If you’re like many of our customers, you have gotten ready for the General Data Protection Regulation (GDPR) that takes effect on May 25. In addition to its regulatory impact on European sales and marketing tactics, many companies consider the principles underlying the GDPR to be generally good business practices. There are many articles summarizing the intent and implications of GDPR and what you need to know, including some concerning the impact on B2B marketers. We’ve linked to a few we think are particularly useful at the end of this blog.

InsideView has spent the past year reviewing and modifying our systems, methodologies, and databases to align with the GDPR.  Here are some of the most common questions we have been asked regarding how our services and data fit with the regulation:

Q: How does InsideView comply with GDPR?

A: InsideView is committed to complying with GDPR and follows privacy and security best practices applicable to our industry.  We have aligned how we process and protect personal data with applicable laws (both domestic and European). We adhere to applicable privacy and security requirements of the GDPR and comply with ISO controls for security of personal data.

InsideView can collect and share this business data because the fundamental rights and freedoms of the individual data subjects are not overridden by our legitimate business interests regarding our publicly-sourced database.

More details on our compliance certifications can be found here: www.insideview.com/compliance.

Q: Does using InsideView data make our customers compliant with GDPR?

A: InsideView is GDPR compliant in sourcing our business contact data and in processing personal data.

Our customers must themselves adhere to laws and regulations that apply to their business and to their use of data that we provide. By way of example, anytime our customers send marketing emails to their own customers, they must adhere to digital marketing laws that apply in the particular data subject’s geographic locale.

Q: How does InsideView source business contact data?

A: InsideView provides our customers with names, professional titles, and business contact information (“Business Data”) to help them locate and engage with other businesses (B2B data).  We maintain a core database of Business Data that is derived from publicly-available sources (e.g. company websites) and in some instances email addresses that have been extrapolated by our systems based on corporate email patterns (e.g., first.last@company.com).  InsideView does not provide individual consumer contact information (no B2C data), or process sensitive personal data. More information about how we source data can be found here: https://insideviewweb.kinsta.cloud/how-we-source-personal-data/

Q: Which lawful means of processing under Article 6 of the GDPR does InsideView rely upon in sourcing business contact data of European data subjects?

A: InsideView relies upon the “legitimate interest” means of processing the publicly-sourced personal data that comprises our business contact database. We note also that Recital 47 of the GDPR explicitly states that “the processing for direct marketing purposes may be regarded as carried out for a legitimate interest.”

Q:  Can EU individuals opt-out of the InsideView database?

A: Yes. InsideView will continue our long-standing practice of permitting individuals residing in the EU (and elsewhere) to opt-out of our database. Our privacy policy will continue to disclose the right of individuals to request that we remove their name and business contact information from our services.

Q: Where can I learn more?

Here are some additional resources that may be helpful. Note that links to third-party articles should not be viewed as recommendations (my legal team advised me say that!):