GDPR & User Consent for FluentCommunity (Posts, Messages & Payments)
Hi,
We run a paid online community using FluentCommunity and FluentCRM, based in the Netherlands, but open to users worldwide. We received GDPR concerns from someone in Germany about whether users need to explicitly agree to:
- Posting in the community (e.g., who can see their posts).
- Sending private messages to other members.
- Adding external social media links to their profile.
- Accepting terms & conditions before payment (to prevent refund disputes).
Additionally, the platform collects first name, last name, and username as part of the user profile. Since these are personal data, do users need to explicitly consent to this upon registration, or is voluntary signup sufficient under GDPR?
Regarding the privacy policy, we have one on the website, but do users need to actively agree to it (e.g., via a checkbox), or is making it accessible enough?
Currently, we have a terms & conditions page, but users donβt explicitly agree before payment. Would adding a checkbox before purchase be the best approach? Also, is it necessary to have a separate consent for posting, messaging, and linking social profiles, or does joining the community already imply agreement?
Thanks for any insights! π
So when you are onboarding user, you should have a terms and condition page which user must need to check to create the account. It's a standard practice as this is how all social media sites work.
Shahjahan JewelΒ What needs to be in the terms and condition page related to the community?
Sam JansenΒ I am not a lawyer but you should state that when joining the site, these data will be available for other users for the community features.
Shahjahan JewelΒ Ok yeah. I though a Privacy Policy would be enough, but users have to agree to the terms and conditions when joining the community?
I created a custom registration page for this issue. The default one didn't seem to allow more than one hyperlinks. Also, I wanted my registration to be paid, so that was my main driver for going custom.
It's not as pretty as the default page, but it functions.
Screenshot attached.
William BeemΒ Great! Can I see your agreements? I wonder what there needs to be in there
Sam JansenΒ Sure. The site isn't ready, but you can visit the page to check out the agreements.
https://community.suburbiapress.com/register/
I use a service called Plainly Legal to generate these contracts and policies - plainlylegal.com. It's only for US law.
William BeemΒ Ok cool, looks good! What do you use btw for the magic login form?
Sam JansenΒ I'm using Fluent Forms Pro. It integrates with Stripe and other payment gateways. I just put it on a regular WordPress page, added a headline & some text.
William BeemΒ I mean the magic login form. Is that fluentauth plugin?
Sam JansenΒ Oh, sorry. That is the default login form with FluentCommunity. The image on the left is something I found on Canva.
If you go to Portal Settings > General, it's there on the bottom. Here's a screenshot of my settings.
William BeemΒ Login via Magic link is that fluent auth a free plugin? I dont use it yet
Sam JansenΒ Oh, sorry for not picking up on that earlier. Yes, that is within FluentAuth in the settings. It's a free plugin.
I think I'll allow the Subscribers to use it. Just playing with things on this site right now.
William BeemΒ Thanks for info. I will try it out myself also.
Just one consent is enough, and it has to be given during registration (and reconfirmed every time the privacy policy is updated).
Other than that, Iβd recommend you consult a lawyer or at least take a GDPR course, because you seem to have some pretty basic doubts you really shouldnβt have π
Linda RandoΒ Ok yeah thanks. Normally for simple static websites there is not so much needed espesially when there is no tracking and login. So that is why I am asking some questions.
Sam JansenΒ Exactly, Iβm saying this for your own good, because itβs something very important and could have serious legal consequences, so itβs worth looking into it carefully :)
Sam JansenΒ GDPR regulations require businesses to handle user data responsibly - particularly when using it for advertising, tracking, or lead generation.
You need explicit consent to collect or process personal data, including through tools like tracking pixels or cookies.
GDPR regulations apply wherever personal data is collected, processed, or stored - including social media/communities platforms.
You must respect EU Citizen and Resident Rights consent even if you have one user from the EU.
Social media marketers (if you use FluentCRM or any other tool for Marketing then read this twice) must ensure these rights are upheld when handling user information, including names, cookies, tracking pixels, and even data collected for advertising (including users profiling - The Right to Avoid Automated Decision-Making).
Explicit, opt-in consent is at the heart of GDPR compliance.
Internet users must actively agree to how their data is collected, stored, and used - consent cannot be implied through inactivity or pre-checked boxes.
Basic GDPR topics:
- The Right to Information
- The Right of Access
- The Right to Rectification
- The Right to Erasure (The "Right to Be Forgotten")
- The Right to Restriction of Processing
- The Right to Data Portability
- The Right to Object
- The Right to Avoid Automated Decision-Making
Read more here to get the idea.