# GDPR 倒计时与合规

**URL:** <https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190>\
**Category:** Community Building\
**Tags:** gdpr\
**Created:** [2018年五月10日 19:08 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190 "2018-05-10T19:08:03Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![angus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/angus/32/341715_2.png) [@angus](https://meta.discourse.org/u/angus)\
**Post date:** [2018年五月21日 00:33 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/43 "2018-05-21T00:33:30Z")

</div>

Last night, I started a legal tools plugin.

The first ‘tool’ included in the plugin extends the user archive feature to include all user information stored in the db.

If you’re worried about providing information under GDPR, you can help me test it and / or suggest additional information that should be included.

> [@Legal Tools Plugin](https://meta.discourse.org/t/legal-tools-plugin/87966):
>
> Repository: [GitHub - paviliondev/discourse-legal-tools: Tools to help with legal compliance when using Discourse](https://github.com/paviliondev/discourse-legal-tools) This plugin provides tools to assist with legal compliance when running a Discourse forum. Tools will be added on an ongoing basis. Please note the disclaimer below. This plugin provides no guarantee of legal compliance. Extended User Download The extended user download is a single CSV with the following entries, each separated by two blank lines: A header (can be edited: Custo…

---

<div class="post-metadata">

**Author:** ![ezworldwide](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ezworldwide/32/49134_2.png) [@ezworldwide](https://meta.discourse.org/u/ezworldwide)\
**Post date:** [2018年五月22日 17:47 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/47 "2018-05-22T17:47:15Z")

</div>

I hate even suggesting such a draconian tactic, but I’m going to offer it up for discussion anyway.

What would the impact be on a discourse site if every single EU and EEA country was blocked via IP range in the admin panel? I imagine having a ridiculous amount of IP address ranges dropped in there would slow a site down significantly - but I would like to hear from the experts on this if they care to share their expertise.

To avoid any headaches in terms of GDPR compliance this could be a viable option - at least in the near term. (I know I can block in CloudFlare - but I stopped using them a while ago thanks to the passionate discussion here in meta).

Obviously, this is far from ideal. I personally have a few hundred active EU users who would need to use a VPN but I’m prepared to ask them to make the sacrifice to avoid having to deal with the overly litigious bad apples out there.

Thoughts?

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)\
**Post date:** [2018年五月22日 18:53 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/48 "2018-05-22T18:53:25Z")

</div>

Absolute non starter for anyone who actually lives there…

The UK’s Information Commissioner Office has good advice on this, go take a read through. I’m inclined to take their advice of “five mandatory checkboxes isn’t consent” and “you should be using legitimate interests most of the time” since they’re the ones that will actually be enforcing it.

* * *

The concern over Right to Access for admins is a legitimate one, but again I think something best resolved with manual actions.

---

<div class="post-metadata">

**Author:** ![ezworldwide](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ezworldwide/32/49134_2.png) [@ezworldwide](https://meta.discourse.org/u/ezworldwide)\
**Post date:** [2018年五月22日 20:06 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/49 "2018-05-22T20:06:32Z")

</div>

Agreed - for those of you in the EU what I’m suggesting wouldn’t work. I should have specified that in my post; however, if those of us in the US want to shut out the EU market, that’s a business decision we have a right to make.

My question was focused on the technical implications of shutting out the EU via IP ranges in the admin panel.

---

<div class="post-metadata">

**Author:** ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)\
**Post date:** [2018年五月22日 20:18 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/50 "2018-05-22T20:18:48Z")

</div>

Problem with this would be the EU citizen travelling abroad.

---

<div class="post-metadata">

**Author:** ![ezworldwide](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ezworldwide/32/49134_2.png) [@ezworldwide](https://meta.discourse.org/u/ezworldwide)\
**Post date:** [2018年五月22日 20:20 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/51 "2018-05-22T20:20:13Z")

</div>

That’s a legal conundrum, not a technical one. Although I understand your point. Same applies to people in the EU using a VPN.

---

<div class="post-metadata">

**Author:** ![ssvenn](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ssvenn/32/86740_2.png) [@ssvenn](https://meta.discourse.org/u/ssvenn)\
**Post date:** [2018年五月22日 20:29 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/52 "2018-05-22T20:29:48Z")

</div>

If you actually were to go through with something like that, it would surely be much better to implement at a OS firewall level that is specifically designed for such things.

And even if there are lawyers planning on exploiting GDPR for frivolous litigation I think it would be excessively paranoid to block EU users from something so harmless as specialist online forums. Even with thousands of users I think the focus will be elsewhere for a long time, like mobile apps, online casinos, large social networks and so on that count their users in the millions.

---

<div class="post-metadata">

**Author:** ![ezworldwide](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ezworldwide/32/49134_2.png) [@ezworldwide](https://meta.discourse.org/u/ezworldwide)\
**Post date:** [2018年五月22日 20:46 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/53 "2018-05-22T20:46:00Z")

</div>

Good points. Thanks for that @ssvenn I’ve run political forums for a couple of decades now and Article 9 is my concern:

> Article 9 carries over from the Directive the concept of “special categories” of especially sensitive data concerning race or ethnicity, **political opinions** , religious or philosophical beliefs, trade union membership, health, or sex life. These generally require express consent or a legal obligation in order to collect or process the data, and they require heightened security and attention to data storage limits. The Regulation adds genetic and biometric data to the categories of sensitive data.

