4 ms·
In the specific case of XMPP, wouldn't I need to have an agreement with every other admin who federates their XMPP server and work out what exactly our roles ar
by anfogoat 8y ago
In the specific case of XMPP, wouldn't I need to have an agreement with every other admin who federates their XMPP server and work out what exactly our roles are as defined by GDPR? XMPP still has active development community around it so this will no doubt get much easier with time, but that's just XMPP.
- viraptor 8y agoIANAL, but unlikely. Sending messages is the primary purpose of the service. As long as users are made aware that messages going outside of your domain are shared with 3rd parties, it's on them to make that decision. Same would apply to email, phones, etc.
- bcheung 8y agoMaybe not: You need to have a "Legal Basis" and only 1 of them is the "subject has given consent" one. There's another: "The processing is NECESSARY FOR THE PERFORMANCE OF A CONTRACT to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract;"
- davorak 8y agoI thought you would have to al least all the admins to agree to follow the GDPR so that data can be retrieved, corrected, and deleted on demand right?
- mandelbulb 8y agoLook at it this way: The service you're using needs a privacy policy, that is not new. The way that policy is organized or shared is no different now, just what rights the user and what obligations the service provider has.