PDA

View Full Version : Event management systems.....what do you use?



Imagine
28-03-2018, 09:55 PM
I'm sure most of you are aware (or should be) about the new GDPR regulations coming into force at the end of May.

I, like a lot of people use DJEP to manage everything. However, there's a problem. They fall short on the eighth principle of Data Protection under the new regs because they're hosting in the USA and at the moment, don't appear to have achieved Privacy Shield status. Therefore....we can't use them once GDPR comes into force (or that's my understanding anyway).

Are there any of these systems which are similar to DJEP which are hosted in the EEU that you're using/have knowledge of?
I'm aware there's a Wordpress one which I can host myself which I'm seriously looking into....but it seems to fall short on things like planning documents (i.e. timelines).

Open to suggestions......

rth_discos
29-03-2018, 07:24 AM
Considering how many users they have in the UK I'd be surprised for DJEP not to comply with GDPR.

They moved quite quickly with SSL once a few users started banging the drum...

yourdj
29-03-2018, 07:28 AM
This is interesting.

1Locate

GDPR requires that you find the personal data you store. Metalogix can help you find your sensitive data and classify it accordingly. Sensitive Content Manager will scan and detect personal data across your SharePoint environments in minutes, based on search criteria that you define.

2Manage

GDPR requires you to track the personal data stored by your organization. Leverage ControlPoint to set and automatically enforce defined governance policies that provide guardrails for normal and compliant business behavior.

3Protect

GDPR requires that you protect personal data from damage, loss, or breach. ControlPoint monitors user behavior to detect and automatically react to unusual activity - like excessive file downloads or unauthorized access requests - helping to protect against potential breaches and support compliance with the GDPR requirement to report breaches within 72 hours.

4Audit

GDPR places greater liability on organizations to prove responsible and transparent management of personal data. Gain visibility into who has accessed or altered personal information and sensitive content over any period of time with ControlPoint. Track and demonstrate compliance through highly granular reporting capabilities to support internal and external audit requests.

I prefer to do things manually, but my friend is quite savvy with this sort of thing and involved quite closely with Digital DJ tips: https://www.djjoesimpson.co.uk

DJ Jules
29-03-2018, 08:21 AM
I'm sure most of you are aware (or should be) about the new GDPR regulations coming into force at the end of May.

I, like a lot of people use DJEP to manage everything. However, there's a problem. They fall short on the eighth principle of Data Protection under the new regs because they're hosting in the USA and at the moment, don't appear to have achieved Privacy Shield status. Therefore....we can't use them once GDPR comes into force (or that's my understanding anyway).

Here's the get out clause:


Organisations must receive explicit consent from their customers for their personal information to be transferred outside of the EEA. GDPR can still hold a company liable even after data has been transferred to another country. These changes mean that companies must consider the impact GDPR could have on their international data transfers.

This could be easily covered off via a change to the privacy policy and/or terms and conditions used. This also isn't new, this principle was introduced with the Data Protection act 1998.

Personally, I think it's worth focusing more on how securely you're keeping data, how good the audit trail is for access/modification and what you're doing with details of old customers and customers who didn't book (if the lead didn't amount to anything you don't have any right to hold their details AT ALL unless they explicitly consented to their information being stored at the point where they submitted the information).

I'm working with a bunch of organisations at the moment who are slowly waking up to the fact that their systems don't record the consents in enough detail and their existing marketing databases can no longer be used!

rth_discos
29-03-2018, 08:47 AM
This whole thing is still a mindfield.

Let's take NeedADisco for example, which provides you with an option to export lead details direct in to DJEP.

At what point can you get explicit consent to transfer that data out of the EEA?

One thing I have noticed with GDPR is there are lots of 'get out of jail' clauses that despite lots of scary sounding bits, also enable you to do quite a bit!

Excalibur
29-03-2018, 09:17 AM
I use (https://www.ebay.co.uk/itm/Collins-A4-Desk-2018-Day-a-Page-Diary-Black-/222748054850?_trksid=p2385738.m4383.l4275.c10)

:sofa:

rth_discos
29-03-2018, 10:08 AM
I use (https://www.ebay.co.uk/itm/Collins-A4-Desk-2018-Day-a-Page-Diary-Black-/222748054850?_trksid=p2385738.m4383.l4275.c10)

:sofa:

You'll need some of this then (https://www.ebay.co.uk/itm/1-x-Tipp-Ex-Correction-Roller-Tape-Tippex-Wizard-Mouse-Same-Day-Dispatch-/400678886653) when a client asks you to remove their details...!

ppentertainments
29-03-2018, 02:01 PM
Anyone else think this whole GDPR thing has not been thought out properly.

So many flaws and get out of jail cards surround it. I have spoken to a few people who have to deliver this to staff at large venues and they are saying even they don't really understand it fully when they get presented with different scenarios

Personally I don't think the government (or whoever is responsible) has rolled it out very efficiently either

rth_discos
29-03-2018, 02:32 PM
Anyone else think this whole GDPR thing has not been thought out properly.



