<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://docs.sandbox.joomla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alphapi</id>
	<title>Joomla! Documentation - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://docs.sandbox.joomla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alphapi"/>
	<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/Special:Contributions/Alphapi"/>
	<updated>2026-05-14T21:39:15Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.0</generator>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=780460</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=780460"/>
		<updated>2021-01-27T17:18:48Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: Add of Article 7 on the 1. Consent to the use of personal data functionalities section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;&amp;lt;languages /&amp;gt;&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:1--&amp;gt; Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection&amp;lt;/translate&amp;gt; &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:2--&amp;gt; This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy.&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:3--&amp;gt; &#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:4--&amp;gt; This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as much as possible.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:5--&amp;gt; &#039;&#039;&#039;Important notice&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:6--&amp;gt; You should not solely rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation.&amp;lt;/translate&amp;gt; &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:7--&amp;gt; &#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|&amp;lt;translate&amp;gt;&amp;lt;!--T:8--&amp;gt; Groups&amp;lt;/translate&amp;gt;&lt;br /&gt;
!width=60%|&amp;lt;translate&amp;gt;&amp;lt;!--T:9--&amp;gt; Personal data processing profile&amp;lt;/translate&amp;gt;&lt;br /&gt;
!width=20%|&amp;lt;translate&amp;gt;&amp;lt;!--T:10--&amp;gt; Related questions&amp;lt;/translate&amp;gt; &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:11--&amp;gt; Group A&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:12--&amp;gt; The extension isn&#039;t expected to process or store any personal data&amp;lt;/translate&amp;gt;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:13--&amp;gt; 7 and 8&amp;lt;/translate&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:14--&amp;gt; Group B&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:15--&amp;gt; The extension is expected to process or store data that can be used to indirectly associate the identity of a person&amp;lt;/translate&amp;gt;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:16--&amp;gt; 1 to 8&amp;lt;/translate&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:17--&amp;gt; Group C&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:18--&amp;gt; The extension is expected to process or store personal data that can be used to directly associate the identity of a person&amp;lt;/translate&amp;gt;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:19--&amp;gt; 1 to 8&amp;lt;/translate&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:20--&amp;gt; Group D&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:21--&amp;gt; The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to&amp;lt;/translate&amp;gt; &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:22--&amp;gt;&lt;br /&gt;
*race and ethnic origin data, &lt;br /&gt;
*religious data, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&amp;lt;/translate&amp;gt;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:23--&amp;gt; 1 to 8&amp;lt;/translate&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:24--&amp;gt; Group E&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:25--&amp;gt; The extension is expected to share personal data with at least one third party service&amp;lt;/translate&amp;gt;&lt;br /&gt;
| &amp;lt;translate&amp;gt;&amp;lt;!--T:26--&amp;gt; 1 to 8&amp;lt;/translate&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &amp;lt;!--T:27--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:28--&amp;gt; Group affected: B, C, D, E&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:29--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2001-1-1 Article 7], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:30--&amp;gt; #&#039;&#039;&#039;Is there any functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:31--&amp;gt; ##A consent collection and logging system already exists.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:32--&amp;gt; ##Such a system partially exists (for example there is a consent checkbox but does not store logs)&amp;lt;/translate&amp;gt; &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:33--&amp;gt; ##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to inform users regarding the privacy policy (upfront the collection of any personal data) and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:34--&amp;gt; #&#039;&#039;&#039;Is there a functionality to allow users to withdraw their consent?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:35--&amp;gt; ##A functionality provides to users the ability to withdraw consent.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:36--&amp;gt; ##There is no functionality to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:37--&amp;gt; #&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:38--&amp;gt; ##Yes, it is connected to the Joomla core Privacy Component.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:39--&amp;gt; ##The consent functionality is based on a custom mechanism.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:40--&amp;gt; ##No, it is not. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will facilitate for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&amp;lt;/translate&amp;gt; &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:41--&amp;gt; #&#039;&#039;&#039;Does your extension allow the generation of additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:42--&amp;gt; ##Yes, there is such functionality that can be used to generate additional consent mechanisms.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:43--&amp;gt; ##Yes, there is such functionality but with limited options (i.e. you can only add one more).&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:44--&amp;gt; ##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &amp;lt;!--T:45--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:46--&amp;gt; *&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:47--&amp;gt; #&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:48--&amp;gt; ##Yes there is such functionality.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:49--&amp;gt; ##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:50--&amp;gt; ##No, there is no such functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:51--&amp;gt; #If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw their consent?&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:52--&amp;gt; ##Yes, there is such functionality&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:53--&amp;gt; ##No, there is no functionality for that, but there is an informational notice for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
