3 ms·
This is going to sound crazy, but I spun up an instance of a simple open-source comments system[1] for a blog that I write, and I chickened out of deploying it
by josecastillo 8y ago
This is going to sound crazy, but I spun up an instance of a simple open-source comments system[1] for a blog that I write, and I chickened out of deploying it because I wasn't sure if it complied with GDPR. I distrust Disqus over their ad-driven model and deep tracking of users, so for now I’m just doing without comments.
Is it possible to self-host something that handles user data (name, comment, IP address) and comply with this regulation? What if there's more data, federated data? Can one just spin up an instance of Friendica, for example, or are there additional steps required for compliance? I'm honestly not sure anymore.
[1]: https://posativ.org/isso/ https://posativ.org/isso/
- ozim 8y agoIf you do it for hobby it is not a problem. For IP address if you don't store it indefinitely, like you can anonymise IP after a month. I think you store IP for spam protection, solving user issues, which is lawful basis so you can protect your good interest. Most important you are not passing it to some third party. Second you can always make consent checkbox. DPO is required only if you really store race, religion, credit card data, health records. If you keep name and IP you do not need a DPO. There is so much FUD about GDPR, it will pass after a year. Now compliance vendors are having part, a lot of champagne will be opened on May 25th. In the end if you know, what data you have, why do you have it and who you share it with, it should be good enough.
- DanBC 8y agoIt doesn't apply to personal projects, unless they're commercial. https://gdpr-info.eu/recitals/no-18/ https://gdpr-info.eu/recitals/no-18/ > This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. 2Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. 3However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.
- KajMagnus 8y ago> Is it possible to self-host something that handles user data (name, comment, IP address) and comply with this regulation? Yes. There's something called GDPR legitimate interest (a subcategory in the "Lawful basis" someone else mentioned here), which lets you store e.g. IP addresses for security reasons, without asking for permission. See: http://www.privacy-regulation.eu/en/recital-49-GDPR.htm http://www.privacy-regulation.eu/en/recital-49-GDPR.htm I think Talkyard ( = open source comments, no ads, no tracking) is GDPR compliant. For example, people can download their personal data and delete their accounts. (I'm developing it). https://www.talkyard.io/blog-comments https://www.talkyard.io/blog-comments