# Vragen over gebruikersanonimisering en GDPR

**URL:** https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200
**Category:** Support
**Tags:** anonymization
**Created:** [13 maart 2024 om 17:02 UTC](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200 "2024-03-13T17:02:52Z")
**Posts on this page:** 3
**Page:** 2

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [15 maart 2024 om 18:59 UTC](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200/22 "2024-03-15T18:59:37Z")

</div>

There is an exception to the “right to be forgotten”, which is stated in [GDPR article 17.3](https://gdpr-info.eu/art-17-gdpr/)

> Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
> 
> - for exercising the right of freedom of expression and information;

[Recital 65](https://gdpr-info.eu/recitals/no-65/) #5

> However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information

(which implies that the retention of personal data is lawful, even when the data subject has withdrawn his or her consent)

and this can be used for forum owners to retain the actual forum posts.

(source: Dutch internet laywer Arnoud Engelfriet, see [article](https://blog.iusmentis.com/2018/04/03/geldt-het-vergeetrecht-onder-de-avg-ook-bij-forumdiscussies/) in Dutch)

Obviously, it would be good if the forum owner would be helpful and redacted any kind of obvious personal information that a user does not want to share anymore. But that’s common sense.

---

<div class="post-metadata">

### Author: ![anon36555649](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@anon36555649](https://meta.discourse.org/u/anon36555649)
#### Post date: [16 maart 2024 om 16:04 UTC](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200/23 "2024-03-16T16:04:56Z")

</div>

> [@RGJ](#):
>
> [Recital 65](https://gdpr-info.eu/recitals/no-65/) #5
> 
> > However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information
> 
> (which implies that the retention of personal data is lawful, even when the data subject has withdrawn his or her consent)
> 
> and this can be used for forum owners to retain the actual forum posts.

That is helpful, thanks for posting that.

Seems the “right to be forgotten” would be lost anytime someone is banned from a site, if their I.P./e-mail are permanently banned then those must be kept in the database to maintain that.

Some other platforms put a hold on account deletion for a couple weeks or so before it is made final, suppose that could be done with discourse manually if someone requests anonymization don’t know if that must be completed within a certain number of days or something?

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [15 april 2024 om 16:05 UTC](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200/24 "2024-04-15T16:05:28Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Vorige pagina](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200.md?page=1)
