GDPR compliant community
It would be good to collect in one place information where we are with GDPR compliance when it comes to the fCommunity itself.
I strongly believe that sooner (not later haha) we will be "OK" in EU region when it comes to the compliance.
Here are couple of points:
-
Deletion of user account and all data - it should be as easy as the user was able to create the community account - how we can implement this process workflow nativly (I am not talking about FluentCRM user data or any external automation here).
Currently Admin manually can delete the user (user data will be deleted with the user). What if the user wants to delete data only in fCommunity but stay in the regular WordPress?
Can we expect: Close This Account option in the user profile at some point?
-
What types of data do we collect and how it is being used. Does fCommunity relay on any other than Gravatar external service or any other 3rd party service)
Giphy? Do we share any user data when Giphy is enabled and user use it in posts?
Do we use any Google Fonts?
What user data we share when remote media storage R2/S2 is enabled - Does the EXIF data being removed from media files when uploading them externally?
-
Data portability - we should enable User Data Export. Will the export (json, csv) option be possible at some point?
-
Can we have the Accept Terms checkbook (db record for that if we dont use any other plugins for that) natively included in the fCommunity login page?
It would be also nice to have this checkbox implemented in the FluentAuth plugin so we could see if someone Agreed / selected this option.
Any other questions related to compliance are welcomed in comments.
Very important points.
Cookie consent banner? (even though it has ruined the Internet π)
thanks Mat β, really good points
btw, Β i ran into issues (video-embeds not shown, social links not shown, color-customizer not shown) while using a cookie banner (Real Cookie Banner), which we mostly sorted out.....
still, as we rely on a banner, im sure there'll be more issues on the way ;-)
- Deletion of user account and all data: All associate data will be deleted when a user account is deleted.
- What types of data do we collect and how it is being used: FluentCommunity does not collect or store any data. So it only store what the a user submit (comment / reaction post). Currently it use gravatar with the WordPress core API. But you can disable that from next version.
- We use proxy for Giphy module. So no user data is being transferred.
- Media: Every media you upload is converted and resized to the webp and use WordPress default functions to handle media. So if you have a plugin to purge meta data it will work with that.
- Data portability: We will include the community data with WordPress's default user data export API.
- If you have a standard WordPress terms and condition page published then it shows on the registration page. I don't think you a need a separate checkbox for login page. (nobody does that).
Shahjahan JewelΒ Thanks for taking your time to reply to Mat ββs questions.
- Can Gravtar and UI-avatar be disabled now?
- Inspecting the network traffic, it looks like Giphy content is loaded from Giphy directly, not proxied.
- Please add native support for removing EXIF data. WordPress doesnβt offer it natively, but WordPress isnβt a community platform itself. Stripping EXIF data must be done.
- You can disable ui-avatars & gravatar from Privacy Settings
- If you enable Giphy then it will load directly. Please note that, no personal info is being transferred to Giphy API. The search is proxied.
- If you use any WordPress plugin to remove EXIF data then it will work with that. Also we convert all the photos to wepb so I belive those data may get stripped on that conversation (no 100% sure).
Shahjahan JewelΒ Thanks for the reply. I just submitted a patch to make it easy for developers to disable UI-avatars in FluentCRM also (#115757). They have to add a filter, but they have to do it anyways since the tracking options must be disabled through filters.
Please consider informing FluentCommunity customers about the importance to use a EXIF stripping plugin along with FluentCommunity. Most of them donβt know how important it is (and that the original files must be removed).
Thanks for all the great work you do with FluentCommuity. Please consider launching a GDPR compliant version in 2025. Weβre many users here in the EU who would love to run a FluentCommunity based community.
Karl Emil NikkaΒ Karl, I don't know about EXIF stripping plugins. Is there one that you recommend? I'm here to learn if you have tips to share.
Dan Ryan NeffΒ I havenβt tested one for FluentCommunity yet. We use LiteSpeedβs image optimizer which might work with FluentCommunity if you enable automatic deletion of original images. FluentCommunity should of course implement this in a fail-safe way since it lets community users upload images.
Karl Emil NikkaΒ thank you!
Karl Emil NikkaΒ Thank You and here I am looking for a means to not strip EXIF data for media as are implementing a photographers community.
This is taking too long Shahjahan JewelΒ . It is absolutely necessary for EU citizens. Please vote for it
