GDPR Support
The General Data Protection Regulation (GDPR) has been in effect since May 25, 2018. Organizations that do not comply with GDPR requirements are subject to significant fines. GDPR replaces the Data Protection Directive 95/46/EC.
Bloomreach Content provides the necessary tools in the Relevance Stack to support your GDPR compliance efforts.
GDPR Compliance Requirements
To comply with GDPR, organizations must:
- Provide all personal data collected about a visitor upon their request.
- Delete all data related to a visitor if the visitor requests erasure.
- Obtain valid consent from visitors before collecting or processing their personal data.
- Understand the risks and consequences of non-compliance with GDPR.
GDPR Support in the Relevance Module
The Relevance Module supports GDPR compliance through pseudonymization, as encouraged by GDPR. For more details, refer to Top 10 operational impacts of the GDPR: Part - 8 Pseudonymization:
The GDPR introduces a new concept in European data protection law – “pseudonymization” – for a process rendering data neither anonymous nor directly identifying. Pseudonymization is the separation of data from direct identifiers so that linkage to an identity is not possible without additional information that is held separately. Pseudonymization, therefore, may significantly reduce the risks associated with data processing, while also maintaining the data’s utility. For this reason, the GDPR creates incentives for controllers to pseudonymize the data that they collect. Although pseudonymous data is not exempt from the Regulation altogether, the GDPR relaxes several requirements on controllers that use the technique.
Bloomreach Content implements pseudonymization as follows:
Info: By default, data stored about a visitor does not contain any information that can re-identify the visitor without a unique random UUID. This UUID is only known by the visitor and is stored on the visitor's client (typically in the browser).
This pseudonymization approach, combined with cookie consent support, enables you to meet GDPR requirements by:
- Implementing cookie consent if not already in place. You may also need to inform visitors about the types of data collected and the purposes for which it is used.
- Adding the Public Relevance REST Endpoint to:
- Provide visitors with access to their personal data upon request.
- Allow visitors to request deletion of their data.
In addition, Bloomreach Content does not store the visitor's IP address in tracked data, as IP addresses can be used for re-identification. Instead, the system stores only the city, country, and a longitude/latitude value with city-level granularity. This information cannot be used to re-identify individual visitors.
Developer Responsibility
While Bloomreach Content provides tools to support GDPR compliance, you are responsible for ensuring your implementation remains compliant. The platform is extensible, allowing you to create Custom Collectors that gather additional data beyond what the default Collectors collect.
If you implement custom collectors that gather data such as 5-digit ZIP codes, gender, and date of birth, you may inadvertently create a dataset that can be re-identified. Research (Simple Demographics Often Identify People Uniquely) has shown that these three data points can uniquely identify 87% of US citizens.
If your custom collectors gather such information, the resulting data may be re-identifiable, and your implementation may no longer be GDPR compliant. You must carefully evaluate the data you collect and ensure it does not result in a re-identifiable dataset.