Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: 1 [2]

Author Topic: Forum Terms of Service - GDPR notification  (Read 44943 times)

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 34100
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Forum Terms of Service - GDPR notification
« Reply #15 on: February 15, 2021, 06:19:54 PM »


-------------------------
Notice for transparency.
-------------------------




SMF update 2.0.16 released 27 Dec 2019 made significant changes to support GDPR compliance within the SMF Core.

Quote from: SMF
Notable changes in 2.0.16

    Support for privacy policy in addition to registration agreement
    GDPR Compliance toggle in Core Features
       Enabling this configures multiple settings and new features to comply with the GDPR, including:
        Requiring members to accept the current privacy policy in order to use the forum
        Asking during registration whether the new member wants to receive announcements via email
        Enabling token-based unsubscribe links in emails so members can unsubscribe without logging in
        Allowing members to download a copy of their profile information
        Adjusting the behaviour of a number of other features in minor ways as necessary
    PHP 7.2 support
    Improved security hashes for the image proxy
    Improved security for the login cookie
    Assorted other security improvements
    Various improvements for both the installer and upgrader

These changes made little GDPR differences to forums (such as kitz.co.uk) who have been GDPR compliant pre May 2018 content wise, but it did mean we had some problems being able to update because of the mod.

Someone kindly wrote a quick mod hack for SMF forums which enables admins to force users to accept the updated policy changes after I bought the topic up on SMF about GDPR.

In order to update to 2.0.17 I had to remove the GDPR helper modification.  Because I was one of those still having problems updating, I made some manual adjustments which mean GDPR helper data collected by the mod was also removed. 
Now that the latest version of SMF is GDPR compliant without this mod, I have no intention of re-installing GDPR helper, as it would force all users to re-read & agree to the privacy policy and registration form that have had no change to content.   

The only change for our members is that the forum privacy policy can now be viewed here
I only noticed the url change yesterday and will update the relevant post above with the new url - which is why Im making this post now.
The new merged page is (and has been) linked in the footer the bottom of each page under Terms and Policies since the update(s).


TLDR version;

  • SMF 2.0.16/2.0.17 updated Dec 2019
  • GDPR compliance included in the SMF Core code.
  • GDPR Helper modification uninstalled.
  • Forum Registration Agreement & Forum Privacy Policy merged into the one page - presumably to make it easier for new registrations.
  • Neither of these had content changed since May 2018.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 34100
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Forum Terms of Service - GDPR notification
« Reply #16 on: February 15, 2021, 06:28:58 PM »

Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5519
    • Thinkbroadband Quality Monitors
Re: Forum Terms of Service - GDPR notification
« Reply #17 on: February 15, 2021, 08:27:57 PM »

This sounds like a sensible approach.  The reason I ditched my own login facility on my sites is I honestly didn't want to have to deal with this problem as like you said, deleting user data would completely break the site.

Arguably I still might have to on my legacy sites if an old user requests it, although I don't think I logged IPs anyway.  My biggest gripe with GDPR is how unclear it is what is and is not considered personal data.  As my sites were compatibility lists for emulators, I always considered anything posted to the sites as then belonging to the site, but GDPR seemed to step on this assumption.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + GL.iNet GL-X3000
Network: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX WiFi: Zyxel NWA210AX + Ubiquity NanoHD
Broadband History & Ping Monitor
Pages: 1 [2]