{"id":6465,"date":"2018-05-21T14:56:13","date_gmt":"2018-05-21T18:56:13","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6465"},"modified":"2020-11-24T09:46:12","modified_gmt":"2020-11-24T14:46:12","slug":"gdpr-customer-service","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/gdpr-customer-service\/","title":{"rendered":"GDPR: Don&#8217;t forget to train your customer service team"},"content":{"rendered":"<h2>Your customer service team is going to get questions about GDPR. Make sure they know what to say.<\/h2>\n<p>You can\u2019t spell GDPR without the PR, and that also holds true for your GDPR compliance efforts. You\u2019re working hard to make the proper updates and adjustments to your business to become compliant with the EU General Data Protection Regulation (which goes into effect this week), but it\u2019s also important to make sure that your customers know that you\u2019re compliant.<\/p>\n<p>In fact, it\u2019s kind of a requirement.<\/p>\n<p>Chances are you\u2019re putting the final touches on an email to inform your customers about your updated GDPR-compliant privacy policy. You may have already done so. That\u2019s a good first step.<\/p>\n<p>But not everyone is going to see the email. Some will skip it, others will miss it entirely, some may end up in spam folders. And then some people may even read it and decide they have more questions. The point is, there is a 99.9% chance that at some point someone will call your company and ask about what you did for GDPR.<\/p>\n<p>And chances are, you won\u2019t be the one taking that call. That\u2019s why it\u2019s critical to train your customer service team to respond to these questions. Let\u2019s hash out how to do that.<span id=\"newline\"><\/span><\/p>\n<h2>Identify the most common questions you\u2019ll be asked<\/h2>\n<p>This should be your starting point. Think about what industry you\u2019re in, what partners you share data with and just generally how data flows through your organization. This shouldn\u2019t be difficult, as you\u2019ve already had to do it to become compliant in the first place. So, it should be fresh in your mind.<\/p>\n<p>Using our organization as an example, here were the questions we came up with:<\/p>\n<ul>\n<li>What is GDPR?<\/li>\n<li>Does the GDPR affect non-Europeans?<\/li>\n<li>Are you GDPR compliant?<\/li>\n<li>What are you doing\/have you done to be compliant?<\/li>\n<li>What information are you collecting about me?<\/li>\n<li>What are you doing with my data?<\/li>\n<li>Are you Privacy Shield certified?<\/li>\n<li>What technical safeguards do you have in place?<\/li>\n<li>Can I get a Data Processing Addendum from you?<\/li>\n<li>Is the GDPR retroactive?<\/li>\n<li>Are your partners GDPR compliant?<\/li>\n<li>How can I verify that you\u2019ve really done all this?<\/li>\n<li>How do I modify or delete my information?<\/li>\n<\/ul>\n<p>Obviously, the questions you field will be largely dependent upon your organization. If you\u2019re in the healthcare sector, you may be asked how GDPR <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-soc2-compliance-how-does-it-affect-your-business\/\">affects HIPAA compliance<\/a>. Likewise, the financial sector may have to explain how the GDPR meshes with various financial regulations. Only you will be able to identify the key questions your company or organization will need to answer.<\/p>\n<h2>Create a customer service cheat sheet<\/h2>\n<p>The nice part about the questions we just discussed is that you can go ahead and refine your answers ahead of time and then just list them on a cheat sheet. While I\u2019m hesitant to load the one we will be using (after all, it\u2019s a proprietary document) I can suggest just creating a simple two column table in Word (or whatever word processing program you use) and then putting the questions down the left side and the answers down the right.<\/p>\n<p>This way, your customer service department won\u2019t be asked to think on their feet about a topic they likely aren\u2019t all that familiar with. Instead, they can just give a bottled answer and satisfy the question. This will also be a good way for your customer support team to familiarize themselves with the new regulation, as the document will contain the majority of the information they need to understand it.<\/p>\n<h2>Create supplemental content for your customer service team to reference<\/h2>\n<p>Don\u2019t just stop at a cheat sheet, go ahead and toss a couple of pages or a PDF on your website so your customer service team can point customers to them. Oftentimes this can save you an entire conversation. You may want to have a specific page that is dedicated to your GDPR efforts. It may also be beneficial to build one for Privacy Shield and one for data rights, too. That way when a customer requests information on a policy, you can easily just send them a URL or a PDF and provide them with the resource they\u2019re looking for.