# GDPR countdown and compliance

**URL:** https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190
**Category:** Community Building
**Tags:** gdpr
**Created:** [May 10, 2018, 7:08pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190 "2018-05-10T19:08:03Z")
**Posts on this page:** 20
**Page:** 4

<div class="post-metadata">

### Author: ![ortnalic940](https://avatars.discourse-cdn.com/v4/letter/o/8491ac/32.png) [@ortnalic940](https://meta.discourse.org/u/ortnalic940)
#### Post date: [May 24, 2018, 6:50pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/66 "2018-05-24T18:50:05Z")

</div>

It also works via the console. An ip\_anonymizer may be helpful as well, i.e., the same behavior with :anonymize\_ip =\>“0.0.0.0” but without anonymizing the user (for some time period).

---

<div class="post-metadata">

### Author: ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)
#### Post date: [May 24, 2018, 6:54pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/67 "2018-05-24T18:54:25Z")

</div>

Mostly via-via to be frank, lawyers I know, lawyers friends know..

Dutch articles are also raving right now about privacy watchdogs getting an easy way for a good income.

But a quick google brings me to:

> **[Happy consumer lawyers due to new data privacy damages claims? — Financier...](https://www.financierworldwide.com/happy-consumer-lawyers-due-to-new-data-privacy-damages-claims/#.WwcJQkiFOUk)**

> **[Law firms planning litigation market for GDPR | Computer Weekly](https://www.computerweekly.com/news/450303191/Law-firms-planning-litigation-market-for-GDPR)**
>
> Businesses should be preparing for the storm of litigation that is likely to be unleashed when the GDPR goes into force, warns Stewart Room of PwC Legal

Apologies for not clarifying that.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [May 24, 2018, 7:00pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/68 "2018-05-24T19:00:13Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/34):
>
> the fine is 2% of your income or up to 20 million

_can_ be up to 4% of your revenue.  
That is, in case you were really making a mess and _deliberately_ infringing on people’s privacy.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/34):
>
> the European Union is in chaos right now

Nope. Don’t see any chaos here. Just a lot of companies that are (finally) taking our privacy seriously.

---

<div class="post-metadata">

### Author: ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)
#### Post date: [May 24, 2018, 7:05pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/69 "2018-05-24T19:05:55Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/38):
>
> _can_ be up to 4% of your revenue.  
> That is, in case you were really making a mess and _deliberately_ infringing on people’s privacy.

Thanks for the correction. And to be fair, that is theory still.

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/38):
>
> Nope. Don’t see any chaos here. Just a lot of companies that are (finally) taking our privacy seriously.

Guess you know better companies than I do. 🙂

The local university in my area is, from what I am hearing through the grapevine, in a bit of a pickle as they’ve hundreds of old systems they can’t simply update. One of the more prestigious ones in the country.

I’ve had a few companies tell me they might outright shut down depending on how the first lawsuits go, and a friend of mine who runs a marketing consultancy has switched careers as she doesn’t expect to be able to do her job anymore.

And to be frank, we’ve heard “GDPR will change everything” so often now, that a lot of people just seem sick and tired of the whole discussion.

Not arguing it’s a bad thing per se, I wish there was an exclusion for smaller companies (some of which are in pretty deep crap, as many are using systems that they haven’t updated in 5+ years and can’t update now) but I definitely would call this a chaotic situation.

There’s so many GDPR workshops, consultancy companies and such around in my area…

Either way I think this is a very serious matter, and I am deeply concerned by how decisively not-ready pretty much everyone seems to be. I don’t think IPB or other forums are fully compliant yet either..

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [May 24, 2018, 7:09pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/70 "2018-05-24T19:09:28Z")

</div>

> [@C-Alexander](#):
>
> I wish there was an exclusion for smaller companies

> **[Dekker: niet meteen boete voor voetbalclub vanwege nieuwe privacywet](https://nos-nl.translate.goog/artikel/2233261-dekker-niet-meteen-boete-voor-voetbalclub-vanwege-nieuwe-privacywet?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=nl)**
>
> In het begin zal schappelijk worden opgetreden, zegt de minister.

> Small Dutch organizations do not have to worry about receiving fines quickly if they have not yet properly protected personal data.

---

<div class="post-metadata">

### Author: ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)
#### Post date: [May 24, 2018, 7:13pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/71 "2018-05-24T19:13:20Z")

</div>

" Minister Dekker does not think that this authority will immediately issue fines to small organizations"

The key here is “think”. The website for the law says explicitely they do have to keep to said law, and the European Union has it’s own authority that seems to be involved here as well.