== 3. Right to Data Portability == &amp;lt;!--T:54--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:55--&amp;gt; *&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:56--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20]&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:57--&amp;gt; #&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:58--&amp;gt; ##Yes, there is such functionality.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:59--&amp;gt; ##Yes, but partially.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:60--&amp;gt; ##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to the Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:61--&amp;gt; #Is the file that is downloaded in a machine readable format (for example XML, CSV)?&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:62--&amp;gt; ##Yes, it is.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:63--&amp;gt; ## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
== 4. Right of Access by the data subject == &amp;lt;!--T:64--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:65--&amp;gt; *&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:66--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:67--&amp;gt; #&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:68--&amp;gt; ##Yes, it provides.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:69--&amp;gt; ##Yes, there is but partially.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:70--&amp;gt; ##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039;&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
==5. Right to be Forgotten == &amp;lt;!--T:71--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:72--&amp;gt; *&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:73--&amp;gt; * Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:74--&amp;gt; #&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:75--&amp;gt; ##There is.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:76--&amp;gt; ##There is, but partially.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:77--&amp;gt; ##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users to submit deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:78--&amp;gt; #&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code to successfully delete all the previous collected users’ data once the Super User decides to uninstall it?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:79--&amp;gt; ##Yes, this operation is included.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:80--&amp;gt; ##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
==6. Privacy by Default== &amp;lt;!--T:81--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:82--&amp;gt; *&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:83--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:84--&amp;gt; #&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:85--&amp;gt; ##Yes, the default settings are in the most private.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:86--&amp;gt; ##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:87--&amp;gt; #&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:88--&amp;gt; ##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:89--&amp;gt; ##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
==7. Security Measures== &amp;lt;!--T:90--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:91--&amp;gt; *&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:92--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:93--&amp;gt; #&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:94--&amp;gt; ##Yes, all the requests are under HTTPS (TLS).&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:95--&amp;gt; ##Some of the resources transmit information insecurely.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:96--&amp;gt; ##All the resources transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s, you can run a test to ensure the security of the certificate used and configuration of this server. There are many tools and services to help you on that, for example you can use [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039;&amp;lt;/translate&amp;gt; &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:97--&amp;gt; #&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:98--&amp;gt; ##Yes, data can be stored encrypted.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:99--&amp;gt; ##Only part of the data can be stored encrypted.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:100--&amp;gt; ##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;To empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt; &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:101--&amp;gt; #&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:102--&amp;gt; ##Yes, data can be anonymized.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:103--&amp;gt; ##Some of the data can be partially anonymized.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:104--&amp;gt; ##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You can use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&amp;lt;/translate&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors== &amp;lt;!--T:105--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:106--&amp;gt; *&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:107--&amp;gt; *Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:108--&amp;gt; #&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:109--&amp;gt; ##Yes, there is a list of all third parties.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:110--&amp;gt; ##No, there is no list of third parties or the list is not full.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:111--&amp;gt; #&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension for the Webmasters that will use it to find it easy to sign them? Even if the third party does not collect any personal data, an agreement for that should exist.&#039;&#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:112--&amp;gt; ##Yes, with all the third parties.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:113--&amp;gt; ##Yes, with some of the third parties.&amp;lt;/translate&amp;gt;&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:114--&amp;gt; ##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&lt;br /&gt;
==Further reading== &amp;lt;!--T:115--&amp;gt;&lt;br /&gt;
&amp;lt;/translate&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:116--&amp;gt; *[[S:MyLanguage/Secure_coding_guidelines|Secure coding guidelines], Joomla Documentation&amp;lt;/translate&amp;gt;  &lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:117--&amp;gt; Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at:&amp;lt;/translate&amp;gt; https://git.io/fjww3  &lt;br /&gt;
&amp;lt;translate&amp;gt;&amp;lt;!--T:118--&amp;gt; *Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&amp;lt;/translate&amp;gt;&lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:119--&amp;gt; Open Source Privacy Standards, by Heather Burns (webdevlaw):&amp;lt;/translate&amp;gt; https://git.io/fjwwG &lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:120--&amp;gt; Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series:&amp;lt;/translate&amp;gt; https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:121--&amp;gt; Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures:&amp;lt;/translate&amp;gt; https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:122--&amp;gt; Koho R., Privacy by default and GDPR, examples and best practises:&amp;lt;/translate&amp;gt; https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:123--&amp;gt; GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG:&amp;lt;/translate&amp;gt; https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;&amp;lt;translate&amp;gt;&amp;lt;!--T:124--&amp;gt; Contributors&amp;lt;/translate&amp;gt;&#039;&#039;&#039;&lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:125--&amp;gt; Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&amp;lt;/translate&amp;gt;&lt;br /&gt;
