# GDPR and anonymizing personal data

**URL:** https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103
**Category:** Community Building
**Tags:** gdpr, privacy
**Created:** [October 15, 2017, 12:40pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103 "2017-10-15T12:40:56Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [January 30, 2018, 11:04pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/41 "2018-01-30T23:04:51Z")

</div>

> [@Mittineague](#):
>
> Nor is removing content from cached “wayback” pages feasible.

That is something between the user and the wayback machine, not between the user and the forum owner.

> [@Mittineague](#):
>
> But unsending sent emails is an impossibility.

Sent emails are usually not stored on the servers managed by the forum provider and are thus outside of the scope of GDPR.

---

<div class="post-metadata">

### Author: ![awlogan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awlogan/32/62208_2.png) [@awlogan](https://meta.discourse.org/u/awlogan)
#### Post date: [January 31, 2018, 12:56am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/42 "2018-01-31T00:56:37Z")

</div>

Sure, here is what we have. I’ll update if we have to make any additional changes: [https://community.zscaler.com/tos](https://community.zscaler.com/tos)

---

<div class="post-metadata">

### Author: ![clay](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/clay/32/102156_2.png) [@clay](https://meta.discourse.org/u/clay)
#### Post date: [February 2, 2018, 6:32pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/43 "2018-02-02T18:32:40Z")

</div>

> [@hlcfan](#):
>
> If user requests to revoke their consent, I think we don’t need to delete the data from our database, we just don’t use it, right?

I think it depends on what they request, [Right to Erasure](https://www.privacy-regulation.eu/en/article-17-right-to-erasure-'right-to-be-forgotten'-GDPR.htm) or [Right to Restriction of Processing](https://www.privacy-regulation.eu/en/article-18-right-to-restriction-of-processing-GDPR.htm). Either way you are obliged to [communicate to the data subject what you did](https://www.privacy-regulation.eu/en/article-19-notification-obligation-regarding-rectification-or-erasure-of-personal-data-or-restriction-of-processing-GDPR.htm).

**Right to erasure**

> **1.** The data subject shall have the right to obtain from the controller the **erasure** of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies…

It’s not clear to me exactly what would be a way to argue that the data is required for a Discourse forum to continue to operate normally. I guess it may depend on the subject matter?

---

<div class="post-metadata">

### Author: ![clay](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/clay/32/102156_2.png) [@clay](https://meta.discourse.org/u/clay)
#### Post date: [February 2, 2018, 7:28pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/44 "2018-02-02T19:28:36Z")

</div>

> [@riking](#):
>
> Is deleting/anonymizing the data after a short period compliant? e.g. replacing the IP address with a sequential number.

Instead of storing and exposing IP, would it be worth salting and hashing the IP and storing that instead? If it cannot be reverse decoded to point to a location, it could perform the same function for spam prevention, etc.

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [February 2, 2018, 10:10pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/45 "2018-02-02T22:10:50Z")

</div>

Discourse automatically creates CIDR notation when 6+ spammers come from the same /24, and I’m not sure there’s a way to do that if we’re hashing the IPs.

---

<div class="post-metadata">

### Author: ![bartv](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bartv/32/130052_2.png) [@bartv](https://meta.discourse.org/u/bartv)
#### Post date: [February 10, 2018, 9:55am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/46 "2018-02-10T09:55:23Z")

</div>

> [@michaeld](#):
>
> At this moment, I only see the ability to download my posts, likes and such, but not my profile data. Or am I overlooking something?

I noticed that the posts download does not include uploaded attachments. I’m assuming they should be part of my data export?

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [March 22, 2018, 9:08pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/47 "2018-03-22T21:08:59Z")

</div>

13 posts were split to a new topic: [Providing data for GDPR](https://meta.discourse.org/t/providing-data-for-gdpr/83595)

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 3, 2018, 7:57am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/48 "2018-04-03T07:57:46Z")

</div>

One of the leading Dutch ICT/Law blogs just published a post titled “does the right to be forgotten in the GDPR apply to forum discussions as well?”

TL;DR: no.

> **[Geldt het vergeetrecht onder de AVG ook bij forumdiscussies? - Ius Mentis](https://blog.iusmentis.com/2018/04/03/geldt-het-vergeetrecht-onder-de-avg-ook-bij-forumdiscussies/)**
>
> Een lezer vroeg me: Ik beheer een relatief groot discussieforum. Moet ik straks onder de AVG van iedereen die dat vraagt zijn berichten weghalen onder het vergeetrecht? Dan houd ik straks geen historie meer over! Het klopt dat je als aanbieder van...

Translation: [Geldt het vergeetrecht onder de AVG ook bij forumdiscussies? - Ius Mentis](https://translate.google.com/translate?sl=auto&tl=en&js=y&prev=_t&hl=nl&ie=UTF-8&u=https%3A%2F%2Fblog.iusmentis.com%2F2018%2F04%2F03%2Fgeldt-het-vergeetrecht-onder-de-avg-ook-bij-forumdiscussies%2F&edit-text=&act=url)  
(AVG is the Dutch term for GDPR)

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [April 3, 2018, 9:14pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/49 "2018-04-03T21:14:12Z")

</div>

Thanks for sharing. But just to make sure I understand: this is irrelevant for anyone using the default ToS that come with discourse and which stipulate that all posts are published under a Creative Commons license, right?

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 5, 2018, 6:03am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/50 "2018-04-05T06:03:02Z")

</div>

> [@tophee](#):
>
> this is irrelevant for anyone using the default ToS that come with discourse and which stipulate that all posts are published under a Creative Commons license, right?

