# So lassen Sie Nutzer der AGB ausdrücklich zustimmen

**URL:** https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480
**Category:** Support
**Tags:** gdpr
**Created:** [21. März 2018 um 14:14 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480 "2018-03-21T14:14:35Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![McBlu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcblu/32/91128_2.png) [@McBlu](https://meta.discourse.org/u/McBlu)
#### Post date: [23. März 2018 um 19:55 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/41 "2018-03-23T19:55:42Z")

</div>

Nicely done, Michael. Sounds like we have a decent contingency of European forums in here for whom this use of the customized field is mandated. I might be an outlier for American forums in terms of wanting this feature. I actually prefer having my members click that they’ve reviewed the guidelines at sign up than having a banner pinned at the top of the forum.

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [23. März 2018 um 20:07 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/42 "2018-03-23T20:07:49Z")

</div>

> [@dnsmichi](#):
>
> That’s exactly what you need, I have implemented that now at [https://monitoring-portal.org](https://monitoring-portal.org)

My hunch is that your wording may not be sufficient:

> I’ve read the [FAQ](https://monitoring-portal.org/faq) and [ToS](https://monitoring-portal.org/tos).

People are only confirming that they have read those documents. There is not hint that they are _consenting_ to something by ticking that check-box, let alone that this “something” regards personal data…

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [23. März 2018 um 21:42 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/43 "2018-03-23T21:42:30Z")

</div>

> I agree to data processing necessary to operate the forum, as laid out in the ToS and Privacy Policy.

So I wrote that down, but isn’t that just laying out the “legitimate interests” allowance?

Of course, the Privacy Policy isn’t really all that accurate if the admins are downloading backups and performing queries on that, is it?

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [23. März 2018 um 22:38 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/44 "2018-03-23T22:38:53Z")

</div>

To complicate things further: let’s say user A accepted to have their data processed as laid out in your tos when they signed up. A few months or years later, you change your tos in such a way that user A would not accept them, i.e. would not sign up. Doesn’t this mean that in order to fulfil the requirement of being able to demonstrate that the user consented, it’s not sifficient to have a record of the ticked check-box but you need a copy of the tos as they were at the sine of sign-up, no?

To me, this suggests that all the necessary information should be next to the custom user field at sign up, it should be self-contained.

> [@riking](#):
>
> isn’t that just laying out the “legitimate interests” allowance?

I’m not sure what you mean here.

---

<div class="post-metadata">

### Author: ![JagWaugh](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagwaugh/32/69335_2.png) [@JagWaugh](https://meta.discourse.org/u/JagWaugh)
#### Post date: [24. März 2018 um 04:33 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/45 "2018-03-24T04:33:48Z")

</div>

> [@tophee](#):
>
> Doesn’t this mean that in order to fulfil the requirement of being able to demonstrate that the user consented, it’s not sifficient to have a record of the ticked check-box but you need a copy of the tos as they were at the sine of sign-up, no?

Similarly if you change the TOS?

Sites like ours which migrated from another platform may also need to make imported users go through the process of accepting the TOS.

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [24. März 2018 um 08:00 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/46 "2018-03-24T08:00:15Z")

</div>

I’m thinking that it might be a good idea to actually store your consent records (also) outside discourse, via a webhook. Who knows, depending on how the law will be interpreted and enforced, handling your consent records might become a third party service (hopefully with a good free contingent for forums)…

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [24. März 2018 um 09:26 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/47 "2018-03-24T09:26:46Z")

</div>

> [@tophee](#):
>
> a copy of the tos as they were at the sine of sign-up

Which is handled by the Discourse post history mechanism, if I am correct.

> [@tophee](#):
>
> A few months or years later, you change your tos in such a way that user A would not accept them, i.e. would not sign up

In such a case it would be sufficient if your ToS would have a clause that states that you will communicate all changes 30 days in advance, and put up a pinned post on your forum that states that continuing to use the forum implies an acceptance of the new ToS.