I would feel a lot better with an official inclusion or perhaps a warning system, or perhaps similar to our tax system a "You have to follow this law in x months if requested to by the authority, or with over xx income in the EU’.

Perhaps this is a different topic though 😛 Regardless, I’d sleep a lot better knowing we’re all in compliance.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [May 24, 2018, 7:17pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/72 "2018-05-24T19:17:06Z")

</div>

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785/41):
>
> The key here is “think”

This is sloppy language of the author and not a quote of the minister.

Translated from [Nieuws & Blogs | ICTRecht](https://ictrecht.nl/2017/09/25/wat-zijn-de-risicos-bij-overtreding-van-de-avg-deel-1-boetes/)

> Considerations when imposing a fine
> 
> From the GDPR it also follows that a supervisor must carefully consider whether the imposition of a fine is appropriate (effective, proportionate and dissuasive) for the violation. When it comes to a small infringement, you can also opt for a reprimand instead of a fine. Supervisors may draw up their penalty policy at their discretion. The supervisory authority must in any case take into consideration the following considerations in its consideration (whether or not to impose a fine and the amount of the fine):

> - The nature, severity and duration of the infringement. This involves looking at the number of affected parties and the extent of the damage suffered by them;
> - Whether the controller or processor acted deliberately or negligently;
> - The measures taken to limit the damage;
> - Previous infringements by the controller or processor;
> - To what extent has the co-operation been granted to the regulator to remedy the infringement and to limit the damage;
> - Which category of personal data is concerned;
> - How the supervisor has been informed of the infringement, in particular whether the controller or processor himself has made a report;
> - Compliance with a previously imposed corrective action;
> - Whether the controller or processor is affiliated with approved codes of conduct or certification mechanisms;
> - Other aggravating or mitigating factors.

---

<div class="post-metadata">

### Author: ![C-Alexander](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/c-alexander/32/97591_2.png) [@C-Alexander](https://meta.discourse.org/u/C-Alexander)
#### Post date: [May 24, 2018, 7:22pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/73 "2018-05-24T19:22:59Z")

</div>

Well, we’ll see how it works in practice and how the other countries are treating this in the coming weeks I guess.

But keep in mind the Minister also is not all powerful in this.

Thank you for the information regardless.

---

<div class="post-metadata">

### Author: ![angus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/angus/32/341715_2.png) [@angus](https://meta.discourse.org/u/angus)
#### Post date: [May 25, 2018, 12:09am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/74 "2018-05-25T00:09:44Z")

</div>

> [@adrianbblk](#):
>
> Still not able to download everything discourse databases have avout my account

You can use the [Legal Tools Plugin](https://meta.discourse.org/t/legal-tools-plugin/87966) to do this.

As @HAWK points out, the ability to do this is not determinative of compliance.

The GDPR is mostly about how you run your forum, rather than the software per se. It’s not that how the software is built is irrelevant, it’s that it shouldn’t be your primary focus.

That said, I completely understand why folks are anxious about the GDPR. It’s not irrational to feel anxious about it, particularly if you’re a small outfit.

If anyone has any remaining specific concerns about the GDPR and Discourse that have not been covered already please raise them here and we can deal with them together.

Whatever it is, we can fix it. But please be specific and read up on what has already been covered first.

---

<div class="post-metadata">

### Author: ![Daniel\_Nevoigt](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/daniel_nevoigt/32/92920_2.png) [@Daniel\_Nevoigt](https://meta.discourse.org/u/Daniel_Nevoigt)
#### Post date: [May 25, 2018, 4:37am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/75 "2018-05-25T04:37:42Z")

</div>

We have many people who are anxious about the GDPR law here in Germany. There are numerous lawyers waiting for the law to be enforced, rubbing their hands in anticipation. The government has done nothing to prevent these lawyers from issuing warnings for even the slightest errors. Thus, it has become a major business, also for the government. They will earn a lot of money when large companies get sued.

I am glad that you guys are taking this matter seriously!

---

<div class="post-metadata">

### Author: ![Bas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bas/32/294929_2.png) [@Bas](https://meta.discourse.org/u/Bas)
#### Post date: [May 25, 2018, 9:19am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/76 "2018-05-25T09:19:48Z")

</div>

> [@C-Alexander](#):
>
> Except the fine is 2% of your income or up to 20 million, whichever is higher, and a horde of lawyers is wringing their hands preparing for a horde of lawsuits similar to class actions.

Please note that (contrary to how this would be in e.g. the US), the fines will not be paid to the plaintiff, but to the state authority. This severely limits the incentive to file bogus lawsuits.

