Skip to main content

GDPR compliant community

It would be good to collect in one place information where we are with GDPR compliance when it comes to the fCommunity itself.

I strongly believe that sooner (not later haha) we will be "OK" in EU region when it comes to the compliance.

Here are couple of points:

  • Deletion of user account and all data - it should be as easy as the user was able to create the community account - how we can implement this process workflow nativly (I am not talking about FluentCRM user data or any external automation here).

    Currently Admin manually can delete the user (user data will be deleted with the user). What if the user wants to delete data only in fCommunity but stay in the regular WordPress?

    Can we expect: Close This Account option in the user profile at some point?

  • What types of data do we collect and how it is being used. Does fCommunity relay on any other than Gravatar external service or any other 3rd party service)

    Giphy? Do we share any user data when Giphy is enabled and user use it in posts?

    Do we use any Google Fonts?

    What user data we share when remote media storage R2/S2 is enabled - Does the EXIF data being removed from media files when uploading them externally?

  • Data portability - we should enable User Data Export. Will the export (json, csv) option be possible at some point?

  • Can we have the Accept Terms checkbook (db record for that if we dont use any other plugins for that) natively included in the fCommunity login page?

    It would be also nice to have this checkbox implemented in the FluentAuth plugin so we could see if someone Agreed / selected this option.

Any other questions related to compliance are welcomed in comments.

Aaron Liang

Very important points.

Cookie consent banner? (even though it has ruined the Internet πŸ™ˆ)

Manuel MΓΌller

thanks Mat β€Ž, really good points

btw, Β i ran into issues (video-embeds not shown, social links not shown, color-customizer not shown) while using a cookie banner (Real Cookie Banner), which we mostly sorted out.....

still, as we rely on a banner, im sure there'll be more issues on the way ;-)

Shahjahan Jewel

  • Deletion of user account and all data: All associate data will be deleted when a user account is deleted.
  • What types of data do we collect and how it is being used: FluentCommunity does not collect or store any data. So it only store what the a user submit (comment / reaction post). Currently it use gravatar with the WordPress core API. But you can disable that from next version.
  • We use proxy for Giphy module. So no user data is being transferred.
  • Media: Every media you upload is converted and resized to the webp and use WordPress default functions to handle media. So if you have a plugin to purge meta data it will work with that.
  • Data portability: We will include the community data with WordPress's default user data export API.
  • If you have a standard WordPress terms and condition page published then it shows on the registration page. I don't think you a need a separate checkbox for login page. (nobody does that).

Karl Emil Nikka

Shahjahan JewelΒ Thanks for taking your time to reply to Mat β€Žβ€™s questions.

  1. Can Gravtar and UI-avatar be disabled now?
  2. Inspecting the network traffic, it looks like Giphy content is loaded from Giphy directly, not proxied.
  3. Please add native support for removing EXIF data. WordPress doesn’t offer it natively, but WordPress isn’t a community platform itself. Stripping EXIF data must be done.

Shahjahan Jewel

Karl Emil NikkaΒ 

  1. You can disable ui-avatars & gravatar from Privacy Settings
  2. If you enable Giphy then it will load directly. Please note that, no personal info is being transferred to Giphy API. The search is proxied.
  3. If you use any WordPress plugin to remove EXIF data then it will work with that. Also we convert all the photos to wepb so I belive those data may get stripped on that conversation (no 100% sure).

Karl Emil Nikka

Shahjahan JewelΒ Thanks for the reply. I just submitted a patch to make it easy for developers to disable UI-avatars in FluentCRM also (#115757). They have to add a filter, but they have to do it anyways since the tracking options must be disabled through filters.

Please consider informing FluentCommunity customers about the importance to use a EXIF stripping plugin along with FluentCommunity. Most of them don’t know how important it is (and that the original files must be removed).

Thanks for all the great work you do with FluentCommuity. Please consider launching a GDPR compliant version in 2025. We’re many users here in the EU who would love to run a FluentCommunity based community.

Dan Ryan Neff

Karl Emil NikkaΒ Karl, I don't know about EXIF stripping plugins. Is there one that you recommend? I'm here to learn if you have tips to share.

Karl Emil Nikka

Dan Ryan NeffΒ I haven’t tested one for FluentCommunity yet. We use LiteSpeed’s image optimizer which might work with FluentCommunity if you enable automatic deletion of original images. FluentCommunity should of course implement this in a fail-safe way since it lets community users upload images.

Dan Ryan Neff

Karl Emil NikkaΒ thank you!

Owen Kane

Karl Emil NikkaΒ  Thank You and here I am looking for a means to not strip EXIF data for media as are implementing a photographers community.

Admin j

This is taking too long Shahjahan JewelΒ . It is absolutely necessary for EU citizens. Please vote for it