Showing posts with label website. Show all posts
Showing posts with label website. Show all posts

Monday, 25 May 2015

How big is yours?

Your mailing list I mean.....

There is lots of talk of how big your mailing list is and this can be a wonderful addition to your business but only if you have collected the information in the right way. I have been talking to a couple of companies recently who are growing their mailing list by adding people to it, without asking their permission.

Generally they are people who have done business with the company before so have some history with them but the company didn't ask the individual if they wanted to receive further information. This usually boils down to a couple of reasons; the company thinks its OK to add people, they think the person might say no but they want the numbers on the list to increase or they didn't understand the benefits of asking the individual.

I would always advocate asking someone if they want to receive further information from you. Firstly it opens the discussion as to how staying in touch can help them keep informed of new events, etc. It also tells them that you will be adding them to a list and they can expect an email at some point in the future. Gives them something to look forward to! Also asking whether you can stay in touch indicates some thought for the persons privacy.

Finally it is always useful to show whether you intend to share the personal information with other companies, I always look to see, when I am providing my information, who it is going to be shared with. Lots of companies now state that they will not sell or share your information with other companies. (Good for them)


Wednesday, 13 May 2015

Sending emails - Will the ICO be sending you to the naughty step?

On one of the forums that I belong to, a question was recently asked about what is considered a spamming email? The responses were very interesting.There was a lot of discussion about whether you can just add people to your mailing list because they gave you their business card. This really split people into two groups along the lines of "they wouldn't have given you their business card if they didn't want you to stay in touch" and "Just because I gave someone my business card, I wouldn't then expect to be out on their mailing list".

So here is the boring legal bit. Under the PECR (Privacy and Electronic Communications Regulations) people must give permission for you to add them to your mailing list, unless they have bought from you previously and the product you are promoting is something similar. If you don't do this and someone complains to the ICO, they could review your data protection practices and send you to the naughty step.

So how do you end up with spam emails? Well, someone you have given permission to have your email address has sold on their list. Yes they should have asked you first but many websites are unclear as to what they are going to do with your information and some companies have no idea that they should be getting your permission first. Many companies are now aware that we hate having our information sold to others and will make a declaration on their website that they never sell or pass on your information. My advice is always be aware when you are providing your email address what it is going to be used for and if it is used for anything else, either unsubscribe or make contact to correct their information.

So back to the business card discussion. Unless at the time you handed over your business card they asked whether you wanted to be on their list (yeah right!) and they noted your permission down, then they shouldn't have added you. More interesting is that the majority of people on the forum said they would unsubscribe immediately if someone did this. Would you?




Sunday, 9 November 2014

ICO warns organisations about cyber security. Could you be at risk?

The Information Commissioners Office has suggested that organisations need to act to ensure that the information collected via their websites is secure. This is after a hotel booking website was hacked and the details of 3814 customers were accessed. You can read the full ICO comment here.

This isn't the first incident of websites being hacked for their customer details. In May 2014, Ebay was the subject of hackers and they advised all their account holders to change their password.

In April 2012, the British Pregnancy Advise Service website was hacked the name and logon details of the administrator leaked. At the time the ICO said “Ignorance is no excuse. It is especially unforgiveable when the organisation is handing information as sensitive as that held by the BPAS. Data controllers must take active steps to ensure that the personal data they are responsible for is kept safe."

Ernst and Young have researched cyber attacks and produced a report. Ernst and Young report. Cyber threats are regularly reported in the media and this indicates that attacks are becoming more sophisticated and persistent. If your organisation has not experienced an attack yet, it will no doubt be targeted.

PWC reports that cyber attacks have increased 41% over the last year and the report shows that most attacks are undertaken by a current employees.

Both the PWC and Ernst and Young report are interesting and show the importance of ensuring appropriate security and policies are in place.

If you would like some help identifying any potential weaknesses, please contact me at Lesley@audit-and-risk.co.uk. I shall be happy to help.