GDPR_进化_而不是革命(英文版)
报告摘要
GDPR: An Evolution, Not a Revolution
Core Content
The General Data Privacy Regulation (GDPR) is a regulatory update that replaces the 1995 Data Protection Directive, aiming to harmonize data privacy laws across all 28 EU member states. It is designed to modernize the legal framework for data protection in light of globalization and technological innovation, while strengthening individual rights and ensuring consistent enforcement by Data Protection Authorities (DPAs).
Key Definitions
- Personal Data: Any information that relates to an identified or identifiable natural person, including online identifiers such as Cookie IDs and Mobile Advertising IDs.
- Sensitive Data: Includes data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, and sexual orientation.
- Pseudonymous Data: Non-directly identifying information that allows the singling out of individual behaviors without identifying the individual.
Criteo collects and processes pseudonymous data, not sensitive data, and is already compliant with data privacy standards.
Legal Bases for Data Processing
GDPR outlines six legal bases for data processing:
- Vital interest of the individual
- Public interest
- Contractual necessity
- Compliance with legal obligations
- Valid unambiguous consent of the individual
- Legitimate interest of the data controller
For most digital marketing activities, valid unambiguous consent and legitimate interest are the most relevant bases. Criteo believes that valid unambiguous consent is the most applicable for its clients and partners.
Criteo's Approach to Data Privacy
Criteo prioritizes data privacy and has implemented Privacy by Design, a principle that ensures privacy and data protection are integral to the development of its products and services.
- Designated a Data Privacy Officer (DPO) since 2013.
- Conducts ongoing Privacy Impact Assessments (PIAs).
- Provides company-wide privacy training and enforces codes of conduct.
- Reviews and updates internal privacy policies regularly.
- Ensures compliance with all applicable data protection laws, including GDPR.
Security Measures
Criteo maintains strict security protocols, including:
- Using modern pseudonymous methods such as MD5 and SHA-256 double hashing.
- Never storing directly identifying personal information.
- Storing EU consumer data in European data centers closest to the user.
- Ensuring data is only retained for as long as necessary, typically 13 months.
Consumer Control and Transparency
Criteo empowers consumers through the Ad Choices program, allowing them to:
- See where and how their data is used.
- Opt-out of targeted advertising with a single click.
- Have their data removed from tracking and retargeting processes.
The program aligns with EU data protection regulations and industry standards.
Industry Leadership and Certifications
Criteo holds numerous certifications and adheres to industry standards, including:
- Network Advertising Initiative (NAI) Standards
- IAB Europe
- Digital Advertising Alliance (DAA) Self-Regulatory Principles
- European Digital Advertising Alliance
- Digital Advertising Alliance of Canada
- TrustArc Trusted Data Collection Certification
These certifications demonstrate Criteo's commitment to data privacy and compliance.
Responsibilities of Businesses
Businesses must:
- Designate a Data Protection Officer (DPO) if required.
- Ensure transparency and control for users by clearly explaining data collection and usage.
- Conduct Privacy Impact Assessments (PIAs) for all data processing activities.
- Implement strict data governance policies and monitor employee access to data.
- Comply with GDPR requirements for data transfers outside the EU.
Impact on Criteo's Solutions
Criteo's Shopper Graph collects and processes pseudonymous technical identifiers, interests, and performance metrics to deliver relevant commerce marketing solutions. It ensures:
- Data is limited to what is strictly necessary.
- No directly identifying information is stored.
- Users can easily opt-out of targeted advertising.
- Data is deleted or made unreliable once the user opts-out.
Conclusion
GDPR is an evolution that brings consistency and clarity to data protection across the EU. It is expected to have limited impact on Criteo's clients and partners due to its existing compliance measures. Criteo remains committed to protecting consumer privacy, providing transparency, and empowering users to control their data. Consumer surveys show that most EU users are aware of targeted advertising and expect relevant ads, reinforcing the importance of balancing personalization with privacy.
试读结束,高清完整版pdf/doc/ppt,请点下载