Yes, you can sue based on a data-breach, but that was already the case afaik.

> [@C-Alexander](#):
>
> A lot of older companies are not capable of being compliant due to their nature,

Then they probably shouldn’t exist. I also can’t run a cocaine farm due to regulation. I won’t shed a single tear.

---

<div class="post-metadata">

### Author: ![GBrowning](https://avatars.discourse-cdn.com/v4/letter/g/f17d59/32.png) [@GBrowning](https://meta.discourse.org/u/GBrowning)
#### Post date: [May 25, 2018, 10:57am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/77 "2018-05-25T10:57:43Z")

</div>

So, to clarify the current status for compliance regarding the issues I raised in the first post:

## Consent to Updated Privacy Policy / Terms of Service ✅

We can use @angus’s amazing custom wizard to construct a consent to new privacy policy and ToS (which can state that emails are used to “notify you about posts and other activity on the forum”):

[https://meta.discourse.org/t/custom-wizard-plugin/73345/111](https://meta.discourse.org/t/custom-wizard-plugin/73345/111)

## IP Addresses ⌛ ✅

Sounds like a ton of work was done with regards to IP addresses and will be part of an upcoming 2.0 or 2.1 build so we’re almost there:

> [@Problematic IP address fields](https://meta.discourse.org/t/problematic-ip-address-fields/83785):
>
> Continuing the discussion from [Providing data for GDPR](https://meta.discourse.org/t/providing-data-for-gdpr/83595/17): I did a first pass over Discourse’s tables, and I found several places where IP addresses are being accidentally correlated with user IDs. This is toxic data generating liability for Discourse forums. List of problematic IP address fields: white_check_mark x incoming\_links: stores timestamped IP address correlated with user ID and an exact post ID, topic ID, and Referer: header Fixed Storage: PR#5826white_check_mark …

## Data Portability ✅

We can use @angus’s Legal Tools Plugin to allow users to download _all_ collected data about themselves.

> [@Legal Tools Plugin](https://meta.discourse.org/t/legal-tools-plugin/87966):
>
> Repository: [GitHub - paviliondev/discourse-legal-tools: Tools to help with legal compliance when using Discourse · GitHub](https://github.com/paviliondev/discourse-legal-tools) This plugin provides tools to assist with legal compliance when running a Discourse forum. Tools will be added on an ongoing basis. Please note the disclaimer below. This plugin provides no guarantee of legal compliance. Extended User Download The extended user download is a single CSV with the following entries, each separated by two blank lines: A header (can be edit…

And perhaps some of this work can go into the normal Download button handler after the IP addresses issue is fully resolved.

Great job everyone! 👏 👏 👏

---

<div class="post-metadata">

### Author: ![arnie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/arnie/32/171412_2.png) [@arnie](https://meta.discourse.org/u/arnie)
#### Post date: [May 25, 2018, 4:49pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/78 "2018-05-25T16:49:36Z")

</div>

How about handling all cookies that are present at Discourse including third-party cookies:

[https://meta.discourse.org/t/list-of-cookies-used-by-discourse/83690/5?u=arnie](https://meta.discourse.org/t/list-of-cookies-used-by-discourse/83690/5)

---

<div class="post-metadata">

### Author: ![angus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/angus/32/341715_2.png) [@angus](https://meta.discourse.org/u/angus)
#### Post date: [May 26, 2018, 10:58am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/79 "2018-05-26T10:58:54Z")

</div>

> [@arnie](#):
>
> How about handling all cookies that are present at Discourse including third-party cookies

This has been discussed in some depth here:

> [@Cookie compliance under GDPR](https://meta.discourse.org/t/cookie-compliance-under-gdpr/85275):
>
> I would like to start a conversation on how to become GDPR compliant with regards to the use of cookies. There was an old topic on EU cookie compliance here, [https://meta.discourse.org/t/compliance-with-eu-cookie-law/17727](https://meta.discourse.org/t/compliance-with-eu-cookie-law/17727) …but GDPR is a completely different requirement. While EU cookie compliance only required a statement placed at the bottom or at the top of the website, that lets the user know cookies are being used, GDPR requires giving the user a real and informed choice. Cookies can be…

tl;dr: Cookie use in standard Discourse is either non-user-specific or or falls under the ‘legitimate Interests’ basis of data processing and storage, rather than consent. If you’re using third-party services, such as analytics or ad-based services, you may need to obtain consent. In the topic I linked to, there’s some examples of using purpose-built services to obtain consent for cookie use.

