<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									GDPR Compliance - General Discussions				            </title>
            <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/</link>
            <description>Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 14 Jul 2026 07:27:27 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15683</link>
                        <pubDate>Wed, 18 Apr 2018 13:57:27 +0000</pubDate>
                        <description><![CDATA[Just found this -and it seems like a really good plugin. Evidently, wpdiscuz has created a hook for this plugin, so I&#039;m wondering if wpForo can do the same.@robert - any thoughts, or are you...]]></description>
                        <content:encoded><![CDATA[<p>Just found this - https://wordpress.org/plugins/wp-gdpr-compliance/ and it seems like a really good plugin. Evidently, wpdiscuz has created a hook for this plugin, so I'm wondering if wpForo can do the same.</p><p>@robert - any thoughts, or are you guys doing something aside specially for wpForo ?</p><p>Thanks</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous3542</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15683</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15218</link>
                        <pubDate>Sat, 31 Mar 2018 09:15:23 +0000</pubDate>
                        <description><![CDATA[Some more reading from Invision standalone forum script]]></description>
                        <content:encoded><![CDATA[<p>Some more reading from Invision standalone forum script:</p><p>https://invisioncommunity.com/news/product-updates/how-invision-communitys-tools-can-help-with-gdpr-compliance-r1052/</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous20</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15218</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15006</link>
                        <pubDate>Wed, 21 Mar 2018 18:02:49 +0000</pubDate>
                        <description><![CDATA[Posted by: anonymous3542@cmw14 @anonymous20 I&#039;m another who doesn&#039;t handle login and register functions via wpforo - I use TML for both (mainly because phenomlab enforces 2FA Auth and also m...]]></description>
                        <content:encoded><![CDATA[<blockquote><div class="wpforo-post-quote-author"><strong>Posted by: anonymous3542</strong></div><p>@cmw14 @anonymous20 I'm another who doesn't handle login and register functions via wpforo - I use TML for both (mainly because phenomlab enforces 2FA Auth and also makes use of more social login capabilities than just Facebook).</p><p>I'm going to look into adding a bit more functionality and I'll post the results here .</p></blockquote><p>I now have this working via Theme My Login at https://www.phenomlab.com/register. If you try and create an account without accepting the policy / agreement (needs rewording to reflect GDPR) then the registration process will fail. Once the register requirements are satisfied, you'll be forwarded onto a "Thank You" page that reminds you to activate your account from the email sent.</p><p>If anyone is using TML and wants a guide on how to implement this, let me know.</p><p>Thanks</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous3542</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-15006</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-15000</link>
                        <pubDate>Wed, 21 Mar 2018 07:32:11 +0000</pubDate>
                        <description><![CDATA[Some great points here @anonymous20 and I&#039;ll do my best to clarify them.Those sites with hundreds if not thousands of comments and forum posts can argue a &quot;legitimate interest&quot; for keeping d...]]></description>
                        <content:encoded><![CDATA[<p>Some great points here @anonymous20 and I'll do my best to clarify them.</p><p>Those sites with hundreds if not thousands of comments and forum posts can argue a "legitimate interest" for keeping data. Those who have previously subscribed to something would only need to attest to their data being used in any site by means of a one time redirect when they login to a terms and conditions page. They are not allowed to proceed any further unless they provide consent .</p><p>In a similar fashion, the right to be forgotten is another conundrum in the sense that (as you've mentioned) the request could originate from a hacked account. There are no clear guidelines around this scenario at present, and an official request is generally enough in order to execute. However, there are various sanity checks that you could leverage to potentially combat this, such as 2FA in order to complete the request etc. Effectively, the user has the right to both request deletion, which can either be automated via the site, or via a secured one time link. By definition, the user also has the right to gain an export of all data held in relation to them as a CSV or XLS file for ingest by another custodian (another site, for example). I tend to prefer the normalisation route, with data being sanitised, removing any pertinent information that may identify the user rather then remove the content .</p><p>Then there's backups. There's no enforced rule within GDPR that dictates you have to restore each backup and remove information - you just provide written attestation that the data is removed from the said date, and will not be reinstated without the express written consent of the owner.</p><p>Lastly, there's the legal side. Regulation always trumps GDPR. For example, if a company is regulated by the FCA or SEC then they have the need to comply with such data retention regulations - in most cases, 7 years, or indefinitely if that associated data is subject to legal hold. Any company exercising this right would need to provide legal evidence of such a retention requirement but that would not be difficult. In essence, the right to be forgotten can only be trumped by regulatory law. Failure to comply with any request is in essence a breach of those regulations and could attract obvious penalties. </p><p>One final thing to consider is the beach reporting requirements. You now have to notify both the ICO and all users within a system that there had been a breach within 72 hours. </p><p>Feeling sick yet ? 😯</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous3542</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-15000</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14999</link>
