# GDPR and anonymizing personal data

**URL:** https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103
**Category:** Community Building
**Tags:** gdpr, privacy
**Created:** [October 15, 2017, 12:40pm UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103 "2017-10-15T12:40:56Z")
**Posts on this page:** 1
**Showing post:** 55

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 12, 2018, 5:58am UTC](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103/55 "2018-04-12T05:58:12Z")

</div>

> [@allu](#):
>
> I am under the impression that the only way to handle the “right to erasure” is that an admin deletes the user including all posts?

No:

> [@RGJ](#):
>
> “does the right to be forgotten in the GDPR apply to forum discussions as well?”
> 
> TL;DR: no.

Anonymizing the user (which includes removing all identifying structured data like IP addresses and such) should be sufficient. If the user has posted information that could lead to their identity in a forum discussion, it is up to the moderator or admin to decide if they are willing to remove those.

> [@riking](#):
>
> The post content is licensed under Creative Commons

Not necessarily, it depends on what license the forum owner has decided to choose.  
If the default Discourse ToS have not been changed, then it is CC.

---

_[View the full topic](https://meta.discourse.org/t/gdpr-and-anonymizing-personal-data/72103)._
