Skip to content

GDPR Compliance #345

@raamdev

Description

@raamdev

There are a few things that need to be done to make Comment Mail GDPR-compliant. This GitHub issue exists to track the requirements and any associated discussion.


Here's a quick summary of items that likely affect Comment Mail:

Three elements of this: Right to Access, Right to Be Forgotten and Data Portability.

  • The right to access provides users with complete transparency in data processing and storage – what data points are being collected, where are these data points being processed and stored, and the reason behind the collection, processing and storage of the data. Users will also have to be provided a copy of their data free of cost within 40 days.
  • The right to be forgotten gives users an option to erase personal data, and stop further collection and processing of the data. This process involves the user withdrawing consent for their personal data to be used.
  • The data portability clause of the GDPR provides users a right to download their personal data, for which they have previously given consent, and further transmit that data to a different controller.

  • An option that allows a site owner to enable GDPR-compliant settings in the plugin
  • GDPR Enabled: All subscriptions should be opt-in only and it should not be possible to opt visitors into subscriptions by default (visitors should be required to click a checkbox to indicate they want to opt-in to the subscription when GDPR is enabled).
  • GDPR Enabled: Comment Mail-related emails should have a link that allows subscribers to erase all data related to their email address.
  • GDPR Enabled: Comment Mail-related emails should have a link that allows subscribers to view/download all subscription data related to their email address.
  • GDPR Enabled: Checkbox on comment form that asks commenters to agree to a privacy policy (see this comment)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions