GDPR & SecurityGDPR and digital cards: what you need to know
A digital business card collects and shares personal data: name, e-mail, phone, sometimes more. In Europe, that places the tool under the GDPR. Here is the essential to stay compliant, without jargon.
Which data is concerned
The GDPR applies as soon as you process data that identifies a person: contact details, photo, role, but also the contacts you receive during an exchange. Knowing what you hold is the first step.
The legal basis
Sharing your own details is your choice. Collecting those of others requires a legal basis: consent at the moment of the exchange, or legitimate interest in a clear professional context. Transparency always comes first.
Minimise and inform
Ask only for what is useful, and say why. A contact form that explains how the data is used inspires trust and respects the principle of minimisation at the heart of the regulation.
People's rights
Anyone can request access to their data, its correction or its erasure. A contact must be able to withdraw as easily as they were added. Plan how you will respond to those requests.
Hosting and security
Where the data is stored matters as much as what is done with it. bloo.Cards keeps data on servers located in the European Union and encrypts exchanges, to keep processing within the European framework.
In practice
Keep a clear privacy policy, enable only the modules you need, and inform your contacts about the use of their data. Compliance is not a brake: it is a mark of seriousness that reassures the people you deal with.
This article is general information and does not constitute legal advice; for your specific situation, consult a legal professional.
Related articles
GDPR & SecurityConfidentialité : Quelles données partager sur votre carte
Guide pour choisir les informations à afficher sur votre carte publique.
GDPR & SecuritySécurisez vos données professionnelles en ligne
Conseils et stratégies pour protéger vos informations de contact.