For those of us PoliSci nerds misfortunate enough to believe that running a political forum was ever a good idea…this is actually a cause for concern. When very long political debate threads heat up…people get silly and do silly things. A sizeable portion of the regular users in my community are retirees - men and women in their 60s - 80s (my oldest user is 91) and these folks speak their minds and live all over the world. My community is the only daily social interaction some of them have anymore. I will protect that fiercly. I’ve taught most of them how to use a VPN at this point so for my existing EU users I’m not concerned. The younger folks will help them stay connected and they know how to get to where they want to go no matter what I do.

Thanks for the suggestion.

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)\
**Post date:** [2018年五月22日 21:07 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/54 "2018-05-22T21:07:34Z")

</div>

Your special category condition is that forum posts are manifestly made public by the act of posting them.

Also you’re not doing much processing about their opinions, right? Just letting people talk to each other.

so: write that down!

> [DRAFT] We are aware that this is a forum focused on political discussion, and that political opinions are “special category” data under the EU GDPR and other regulations. As this is a publically accessible forum, you should be aware that observers may be able to identify your political opinions based on your posts. Processing of this data is allowed under Article 9(2) condition (e) - the data is made public by you posting it. [DRAFT]

---

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [2018年五月22日 21:58 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/55 "2018-05-22T21:58:04Z")

</div>

> [@itsbhanusharma](#):
>
> Problem with this would be the EU citizen travelling abroad.

No. GDPR 3.2 says that “This Regulation applies to the processing of personal data of data subjects who are in the Union”. It’s not about EU citizens, it’s about people who are in the EU.

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [2018年五月23日 02:53 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/56 "2018-05-23T02:53:06Z")

</div>

I have a client interested in blocking those outside of the US. It’s a US specific topic. I was going to look in to doing it outside of discourse.

---

<div class="post-metadata">

**Author:** ![Cameron\_D](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cameron_d/32/97535_2.png) [@Cameron\_D](https://meta.discourse.org/u/Cameron_D)\
**Post date:** [2018年五月23日 04:15 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/57 "2018-05-23T04:15:20Z")

</div>

I saw this earlier this week and I think it has a few points on topic here.

> **[GDPR Hysteria · Jacques Mattheij](https://jacquesmattheij.com/gdpr-hysteria/)**

Notably, now:

> **I can’t afford the risks associated with this law so I am shutting down/I will lock Europeans out**  
> Ok. Bye. But make sure you really understand those risks and please understand as well that it may not be possible for you to lock Europeans out reliably enough to not have any exposure under the law and realize that there are lots of other laws that you are also exposed to that could cause you to be wiped out. This law is really no different than any others in that respect. The price of using the web as a world stage is that you effectively are interacting with the legal domains of every country that you do business with.

One other thing I’ve considered in the past few days is also that under current Australian law it is [necessary for any company to hand over a copy of all personal data they hold on a person](https://www.oaic.gov.au/agencies-and-organisations/app-guidelines/chapter-12-app-12-access-to-personal-information) if it is requested by that person. Additionally I believe a person can request deletion of that data, though I’m not sure of the specifics here.

Now, I’m fairly sure that the scope of those laws is not quite as extensive as the GDPR, but it just shines a light on the fact that the EU is not the only place with this sort of regulation.

---

<div class="post-metadata">

**Author:** ![ljpp](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ljpp/32/96506_2.png) [@ljpp](https://meta.discourse.org/u/ljpp)\
**Post date:** [2018年五月23日 19:08 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/58 "2018-05-23T19:08:28Z")

</div>

I just translated and updated our TOS and Privacy Policy.

Why is the commonmark on these pages rendered with a slightly different styling than in forum posts? For example tables do not look as good (v1.9 stable).

---

<div class="post-metadata">

**Author:** ![adrianbblk](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/adrianbblk/32/87512_2.png) [@adrianbblk](https://meta.discourse.org/u/adrianbblk)\
**Post date:** [2018年五月24日 13:55 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/59 "2018-05-24T13:55:55Z")

</div>

May 25 tomorrow and discourse do bot follow the GDPR law yet. Still not able to download everything discourse databases have avout my account. Just posts and reply’s are not enought. PM’s, photos, fields and logs have to be included as well.

---

<div class="post-metadata">

**Author:** ![ssvenn](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ssvenn/32/86740_2.png) [@ssvenn](https://meta.discourse.org/u/ssvenn)\
**Post date:** [2018年五月24日 14:48 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/60 "2018-05-24T14:48:06Z")

</div>

Think of all the millions we’re missing out on!