---

<div class="post-metadata">

### Author: ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### Post date: [24. März 2018 um 10:11 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/48 "2018-03-24T10:11:46Z")

</div>

> [@RGJ](#):
>
> In such a case it would be sufficient if your ToS would have a clause that states that you will communicate all changes 30 days in advance

Not needed, the onus is on the member  
[https://meta.discourse.org/tos#12](https://meta.discourse.org/tos#12)

> CDCK reserves the right, at its sole discretion, to modify or replace any part of this Agreement. It is your responsibility to check this Agreement periodically for changes. Your continued use of or access to the Website following the posting of any changes to this Agreement constitutes acceptance of those changes.

---

<div class="post-metadata">

### Author: ![Krzysztof\_Daniel](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/krzysztof_daniel/32/120191_2.png) [@Krzysztof\_Daniel](https://meta.discourse.org/u/Krzysztof_Daniel)
#### Post date: [24. März 2018 um 13:31 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/49 "2018-03-24T13:31:33Z")

</div>

> [@RGJ](#):
>
> In such a case it would be sufficient if your ToS would have a clause that states that you will communicate all changes 30 days in advance, and put up a pinned post on your forum that states that continuing to use the forum implies an acceptance of the new ToS.

This is not a legal advice.

It is a little bit more complicated and depends very much on the services, content and fees you are going to deliver. The bigger value you handle, and the bigger is your risk in the case of user misbehaviour, the more should you invest in user verification and the more proofs you should have that the user agreed to what he agreed.

In case of a free forum such things rarely matter, but imagine a situation where there is a significant fee introduced with a ToS change. In EU, you cannot do that without getting an explicit consent from the customer (checkbox/button).

I have started this discussion to investigate what should I do with my setup, and it looks like I will have to implement TOS and privacy policy agreements in the SSO tool (Auth0).

---

<div class="post-metadata">

### Author: ![dnsmichi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dnsmichi/32/379505_2.png) [@dnsmichi](https://meta.discourse.org/u/dnsmichi)
#### Post date: [24. März 2018 um 13:40 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/50 "2018-03-24T13:40:19Z")

</div>

> [@tophee](#):
>
> People are only confirming that they have read those documents. There is not hint that they are consenting to something by ticking that check-box, let alone that this “something” regards personal data…

You’re correct, thanks. I’m not sure what’s the perfect wording to not annoy users when they register. But still to make them aware that actually clicking the URLs and reading them is important.

Actually, it would need 2 fields - one for accepting the ToS, and the second to have read and understood the FAQ/guidelines. I’ve heavily modified the FAQ as the platform is more like QA and users tend to not know what to collect when asking a question. Similar thing with GitHub and issue templates, e.g. provide the OS, configs, logs and where to look for “troubleshoot on your own”.

I’ve asked our community what they do think, might need til next week for feedback. Weekend is where not many look into monitoring questions in their spare time and there’s expected low traffic.

> [@McBlu](#):
>
> I actually prefer having my members click that they’ve reviewed the guidelines at sign up than having a banner pinned at the top of the forum.

If you scroll down on [https://monitoring-portal.org](https://monitoring-portal.org), you’ll recognise the footer. I’ve added this as German law requires your to have an URL to your legal notice (“impressum” in German) on every single page. This lists personal details such as name and address where the owner can be contacted. I haven’t had that in Austria, but Germany is more special on that.

It is far from perfect and not very “fancy”, but it works for me to be on the safe legal side. Germany is known for legal notice trolls because of that law requirement.

---

<div class="post-metadata">

### Author: ![McBlu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcblu/32/91128_2.png) [@McBlu](https://meta.discourse.org/u/McBlu)
#### Post date: [24. März 2018 um 15:08 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/51 "2018-03-24T15:08:00Z")

</div>

> [@dnsmichi](#):
>
> If you scroll down on [https://monitoring-portal.org](https://monitoring-portal.org) , you’ll recognise the footer. I’ve added this as German law requires your to have an URL to your legal notice (“impressum” in German) on every single page. This lists personal details such as name and address where the owner can be contacted. I haven’t had that in Austria, but Germany is more special on that.