*&amp;lt;translate&amp;gt;&amp;lt;!--T:126--&amp;gt; Contributors&amp;lt;/translate&amp;gt;: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
[[Category:Joomla! 3.9{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=JDOC:Documentation_Translators&amp;diff=634837</id>
		<title>JDOC:Documentation Translators</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=JDOC:Documentation_Translators&amp;diff=634837"/>
		<updated>2019-10-16T10:58:51Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: /* el - Ελληνικά - Greek */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:JDOC translation icon.png|right]]&lt;br /&gt;
Here, people &#039;&#039;&#039;translating&#039;&#039;&#039; {{SITENAME}} can sign up as a translator. Please be sure to read the required reading list below. &lt;br /&gt;
&lt;br /&gt;
After you add your username to the list below under the appropriate language heading, a [[JDOC:Translation Administrators|Translation Administrator]] will assign your username translator permissions. After your username is added as a translator you can start translating! Please be on the look out for a [[Template:Translator welcome|welcome message]] with more information posted to your user talk page.{{-}}&lt;br /&gt;
&lt;br /&gt;
==Required Reading==&lt;br /&gt;
* Getting started, read [[JDOC:Page Translation Quickstart Guide|Page Translation Quickstart Guide]]&lt;br /&gt;
* Detailed explanation of translating, [[JDOC:Page Translation Explained|Page Translation Explained]].&lt;br /&gt;
* Our [[JDOC:Language policy|Language policy]]&lt;br /&gt;
* [[JDOC:Translator Tips|Translator Tips]]&lt;br /&gt;
* [[Joomla:JDOC%27s_Translation_Guidelines|Translation Guidelines]]&lt;br /&gt;
* Having an [[JDOC:Translation Questions|issue or need help]]?&lt;br /&gt;
&lt;br /&gt;
{{tip|text=Dear translators! Please [[Special:TranslatorSignup|register for translator notifications about your language]]. You are placed on a list to receive notices about new/updated pages that need translation.|title=A Tip for Translators}}&lt;br /&gt;
&lt;br /&gt;
===Add Your Language===&lt;br /&gt;
If your language isn&#039;t listed below, please add it using the format:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;&amp;lt;lang code&amp;gt; -  Localised language name - English language name &amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Use the syntax, &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;* {{User|YourUsername}}&amp;lt;/nowiki&amp;gt; - requested&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When a Translation Administrator adds you as a translator, they will remove the &amp;quot;- requested&amp;quot; from your username.&lt;br /&gt;
&lt;br /&gt;
==Current Translations Teams==&lt;br /&gt;
&lt;br /&gt;
Documentation language codes are different from Joomla! language codes, they are ISO 639-1 2 letter code. A small quantity of 4 letter language codes are used as an exception, but these language codes are all lowercase.&lt;br /&gt;
&lt;br /&gt;
=== ar - عربي - arabe ===&lt;br /&gt;
* {{User|ghilo}}&lt;br /&gt;
* {{User|HawraMilani}}&lt;br /&gt;
* {{User|hossen}}&lt;br /&gt;
* {{User|ahmadm42}}&lt;br /&gt;
&lt;br /&gt;
=== af - Afrikaans ===&lt;br /&gt;
*{{User|JoeSA}}&lt;br /&gt;
&lt;br /&gt;
=== be - Беларуская - Belarusian ===&lt;br /&gt;
* {{User|Nikolice}}&lt;br /&gt;
&lt;br /&gt;
=== bg - Български - Bulgarian ===&lt;br /&gt;
* {{User|bdimov}}&lt;br /&gt;
* {{User|Mastwd}}&lt;br /&gt;
&lt;br /&gt;
=== bn - বাংলা - Bengali ===&lt;br /&gt;
* {{User|ashiks}}&lt;br /&gt;
* {{User|smsnobin77}}&lt;br /&gt;
&lt;br /&gt;
=== ca - Català - Catalan === &lt;br /&gt;
* {{User|el_libre}}&lt;br /&gt;
&lt;br /&gt;
=== cs - Čeština - Czech ===&lt;br /&gt;
* {{User|fredericco-cz}}&lt;br /&gt;
* {{User|Bart}}&lt;br /&gt;
* {{User|n3tcz}}&lt;br /&gt;
* {{User|svatas}}&lt;br /&gt;
&lt;br /&gt;
=== da - Dansk - Danish ===&lt;br /&gt;
* {{User|ot2sen}}&lt;br /&gt;
* {{User|rbuelund}}&lt;br /&gt;
&lt;br /&gt;
=== de - Deutsch - German ===&lt;br /&gt;
* {{User|Astridx}}&lt;br /&gt;
* {{User|Assmann}}&lt;br /&gt;
* {{User|Alexander-metzler}}&lt;br /&gt;
* {{User|Balzercomp}}&lt;br /&gt;
* {{User|Batmin}}&lt;br /&gt;
* {{User|bbkSecond}}&lt;br /&gt;
* {{User|ceus1984}}&lt;br /&gt;
* {{User|Chmst}}&lt;br /&gt;
* {{User|chrishoefliger}}&lt;br /&gt;
* {{User|Dimkk}}&lt;br /&gt;
* {{User|FancyFranci}}&lt;br /&gt;
* {{User|Farrell}}&lt;br /&gt;
* {{User|Florian}}&lt;br /&gt;
* {{User|FLin1}}&lt;br /&gt;
* {{User|FrankyD}}&lt;br /&gt;
* {{User|Franz.wohlkoenig}}&lt;br /&gt;
* {{User|fruppel}}&lt;br /&gt;
* {{User|goethe}}&lt;br /&gt;
* {{User|gorgonz}}&lt;br /&gt;
* {{User|Hleithner}}&lt;br /&gt;
* {{User|jehacgn}}&lt;br /&gt;
* {{User|JDocDummy}}&lt;br /&gt;
* {{User|joomla-agency}}&lt;br /&gt;
* {{User|Joomti}}&lt;br /&gt;
* {{User|Ka3media}}&lt;br /&gt;
* {{User|King_Louis_1}}&lt;br /&gt;
* {{User|Knig.Markus}}&lt;br /&gt;
* {{User|Kolvar}}&lt;br /&gt;
* {{User|Kurztipp}}&lt;br /&gt;
* {{User|LadySolveig}}&lt;br /&gt;
* {{User|m-b-o}}&lt;br /&gt;
* {{User|Maggus}}&lt;br /&gt;
* {{User|Max123kl}}&lt;br /&gt;
* {{User|michaelmyk}}&lt;br /&gt;
* {{User|Nathan.k}}&lt;br /&gt;
* {{User|oliverhh}}&lt;br /&gt;
* {{User|Paterna}}&lt;br /&gt;
* {{User|Pc-doppler}}&lt;br /&gt;
* {{User|Pete71}}&lt;br /&gt;
* {{User|phillopp}}&lt;br /&gt;
* {{User|plocher}}&lt;br /&gt;
* {{User|Prof.Logout}}&lt;br /&gt;
* {{User|quiltgabi}}&lt;br /&gt;
* {{User|RMajewski}}&lt;br /&gt;
* {{User|Schmidie64}}&lt;br /&gt;
* {{User|SeigetsuShoen}}&lt;br /&gt;
* {{User|Sieger66}}&lt;br /&gt;
* {{User|Sisko1990}}&lt;br /&gt;
* {{User|Spannama}}&lt;br /&gt;
* {{User|Stefanie}}&lt;br /&gt;
* {{User|tfecha}}&lt;br /&gt;
* {{User|Tkahl}}&lt;br /&gt;
* {{User|UCFnet002}}&lt;br /&gt;
* {{User|Usimon}}&lt;br /&gt;
* {{User|Webberry}}&lt;br /&gt;
* {{User|Yvesh}}&lt;br /&gt;
* {{User|zero24}}&lt;br /&gt;
* {{User|Xadomir}}&lt;br /&gt;
* {{User|waldiwhz}}&lt;br /&gt;
* {{User|Widmann}}&lt;br /&gt;
* {{User|Zeroweb1}}&lt;br /&gt;
* {{User|Zeroweb2}}&lt;br /&gt;
&lt;br /&gt;
=== el - Ελληνικά - Greek ===&lt;br /&gt;
* {{User|Aris_Ntatsis}}&lt;br /&gt;
* {{User|pnkr}}&lt;br /&gt;
* {{User|SiteworksGr}}&lt;br /&gt;
* {{User|Tonia_Chan}}&lt;br /&gt;
* {{User|Alphapi}}&lt;br /&gt;
&lt;br /&gt;
=== es - Español - Spanish ===&lt;br /&gt;
* {{User|Abulafia}}&lt;br /&gt;
* {{User|Andrea Gentil}}&lt;br /&gt;
* {{user|Antoniofmunoz}}&lt;br /&gt;
* {{User|BNovoa.S}}&lt;br /&gt;
* {{User|brucevalle}}&lt;br /&gt;
* {{User|carcam}}&lt;br /&gt;
* {{User|cristobal.vio}}&lt;br /&gt;
* {{User|Crsanchez}}&lt;br /&gt;
* {{User|danielperaza}}&lt;br /&gt;
* {{User|duoduo}}&lt;br /&gt;
* {{User|filisfutsarov}}&lt;br /&gt;
* {{User|framon}}&lt;br /&gt;
* {{User|Irene.lopez}}&lt;br /&gt;
* {{User|isidrobaq}}&lt;br /&gt;
* {{User|ivanramosnet}}&lt;br /&gt;
* {{User|Javiparati}}&lt;br /&gt;
* {{User|Jcollver}}&lt;br /&gt;
* {{User|Jolfig}}&lt;br /&gt;
* {{User|Koa}}&lt;br /&gt;
* {{User|Leo_Soto}}&lt;br /&gt;
* {{User|netandsoftware}}&lt;br /&gt;
* {{User|pdavila2709}}&lt;br /&gt;
* {{User|NunoLopes}}&lt;br /&gt;
* {{User|pfvidal}}&lt;br /&gt;
* {{User|shaz}}&lt;br /&gt;
* {{User|Urielmx}}&lt;br /&gt;
* {{User|VictorYork87}}&lt;br /&gt;
* {{User|viena}}&lt;br /&gt;
* {{User|Willin}}&lt;br /&gt;
&lt;br /&gt;
=== et - Eesti - Estonian ===&lt;br /&gt;
* {{User|Eraser}}&lt;br /&gt;
&lt;br /&gt;
=== fa - فارسی - Persian ===&lt;br /&gt;
* {{User|azolfagharj}}&lt;br /&gt;
* {{User|Grand}}&lt;br /&gt;
* {{User|Heydari}}&lt;br /&gt;
* {{User|Joomlafarsi}}&lt;br /&gt;
* {{User|Levelup}}&lt;br /&gt;
* {{User|mhehm}}&lt;br /&gt;
&lt;br /&gt;
=== fr - Français - French ===&lt;br /&gt;
* {{User|david613}}&lt;br /&gt;
* {{User|edelouche}}&lt;br /&gt;
