3 ms·
Ask HN: Is there a GDPR compliance privacy statement template for small blogs?
Open source licenses has done wonders for individual software developers who want to publish free/libre/open source software on the internet. We don't have to hire lawyers to carefully draft a license that to give away our software for free while protecting ourselves with disclaimers.
Is there something similar for privacy statements that can be used by small blog owners to remain compliant with GDPR?
Assume the blog is hosted on a Digital Ocean virtual machine hosted in EU, runs on self-hosted Wordpress or another self-hosted free CMS with a built-in comment form. Assume it only writes Apache/Nginx access logs, does not have any analytics in the pages, no cookies, no tracker. Only user comments and access logs. Anything handy for such blogs?
- mytailorisrich 4y agoWhy do you think you need any privacy statements at all?
- eminent101 4y agoBecause name field in a comment form is personal data in GDPR. IP address is also considered personal data in GDPR. And GDPR requires that we publish a privacy statement about how personal data is going to be stored/used/shared. I am not going to share this data with any party. But due to access logs and showing comments, this data is going to be saved on disk. A good template for privacy statement can help a lot. This is a solved problem for open source licenses. It would be great if there is something like that for privacy statement too.
- mytailorisrich 4y agoIP addresses in themselves are not personal data but it is indeed a good idea to handle them carefully. If you do collect personal data and are stickler for the letter of the law you can just state which personal data you collect and for what purpose. No-one will bother you if you are indeed only a small blog.
- eminent101 4y agoIP address seems to be personal data here: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... Many other articles I read also agree with above.
- mytailorisrich 4y agoWe're diverging from your question here, but I'll stick to my previous comment: an IP address is not in itself personal data. A more nuanced, and realistic explanation may be found at [1] (UK GDPR is the same as EU GDPR but Brexit...) That does not really help about your question, though. Again, if you clearly state what is collected and why you should be more than fine. [1] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/what-is-personal-data/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- ThePowerOfFuet 4y ago> We're diverging from your question here, but I'll stick to my previous comment: an IP address is not in itself personal data. iP addresses are within scope of GDPR, period. Source: I hold CIPP/E certification
- mytailorisrich 4y ago> iP addresses are within scope of GDPR, period. This sentence does not mean anything. The actual position regarding IP addresses as personal data is that "an IP address may be personal data if you are able to access additional information which enable you to identify the user behind the IP address", hence my previous statement. Unfortunately, this is often oversimplified (as tends to happen to any non-trivial issue) to "an IP address is personal data". It does mean, though, that one must be careful when handling IP addresses and may treat them as personal data by default as a belt and braces approach (as I already mentioned in my first comment), but that's not the same thing.
- brtkdotse 4y ago> Digital Ocean virtual machine hosted in EU The Schrems II ruling says it's not enough to have the data hosted in EU since DO is a US corp. One trick I've seen people use is to move the discussion to a different forum, like posting the article to HN and having a link in the article saying "Discussion on Hacker News".