What it means

How 360 Alumni Addresses the Need

Lawful Basis of Proceeding

But first, a quick primer on the legalese associated with the GDPR. Let’s say that Maria is a constituent of yours and an EU citizen. She's called the "data subject," and your organization (let's call you Smith School) is called the "controller" of that data. If you're a 360Alumni customer, then 360Alumni acts as the "processor" of Maria's data on behalf of Smith School. With the introduction of the GDPR, data subjects like Maria are given an enhanced set of rights, and controllers and processors like Smith School and 360Alumni, respectively, an enhanced set of regulations.

360Alumni enables you to track lawful basis through associations in the user’s profiles. This feature allows you to designate how each member of the community is associated with your organization, for example what program they participated in, when and where; or whether they are a student, parent, alumnus/a, or staff member.

To ensure that every member of your community has at least one association designated, email support@360alumni.com to request a list to be created of all those alumni that do not have one specified in their profile. You can then edit these profiles individually or in bulk, or reach out to these users to have them activate their account and complete their profile.

You can also use custom fields to track the type of lawful basis for users subject to GDPR regulations.

Consent

One type of lawful basis of processing is consent with proper notice. If you can not demonstrate legitimate interest (i.e. they participated in your program or are attending your event) then you’ll need to demonstrate consent.

In order for Maria to grant consent under the GDPR, a few things need to happen:

• She needs to be told what she’s opting into. That’s called “notice.”

• She needs to affirmatively opt-in. Pre-checked checkboxes are NOT valid under the GDPR. Her filling out a form alone cannot implicitly opt her into everything your company sends.

• The consent needs to be granular, meaning it needs to cover the various ways you process and use Maria’s personal data (e.g. marketing emails or donation appeals). You must log auditable evidence of what Maria consented to, what she was told (notice), and when she consented.

The most common ways that 360Alumni customers acquire new users are through the donation, RSVP, and account creation/activation forms.  All of these contain a check box where they opt-in to the Terms of Service (clearly linked next to the box). This way you are collecting the appropriate consent when Maria is ready to grant it, and telling her clearly what she is opting into.

For ‘pre-loaded’ alumni, it is important that you articulate in your community guidelines or GDPR statements how you selected who to create an account for, and the defaults you are setting for accounts that have and have not yet been activated.

You can download your data at any time to review or extract data such as email addresses, mailing addresses - anything in a user’s profile -to help fulfill GDPR-related requests. But if you receive one, let us know so we can conduct a full scan to ensure your response is complete.

If you need to link out to additional notice provisions (like privacy notices or community guidelines), you can do so using hyperlinks in the footer.

Once Maria creates or activates her account, we will store the date and time of this opt-in. We also retain past versions of our terms and conditions in our Legal Archives.

Withdrawal of consent (or opt out)

Maria needs the ability (as data subject) to see what she’s signed up for, and withdraw her consent (or object to how you’re processing her data) at any time. In other words, withdrawing consent needs to be just as easy as giving it.

In 360Alumni, Maria can withdraw her consent to marketing and transactional and other system-generated emails right from her Notification Settings page. If a user wants to be removed entirely from the community, they can send a message or email to either a community administrator or the 360Alumni Support Team, and their account will be deactivated. Please see “Data Retention” in our Privacy Policy for more information.

Cookies

Maria needs to be given notice that you're using cookies to track her (in language she can understand) and needs to consent to being tracked by cookies.*We know the ePrivacy Regulation is coming, and that it may have an impact on how cookies are regulated. We’ll adjust our product accordingly.

We’ll update the default language for enabling cookies on 360Alumni-hosted websites to reflect affirmative opt-ins, and make it possible to show the cookie-consent message in the right language, based on Maria's location.

Deletion

Maria has the right to request that you delete all the personal data you have about her. The GDPR requires the permanent removal of Maria’s contact from your database, including email tracking history, call records, form submissions and more.In many cases, you’ll need to respond to her request within 30 days. The right to deletion is not absolute, and can depend on the context of the request, so it doesn’t always apply.

Upon request, within 30 days 360Alumni will perform a GDPR-compliant permanent delete of a user's record and all their contact and profile data. If there has been financial activity associated with the user, we will anonymize the transaction information.  Analytics (from event attendance count to site visits) will not change, but no contact information will appear for the individual metrics.

Access/ Portability

Just as she can request that you delete her data, Maria can request access to the personal data you have about her. Personal data is anything identifiable, like her name and email address. If she requests access, you (as the controller) need to provide a copy of the data, in some cases in machine-readable format (e.g. CSV or XLS).Maria can also request to see and verify the lawfulness of processing (see above).

Upon request, 360Alumni can export all of a user’s profile and engagement history into an excel file. If Maria was a pre-loaded alumna, you will need to verify the lawfulness.

Modification

Just as she can request to delete or access her data, Maria can ask your organization to modify her personal data if it’s inaccurate or incomplete. If and when she does, you need to be able to accommodate that modification request.

In 360Alumni, Maria can change almost all of her information herself.  If Maria asks you to change her information, you or your portal administrators can do so from within her profile.

Security Measures

The GDPR requires a slew of data protection safeguards, from encryption at rest and in transit to access controls to data pseudonymization and anonymization.

As part of 360Alumni’s response to the GDPR, we’ve strengthening our security controls across the board. In addition to industry standard practices around encryption, 360Alumni’s infrastructure teams have improved our systems for authentication, authorization, and auditing to better protect our customer's data. For more information, you can request our security overview by emailing support@360alumni.com.