Skip to main content
Door double exposure onherkenbaar persoon, het lijkt een soort schim.

Working GDPR-proof: what does it entail?

What audience data are you allowed to collect as a cultural institution? In what ways can you use audience data to reach the public? How can you do this safely and thus GDPR-proof? Are all employees aware of the correct guidelines? And there are many more questions surrounding the GDPR. Where do you start? DEN is happy to help you get started!

3 min. reading28 jan `25

Why is there GDPR legislation?

In a society that is increasingly online, more and more data is being generated. Data that can be stored and analyzed using the right tools and algorithms to reach the audience with a specific message. These developments have positive aspects: audience data can be used to reach existing and new audiences in a personalized way. However, misuse can compromise the privacy of visitors.

To safeguard this privacy and ensure that organizations handle visitors' sensitive data securely, the GDPR (General Data Protection Regulation) has been in effect across the EU since 2018. This law (opens in new tab) grants rights to the public and makes organizations responsible for carefully handling (digital) personal data. This includes data such as names, email addresses, but also medical or educational information.

What does this mean for your organization?

In short, GDPR means that every organization must respect and safeguard the privacy of customers and relationships. This implies that responsibilities, systems, and processes are designed accordingly. It is also important to be aware of the regulations, for example, by having an expert review existing and new processes involving the use of audience data. For smaller institutions, it may be interesting to tackle such a process collectively with several other institutions.

Working with an Excel file in which you store personal data is no longer feasible in this digital world

How do you integrate GDPR into your work processes?

To handle data responsibly, drafting a privacy policy is an important step. In this policy, you outline how your organization intends to handle privacy. Such a policy could include the following components:

  • The way personal data is processed
  • Transparency about data processing in a privacy policy
  • How data is stored
  • Direct marketing: when is it allowed and when is it not
  • Describing methods to minimize data processing
  • Ensuring data quality
  • Organizational and technical security measures

Working GDPR-proof

The 'Step-by-step Guide to Working GDPR-proof' outlines in five clear steps what your organization needs to do to comply with privacy laws and regulations.

Download the step-by-step guide

The Cultural Audience Model

Many institutions, cities, and regions work with the Cultural Audience Model (opens in new tab) developed by Rotterdam Festivals. Does this apply to your organization as well? Then read this document in which a legal expert delves into GDPR aspects related to the use of this model (opens in new tab).

Share this news article