# 利用者が利用規約に明示的に同意する方法

**URL:** https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480
**Category:** Support
**Tags:** gdpr
**Created:** [2018 年 3 月 21 日午後 2:14 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480 "2018-03-21T14:14:35Z")
**Posts on this page:** 1
**Showing post:** 60

<div class="post-metadata">

### Author: ![angus](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/angus/32/341715_2.png) [@angus](https://meta.discourse.org/u/angus)
#### Post date: [2018 年 4 月 29 日午前 12:19 UTC](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480/60 "2018-04-29T00:19:05Z")

</div>

You could use my [Custom Wizard plugin](https://meta.discourse.org/t/custom-wizard-plugin/73345) to obtain consent under the GDPR, and I would be happy to work through any issues for that use case, however unless you’re using Discourse data for something other than just running a Discourse forum, it seems (at this preliminary stage) the more suitable basis for processing and control of data in Discourse is ‘Legitimate Interests’ rather than consent.

If you’re looking for some plain language explanations from a trusted source on this question, I would recommend the UK’s [Information Commissioner’s Office](https://ico.org.uk/).

[Consent](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/)

In particular the ICO notes that consent needs to be granular, possible to withdraw and cannot be a precondition of service, each of which raises issues for the way you’re proposing to obtain consent in Discourse.

Moreover, they state:

> But you often won’t need consent. If consent is difficult, look for a different lawful basis.

[Legitimate Interests](https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/)

They note: (highlights are mine)

> - Legitimate interests is the most flexible lawful basis for processing, but you cannot assume it will always be the most appropriate.
> 
> - It is likely to be most appropriate where you **use people’s data in ways they would reasonably expect** and which have a minimal privacy impact, or where there is a compelling justification for the processing.

It seems to me that it would be reasonable to expect that when signing up for a discussion forum that the details you provide would be stored and processed for the purposes of running the forum.

See further:

> [@Providing data for GDPR](https://meta.discourse.org/t/providing-data-for-gdpr/83595/38):
>
> For anyone reading this topic, it’s important to keep in mind that we’re talking about a major law reform that is not yet in force, has not yet been applied in practice by any authority and not been tested in any court. It does build on previous laws, but it also introduces substantive changes. It is also important to keep in mind that regulators are not going to be focused on your (relatively speaking) small community when they have to deal with companies like Facebook. This is not to say that…

Please note that none of this is legal advice and cannot be relied on as such. I am not your lawyer.

---

_[View the full topic](https://meta.discourse.org/t/how-to-make-users-to-explicitly-agree-to-tos/83480)._
