GDPR and Direct Mail

gdpr and direct mail

There are many things to take into account when setting up a direct mail campaign, including protecting your customers. Personal data is a sensitive matter and you need to make sure your campaign is GDPR compliant before implementation. So what exactly is direct mail and how does it relate to GDPR?

Decoding Direct Mail

Despite the ever increasing need for new and alternative technologies, direct mail is a marketing campaign that diverts back to paper advertising. It relies on printed materials and posting services to get a company’s message out into the world. It’s effectiveness has increased over the past few years, with the response rate surpassing that of emails and rising up to the ranks of social media. 

A business’s campaign can be as small or as big as they wish, from a few hundred to a few hundred thousand mailed to current and future customers. They work with us to create their ideal mail out, designing and tailoring their content to their target audience. 

An example of this could be a catalogue containing coupons or offers, sent out to participating customers in order to increase and encourage business. 

Grasping GDPR

Standing for General Data Protection Regulation, GDPR is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union. It is the toughest privacy and security law in the world. It’s use is not limited to EU citizens, granted that organisations collect data from people within the EU. 

Remember cookies? As a browser you must be notified what personal information is being collected from you as you visit each site, only under your consent. You must also be notified if any of your personal data held by the site is breached. This is all under the new GDPR, introduced recently in May 2018. 

How do they relate? 

When running a direct mail campaign the GDPR provision you should pay attention to is referred to as “legitimate interest”. Legitimate interest includes using a person’s data, such as an email or personal address, in ways they would expect. Either for your own interests or the interests of third parties. For example, signing up for a mailing list would result in correspondence from that same company, as they use your data to target your interests. 

With direct mail, personal data use would include sending promotional content to customers’ home or work addresses in order to increase profit. The bottom line is that you shouldn’t be surprised to receive the content you have, meaning that a business hasn’t used other, unethical, methods to collect data and increase their outreach. 

As a business looking to use direct mail as a marketing tool, there are laws and regulations involved to make sure your campaign is GDPR compliant. Protecting the data of your customers and running mail campaigns based solely on legitimate interests. 

How do I make my campaign GDPR compliant? 

There are certain steps you can take in order to guarantee a GDPR compliant campaign.

  1. Ensure that any data you are sharing with third parties is essential. Think, does this really need to be shared? Are they handling it in an appropriate manner? By eliminating this aspect you are increasing the legitimacy of your campaign. 
  2. Educate your staff so any data breaches can be reported as soon as possible, reducing the risk of a vast amount of data being released. 
  3. If you still have data from unsubscribed customers, it is vital you do not contact them again. Companies who have can easily be fined thousands of pounds, it’s not worth the risk. 

If you are interested in setting up a direct mail campaign, making sure it follows GDPR guidelines, don’t hesitate to contact us here

*Please keep in mind that due to new Brexit legislation, the UK is now a third party GDPR meaning that documentation and privacy notices will need to be updated to cover the transfer of data.