
Regulations concerning privacy
In this article, we discuss the regulations surrounding privacy. We have outlined the most important points for you here, supplemented with links to websites that can provide you with more information.
In this article, we’ll discuss privacy regulations. This is a topic that’s frequently discussed these days, and as a cultural entrepreneur, you’d be wise to keep a few things in mind. We’ve outlined the most important points for you here, along with links to websites where you can find more information.
Privacy and the GDPR
The General Data Protection Regulation (GDPR) has been in effect since May 25, 2018. This law was enacted to protect the privacy of you, us, and all other citizens. It affects people who run a business and, in doing so, come into contact with others, such as visitors. There are guidelines for how to handle personal data (data that can be used to identify someone). For example, you may only collect data from visitors or customers if you have a very good reason to do so and can explain that reason. You may then only use the data for the purposes for which the other party has given consent. If someone buys a ticket for your performance, you may not automatically send them a newsletter.
Tips for Complying with the New GDPR
Below are a number of action items—courtesy of De Nieuwe Oost—that you can implement to ensure compliance with the new GDPR.
Privacy and Websites
If you have a website—whether for your organization, an event, or a performance—there are a few things you’ll need to keep in mind:
- Guests must actively give their consent to receive a newsletter or share their location with you. You can ask them to confirm this by having them click “Agree.”
- It's important to have a privacy policy on your website, and it should be visible on every page. You can place it at the bottom of the website, for example. If you don't have a privacy policy yet, we recommend checking out this easy-to-use generator.
- Make it clear that you use cookies, if you do. Ensure that people understand which cookies you place on their computers and obtain their consent. A pop-up is the clearest way to do this. In this pop-up, visitors can click a link to the cookie policy.
- For websites with a contact form, be sure to clearly mention the privacy policy again in the contact form.
- In the section where people indicate that they want to receive your newsletter, you must specify how often it will be sent—for example: “Receive our monthly newsletter.” Be sure not to send a newsletter more often than you indicate in that section (since you don’t have permission to do so).
Privacy Regarding Documents You Send Out
Be careful if you have personal information about people you work with included in, for example, a script, project plan, drawing, or other document. If you want to share this with others, you’ll need to obtain written consent from everyone involved.
Create a processing log
If you are a business or organization, you are required to maintain a processing register. It often takes some time to set it up, but it’s also very useful for you personally. In it, you describe all the processes within the organization that involve the use of third-party personal data. You can use this to demonstrate that you comply with the GDPR, but it also serves as a handy overview of how things work within your organization. The Chamber of Commerce explains how to create a processing register.
Data Processing Agreement
If you have a third party process your data through an intermediary, you are required to enter into a data processing agreement with that party. For example, if you have employees or hire volunteers and have their pay processed by a payroll service—or if your administrative tasks are handled by that service—you must draw up an agreement. Read more about this in this article on justitia.nl.
Don't leave anything lying around
If you have documents containing other people’s personal information, such as volunteer declarations, make sure they are kept under lock and key. They should only be accessible to the people directly involved. The same applies to personal information you collect online. Make sure that not everyone has access to, for example, the personal information of colleagues, performers, or employees. Employers may only keep a copy of the passport or ID of their own employees, not of temporary workers or independent contractors.
Job Applications and Privacy
If you decide to accept applications for a position within your organization or project, there are a number of things you need to take into account. For example, when posting a job opening, you should specify how the screening and reference checks will be conducted. This means you should indicate whether you plan to call a former employer or look up the person online. You’re also required to explain why all of this is necessary. Application materials—such as emails, letters, or resumes—may not be retained longer than necessary. An exception applies if the applicant asks you to keep them on file for any future positions that may become available.
Learn more
Privacy regulations and the GDPR are still subject to change. You can find more information on the Chamber of Commerce website, and this information will remain up to date.
If, from your expertise, you yourself have knowledge that would fit this topic, or if you see opportunities to improve this text, we look forward to receiving your message at info@cultuuracademy.nl.