I don’t think it is completely irrelevant, and the default ToS that comes with Discourse will not hold up in court in many European countries.

---

<div class="post-metadata">

### Author: ![allu](https://avatars.discourse-cdn.com/v4/letter/a/cdc98d/32.png) [@allu](https://meta.discourse.org/u/allu)
#### Post date: [April 11, 2018, 8:39pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/51 "2018-04-11T20:39:16Z")

</div>

Reading through this topic (and being new to Discourse), I am under the impression that the only way to handle the “right to erasure” is that an admin deletes the user including all posts? If so, and as others have stated, this is quite disruptive for a discussion community. A better approach would be to anonymize all user data (removing Email, any stored IP addresses, and changing user name, also in all posts). Would this approach suffice for the “right to forget” requirement? If so, is my understanding correct, that Discourse doesn’t provide any functionality to support this?

Edit:  
The other question is, does the right to erasure even apply to a public discussion forum? ICO states:

#### When does the right to erasure not apply?

- to exercise the right of freedom of expression and information;
- for archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing;

Wouldn’t both apply in the case of a discussion forum?  
[https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/)

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [April 11, 2018, 9:19pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/52 "2018-04-11T21:19:28Z")

</div>

The “anonymize user” functionality does what you said - change name, email, remove IP addresses. The post content is licensed under Creative Commons and should be reviewed for personal info on a case-by-case basis if the user requests such a review.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [April 12, 2018, 12:16am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/53 "2018-04-12T00:16:27Z")

</div>

> [@riking](#):
>
> remove IP addresses

As you correctly pointed out in an earlier post, we need to make sure it is removing the IP from everywhere it can at the time of anonymization, though – feel free to send through PRs on that if you can assist.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 12, 2018, 2:41am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/54 "2018-04-12T02:41:03Z")

</div>

Also I definitely agree with removing IP logging where it is pointless, @riking isolated a few spots, PR also super welcome on that.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 12, 2018, 5:58am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/55 "2018-04-12T05:58:12Z")

</div>

> [@allu](#):
>
> I am under the impression that the only way to handle the “right to erasure” is that an admin deletes the user including all posts?

No:

> [@RGJ](#):
>
> “does the right to be forgotten in the GDPR apply to forum discussions as well?”
> 
> TL;DR: no.

Anonymizing the user (which includes removing all identifying structured data like IP addresses and such) should be sufficient. If the user has posted information that could lead to their identity in a forum discussion, it is up to the moderator or admin to decide if they are willing to remove those.

> [@riking](#):
>
> The post content is licensed under Creative Commons

Not necessarily, it depends on what license the forum owner has decided to choose.  
If the default Discourse ToS have not been changed, then it is CC.

---

<div class="post-metadata">

### Author: ![SMx](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/smx/32/83713_2.png) [@SMx](https://meta.discourse.org/u/SMx)
#### Post date: [April 17, 2018, 8:39am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/56 "2018-04-17T08:39:36Z")

</div>

> [@RGJ](#):
>
> ving all identifying structured data like IP addresses and such) should be sufficient. If the user has posted information that could lead to their identity in a forum discussion, it is up to the moderator or admin to decide if they are willing to remove those.

Hello there, is Discourse going to include GDPR specific tools with the upcoming updates ? ETA of 25th of May is closing in fast and it’s pretty serious stuff.

If you ask me, it should contain the basis, like the first registration process, maybe anonymization and NOT the entire GDPR fixtures.

Thank you.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 17, 2018, 10:10am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/57 "2018-04-17T10:10:06Z")

</div>

I was just writing up some stuff and making screenshots of the anonymization process and then I saw something I had never noticed before: anonymization apparently keeps the signup and last login IP addresses. Those should really be included in the anonymization process.

 ![image](https://global.discourse-cdn.com/meta/original/3X/c/8/c8d6d7e0478c8259553cc0b8f7e3071fbbe5dc4b.png)

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [April 17, 2018, 11:28am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/58 "2018-04-17T11:28:28Z")

</div>

> [@RGJ](#):
>
> If the user has posted information that could lead to their identity in a forum discussion, it is up to the moderator or admin to decide if they are willing to remove those

I fully agree with this, but perhaps the procedure should be made transparent (not sure if this is legally necessary, but it surely would help if both users and admins understand the distribution of responsibilities). What I mean is: I would like to assume that it is the user who has to point out each individual post that needs to be sanitized. In other words: it’s not enough to request “deletion” (aka anonymization) and assume that this will include any personal information in any post.

> [@RGJ](#):
>
> If the default Discourse ToS have not been changed, then it is CC.

Perhaps the default ToS could be clarified in relation to deletion request. Currently, the elaboration of the CC user content license seems preoccupied about the site owner being allowed to remove content. How about also mentioning that the site owner can _refuse_ the removal of content? Not sure whether it should say “within the limitations of applicable law” or something like that, but with or without that clause it would help make people aware of what they’re agreeing to.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [April 17, 2018, 5:52pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/59 "2018-04-17T17:52:24Z")

</div>

> [@SMx](#):
>
> ETA of 25th of May is closing in fast and it’s pretty serious stuff.

I had breakfast this morning for someone who works with a major ad company and predicts that they’ll basically shut down a bunch of their services when 25 May hits because they don’t quite know what to do.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 17, 2018, 7:34pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/60 "2018-04-17T19:34:19Z")

</div>

> [@pfaffman](#):
>
> basically shut down a bunch of their services when 25 May hits

Yes, I know a few companies as well that will shut down some of their applications on May 24, just because it’s too big a problem to fix and the liabilities will be too high.

[Previous page](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103.md?page=2)

[Next page](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103.md?page=4)