* {{User|Erix}}&lt;br /&gt;
* {{User|Garstud}}&lt;br /&gt;
* {{User|Lorangerart}}&lt;br /&gt;
* {{User|MaximeK7}}&lt;br /&gt;
* {{User|Opware2000}}&lt;br /&gt;
* {{User|Perete}}&lt;br /&gt;
* {{User|Remi1945}}&lt;br /&gt;
* {{User|Sandra97}}&lt;br /&gt;
* {{User|Shim-sao}}&lt;br /&gt;
* {{User|Twister65}}&lt;br /&gt;
* {{User|alatak}}&lt;br /&gt;
&lt;br /&gt;
=== ga - Gaeilge - Irish ===&lt;br /&gt;
* {{User|rvbgnu}}&lt;br /&gt;
&lt;br /&gt;
=== he - עברית - Hebrew ===&lt;br /&gt;
* {{User|ydl}}&lt;br /&gt;
* {{User|shirdesign}}&lt;br /&gt;
&lt;br /&gt;
=== hi - हिंदी - Hindi ===&lt;br /&gt;
* {{User|AlamM}}&lt;br /&gt;
* {{User|Rana}}&lt;br /&gt;
* {{User|Syhussaini}}&lt;br /&gt;
* {{User|Shivamrajput}}&lt;br /&gt;
* {{User|ankitify}}&lt;br /&gt;
&lt;br /&gt;
=== hr - Hrvatski - Croatian ===&lt;br /&gt;
* {{User|limoo}}&lt;br /&gt;
&lt;br /&gt;
=== hu - Magyar - Hungarian ===&lt;br /&gt;
* {{User|Balazs}}&lt;br /&gt;
* {{User|webgobe}}&lt;br /&gt;
&lt;br /&gt;
=== hy - Հայերեն - Armenian ===&lt;br /&gt;
* {{User|Aaleksanyants}}&lt;br /&gt;
&lt;br /&gt;
=== id - Bahasa Indonesia - Indonesian ===&lt;br /&gt;
* {{User|dw1Rianto}}&lt;br /&gt;
* {{User|Micokelana}}&lt;br /&gt;
* {{User|sikumbang}}&lt;br /&gt;
&lt;br /&gt;
=== it - Italiano - Italian ===&lt;br /&gt;
* {{User|alexred}}&lt;br /&gt;
* {{User|aleorco}}&lt;br /&gt;
* {{User|alikon}}&lt;br /&gt;
* {{User|Andreacarriero}}&lt;br /&gt;
* {{User|CinziaDesign}}&lt;br /&gt;
* {{User|donato}}&lt;br /&gt;
* {{User|ino}}&lt;br /&gt;
* {{User|Ladyj}}&lt;br /&gt;
* {{User|Luca.marzo}}&lt;br /&gt;
* {{User|marioluciani}}&lt;br /&gt;
* {{User|moqui}}&lt;br /&gt;
* {{User|nemo_bis}} (occasionally)&lt;br /&gt;
* {{User|Paolo Alberti}}&lt;br /&gt;
* {{User|Fabio Caracciolo}}&lt;br /&gt;
* {{User|robertolongo}}&lt;br /&gt;
* {{User|ste}}&lt;br /&gt;
* {{User|Ing Pulizzi}}&lt;br /&gt;
&lt;br /&gt;
=== ja - 日本語 - Japanese ===&lt;br /&gt;
* {{User|Koji Hijikuro}}&lt;br /&gt;
* {{User|Nori}}&lt;br /&gt;
* {{User|Richell}}&lt;br /&gt;
* {{User|Yama}}&lt;br /&gt;
* {{User|Yui}}&lt;br /&gt;
&lt;br /&gt;
=== nl - Nederlands - Dutch ===&lt;br /&gt;
* {{User|AboutTime}}&lt;br /&gt;
* {{User|Alex0703}}&lt;br /&gt;
* {{User|Annemiek}}&lt;br /&gt;
* {{User|Arkomat}}&lt;br /&gt;
* {{User|bcdesign}}&lt;br /&gt;
* {{User|crommie}}&lt;br /&gt;
* {{User|Grubosoft}}&lt;br /&gt;
* {{User|fcschippers}}&lt;br /&gt;
* {{User|HermanPeeren}}&lt;br /&gt;
* {{User|Hvdmeer}}&lt;br /&gt;
* {{User|janvankuijk}}&lt;br /&gt;
* {{User|John Flour}}&lt;br /&gt;
* {{User|JorSanders}}&lt;br /&gt;
* {{User|Josien}}&lt;br /&gt;
* {{User|Lara}}&lt;br /&gt;
* {{User|LtB}}&lt;br /&gt;
* {{User|Lianne}}&lt;br /&gt;
* {{User|klatte88}}&lt;br /&gt;
* {{User|ManuAmpe}}&lt;br /&gt;
* {{User|Marcelk}}&lt;br /&gt;
* {{User|marionnijhuis}}&lt;br /&gt;
* {{User|Marnix}}&lt;br /&gt;
* {{User|MartijnM}}&lt;br /&gt;
* {{User|Meta}}&lt;br /&gt;
* {{User|metdick}}&lt;br /&gt;
* {{User|Mtb}}&lt;br /&gt;
* {{User|n9iels}}&lt;br /&gt;
* {{User|Nemphias}}&lt;br /&gt;
* {{User|Nico-van-Leeuwen}}&lt;br /&gt;
* {{User|Onderzoekspraktijk}}&lt;br /&gt;
* {{User|rachel73}}&lt;br /&gt;
* {{User|Renem}}&lt;br /&gt;
* {{User|Ries}}&lt;br /&gt;
* {{User|Rineke}}&lt;br /&gt;
* {{User|Schrijvers123}}&lt;br /&gt;
* {{User|slibbe}}&lt;br /&gt;
* {{User|Sloekers}}&lt;br /&gt;
* {{User|Stitch123}}&lt;br /&gt;
* {{User|Vertaalbirdy}}&lt;br /&gt;
* {{User|webmiep}}&lt;br /&gt;
* {{User|Webcase}}&lt;br /&gt;
* {{User|webcatsolutions}}&lt;br /&gt;
* {{User|willoweb}}&lt;br /&gt;
* {{User|wimstrik}}&lt;br /&gt;
&lt;br /&gt;
=== pl - Polski - Polish ===&lt;br /&gt;
* {{User|Derek}}&lt;br /&gt;
* {{User|justyna}}&lt;br /&gt;
* {{User|MiloW}}&lt;br /&gt;
* {{User|Zwiastun}}&lt;br /&gt;
&lt;br /&gt;
=== pt - Português (Portugal) - Portuguese (Portugal) ===&lt;br /&gt;
* {{User|Djesus}}&lt;br /&gt;
* {{User|Horus_68}}&lt;br /&gt;
* {{User|Lampreia Lopes}}&lt;br /&gt;
* {{User|Mansil}}&lt;br /&gt;
* {{User|Nunof}}&lt;br /&gt;
* {{User|NunoLopes}}&lt;br /&gt;
* {{User|Ricardo.fusco}}&lt;br /&gt;
&lt;br /&gt;
=== pt-br - Português Brasil - Brazilian Portuguese ===&lt;br /&gt;
* {{User|Airton}}&lt;br /&gt;
* {{User|alangustavo}}&lt;br /&gt;
* {{User|AleMorettiSan}}&lt;br /&gt;
* {{User|Anabarcellos}}&lt;br /&gt;
* {{User|Ariadnepinheiro}}&lt;br /&gt;
* {{User|Belisards}}&lt;br /&gt;
* {{User|Dagoberto}}&lt;br /&gt;
* {{User|DiLeu}}&lt;br /&gt;
* {{User|Filipetorres}}&lt;br /&gt;
* {{User|Gleisonsoares}}&lt;br /&gt;
* {{User|Helvecio}}&lt;br /&gt;
* {{User|Henrydouglas}}&lt;br /&gt;
* {{User|Jeann Wilson}}&lt;br /&gt;
* {{User|Juliano.freitas}}&lt;br /&gt;
* {{User|Murilotimo}}&lt;br /&gt;
* {{User|VitorAdonai}}&lt;br /&gt;
* {{User|Vizetti}}&lt;br /&gt;
* {{User|Welkson Ramos}}&lt;br /&gt;
&lt;br /&gt;
=== ro - Română - Romanian ===&lt;br /&gt;
* {{User|andreeastefan}}&lt;br /&gt;
* {{User|isac}}&lt;br /&gt;
* {{User|Dudi161}}&lt;br /&gt;
&lt;br /&gt;
=== ru - Русский - Russian ===&lt;br /&gt;
* {{User|AlexSmirnov}}&lt;br /&gt;
* {{User|Antonio3}}&lt;br /&gt;
* {{User|b2z}}&lt;br /&gt;
* {{User|cadko}}&lt;br /&gt;
* {{User|Cronolio}}&lt;br /&gt;
* {{User|Dosfanat}}&lt;br /&gt;
* {{User|Dzandut}}&lt;br /&gt;
* {{User|Igor}}&lt;br /&gt;
* {{User|Kanta}}&lt;br /&gt;
* {{User|Leo240}}&lt;br /&gt;
* {{User|Nikitm}}&lt;br /&gt;
* {{User|Nikolice}}&lt;br /&gt;
* {{User|Serg SSN}}&lt;br /&gt;
* {{User|Vyatka}}&lt;br /&gt;
* {{User|Yambergaa}}&lt;br /&gt;
&lt;br /&gt;
=== si - සිංහල - Sinhala ===&lt;br /&gt;
* {{User|Yasirunilan}}&lt;br /&gt;
* {{User|Supun}}&lt;br /&gt;
&lt;br /&gt;
=== sk - Slovenčina - Slovak ===&lt;br /&gt;
* {{User|adambako}}&lt;br /&gt;
&lt;br /&gt;
=== yu - Srpski (Latin) - Serbian (Latin) ===&lt;br /&gt;
* {{User|novii}}&lt;br /&gt;
&lt;br /&gt;
=== sr - Српски (Ћирилица) - Serbian (Cyrillic) ===&lt;br /&gt;
* {{User|novii}}&lt;br /&gt;
&lt;br /&gt;
=== sv - Svenska - Swedish ===&lt;br /&gt;
* {{User|Propellerhuvud}}&lt;br /&gt;
* {{User|Sgagner}}&lt;br /&gt;
&lt;br /&gt;
=== sw - Kiswahili - Swahili ===&lt;br /&gt;
* {{User|Ayeko}}&lt;br /&gt;
&lt;br /&gt;
=== th - ไทย - Thai ===&lt;br /&gt;
* {{User|Supachai_chai}}&lt;br /&gt;
* {{User|Mrs.siam}}&lt;br /&gt;
* {{User|Ariesanywhere}}&lt;br /&gt;
&lt;br /&gt;
=== tr - Türkçe - Turkish ===&lt;br /&gt;
* {{User|Ugur}}&lt;br /&gt;
* {{User|Umitkenan}}&lt;br /&gt;
&lt;br /&gt;
=== ukr - Українська - Ukrainian ===&lt;br /&gt;
* {{User|Olesya6968ak}}&lt;br /&gt;
* {{User|sera527}}&lt;br /&gt;
* {{User|trv}}&lt;br /&gt;
&lt;br /&gt;
=== ur - ur-PK - اردو - Urdu Pakistan ===&lt;br /&gt;
* {{User|hoornayyer}}&lt;br /&gt;
&lt;br /&gt;
=== vec - Veneto - Vèneto ===&lt;br /&gt;
* {{User|ino}}&lt;br /&gt;
&lt;br /&gt;
=== vi - Tiếng Việt - Vietnamese ===&lt;br /&gt;
* {{User|huyhoa}}&lt;br /&gt;
&lt;br /&gt;
=== zh - 中文 - Chinese ===&lt;br /&gt;
* {{User|asika32764}}&lt;br /&gt;
* {{User|eyesofkids}}&lt;br /&gt;
* {{User|Guozhanfeng}}&lt;br /&gt;
* {{User|KellyXYM}}&lt;br /&gt;
* {{User|lai32290}}&lt;br /&gt;
* {{User|Mori0725ken}}&lt;br /&gt;
* {{User|myskies}}&lt;br /&gt;
* {{User|Wulijun01234}}&lt;br /&gt;
* {{User|Zace}}&lt;br /&gt;
* {{User|Zhang19min88}}&lt;br /&gt;
* {{User|Zhous98}}&lt;br /&gt;
&lt;br /&gt;
=== zh-tw - 繁體中文 - Traditional Chinese ===&lt;br /&gt;
* {{User|Yuhoward}}&lt;br /&gt;
&lt;br /&gt;
==Translation Administrators==&lt;br /&gt;
&lt;br /&gt;
The responsibilities of a Translation Administrator will require slightly more attention to the documents for translation. Translation Administrators should feel comfortable with using wiki markup, made hundreds of contributions to their specific language and assisted others in translation of docs. Administrators will need to check the documentation every few days and perform any required tasks. These tasks include re-marking pages in en-GB with edit changes, tracking language units which need translation and welcoming new translators. Ideally, we should have at least one Translation Administrator who will not be tied to any specific language and when the time comes, one Translation Administrator for active language teams.&lt;br /&gt;