I did that too - have links in the footer - using the Flex Footer Theme Component.

 ![26%20AM](https://global.discourse-cdn.com/meta/original/3X/b/4/b4538fef55800834d243ef1dd61714d249cfae36.png)

I am not required to show a url so just linked words instead.

I don’t include ‘about us’ because we aren’t required to in the US, but once we launch that could change depending on what people find useful.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [24. März 2018 um 17:37 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/52 "2018-03-24T17:37:56Z")

</div>

> [@Mittineague](#):
>
> Not needed, the onus is on the member
> 
> [Terms of Service - Discourse Meta](https://meta.discourse.org/tos#12)
> 
> CDCK reserves the right, at its sole discretion, to modify or replace any part of this Agreement. It is your responsibility to check this Agreement periodically for changes.

This definitely will not hold up in court in Europe, and our legal guy says he thinks it’s not accepted in the USA either - after he stopped laughing.

You have to **actively** inform your users of such a change.

---

<div class="post-metadata">

### Author: ![McBlu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcblu/32/91128_2.png) [@McBlu](https://meta.discourse.org/u/McBlu)
#### Post date: [25. März 2018 um 02:50 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/53 "2018-03-25T02:50:26Z")

</div>

Usually when fees go up I have been required to click to accept fee increases like with Netflix for example. I got email notices before that. Click to accept changes in tos at sign in would be smart. Along with notices to members prior to that.

---

<div class="post-metadata">

### Author: ![hlcfan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hlcfan/32/64357_2.png) [@hlcfan](https://meta.discourse.org/u/hlcfan)
#### Post date: [28. März 2018 um 06:10 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/54 "2018-03-28T06:10:41Z")

</div>

I’m thinking another case with SSO. User A logged in Discourse, some day user A revokes consent from, say passport (if we have a passport site, i.e. [passport.example.org](http://passport.example.org)), how would we handle it?

I can think of a way to handle this, to add a javascript to check with passport site whether current user consented, if not, then ask user to consent, either redirect to passport site or show a modal in Discourse.

---

<div class="post-metadata">

### Author: ![tm2017](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@tm2017](https://meta.discourse.org/u/tm2017)
#### Post date: [26. April 2018 um 13:50 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/55 "2018-04-26T13:50:32Z")

</div>

Discourse currently has ability to “Deactivate account” via Admin panel. I am wondering if we could use it to implement “Voluntary consent” required by GDPR for existing users.  
Something like mass deactivation with custom activation email text explaining why existing users need to give consent by clicking link in activation email.  
And to be legal this has to be done before May 25.

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [26. April 2018 um 18:22 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/56 "2018-04-26T18:22:20Z")

</div>

No, “activation” is only “prove you own this email” and unactivated accounts (with no posts, because of admins doing this kind of thing) are deleted after 7 days.

---

<div class="post-metadata">

### Author: ![tm2017](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@tm2017](https://meta.discourse.org/u/tm2017)
#### Post date: [26. April 2018 um 21:33 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/57 "2018-04-26T21:33:54Z")

</div>

Yes I know that, but I was just thinking about easy method to do what original poster asked about, i.e. make existing users to give _explicit voluntary consent_ to process their data via _clear affirmative action_. Under GDPR you need to collect such consent from _existing_ users and be able to demonstrate they gave it actively and **when** they gave it. I just thought that existing functionality could be used to collect that.

While it is easy to ask **new users** for consent at the **sign up** time by adding user field in the admin panel and making it required, Discourse has no functionality to collect required GDPR consent from **existing users** (except maybe asking everyone individually). As May 25 deadline approaches every working method (even if not perfect) would be good.

