ll want to make sure you’re compliant. We recommend you get started now by talking to your lawyer(s) about what this means for your business specifically. While the rules outlined in the GDPR apply only to EU-local individuals, we plan to adopt a broad, one-size-fits-all approach* to implementation, and changes to how data is collected and handled may happen on a global scale as companies modify their existing practices to ensure they are compliant with these new regulations. Rest assured, we are doing everything we can to minimize disruption to our domain management and registration processes for both registrants and resellers.

Our approach to the GDPR

Our guiding principles

In designing our approach to GDPR compliance, we’re keeping two things in mind: our need to operate within the bounds of legal requirements, and our commitment to keeping domain purchase and management as straightforward, simple, and instantaneous as possible for the end-user.

We’d also like to take a moment to reinforce this point: Tucows (our parent company) does not share personal data beyond what’s needed to provide the service that the client ordered. We have never sold our clients’ personal information, and we certainly aren’t going to start now.

Our plan

The GDPR’s scope of applicability may appear to be limited to the European Union, but we are working toward a unified implementation plan* that will extend the same heightened privacy protections to all OpenSRS reseller partners and end-users, regardless of their location. This streamlined solution ensures that our platform is secure and GDPR-compliant, and recognizes that there are privacy laws worldwide, beyond the GDPR, which must be respected.

Here’s a high-level look at how we’ve broken down the GDPR and the steps we are taking to achieve compliance by May 25, 2018. In the drop-down menu below, you’ll find resources that provide greater context and additional information on specific topics.

Resources related to our approach

Consent and control

Enter an icon name
Enter an icon name
Enter an icon name

Transparency

Enter an icon name

Right to be forgotten

Enter an icon name

Reseller FAQ

You can view all our GDPR Reseller FAQs in our Knowledge Base.

Here are some of the most commonly asked questions:

How will Whois change?
Enter an icon name
Do we still need Whois privacy?
Enter an icon name
How will the domain transfer process change?
Enter an icon name
How will OpenSRS obtain data subject's content?
Enter an icon name
What personal data will OpenSRS process“via” contract?
Enter an icon name
What personal data will OpenSRS process “via” consent?
Enter an icon name

Additional resources

Enter an icon name
Enter an icon name
Enter an icon name
Enter an icon name
Enter an icon name

Third-party resources

Enter an icon name
Enter an icon name
Enter an icon name

*Previously, we had discussed plans to apply our internal, GDPR-related process changes only to EU-locals. We have since changed our approach and now plan to apply these changes platform-wide.