- Posts: 12
- Thank you received: 1
GDPR - New European Privacy and Consent Rules!
- Francesco Mulassano
- Offline
- New Member
-
Less
More
7 years 3 months ago #112172
by Francesco Mulassano
Replied by Francesco Mulassano on topic GDPR - New European Privacy and Consent Rules!
Hi Guys, any news about this?
I'm in Italy and I collect data with event-booking and MailChimp plugin from European and non European customer
At the end of the ticket's form, I have the check for Term and Conditions but GDPR needs another check to consent the registration on our mailing list. If you do not consent this checkbox, you can still buy tickets!
Is a first important step toward GDPR.
I'm in Italy and I collect data with event-booking and MailChimp plugin from European and non European customer
At the end of the ticket's form, I have the check for Term and Conditions but GDPR needs another check to consent the registration on our mailing list. If you do not consent this checkbox, you can still buy tickets!
Is a first important step toward GDPR.
The following user(s) said Thank You: József Gonda
Please Log in or Create an account to join the conversation.
- Angeles Sánchez Gómez
- Offline
- New Member
-
Less
More
- Posts: 3
- Thank you received: 0
7 years 2 months ago #112264
by Angeles Sánchez Gómez
Replied by Angeles Sánchez Gómez on topic GDPR - New European Privacy and Consent Rules!
Hello Tuam,
Any news on the subject?
I know that a time is needed to carry out the programming and modifications to comply with GDPR, but it is urgent for those of us who use eventbooking and we are in the European Union. We need a time to be able to do tests.
If these changes are not contemplated in future updates, we have to look for an alternative.
Thank you very much and greetings
Angeles
Any news on the subject?
I know that a time is needed to carry out the programming and modifications to comply with GDPR, but it is urgent for those of us who use eventbooking and we are in the European Union. We need a time to be able to do tests.
If these changes are not contemplated in future updates, we have to look for an alternative.
Thank you very much and greetings
Angeles
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
7 years 2 months ago #112265
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic GDPR - New European Privacy and Consent Rules!
This's easy to add, don't worry. So basically, if users check on this second checkbox, they will be added to mailing list? If they don't check, they won't be added to Mailing List?
What newsletter extension you are using?
Tuan
What newsletter extension you are using?
Tuan
Please Log in or Create an account to join the conversation.
- Francesco Mulassano
- Offline
- New Member
-
Less
More
- Posts: 12
- Thank you received: 1
7 years 2 months ago #112268
by Francesco Mulassano
Replied by Francesco Mulassano on topic GDPR - New European Privacy and Consent Rules!
I'm Using Mailchimp
maybe this link is useful kb.mailchimp.com/accounts/management/col...sent-with-gdpr-forms
maybe this link is useful kb.mailchimp.com/accounts/management/col...sent-with-gdpr-forms
Please Log in or Create an account to join the conversation.
- Angeles Sánchez Gómez
- Offline
- New Member
-
Less
More
- Posts: 3
- Thank you received: 0
7 years 2 months ago #112269
by Angeles Sánchez Gómez
Replied by Angeles Sánchez Gómez on topic GDPR - New European Privacy and Consent Rules!
I'm using Acymailing
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
7 years 2 months ago #112271
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic GDPR - New European Privacy and Consent Rules!
For ACYMailing, we might support it out of the box already. See
eventbookingdoc.joomservices.com/basic-s...to-join-waiting-list
So basically, you can create a custom field (Checkboxes or Radio) to allow users to choose whether they want to subscribe to your mailing list
If they select Yes, then they will be subscribed. If no, then they won't. Will that work?
Tuan
So basically, you can create a custom field (Checkboxes or Radio) to allow users to choose whether they want to subscribe to your mailing list
If they select Yes, then they will be subscribed. If no, then they won't. Will that work?
Tuan
Please Log in or Create an account to join the conversation.
- Graham Swann
- Offline
- New Member
-
Less
More
- Posts: 5
- Thank you received: 0
7 years 2 months ago #112368
by Graham Swann
Replied by Graham Swann on topic GDPR - New European Privacy and Consent Rules!
I have done exactly that.
Added extra field with checkboxes that 1 has to be ticked to process and the choices are
Email
Post
Phone
No Thanks
Graham,
Added extra field with checkboxes that 1 has to be ticked to process and the choices are
Post
Phone
No Thanks
Graham,
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
7 years 2 months ago #112369
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic GDPR - New European Privacy and Consent Rules!
@Graham Maybe you can share your setup by sending us the link to registration form on your site?
@Francesco Did you check the link I provided? Will it solve this GPDR requirement?
@Angeles Sánchez Gómez The same is applied for Mailchimp. Could you please check it as well?
Regards,
Tuan
@Francesco Did you check the link I provided? Will it solve this GPDR requirement?
@Angeles Sánchez Gómez The same is applied for Mailchimp. Could you please check it as well?
Regards,
Tuan
Please Log in or Create an account to join the conversation.
- DMTGMBH
- Offline
- New Member
-
Less
More
- Posts: 10
- Thank you received: 1
7 years 2 months ago #112408
by DMTGMBH
Replied by DMTGMBH on topic GDPR - New European Privacy and Consent Rules!
