Membership Pro and the new GDPR regulations

More
7 years 1 month ago #112790 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Membership Pro and the new GDPR regulations
Yes, I saw that, actually, I watch Joomla development very closely. Still need to finish few things here and then starting next week, I will look at GPDR requirement. Yes, I am in favor of having the extension works with the core, however, I am afraid of it might be too late (I don't think the core can come up with a solution before 25th this month), so I will look at other options as well

Someone mentioned that this third party extension storejextensions.org/extensions/gdpr.html is compatible with GPDR and support Membership Pro, too

Tuan

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112812 by Christian Jull
Replied by Christian Jull on topic Membership Pro and the new GDPR regulations
From what I've seen quite widely, a single checkbox to accept the privacy policy (which needs to be GDPR compliant, of course) should cover most things. As mentioned, the GDPR extension now incorporates Membership Pro and solves this (I also use this excellent extension). I haven't checked it's ability to delete account info though.

However, as there is MailChimp integration in Membership Pro, there needs to be a checkbox to agree to subscription to that. Also, there DEFINITELY needs to be a setting for double opt-in (where a confirmation email is sent by MailChimp with a verification link for the subscriber to confirm). This currently doesn't happen and breaks the *existing* EU data protection requirement, let alone GDPR. Without this, MailChimp integration is useless to your EU customers.

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112835 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Membership Pro and the new GDPR regulations
Hi Christinan

1. For a single checkbox to accept the privacy policy option, could you please attach a screenshot of how it should work so that I can understand the requirement better? Seem like the terms and conditions checkbox? Mean just need another checkbox?

2. For Mailchimp, I am going to look at it and get it improved to have it compatible with new rule

Regards,

Tuan

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112836 by Christian Jull
Replied by Christian Jull on topic Membership Pro and the new GDPR regulations
The GDPR extension adds this checkbox and won't allow form processing until it is checked. The text links to the privacy policy. Ideally, the checkbox needs to be with the T&Cs checkbox, but extension limitation won't allow it here.



As you can see, I have added additional text for MailChimp. This currently isn't correct, as MSP bypasses double opt-in. A checkbox is also needed and MailChimp subscription should only be sent if it's checked.

The new GDPR is not very friendly to companies that like to opt people into things they didn't specifically say they wanted. And that's why we have the GDPR... :dry:
Attachments:

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112837 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Membership Pro and the new GDPR regulations
So as I can see, there are two things we should implement first;

1. Add option to allow enable showing Privacy Policy checkbox?

2. Add option to allow choosing whether users want to join newsletter?

Is that correct? If so, the first two items can be implemented easily and available sometime next week

Tuan

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112842 by Christian Jull
Replied by Christian Jull on topic Membership Pro and the new GDPR regulations
I can't speak for others' requirements, but these two are certainly a good start. Along with double opt-in for the newsletter. Without double opt-in we can't legally use it in the EU (there needs to be written proof that someone consented to sign-up).

I would also add that the Privacy Policy checkbox may benefit from customisable text and needs to link to the policy page. Linking to a page would also be a good option for the T&Cs rather than a modal. A modal for more info about the newsletter might be good too.

This explains MailChimp's GDPR preparations: kb.mailchimp.com/accounts/management/abo...rotection-regulation

This explains double opt-in: kb.mailchimp.com/lists/signup-forms/about-double-opt-in

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112871 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Membership Pro and the new GDPR regulations
OK. So I just have basic implementation for this requirement:

1. Added a new section in Configuration to allow changing related GDPR settings



2. On subscription form, display options which:

- Force users to agree to privacy policy of configured
- Allow users to choose whether they want to subscribe to newsletter



3. Adding users to newsletter only processed if:

- Users agree to subscribe
- double opt-in is implemented for Mailchimp plugin

Could you please take a look to see whether it is OK to have system works like that?

Regards,

Tuan
Attachments:

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112872 by Christian Jull
Replied by Christian Jull on topic Membership Pro and the new GDPR regulations
To me it looks awesome, but I'd need to see it in place and test it when the new version is ready. :)

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112873 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Membership Pro and the new GDPR regulations
You can submit a support ticket and I will send you updated version when it's ready? Working on some small clean up at the moment

Tuan

Please Log in or Create an account to join the conversation.

More
7 years 1 month ago #112874 by Christian Jull
Replied by Christian Jull on topic Membership Pro and the new GDPR regulations
Done.

Please Log in or Create an account to join the conversation.