Skip to content

Data Protection Policy

In particular, this page describes how Whisper complies with the GDPR, the EEA data protection policy that comes into force on 25 May 2018.

The GDPR doesn’t introduce any new requirements about sending data for processing outside the EU. Many of the larger data processors such as MailChimp will have EU-approved Privacy Shield certification (successor to the Safe Harbor scheme).

MailChimp’s EEA (and Swiss) customers should be able to continue to rely on MailChimp’s Privacy Shield certification in order to transfer their lawfully obtained personal data to MailChimp under the GDPR.

It’s not necessary to reobtain consent to send e-mails when the GDPR comes into force, provided that consent was originally obtained in accordance with GDPR principles.

MailChimp is preparing GDPR-compliant signup forms that record the user’s IP address and the actual wording of the form at the time, to allow compliance to be demonstrated.

Gift Aid processing

Sponsored children