<\/p>\n<p>While writing GDPR content is another topic entirely, try to at least remember to make yours friendly. And by that I mean write clearly, avoiding technical jargon and acronyms, so that customers can read it once and feel like they have a good sense of your data practices. People notoriously don\u2019t read privacy policies or terms of service because the are long dense and boring. So don\u2019t make these pages feel like that. After all, you\u2019re trying to build trust and nothing builds it quicker than being straightforward and easy to understand.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-6469 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-Line-Icons-Set-On-White-B-240508939.jpg\" alt=\"GDPR\" width=\"1600\" height=\"900\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-Line-Icons-Set-On-White-B-240508939.jpg 1600w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-Line-Icons-Set-On-White-B-240508939-300x169.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-Line-Icons-Set-On-White-B-240508939-768x432.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-Line-Icons-Set-On-White-B-240508939-1024x576.jpg 1024w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/p>\n<p>These last two topics also deal with compliance, which makes them especially important.<\/p>\n<h2>Train your customer service team to escalate certain requests<\/h2>\n<p>There are two scenarios where you may want your customer service team to escalate a call. The first has to do with a customer exercising their data rights. We\u2019ll refer to this as a data request. The GDPR gives customers a lot of control over their data. They are allowed to get a copy of what you have collected about them, they can choose to modify it or the Right to be Forgotten means they can even ask you to delete it entirely. Unless you plan on training you customer support team to handle data requests themselves (which is ill-advised), they\u2019re going to need to escalate the call to some one who can.<\/p>\n<figure id=\"attachment_6471\" aria-describedby=\"caption-attachment-6471\" style=\"width: 300px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6471 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Woman-Screaming-On-Telephone-C-17814479-300x200.jpg\" alt=\"Customer Service Team\" width=\"300\" height=\"200\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Woman-Screaming-On-Telephone-C-17814479-300x200.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Woman-Screaming-On-Telephone-C-17814479-768x512.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Woman-Screaming-On-Telephone-C-17814479-1024x683.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Woman-Screaming-On-Telephone-C-17814479.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption id=\"caption-attachment-6471\" class=\"wp-caption-text\">I&#8217;d say this escalation went well.<\/figcaption><\/figure>\n<p>The second, far less frequent scenario is that you\u2019re going to get the occasional caller that is asking deeper questions than your customer support team can comfortably handle. A lot of times these are just extremely judicious customers, but it\u2019s also possible that come Friday (May 25, when the GDPR becomes enforceable) there will be some unscrupulous types that will be probing for potential issues they can exploit. Either way, you don\u2019t want to give your customer service team the opportunity to mis-speak or get something wrong. Again, this is not meant as a slight towards customer support reps \u2013 they are the backbone of many companies \u2013 it\u2019s just a matter of GDPR not being a familiar topic.<\/p>\n<p>So, if questions are a little too specific, or beyond the knowledge of the customer service department &#8211; or you are dealing with a data request &#8211; you need to train your team to escalate the request. The hierarchy you put in place is up to you. You may want to put a manager up the next rung, provided they are more familiar, as a buffer. Regardless, at the top of the food chain should be your Data Protection Officer (or the employee that oversees your GDPR and Data Security efforts). You may choose to put any questions or requests in writing, in the form of a ticket, before passing it up the chain, but the GDPR requires you to have an accessible DPO in Europe, and while US companies aren\u2019t required to have a DPO, they still need someone to run point on data requests.<\/p>\n<p>Remember, you also have to list that person&#8217;s contact details on your privacy page. Just don\u2019t be fooled into thinking that listing it there will stop customers from dialing up support to get their questions answered though. It won&#8217;t. People are still going to call. So make sure your team knows which questions to field and when to say, \u201cLet me connect you with someone who can better answer that question.\u201d<\/p>\n<h2>If you\u2019re recording the call, make sure you notify the caller<\/h2>\n<p>This is already considered a best practice, and while the GDPR is ambiguous in a number of areas\u2014this is one issue where it is not. It\u2019s quite clear that you need to notify a data subject anytime you collect data. I know right now you may be asking, \u201c<em>but this is a telephone, I thought the GDPR was for computers<\/em>.\u201d In reality, those are both wrong. The GDPR is about personal data. And yes, you may be collecting it on a telephone but you\u2019re likely entering it into a computer to look up and account or an order\u2014that\u2019s processing. So you definitely need to make certain notifications over the phone.