> It's a copy of a reply to another topic, with added infos. But I think here's the right place for it, too.
The GDPR (General Data Protection Regulation) doesn't forbid the storing of IPs or personal data. If you sell products online, offer contact forms, allow users commenting or to registrate you can store personal data like name, address, ip and so on. But you must inform the user which data are stored in which way and what you will do with this. Please be aware that you ask your customer/user/visitor only for strictly necessary data, another obligatory principle of the GDPR is data minimization.
If you make a "contract" with the user in almost all - not only european - countries the constitutional laws engage you to store personal data and keep it from 3 up to 10 years. In this case the GDPR has no effects.
If you offer event registration (or any other service with registration), whether free of charge or in return for payment, I recommend you the storage of the IP. All other infos by the user can be faked, if he has access to an valid email. Only in combination of the ip and the time stamp you can protect your event booking (or any other service) against fraud. If you know the IP and the time stamp you can identify in case of fraud with the support of the ISP the physical user.
IMPORTANT: TO STORE THE FULL IP IN THE DATABASE AND ONLY NOT TO DISPLAY IN FRONTEND AND BACKEND IS NO ALTERNATIVE FOR ANONYMIZATION. IN THIS CASE YOU MUST INFORM THE USER AS DESCRIBED ABOVE.
A more better solution for all cases of identified and anonymous registration would be to implement a feature that allows you the anonymization of IPs. My suggestion is to do it in this way:
Select, how many bytes of the visitor ip should be masked:
1-byte(s), e.g. 192.168.100.xxx
2-byte(s), e.g. 192.168.xxx.xxx
3-byte(s), e.g. 192.xxx.xxx.xxx
Select, if geolaocation should use masked or full ip:
masked ip
full ip
All other fields can be setup by the extensions in compliance with the GDPR. For example in Germany it is forbidden to make phone input field required.
Best regards,
Jürgen
The GDPR (General Data Protection Regulation) doesn't forbid the storing of IPs or personal data. If you sell products online, offer contact forms, allow users commenting or to registrate you can store personal data like name, address, ip and so on. But you must inform the user which data are stored in which way and what you will do with this. Please be aware that you ask your customer/user/visitor only for strictly necessary data, another obligatory principle of the GDPR is data minimization.
If you make a "contract" with the user in almost all - not only european - countries the constitutional laws engage you to store personal data and keep it from 3 up to 10 years. In this case the GDPR has no effects.
If you offer event registration (or any other service with registration), whether free of charge or in return for payment, I recommend you the storage of the IP. All other infos by the user can be faked, if he has access to an valid email. Only in combination of the ip and the time stamp you can protect your event booking (or any other service) against fraud. If you know the IP and the time stamp you can identify in case of fraud with the support of the ISP the physical user.
IMPORTANT: TO STORE THE FULL IP IN THE DATABASE AND ONLY NOT TO DISPLAY IN FRONTEND AND BACKEND IS NO ALTERNATIVE FOR ANONYMIZATION. IN THIS CASE YOU MUST INFORM THE USER AS DESCRIBED ABOVE.
A more better solution for all cases of identified and anonymous registration would be to implement a feature that allows you the anonymization of IPs. My suggestion is to do it in this way:
Select, how many bytes of the visitor ip should be masked:
1-byte(s), e.g. 192.168.100.xxx
2-byte(s), e.g. 192.168.xxx.xxx
3-byte(s), e.g. 192.xxx.xxx.xxx
Select, if geolaocation should use masked or full ip:
masked ip
full ip
All other fields can be setup by the extensions in compliance with the GDPR. For example in Germany it is forbidden to make phone input field required.
Best regards,
Jürgen
Please Log in or Create an account to join the conversation.
- DMTGMBH
- Offline
- New Member
-
Less
More
- Posts: 10
- Thank you received: 1
7 years 2 months ago #112409
by DMTGMBH
Replied by DMTGMBH on topic GDPR - New European Privacy and Consent Rules!
Some important things:
1. The user has the right of information: If he asks, you must tell him which data about him you have stored
2. The user has the right of correction: If he asks, you must correct his data
3. The user has the right of transfer: If he asks, you must give him his data in a common format
4. The user has the right of deletion: If he asks, you must delete partial or all his data
One exception: If the data are relating to a contract, invoice, offer, active subscription and so on, they are not affected of point 2 (only for the past / existing contracts etc.) and 4.
Be aware of the obligation to keep a procedure index in which you have to document the use of personal data. You must record each use
Best regards,
Jürgen
1. The user has the right of information: If he asks, you must tell him which data about him you have stored
2. The user has the right of correction: If he asks, you must correct his data
3. The user has the right of transfer: If he asks, you must give him his data in a common format
4. The user has the right of deletion: If he asks, you must delete partial or all his data
One exception: If the data are relating to a contract, invoice, offer, active subscription and so on, they are not affected of point 2 (only for the past / existing contracts etc.) and 4.
Be aware of the obligation to keep a procedure index in which you have to document the use of personal data. You must record each use
Best regards,
Jürgen
Please Log in or Create an account to join the conversation.
Moderators: Tuan Pham Ngoc
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.