&lt;br /&gt;
===Current Volunteer Translation Administrators===&lt;br /&gt;
{{:Special:ListUsers/translationadmins}}&lt;br /&gt;
&lt;br /&gt;
==Common Language Codes==&lt;br /&gt;
&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; afr - Afrikaans - Afrikaans&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ar - عربي - Arabic&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; be - Беларуская - Belarusian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; bg - Български - Bulgarian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; bn - বাংলা - Bengali&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; bo - བོད་ཡིག - tibetan&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ca - Català - Catalan&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ce - Nohçi - Chechen&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; da - Dansk - Danish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; de - Deutsch - German&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; es - Español - Spanish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; fa - فارسی - Persian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; fi - Suomi - Finnish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; fr - Français - French&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; hu - Magyar - Hungarian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; hy - Հայերեն - Armenian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; id - Bahasa Indonesia - Indonesian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; is - Íslenska - Icelandic&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; it - Italiano - Italian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ja - 日本語 - Japanese&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ko - 한국어 - Korean&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; lb - Lëtzebuergesch - Luxembourgish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; min - Baso Minangkabau - Minang&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ml - liviox alvax - Malayalam&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; mr - मराठी - Marathi&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ms - Bahasa Melayu - Malay&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; nl - Nederlands - Dutch&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; pl - Polski - Polish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; pt - Português - Portuguese&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; pt-br - Português do Brasil - Brazilian Portuguese&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ro - Română - Romanian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ru - Русский - Russian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; sl - Slovenščina - Slovenianjtökók&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; sq - Shqip - Albanian&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; sv - Svenska - Swedish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; sw - Kiswahili - Swahili&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; ta - தமிழ் - Tamil&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; th - ไทย - Thai&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; tr - Türkçe - Turkish&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; vi - Tiếng Việt - Vietnamese&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; zh - 中文 - Chinese&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;div class=&amp;quot;small-4 columns&amp;quot;&amp;gt; zh-tw - 繁體中文 - Traditional Chinese&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Documentation Wiki Policies and Guidelines]]&lt;br /&gt;
[[Category:Documentation Translation]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616411</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616411"/>
		<updated>2019-06-24T11:52:25Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as much as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not solely rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there any functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection and logging system already exists.&lt;br /&gt;
##Such a system partially exists (for example there is a consent checkbox but does not store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to inform users regarding the privacy policy (upfront the collection of any personal data) and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to allow users to withdraw their consent?&#039;&#039;&#039;&lt;br /&gt;
##A functionality provides to users the ability to withdraw consent.&lt;br /&gt;
##There is no functionality to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it is not. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will facilitate for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Does your extension allow the generation of additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more).&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality.&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there is no such functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw their consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality.&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to the Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##There is, but partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users to submit deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code to successfully delete all the previous collected users’ data once the Super User decides to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under HTTPS (TLS).&lt;br /&gt;
##Some of the resources transmit information insecurely.&lt;br /&gt;
##All the resources transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s, you can run a test to ensure the security of the certificate used and configuration of this server. There are many tools and services to help you on that, for example you can use [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##Only part of the data can be stored encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;To empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Some of the data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You can use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of all third parties.&lt;br /&gt;
##No, there is no list of third parties or the list is not full.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension for the Webmasters that will use it to find it easy to sign them? Even if the third party does not collect any personal data, an agreement for that should exist.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616410</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616410"/>
		<updated>2019-06-24T11:39:50Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as much as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not solely rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there any functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection and logging system already exists.&lt;br /&gt;
##Such a system partially exists (for example there is a consent checkbox but does not store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to inform users regarding the privacy policy (upfront the collection of any personal data) and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to allow users to withdraw their consent?&#039;&#039;&#039;&lt;br /&gt;