To your specific point about notices, you can provide a statement about your cookie use in your [privacy policy](https://meta.discourse.org/privacy), in a globally pinned topic and / or in a [banner](https://meta.discourse.org/t/banner-themes-and-instructions-for-customizing-them/82368).

---

<div class="post-metadata">

### Author: ![Mayzie](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Mayzie](https://meta.discourse.org/u/Mayzie)
#### Post date: [June 2, 2018, 5:29am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/80 "2018-06-02T05:29:11Z")

</div>

The [drone.io](http://drone.io) Discourse forum is shutting down due to GDPR.

[https://discourse.drone.io/t/shutting-down-forum-gdpr/2297](https://discourse.drone.io/t/shutting-down-forum-gdpr/2297)

---

<div class="post-metadata">

### Author: ![Amashino](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Amashino](https://meta.discourse.org/u/Amashino)
#### Post date: [June 2, 2018, 12:15pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/81 "2018-06-02T12:15:02Z")

</div>

I don’t think it’s a good measure to shutdown the forum because GDPR, in fact, moving to reddit does not solve the problem at all.

GDPR is here to stay, and we need to learn to be complaint. And the Discourse community is doing their best to prepare the platform. Just my view.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [June 2, 2018, 12:47pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/82 "2018-06-02T12:47:45Z")

</div>

Wouldn’t it be beneficial to everyone if the admin shared an anonimized version of the requests and perhaps we could help agree an appropriate response together? We could then understand the result and ultimately develop a standard response to such requests? This is going to be repeated on forum after forum and it’s best we don’t reinvent the wheel every time?

I would also like to understand if these requests are from an individual or an agency?

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [June 2, 2018, 4:51pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/83 "2018-06-02T16:51:15Z")

</div>

Wow, embedded in that thread are two incredibly useful and insightful articles.

One from LinkedIn, where a PwC consultant, presumably a lawyer, has kindly drafted a ‘worst case’ letter that you might receive so you can prepare how to respond in the ‘worst case’ (please _don’t_ send this to your forum admins, be nice 😉 ):

> **[The Nightmare Letter: A Subject Access Request under GDPR](https://www.linkedin.com/pulse/nightmare-letter-subject-access-request-under-gdpr-karbaliotis/)**
>
> Update August 14 2025: Well, nothing stands still, and in particular, this letter continues to have legs. It is still being used for instruction and translated for multiple languages.

(you will note the article has a lot of good feedback and a number of good samaritans have translated it into other languages including Dutch & Greek, links in the comments)

Also, here is someone’s proposed response:

> **[So Your Startup Received the Nightmare GDPR Letter · Jacques Mattheij](https://jacquesmattheij.com/so-your-start-up-receive-the-nightmare-gdpr-letter/)**

---

<div class="post-metadata">

### Author: ![awesomerobot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/awesomerobot/32/142900_2.png) [@awesomerobot](https://meta.discourse.org/u/awesomerobot)
#### Post date: [June 4, 2018, 8:36pm UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/84 "2018-06-04T20:36:42Z")

</div>

> [@Amashino](#):
>
> moving to reddit does not solve the problem at all.

It doesn’t solve the problem, but it does shift the problem to someone else. Unfortunately as that admin pointed out, it makes your privacy as a user _worse_ and of course and limits your agency as an admin (reddit can do anything they want with content you post on their site). In this case the admin was afraid of theoretical fines to the point where they thought the trade-off was worth it.

Seems a bit extreme because at this point there’s no indication that the GDPR can be used maliciously to fine someone acting in good-faith to the point of financial ruin… there’s just a lot of fear-mongering.

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [June 5, 2018, 8:19am UTC](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190/85 "2018-06-05T08:19:49Z")

</div>

> [@awesomerobot](#):
>
> Seems a bit extreme because at this point there’s no indication that the GDPR can be used maliciously to fine someone acting in good-faith to the point of financial ruin… there’s just a lot of fear-mongering.

Totally agree. And who was this troll? It’s very different if the EU’s legal department is calling you up or if it’s a layman who has a sketchy interpretation of the law.

I believe the admin should simply be more thick skinned, do what is reasonable and see how things go. Arguably, he doesn’t need any legal counsel unless he’s summoned to court. Would the troll really go so far? And even if it got to that stage, some legal eagle with a reputation to enhance is going to offer pro bono support because it will be a headline grabbing test case that will attract more business … that is if there is any case to answer!

[Previous page](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190.md?page=3)

[Next page](https://meta.discourse.org/t/gdpr-countdown-and-compliance/87190.md?page=5)
