Privacy Guidance for Joomla Extensions: Difference between revisions
From Joomla! Documentation
Created page with " {{Top portal heading|color=white-bkgd|icon=lock|icon-color=#5091cd|size=3x|text-color=#333|title= Find your extension’s Achilles heel (weakness)<br/> in terms of personal d..." |
No edit summary |
||
| Line 7: | Line 7: | ||
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou (Joomla! Compliance team) for the cross-CMS privacy working group. | This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the [https://github.com/joomla/cross-cms-compliance/blob/master/audit-your-software-extension.md v1 draft] devised by Achilleas Papageorgiou (Joomla! Compliance team) for the cross-CMS privacy working group. | ||
===Global Recommendation=== | ====Global Recommendation==== | ||
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with as most A) answers as possible. | This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with as most A) answers as possible. | ||
===Important notice=== | ====Important notice==== | ||
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. | You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation. | ||
==Choose the severity group of your extension in terms of privacy== | ==Choose the severity group of your extension in terms of privacy== | ||
=== 1.Consent to the use of personal data functionalities=== | |||
*Group affected: B, C, D, E | |||
*Where can I read more regarding this legal requirement on GDPR: Articles 4 (Definition 11), 13 & Recitals 32, 42 | |||
===Contributors=== | ##Is there functionality to collect and log consents from users that submit their personal data? | ||
A consent collection & logging system exists | |||
Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) | |||
There is no consent collection and logging system | |||
Recommended action: | |||
A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents. | |||
1.2 Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what? | |||
The functional ability to withdraw consent is offered to users. | |||
There is no functional ability to withdraw consent. | |||
Recommended action: | |||
A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw. | |||
1.3 Is the consent functionality connected to the Joomla core Privacy Component? | |||
Yes, it is connected to the Joomla core Privacy Component. | |||
The consent functionality is based on a custom mechanism. | |||
No, it isn’t. | |||
Recommended action: | |||
Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. | |||
Read here how you can make it happen. | |||
1.4 Is there a functionality to generate additional consent functionalities (checkboxes?) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data? | |||
Yes, there is such functionality that can be used to generate additional consent mechanisms. | |||
Yes, there is such functionality but with limited options (i.e. you can only add one more) | |||
No, there is no functionality to generate additional consent functionalities. | |||
Recommended action: | |||
A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing. | |||
====Contributors==== | |||
*Author: Achilleas Papageorgiou, Team Leader of Compliance Team | *Author: Achilleas Papageorgiou, Team Leader of Compliance Team | ||
*Contributors: Luca Marzo, Sander Potjer, Roland Dalmulder | *Contributors: Luca Marzo, Sander Potjer, Roland Dalmulder | ||
Revision as of 20:49, 19 June 2019
in terms of personal data protection
This is a compliance audit template to map the GDPR compliance level of your Joomla! extensions. This workflow is based on the v1 draft devised by Achilleas Papageorgiou (Joomla! Compliance team) for the cross-CMS privacy working group.
Global Recommendation
This guide presents possible answers to each question and you can consider that, while there is no score to succeed, your extension should be aligned with as most A) answers as possible.
Important notice
You should not only rely on the information below only to complete your full compliance plan regarding your software tools and business. Nevertheless, it is expected that the following information can provide you a useful and easy way to find your software’s weaknesses and improve them based on GDPR requirements and through the provided link to the how-to Joomla! documentation.
Choose the severity group of your extension in terms of privacy
1.Consent to the use of personal data functionalities
- Group affected: B, C, D, E
- Where can I read more regarding this legal requirement on GDPR: Articles 4 (Definition 11), 13 & Recitals 32, 42
- Is there functionality to collect and log consents from users that submit their personal data?
A consent collection & logging system exists Such a system exists partially (for example there is a consent checkbox but doesn’t store logs) There is no consent collection and logging system Recommended action: A functionality to up front inform users regarding the privacy policy and log consents (if not legal basis exists) from users that their personal data are collected and/or processed. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily understand all the appropriate information (that Webmasters should provide) and freely provide their consents.
1.2 Is there a functionality that gives the user the ability to withdraw their consent? If yes, to what? The functional ability to withdraw consent is offered to users. There is no functional ability to withdraw consent. Recommended action: A functionality that users can use to withdraw any already given consent should provided. A special focus should be given regarding the UX of this functionality in order to provide a simple and easy flow to users to easily find an easy way to withdraw.
1.3 Is the consent functionality connected to the Joomla core Privacy Component? Yes, it is connected to the Joomla core Privacy Component. The consent functionality is based on a custom mechanism. No, it isn’t. Recommended action: Empower your compliance efforts by connecting your extension’s functions to Joomla’s core Privacy Component. This will make it easier for site creators to setup a clear and proper consent functionality for Joomla websites. Read here how you can make it happen.
1.4 Is there a functionality to generate additional consent functionalities (checkboxes?) for the up front consent of the users to the use of personal data in case of marketing, profiling, children data, sensitive data? Yes, there is such functionality that can be used to generate additional consent mechanisms. Yes, there is such functionality but with limited options (i.e. you can only add one more) No, there is no functionality to generate additional consent functionalities. Recommended action: A functionality to generate, additional to the 1.1 requirement, consents (if not legal basis exists) from users that need to provide additional consent, such as the processing of special personal data categories that require explicit consent, or to provide their consent for a different scope of processing.
Contributors
- Author: Achilleas Papageorgiou, Team Leader of Compliance Team
- Contributors: Luca Marzo, Sander Potjer, Roland Dalmulder