Data Protection for Campaigns (GDPR)
Definition
Data Protection for Campaigns (GDPR) covers the obligations under the EU’s General Data Protection Regulation (Regulation 2016/679, in force from 25 May 2018) and its national variants — the UK GDPR, the Swiss FADP, and similar frameworks — that apply to how campaigns collect, store, share, and use supporter data.
The headline rules — lawful basis, purpose limitation, data minimisation, retention limits, security, breach notification within 72 hours, and data-subject rights (access, rectification, erasure, portability, objection) — apply to any organisation processing EU residents’ data, regardless of where it is incorporated. That makes GDPR the de facto global baseline for digital campaigning.
Strategic practice: design data flows around the strictest reading — collect what is needed, keep it only as long as it can be justified, document the lawful basis in writing, run a legitimate-interests assessment (LIA) when consent is not the basis, have an incident-response plan before it is needed.
It is adjacent to digital-security, digital-first-aid, and civic-tech design.
FAQ
What is Data Protection for Campaigns (GDPR)?
Data Protection for Campaigns (GDPR) is the set of obligations under the EU General Data Protection Regulation and related national variants that govern how campaigns collect, store, share, and use supporter data. It covers frameworks including the UK GDPR and Swiss FADP, and applies to organisations processing EU residents’ data regardless of where they are incorporated. It is presented as the de facto global baseline for digital campaigning.
What does GDPR require campaigns to do with supporter data?
GDPR requires campaigns to establish a lawful basis, limit data to its purpose, minimise what they collect, respect retention limits, maintain security, and plan for breach notification within 72 hours. It also provides data-subject rights including access, rectification, erasure, portability, and objection. These obligations apply to organisations processing EU residents’ data, regardless of where they are incorporated.
How should campaigns apply GDPR to their data flows?
Campaigns should design data flows around the strictest reading: collect what is needed, retain it only as long as it can be justified, and document the lawful basis in writing. When consent is not the basis, they should run a legitimate-interests assessment and have an incident-response plan before it is needed.
What is a legitimate-interests assessment for campaigns?
Campaigns should run a legitimate-interests assessment when consent is not the basis for processing supporter data. The assessment belongs within a data-flow practice that documents the lawful basis in writing and follows the strictest reading. That practice also limits collection to what is needed, retains data only as long as justified, and includes an incident-response plan.
Full page: [[data-protection-gdpr]].
