6 ms·
From the thread: >I don't expect any major changes are needed for compliance, which is why it's been pretty low priority. it's just a matter of getting a docum
by daveid 8y ago
From the thread:
>I don't expect any major changes are needed for compliance, which is why it's been pretty low priority. it's just a matter of getting a document together that better informs admins.
Mastodon has all the features needed for compliance, and does not collect or store any data that's not for its primary purpose.
- amelius 8y agoDoes that mean that in ActivityPub, I can't share messages with a restricted group of people?
- rainbowmverse 8y agoYou can do DMs, but it's possible for admins with sufficient access on each recipient's instance to read them. edit: I didn't see that this was in the context of GDPR.
- amelius 8y agoOk, that sounds like they don't comply with the GDPR then. Also, doesn't ActivityPub allow closed groups?
- detaro 8y agoJust as GDPR-incompliant as e-mail then, or any social media platform that's not e2e encrypted?
- Kiro 8y agoYes, which is why you can't use email to send sensitive personal data anymore.
- detaro 8y agoThat doesn't mean your mail provider isn't GDPR compliant. And with the proper agreements and technical steps in place, a business sending personal data via e-mail could be totally fine to. (a big one would be requiring transport encryption, which is a sensible choice for ActivityPub too, and made by implementations, e.g. Mastodon) It's specific to the use case and what guarantees you have, and not a strict property of a protocol.
- Kiro 8y agoWhat technical steps? My business used to send personal data to normal people via email (their own data). Now we can't do that anymore.
- kyberias 8y agoWhy can't you do that? GDPR does not require end-to-end email encryption.
- albertgoeswoof 8y agoYes you can.
- icedchai 8y agoWhat do you do instead? Ship it to them on CD?
- phoe-krk 8y agoGDPR does not imply end-to-end encryption. Instance administrators on each and every service that isn't E2EE have the technical possibilities to read users' messages simply because they are not encrypted, and that behavior is GDPR-compliant.
- detaro 8y agoNo, you can have closed groups, by addressing a list of people (if I remember correctly, either explicitly listing people or referencing a list defined elsewhere)
- pjc50 8y agoWhy do you think that? Please explain with reference to the text of the directive.