[![](https://global.discourse-cdn.com/meta/original/4X/0/5/5/055d1e6756287ff2e489ee519d0c0460ace66e1a.jpeg "GDPR Millionaire") ](https://www.youtube.com/watch?v=ub8NHmyFL0s)

---

<div class="post-metadata">

**Author:** ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)\
**Post date:** [2018年五月24日 22:27 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/61 "2018-05-24T22:27:29Z")

</div>

You can put in a request to an admin to provide you with that information.

---

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [2018年五月24日 18:11 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/62 "2018-05-24T18:11:03Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/31):
>
> all of the problematic IPs identified in the OP are replaced

No, the most problematic IP’s are the ones without a user ID attached, since those people never consented to their IP address being stored.

---

<div class="post-metadata">

**Author:** ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)\
**Post date:** [2018年五月24日 18:16 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/63 "2018-05-24T18:16:25Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/32):
>
> No, the most problematic IP’s are the ones without a user ID attached, since those people never consented to their IP address being stored.

I am simply referring to what @riking identified as problematic in the OP, I am not making a call about what is the most problematic.

---

<div class="post-metadata">

**Author:** ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)\
**Post date:** [2018年五月24日 18:36 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/64 "2018-05-24T18:36:54Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/5):
>
> es, just like the EU’s cookie law prevented use of websites without a cookie notice. Total jurisdictional destruction, worldwide, immediately preventing use of every single website without a cookie notice. 🤦‍♀️
> 
> If the argument is that the IP isn’t _necessary_ , that is fine, but filing it as a bug will be met with extreme resistance.

Except the fine is 2% of your income or up to 20 million, whichever is higher, and a horde of lawyers is wringing their hands preparing for a horde of lawsuits similar to class actions.

I don’t think you grasp the gravity of the situation - the European Union is in chaos right now, I know multiple lawyers expecting their best year ever and even public institutions are severely worried. Companies _are_ pulling their website from the EU for this reason (even Microsoft shut down two services for this reason).

Please understand - for many of us, me included, this is a make or break for our companies, careers or w/e. I don’t think many people in the EU (or with serious business in the EU) will want to take the risk. I, for one, do not condone risking every job in the company because third parties think it’ll blow over…

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/7):
>
> Well, GDPR is not causing _that_ much panic, but people do want to be sure that they’re compliant. And as long as they’re not sure, they’re not even _starting_ a forum.

Depends on the industry really, and the software. A lot of older companies are not capable of being compliant due to their nature, but in general, agreed.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/8):
>
> (1) is a much much stronger and valuable argument that applies universally. GDPR is intended to protect privacy, demonstrate how privacy is potentially impacted and then make a case for the change

We are legally obliged to offer the ability to use our services while not using any personal identifiers (including IP’s) that are not strictly needed.

Is this strictly needed to use our services?

I would argue it isn’t…

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/11):
>
> If discourse has an official page, with a big fat green checkmark next to GDPR, that could be quite good for adoption.

Agreed. I think the forums not supporting the GDPR are liable to lose a _lot_ of usage. If the lawyers get their way, people will be scrambling to get rid of anything not explicitely compliant.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/16):
>
> Hashed IPs can be brute forced fairly easily (by calculating the hash of all 2^32 IPs and finding the one that matches the relevant hash in the database). Maybe there isn’t much difference between storing a real IP, and a hashed IP?

To be fair, it’d be harder using ipv6. It could also be hashed with something else.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/22):
>
> For the record, I absolutely deplore laws like this as do a poor job of protecting our rights yet they harm millions of businesses and scare the hell out of well-meaning and ethical operators.

It’s a painful law but ultimately I think it’s possible. The simple proof ot that to my opinion is that so many businesses are in panic - as they simply had _no clue_ how they were handling sensitive data. Scary if you think about it. But I digress.

I think you’re right on most of what you said, but there’s something else I’d like to note: You’re also legally obliged to offer your service with the minimal amount of personal identifier needed for basic usage. There’s a strong argument to be made that IP’s aren’t actually needed whatsoever, but serve to enrich the service. Which means it has to be optional, according to the new law.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/29):
>
> Although I do absolutely welcome these PR’s I do want to emphasize that storing the IP addresses of visitors **without** an account (for a longer time than needed for deduplication) is a much more problematic issue since those people cannot easily be asked to give their consent.

Very much true.

And to be frank, if someone wants to avoid being seen by IP, they will be able to avoid it incredibly easily using proxies. Can be asked if simply adding a cookie doesn’t suffice to offer similar protection for less trouble. Could also store a hash of the IP \* the 6 hour period perhaps, not sure if that’d help legally.

All this said and done, let’s pray to the ip god that the lawyers dont get their way.

---

<div class="post-metadata">

**Author:** ![zogstrip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zogstrip/32/512781_2.png) [@zogstrip](https://meta.discourse.org/u/zogstrip)\
**Post date:** [2018年五月24日 18:44 UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/65 "2018-05-24T18:44:30Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/34):
>
> a horde of lawyers is wringing their hands preparing for a horde of lawsuits similar to class actions.

Have you got any proofs of that? Or is that just speculations?

[上一頁](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190.md?page=2)

[下一頁](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190.md?page=4)
