OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

OPENSRS

GDPR Overview

Latest update: March 6 2018

GDPR Basics

What is the GDPR?

The European Union’s General Data Protection Regulation (GDPR) lays out a new set of rules for how the personal data of people living within the EU (“EU-local individuals”) should be handled. The policy comes into full effect on May 25, 2018, and we recommend that you start preparing now by speaking with a lawyer and familiarizing yourself with the information we’ve provided here.
Though it’s complex and far-reaching, at a high level, the GDPR can be understood in terms of three fundamental concepts:
1. Consent and control
Clear, informed consent and individual control over the use of personal data are basic rights in the GDPR. Any business collecting and processing personal data must not only obtain consent to do so, but must also explain what they need the information for. What’s more, they’re only allowed to collect the minimum amount of information required to get the job done, and can’t use the info for any purpose other than that to which the individual initially agreed. This puts the individual in charge of how their info is used from the very start.
2. Transparency
The GDPR imposes requirements around how companies should address security breaches that expose sensitive personal information. In the event of a breach, anyone whose information may have been exposed must be notified as soon as possible, and that notice should include an explanation of what happened, what’s being done to fix it, and what those affected should do to protect themselves. This type of information empowers each person to respond in the way they think is best in each circumstance in order to protect their own privacy.
3. The right to be forgotten
Under these new rules, EU-local individuals have the right to revoke consent for a service provider to use their data. When this happens, the provider must essentially erase all record of the individual, giving them a fresh start. This requirement is not without consequences or limitations: some services can’t be provided without personal information, and sometimes personal information has to be kept for reasons of public interest or relating to legal claims.

What is the purpose of GDPR?

Will GDPR impact your business?

Our approach to the GDPR

Our guiding principles

In designing our approach to GDPR compliance, we’re keeping two things in mind: our need to operate within the bounds of legal requirements, and our commitment to keeping domain purchase and management as straightforward, simple, and instantaneous as possible for the end-user.

We’d also like to take a moment to reinforce this point: Tucows (our parent company) does not share personal data beyond what’s needed to provide the service that the client ordered. We have never sold our clients’ personal information, and we certainly aren’t going to start now.

Our plan

The GDPR’s scope of applicability may appear to be limited to the European Union, but we are working toward a unified implementation plan* that will extend the same heightened privacy protections to all OpenSRS reseller partners and end-users, regardless of their location. This streamlined solution ensures that our platform is secure and GDPR-compliant, and recognizes that there are privacy laws worldwide, beyond the GDPR, which must be respected.

Here’s a high-level look at how we’ve broken down the GDPR and the steps we are taking to achieve compliance by May 25, 2018. In the drop-down menu below, you’ll find resources that provide greater context and additional information on specific topics.

Resources related to our approach

Consent and control

Transparency

Right to be forgotten

Reseller FAQ

You can view all our GDPR Reseller FAQs in our Knowledge Base.

Here are some of the most commonly asked questions:

How will Whois change?
Do we still need Whois privacy?
How will the domain transfer process change?
How will OpenSRS obtain data subject's content?
What personal data will OpenSRS process “via” contract?
What personal data will OpenSRS process “via” consent?

*Previously, we had discussed plans to apply our internal, GDPR-related process changes only to EU-locals. We have since changed our approach and now plan to apply these changes platform-wide.