##A functionality provides to users the ability to withdraw consent.&lt;br /&gt;
##There is no functionality to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it is not. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will facilitate for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Does your extension allow the generation of additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more).&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality.&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there is no such functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw their consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality.&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to the Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to allow users request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##There is, but partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users to submit deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code to successfully delete all the previous collected users’ data once the Super User decides to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616409</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616409"/>
		<updated>2019-06-24T11:31:24Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as much as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not solely rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there any functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection and logging system already exists.&lt;br /&gt;
##Such a system partially exists (for example there is a consent checkbox but does not store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to inform users regarding the privacy policy (upfront the collection of any personal data) and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to allow users to withdraw their consent?&#039;&#039;&#039;&lt;br /&gt;
##A functionality provides to users the ability to withdraw consent.&lt;br /&gt;
##There is no functionality to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it is not. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will facilitate for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Does your extension allow the generation of additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more).&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616408</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616408"/>
		<updated>2019-06-24T11:21:54Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as much as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not solely rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there any functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection and logging system already exists.&lt;br /&gt;
##Such a system partially exists (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to inform users regarding the privacy policy (upfront the collection of any personal data) and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616404</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616404"/>
		<updated>2019-06-23T23:05:00Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Umbraco and of course Joomla! are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616403</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616403"/>
		<updated>2019-06-23T22:57:15Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group where representatives from the communities of WordPress, Drupal, Joomla and Umbraco are collaborating in privacy. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616393</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616393"/>
		<updated>2019-06-23T14:50:55Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below to design your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and let you improve it based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616328</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616328"/>
		<updated>2019-06-23T09:46:45Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616327</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616327"/>
		<updated>2019-06-23T09:45:31Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommended Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616324</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616324"/>
		<updated>2019-06-23T08:59:02Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: /* Further reading */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://git.io/fjww3  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://git.io/fjwwG &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616269</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616269"/>
		<updated>2019-06-22T16:51:14Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: /* Further reading */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://github.com/webdevlaw/open-source-privacy-standards &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: [https://volunteers.joomla.org/joomlers/2399-achilleas-papageorgiou Achilleas Papageorgiou], Team Leader of Compliance Team&lt;br /&gt;
*Contributors: [https://volunteers.joomla.org/joomlers/312-luca-marzo Luca Marzo], [https://volunteers.joomla.org/joomlers/60-sander-potjer Sander Potjer], [https://volunteers.joomla.org/joomlers/155-roland-dalmulder Roland Dalmulder]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616263</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616263"/>
		<updated>2019-06-22T16:46:17Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: /* 1. Consent to the use of personal data functionalities */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://github.com/webdevlaw/open-source-privacy-standards &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: Achilleas Papageorgiou, Team Leader of Compliance Team&lt;br /&gt;
*Contributors: Luca Marzo, Sander Potjer, Roland Dalmulder&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
	<entry>
		<id>https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616262</id>
		<title>Privacy Guidance for Joomla Extensions</title>
		<link rel="alternate" type="text/html" href="https://docs.sandbox.joomla.org/index.php?title=Privacy_Guidance_for_Joomla_Extensions&amp;diff=616262"/>
		<updated>2019-06-22T14:32:40Z</updated>

		<summary type="html">&lt;p&gt;Alphapi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title=&lt;br /&gt;
Find your extension’s Achilles heel (weakness)&amp;lt;br/&amp;gt; in terms of personal data protection &lt;br /&gt;
}}&lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou ([https://volunteers.joomla.org/teams/compliance-team Joomla! Compliance team]) for the cross-CMS privacy working group. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Global Recommendation&#039;&#039;&#039;&lt;br /&gt;
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with the first answer (1.) of each question as possible.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Important notice&#039;&#039;&#039;&lt;br /&gt;
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. &lt;br /&gt;
{{-}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Choose the severity group of your extension in terms of privacy:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;width:100%; vertical-align:top; border:1px solid Sienna; background-color:Cornsilk;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color:Wheat; font-weight:bold; text-align: left;&amp;quot;&lt;br /&gt;
!width=20%|Groups&lt;br /&gt;
!width=60%|Personal data processing profile&lt;br /&gt;
!width=20%|Related questions &lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group A&#039;&#039;&#039;&lt;br /&gt;