---

<div class="post-metadata">

### Author: ![ChrisBeach](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chrisbeach/32/214628_2.png) [@ChrisBeach](https://meta.discourse.org/u/ChrisBeach)
#### Post date: [26. April 2018 um 22:30 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/58 "2018-04-26T22:30:03Z")

</div>

This plugin may be helpful:

> [@Custom Wizard Plugin mage](https://meta.discourse.org/t/custom-wizard-plugin/73345):
>
> pavilionSummary Forms for Discourse. This plugin lets you make rich and powerful forms for your Discourse forum. Better user onboarding, structured posting, data enrichment, automated actions and much more for your community.hammer_and_wrenchRepository Link [https://github.com/paviliondev/discourse-custom-wizard](https://github.com/paviliondev/discourse-custom-wizard)open_bookInstall Guide [How to install plugins in Discourse](https://meta.discourse.org/t/install-plugins-in-discourse/19157)people_huggingCommunity Community based support and discussions about this plugin are hosted on th…

> [@Custom Wizard Plugin mage](https://meta.discourse.org/t/custom-wizard-plugin/73345/1):
>
> You can automatically redirect users to wizards:
> 
> …
> 
> - After a certain time (e.g. when you update terms and conditions). When the specified time is reached all users (including those currently logged in / active) will be redirected to the wizard.

It’d be useful to know if anyone has used it for GDPR purposes, and if they could share their wording and config?

---

<div class="post-metadata">

### Author: ![tm2017](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@tm2017](https://meta.discourse.org/u/tm2017)
#### Post date: [27. April 2018 um 08:52 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/59 "2018-04-27T08:52:24Z")

</div>

One important thing that is missing in requesting GDPR consent as “user field” is that changing user fields does **not** generate any entry in Users “Action logs”. Under GDPR it is important to be able to demonstrate **when** consent was given. For this Discourse should log such event in the user’s “Action log”.

It would be highly appreciated if Discourse team could tell us if Action logs can be improved to include user field change event.

---

<div class="post-metadata">

### Author: ![angus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/angus/32/341715_2.png) [@angus](https://meta.discourse.org/u/angus)
#### Post date: [29. April 2018 um 00:19 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/60 "2018-04-29T00:19:05Z")

</div>

You could use my [Custom Wizard plugin](https://meta.discourse.org/t/custom-wizard-plugin/73345) to obtain consent under the GDPR, and I would be happy to work through any issues for that use case, however unless you’re using Discourse data for something other than just running a Discourse forum, it seems (at this preliminary stage) the more suitable basis for processing and control of data in Discourse is ‘Legitimate Interests’ rather than consent.

If you’re looking for some plain language explanations from a trusted source on this question, I would recommend the UK’s [Information Commissioner’s Office](https://ico.org.uk/).

[Consent](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/)

In particular the ICO notes that consent needs to be granular, possible to withdraw and cannot be a precondition of service, each of which raises issues for the way you’re proposing to obtain consent in Discourse.

Moreover, they state:

> But you often won’t need consent. If consent is difficult, look for a different lawful basis.

[Legitimate Interests](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/)

They note: (highlights are mine)

> - Legitimate interests is the most flexible lawful basis for processing, but you cannot assume it will always be the most appropriate.
> 
> - It is likely to be most appropriate where you **use people’s data in ways they would reasonably expect** and which have a minimal privacy impact, or where there is a compelling justification for the processing.

It seems to me that it would be reasonable to expect that when signing up for a discussion forum that the details you provide would be stored and processed for the purposes of running the forum.

See further:

> [@Providing data for GDPR](https://meta.discourse.org/t/providing-data-for-gdpr/83595/38):
>
> For anyone reading this topic, it’s important to keep in mind that we’re talking about a major law reform that is not yet in force, has not yet been applied in practice by any authority and not been tested in any court. It does build on previous laws, but it also introduces substantive changes. It is also important to keep in mind that regulators are not going to be focused on your (relatively speaking) small community when they have to deal with companies like Facebook. This is not to say that…

Please note that none of this is legal advice and cannot be relied on as such. I am not your lawyer.

[Vorherige Seite](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480.md?page=2)

[Nächste Seite](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480.md?page=4)