                        <pubDate>Wed, 21 Mar 2018 07:16:25 +0000</pubDate>
                        <description><![CDATA[@anonymous20 you are correct there. It&#039;s much more in fact. The tick boxes in terms of auto signups, comments, contact forms etc all have to be unticked by default to prove that you are not ...]]></description>
                        <content:encoded><![CDATA[<p>@anonymous20 you are correct there. It's much more in fact. The tick boxes in terms of auto signups, comments, contact forms etc all have to be unticked by default to prove that you are not sending the user unnecessary junk. </p><p>GDPR is wide ranging in terms of reach, and whilst it certainly does protect the individual who is the owner of that data, it makes it a complete nightmare for custodians .</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous3542</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14999</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-14997</link>
                        <pubDate>Wed, 21 Mar 2018 00:12:24 +0000</pubDate>
                        <description><![CDATA[Some good reading:]]></description>
                        <content:encoded><![CDATA[<p>Some good reading:</p><p> </p><p>https://www.imperva.com/blog/2018/01/three-reasons-why-gdpr-encourages-pseudonymization/</p><p> </p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous20</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/3/#post-14997</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14996</link>
                        <pubDate>Wed, 21 Mar 2018 00:00:43 +0000</pubDate>
                        <description><![CDATA[@cmw14 Please don&#039;t get me wrong. I&#039;m equally confused about this GDPR crap as you. Just saying that if some PLUGIN exists for all that, maybe we should consider it.Just thinking loudly.Chec...]]></description>
                        <content:encoded><![CDATA[<p>@cmw14 Please don't get me wrong. I'm equally confused about this GDPR crap as you. Just saying that if some PLUGIN exists for all that, maybe we should consider it.</p><p>Just thinking loudly.</p><p>Checking Wordpress plugins repo for GDPR i see only 4 plugins, that seems<strong> not</strong> very promising. But interesting.</p><p>Also right now i know a huge ammount of sites that base their popularity and rank due to the ammount of comments or/and forum post. HUGE ammount of information. What will happens to all that ? They should scrap everything on request ? Just scrap the link to a name/account and just annonymize the comments/posts ?</p><p>How should we know that the people that REQUEST to be deleted is actually the person of the email belongs ? Hacked email accounts ? How do we verify ? An email confirmation is enough ?</p><p> </p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous20</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14996</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14995</link>
                        <pubDate>Tue, 20 Mar 2018 23:54:44 +0000</pubDate>
                        <description><![CDATA[I think there is more than ticks for comments and posts. I read now the Right to be Forgotten for example.What happens if someone requests to be &quot;forgotten&quot; and the forum posts ?]]></description>
                        <content:encoded><![CDATA[<p>I think there is more than ticks for comments and posts. I read now the <em><strong>Right to be Forgotten</strong></em> for example.</p><p>What happens if someone requests to be "forgotten" and the forum posts ?</p><p> </p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous20</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14995</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14994</link>
                        <pubDate>Tue, 20 Mar 2018 23:41:03 +0000</pubDate>
                        <description><![CDATA[@cmw14 @anonymous20 I&#039;m another who doesn&#039;t handle login and register functions via wpforo - I use TML for both (mainly because phenomlab enforces 2FA Auth and also makes use of more social ...]]></description>
                        <content:encoded><![CDATA[<p>@cmw14 @anonymous20 I'm another who doesn't handle login and register functions via wpforo - I use TML for both (mainly because phenomlab enforces 2FA Auth and also makes use of more social login capabilities than just Facebook).</p><p>I'm going to look into adding a bit more functionality and I'll post the results here .</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>Anonymous3542</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14994</guid>
                    </item>
				                    <item>
                        <title>RE: GDPR Compliance</title>
                        <link>https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14993</link>
                        <pubDate>Tue, 20 Mar 2018 23:15:58 +0000</pubDate>
                        <description><![CDATA[Posted by: Anonymous20Well i think most of us don&#039;t use wpForo like that. And a simple standard WP Signup is enough.Agreed I&#039;m likely in the minority and I respect that. 👍However rather than...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>Posted by: Anonymous20</strong></p><p>Well i think most of us don't use wpForo like that. And a simple standard WP Signup is enough.</p></blockquote><p>Agreed I'm likely in the minority and I respect that. 👍</p><p>However rather than being dismissive of the possibility, it could always be an option to switch on or off. That way everyone is catered for, those that wish to use it can those that don't , don't. Pretty much how many of the wpForo options currently work. All academic anyway, the wpForo team ultimately decide what's included or not.</p>]]></content:encoded>
						                            <category domain="https://wpforo.com/community/general-discussions/">General Discussions</category>                        <dc:creator>cmw14</dc:creator>
                        <guid isPermaLink="true">https://wpforo.com/community/general-discussions/gdpr-compliance-2/paged/2/#post-14993</guid>
                    </item>
							        </channel>
        </rss>
		