| The extension isn&#039;t expected to process or store any personal data&lt;br /&gt;
| 7 and 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group B&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store data that can be used to indirectly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group C&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data that can be used to directly associate the identity of a person&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group D&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to process or store personal data and also special categories of personal data that can include, but not limited to &lt;br /&gt;
*race and ethnic origin, &lt;br /&gt;
*religious, &lt;br /&gt;
*genetic data, &lt;br /&gt;
*health data.&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Group E&#039;&#039;&#039;&lt;br /&gt;
| The extension is expected to share personal data with at least one third party service&lt;br /&gt;
| 1 to 8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 1. Consent to the use of personal data functionalities== &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e1489-1-1 Articles 4] (Definition 11), [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2254-1-1 13] &amp;amp; [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 32, 42]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there functionality to collect and log consents from users that submit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##A consent collection &amp;amp; logging system exists&lt;br /&gt;
##Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) &lt;br /&gt;
##There is no consent collection and logging system&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what?&#039;&#039;&#039;&lt;br /&gt;
##The functional ability to withdraw consent is offered to users.&lt;br /&gt;
##There is no functional ability to withdraw consent. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the consent functionality connected to the Joomla core Privacy Component?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it is connected to the Joomla core Privacy Component.&lt;br /&gt;
##The consent functionality is based on a custom mechanism.&lt;br /&gt;
##No, it isn’t. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen. &lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality to generate additional consent functionalities (checkboxes?) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality that can be used to generate additional consent mechanisms.&lt;br /&gt;
##Yes, there is such functionality but with limited options (i.e. you can only add one more)&lt;br /&gt;
##No, there is no functionality to generate additional consent functionalities.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 2. Consent for Cookies collecting personal data == &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;If your extension uses cookies that process personal data, is there a functionality for the up front consent by the user in case the software installs cookies that are collecting any personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes there is such functionality&lt;br /&gt;
##No, there is no functionality for cookies, but there is an informational notice in order for the webmaster to use such a functionality&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to upfront the installation consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#If a functionality to collect consents is provided, is there also a functionality for the user/s to withdraw consent?&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##No, there is no functionality for that, but there is an informational notice in order for the webmaster to use such a functionality.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to withdraw their already given consent to cookies. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 3. Right to Data Portability ==&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2753-1-1 Article 20] &lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that gives users the ability to request and download their data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is such functionality&lt;br /&gt;
##Yes, but partially.&lt;br /&gt;
##No, there is no functionality for that.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#Is the file that is downloaded in a machine readable format (for example XML, CSV)?&lt;br /&gt;
##Yes, it is.&lt;br /&gt;
## No it isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality should exist to provide users with the ability to request and download their data to a machine readable format (for example XML, CSV). Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== 4. Right of Access by the data subject ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2599-1-1 Article 16]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case the extension collects personal data, does the extension provides a dashboard to the users with settings to edit their personal data?&#039;&#039;&#039;&lt;br /&gt;
##Yes, it provides.&lt;br /&gt;
##Yes, there is but partially.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A view should exist to provide users with the ability to preview and edit their data.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==5. Right to be Forgotten ==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
* Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e2606-1-1 Article 17], Recital [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 65]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there a functionality that offers to users the request to remove/delete all of their data?&#039;&#039;&#039;&lt;br /&gt;
##There is.&lt;br /&gt;
##But partially.&lt;br /&gt;
##There isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;A functionality and an easy to use flow should be provided to users in order to create deletion requests. At the same time a procedure for the Webmasters to manage those requests should exists at the administration side of their websites. Empower your compliance efforts by connecting your extension’s functions to Joomla’s core API. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Does the extension include an uninstall operation to your extensions code in order to successfully delete all the previous collected users’ data the time that the Super User will decide to uninstall it?&#039;&#039;&#039;&lt;br /&gt;
##Yes, this operation is included.&lt;br /&gt;
##No, there isn’t.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should use the proposed steps [[S:MyLanguage/J3.2:Developing_an_MVC_Component/Adding_an_install-uninstall-update_script_file|here]] to successfully include the uninstall operation and also include any code and files needed based on the Joomla MVC to succeed the complete deletion. Don’t forget to include database tables with users’ data to the uninstall process.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==6. Privacy by Default==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3063-1-1 Article 25]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Does the software have all the settings set to the most private possible due to its scope?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the default settings are in the most private.&lt;br /&gt;
##No, the default settings are not in the most private.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the settings regarding the personal data collection/processing/storage should be set to the most private possible due to its scope of processing.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;Is the extension collecting personal data that is not needed/being used currently?&#039;&#039;&#039;&lt;br /&gt;