<\/p>\n<figure id=\"attachment_6466\" aria-describedby=\"caption-attachment-6466\" style=\"width: 300px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6466 size-medium\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-207676075-300x200.jpg\" alt=\"GDPR notification\" width=\"300\" height=\"200\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-207676075-300x200.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-207676075-768x512.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-207676075-1024x683.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-207676075.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption id=\"caption-attachment-6466\" class=\"wp-caption-text\">&#8220;By the way, I&#8217;been recordin&#8217; ya the whole time.&#8221;<\/figcaption><\/figure>\n<p>Now, I don\u2019t think you need to be as granular as you would be on a website. There are certain implications with phone calls. For instance, if someone calls about an order, there\u2019s no need to say, \u201cI will use your name to look up your account.\u201d Simply requesting the name serves as notification enough, the user can easily imply that it\u2019s going to be used to look up his order.<\/p>\n<p>However, you can make no such case for recording someone. And here\u2019s the other thing, unless you\u2019ve got a legal basis for recording the calls (contractual, legal obligation, legitimate interests, etc.) you also need to get a caller\u2019s consent. Like I said, there are five alternative legal bases to use. But failing the other five, you have to get compliance to record calls. Obviously, in this case a pre-recorded message played at the start of the call is no longer sufficient unless it provides an option to consent or decline. It will be important for you to not only train staff on making the notification, but you may also want to try and refine the notification, and the way it\u2019s pitched, to maximize positive outcomes.<\/p>\n<p>And one more time, while the need for consent may be debatable, the need for notification is not.<\/p>\n<h2>A closing thought on preparing customer support for GDPR<\/h2>\n<p>The GDPR requires any company that does business with Europe to review and adjust its data policies. But for a great number of the companies and organizations affected, the bulk of their effort has been spent on websites and email.<\/p>\n<p>Don\u2019t forget about the people answering the phones and manning your live chat. They are public facing and will likely have some interaction with GDPR-related topics. It\u2019s not hard to schedule a quick meeting (or multiple ones if you can\u2019t leave the floor empty) just to go over the basics, show them some online content they can reference and provide them with a cheat sheet. It will go a long way.<\/p>\n<p>As always, leave any comments or questions below.<\/p>\n<h2>Hashed Out GDPR Compliance Series:<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/preparing-gdpr-introduction-1\/\">GDPR: Introduction to a Series<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-domain-industry-registries-registrars\/\">GDPR: How it affects the Domain Industry<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/7-tips-web-hosts-preparing-gdpr\/\">GDPR: How it affects Web Hosts<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-whois-icann-match-made-hell\/\">GDPR: Problems for ICANN\/WHOIS?<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-privacy-shield-compliance-us-businesses\/\">GDPR: Complying with EU-US Privacy Shield<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/data-protection-officer\/\">GDPR: What is a Data Protection Officer?<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-privacy-notices\/\">GDPR: Best Practices for Privacy Notices<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/cookies-gdpr-compliance-involves-consent\/\">GDPR: What you need to know about Cookies<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/right-to-be-forgotten\/\">GDPR: What is the Right to be Forgotten?<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-data-audit\/\">GDPR: How to perform a Data Audit<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-encryption-best-practices-wp29\/\">GDPR: Encryption Best Practices<\/a><\/li>\n<\/ul>\n\n","protected":false},"excerpt":{"rendered":"<p>Your customer service team is going to get questions about GDPR. Make sure they know what to say. You can\u2019t spell GDPR without the PR, and that also holds true&#8230;<\/p>\n","protected":false},"author":6,"featured_media":6467,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[5742],"class_list":["post-6465","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-gdpr","post-with-tags"],"views":16735,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/05\/bigstock-Gdpr-general-Data-Protection-235058500.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6465"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6465\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6467"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}