In all honesty, I don't think we need to do much.

Let's look at the very basics of GDPR:

Respect people's personal data, and take reasonable steps to protect it.

Don't spam people

Work on the above basis and you won't go far wrong.

I can't see those PPI calls stopping any time soon, and I can see far worse breaches of GDPR than a mobile DJ.

One thing I've seen that we need to be careful with is 'passing on details'. If someone contacts you and you're not available, you must have permission to pass on the details of that gig.

Other than that, I really can't see what else needs to be done at our level of business.

I'm sure this is a big headache for larger organisations who do deal and store a *lot* of information.

For us, just be sensible with people's data is the crux of it.

There will be plenty who won't be, and they will be further up the list of priorities for what I'm sure will be an inadequately small team to deal with data breaches!

yourdj
29-03-2018, 02:50 PM
Let's look at the very basics of GDPR:

Respect people's personal data, and take reasonable steps to protect it.

Don't spam people

Work on the above basis and you won't go far wrong.


I think you will only run into problems if someone reports you or data is quite clearly being sold off to marketing companies and such like without permission. I guess you could add the details of the management system in a business privacy policy?

Given the size and nature of our business it wont happen often I guess? All my systems are private, managed manually and all info stored on paper or Google Calendar so I am OK. If I really wanted too I could sell my information to a group of suppliers further down the line, but I guess I would be in hot water sooner than later. :)

Daryll
29-03-2018, 04:09 PM
Client contacts me for a disco.
I take down all details
After the gig , shred/delete the lot.
Problem solved

DJ Jules
31-03-2018, 09:29 AM
Client contacts me for a disco.
I take down all details
After the gig , shred/delete the lot.
Problem solved

And if a corporate client comes back to you and asks for the same package/deal as last year....? How good is your memory? :sofa:

Julian

Daryll
31-03-2018, 09:56 AM
Easy , As I am part time , I can pick and choose gigs , corporate events are a no..no

Daryll

DazzyD
31-03-2018, 11:29 AM
From early reports, I was led to believe that, for the first time ever, businesses needed to become their own Information/Data Commissioners. If this is the case, then it's often a legal requirement to keep data for 6 years so shredding details after a gig might not the best way to go about it? :confused:

Imagine
11-04-2018, 12:25 AM
OK - back to the plot!

DJEP are blatantly ignoring all requests about GDPR. I can't wait any longer because I've always done things by the book....so I'm jumping ship.
For those not in the know about GDPR - the eighth principle of data protection is that data must be stored in an EEC approved country - the USA (where DJEP is hosted) is NOT included unless the provider adheres to certain criteria....at the moment DJEP don't and haven't been certified as such. The fines for ignoring GDPR are enormous and although it's unlikely the DPC will come for us....it's not a risk I'm willing to take.

This law applies to us even after we've left the EU by the way! DeckBooks are based right here in good old Blighty and confirm to all the necessary red tape :)

I'm in the process of moving over to DeckBooks. To be honest - it's a much better system (although I've still got to get my brain cell around a LOT of different ways of working). Lee (the developer) has been AWESOME in transferring my data across from DJEP to his system. As a bonus - if you're a member of the horrid NADJ or the excellent AMPDJ, there's mahusive discounts to be had :)

Much work still to be done - but it's looking like I'm going to be fully compliant by the date GDPR comes into force :)

DJ Jules
11-04-2018, 07:22 AM
For those not in the know about GDPR - the eighth principle of data protection is that data must be stored in an EEC approved country - the USA (where DJEP is hosted) is NOT included unless the provider adheres to certain criteria....at the moment DJEP don't and haven't been certified as such.

As I'm getting more and more into conversations with people about GDPR I'm finding that the original intent behind the regulations is becoming lost.

As others have pointed out, the data does not have to be stored in an EEC approved country. It states that it cannot be stored in, or moved out of an EEC approved country without the users informed consent. The intention behind this regulation is to prevent customers data being gathered in the EU under GDPR where they have rights and protections and the data then being transferred or sold into a jurisdiction where the same protections do not exist.

As long as where the data is stored, the protections that are in place and how the data is going to be used are all made clear at the point where the data is gathered, then it's fine.

Regardless, the ICO is not going to come after DJ's, they'd be having words with DJEP and the worst case scenario is that DJEP would withdraw from European markets and leave their customers high and dry (can't see that happening) or shift their hosting to an EU country (I'd be surprised if this hasn't happened already, especially if they're hosting on an AWS or Azure cloud). The reality here is that we're all using many, many applications that are hosted in countries outside of the EU and the ICO really doesn't have the resource to police every single one of them. They're only going to target the big boys (e.g. Facebook - and look what it's taken for them to actually get involved in that one!!!)

That all said, if you've found another supplier that is UK based, then feel free to shout about it :)

Julian