##Yes, the extension collects only the minimum needed to offer to Super Users and users the expected functionalities.&lt;br /&gt;
##The extension collects by default additional information that could potentially be used by Super Users.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;The extension should, by default, collect only the strictly needed users data that are mandatory to be functional based on its description. Any additional features that result to data collection (for example the IP collection) should be by default set OFF. the extension should provide a dashboard to let administrators manage those settings based on their needs and Privacy policies.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==7. Security Measures==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e3383-1-1 Article 32], [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 6 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;Is there secure transmission for all the resources used by the functionality?&#039;&#039;&#039;&lt;br /&gt;
##Yes, all the requests are under https (TLS).&lt;br /&gt;
##Some of the resources are transmit information insecurely.&lt;br /&gt;
##All the resources are transmit information insecurely. &amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;All the used resources, local or called via a third party host, should transmit data only through encrypted connections.You could inspect the HTTP requests through your browser or even use a tool for that like [https://www.screamingfrog.co.uk/seo-spider/ Screaming Frog]. You should always use well configured certificates on your web servers to ensure secure transmission. In case your extension requests from or transmits data to a web server/s you can run a security test to ensure the certificate and configuration of this server. There are many tools and services to help you on that, for example you can you this [https://www.ssllabs.com/ssltest/ SSL Server Test]. &#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If your extension will be used to store special personal data categories (like those described in Group D), is the data stored encrypted?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be stored encrypted.&lt;br /&gt;
##The data partially are encrypted.&lt;br /&gt;
##No, no data are encrypted by the extension.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use encryption functions to encrypt the data in the database. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. View on [https://github.com/joomla/joomla-cms/tree/staging/libraries/src/Crypt GitHub] to learn how you can make it happen.&#039;&#039; &lt;br /&gt;
#&#039;&#039;&#039;If there is a need to apply anonymization techniques are they applied?&#039;&#039;&#039;&lt;br /&gt;
##Yes, data can be anonymized.&lt;br /&gt;
##Yes, data can be partially anonymized.&lt;br /&gt;
##No, there is no ability to anonymize data.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;In order to empower the compliance level of your extension you could use anonymization functions for the collected data. This will make your extension more suitable to be used by websites that want to apply and prove strict security measures. Read [[S:MyLanguage/J3.x:Integrate_Extensions_with_the_Privacy_Component|here]] how you can make it happen.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
==8. (In case of) Third parties/Sub-processors==&lt;br /&gt;
*&#039;&#039;&#039;Group affected: A, B, C, D, E&#039;&#039;&#039;&lt;br /&gt;
*Legal requirement on GDPR: [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN#d1e40-1-1 Recitals 58 and 78]&lt;br /&gt;
&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties to provide a service or a functionality, have you included it to your third parties or sub-processors list?&#039;&#039;&#039;&lt;br /&gt;
##Yes, there is a list of the third parties.&lt;br /&gt;
##No, there is no list of third parties.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a list with all the third party services used by your extension in order to make easier for the Webmasters to also include them to their Processors list in their websites Privacy Policy.&#039;&#039;&lt;br /&gt;
#&#039;&#039;&#039;In case you use third parties, do you provide a notice including a link to the Data Protection Agreement/Addendum (DPA) of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them? Even the third party does not collect any personal data, an agreement for that should exists.&#039;&#039;&#039;&lt;br /&gt;
##Yes, with all the third parties.&lt;br /&gt;
##Yes, with some of the third parties.&lt;br /&gt;
##No, there is no DPA signed.&amp;lt;br /&amp;gt;&#039;&#039;&#039;{{rarr}}Recommanded Action:&#039;&#039;&#039; &amp;lt;br /&amp;gt;&#039;&#039;You should provide a notice including a link to the Data Protection Agreements/Addendums of the third parties used by your extension in order to for the Webmasters that will use it to find it easy to sign them. This will help them review, audit and provide information to their users regarding the compliance of those third parties. &#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Further reading==&lt;br /&gt;
&lt;br /&gt;
*Secure coding guidelines, Joomla Documentation https://docs.joomla.org/Secure_coding_guidelines  &lt;br /&gt;
*Compliance audit template to map the GDPR compliance level of your software extension, Cross-CMS Coalition Online at: https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md  &lt;br /&gt;
*Papageorgiou A., Strigkos M., Politou E., Alepis E., Solanas S., Patsakis C., Security and privacy analysis of mobile health applications: The alarming state of practice, online at: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amp;amp;arnumber=8272037. This work was supported by the European Commission under the Horizon 2020 Programme (H2020), as part of the OPERANDO project (Grant Agreement no. 653704) and the CRYPTACUS COST action (COST Action IC1403).&lt;br /&gt;
*Open Source Privacy Standards, by Heather Burns (webdevlaw), online at: https://github.com/webdevlaw/open-source-privacy-standards &lt;br /&gt;
*Nutricati A. and Papageorgiou A., GDPR Overview: Decrypting the regulation in series, online at: https://magazine.joomla.org/issues/issue-feb-2018/item/3306-gdpr-overview-decrypting-the-regulation-in-series &lt;br /&gt;
*Papageorgiou A., GDPR Awareness: From privacy risks to the need for countermeasures, online at: https://magazine.joomla.org/issues/issue-mar-2018/item/3314-gdpr-awareness-from-privacy-risks-to-the-need-for-countermeasures &lt;br /&gt;
*Koho R., Privacy by default and GDPR, examples and best practises, online at: https://magazine.joomla.org/issues/issue-apr-2018/item/3318-privacy-by-default-and-gdpr-examples-and-best-practises &lt;br /&gt;
*GDPR – A Practical Guide for Developers, BOZHO&#039;S TECH BLOG, online at: https://techblog.bozho.net/gdpr-practical-guide-developers/ &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contributors&#039;&#039;&#039;&lt;br /&gt;
*Author: Achilleas Papageorgiou, Team Leader of Compliance Team&lt;br /&gt;
*Contributors: Luca Marzo, Sander Potjer, Roland Dalmulder&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
[[Category:Privacy{{#translation:}}]]&lt;br /&gt;
[[Category:Components{{#translation:}}]]&lt;br /&gt;
[[Category:Plugins{{#translation:}}]]&lt;br /&gt;
[[Category:Modules{{#translation:}}]]&lt;br /&gt;
[[Category:Tutorials{{#translation:}}]]&lt;br /&gt;
[[Category:Extension_development{{#translation:}}]]&lt;br /&gt;
[[Category:Extensions{{#translation:}}]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Alphapi</name></author>
	</entry>
</feed>