Forums

GDPR for Clans

Quick find code: 86-87-496-65996603

Roving
Jan Member 2019

Roving

Posts: 3,523 Adamant Posts by user Forum Profile RuneMetrics Profile
Hi all

Been a while!

Just thought that you should know about the GDPR that's coming in May, should you keep data about people - be that in the form of clan admin records/notes or forum accounts.

To be honest, this isn't something to worry anybody and most RS players probably won't care about this, but it covers your back in case a bad egg does try to kick off.

Going to put a disclaimer here to say that this is just through the training I've received at work in the UK. If someone here is more legally advanced and has a better view, probably take their word for it.
:P

GDPR is a data protection regulation coming in and applies to organisations that interact with the population of the EU - That's probably you. I'm going to leave out all of the regulations as they're quite thorough and just run through some scenarios that apply to clan admin. Here's an in-depth from the Information Commissioner's Office in the UK: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/

So... Clans

1. Obtaining explicit consent
- In order to have someone sign up to your clansite/offsite forums, you need to make sure that they know what you do with the sign up information. This includes who looks after the information and what you do with it.

- If you have an email newsletter, people need to explicitly agree to you sending them emails via opt-in. Most forum softwares have this now.

- If you run an Invision Power Board forum, there are a few tools (https://invisioncommunity.com/news/product-updates/how-invision-communitys-tools-can-help-with-gdpr-compliance-r1052/) in the last couple of updates that helps you with this. You should probably get people to re-agree to the terms and conditions of your website and copy/paste a GDPR template into your terms of service.
Roving @mrm­jprice |
Spirits of Arianwyn
@SoA_RS |
RuneFest 2010-16

11-Mar-2018 12:17:46 - Last edited on 11-Mar-2018 12:36:46 by Roving

Roving
Jan Member 2019

Roving

Posts: 3,523 Adamant Posts by user Forum Profile RuneMetrics Profile
2. Right to be forgotten
- People can ask for their data to be deleted where there is no compelling reason for you to continue processing the data.

- In this context, you probably only need to delete their account on clan sites, which most software providers will allow you to do. More often than not, you delete the member and move posts to a random account name or anonymous user account.

- I would argue that if you have some notes about individuals in your private staff forums, you could keep these. If they're leaving the clan, it could be of their own accord or they might be a pain in the arse. If the latter, you probably want some notes to refer back to if they want to join your clan in future. It's in the interest of your clan for you to have these notes to refer back to.

--------------

I think that these two points are the main ones that affect clans, but please post below if you've got anymore points.

- Roving
Roving @mrm­jprice |
Spirits of Arianwyn
@SoA_RS |
RuneFest 2010-16

11-Mar-2018 12:17:54 - Last edited on 11-Mar-2018 12:24:14 by Roving

Macka
Oct Member 2010

Macka

Posts: 4,318 Adamant Posts by user Forum Profile RuneMetrics Profile
Australia has also talked/released in March a new measure about this recently and we call it 'Protective Data Security Standards/Protective Data Security Framework' that talks about the collection, use and handling of personal information but realistically it only applies to organisations/government that deal with sensitive personal data that could potentially be used to steal someone's identity or pose a financial risk.

I recently also had to undergo this compulsory Australian government training couple weeks ago for my work that does deal with sensitive private information and I really don't think clans would be involved at all. (Because our company turns over the minimum 3million and is listed on ASX)

To be very truthful; even though the data may be deleted from one point, it is still stored on another but rest assured it still has to comply within the Act as the party could face hundred thousand to millions of dollars fine within Australia.

http://www.aon.com.au/australia/insights/are-you-ready-for-the-new-australian-data-protection-regulations.jsp
My physique is a product of my mindset

Macka#7877
-
Taiwanese Aussie Physique Bodybuilder

11-Mar-2018 13:52:27 - Last edited on 11-Mar-2018 13:54:19 by Macka

Macka
Oct Member 2010

Macka

Posts: 4,318 Adamant Posts by user Forum Profile RuneMetrics Profile
https://www.oaic.gov.au/media-and-speeches/news/general-data-protection-regulation-guidance-for-australian-businesses
My physique is a product of my mindset

Macka#7877
-
Taiwanese Aussie Physique Bodybuilder

11-Mar-2018 13:56:52

Roving
Jan Member 2019

Roving

Posts: 3,523 Adamant Posts by user Forum Profile RuneMetrics Profile
Macka said :
x


Yeah, it's good to see governments getting tough on this as data breaches can be pretty damaging across the board.

Glad to see that those regs won't affect clans, it's a shame that we couldn't have had a set of UN rules for data protection and everyone's had to go it alone. Means that people operating global sites are walking through a minefield on data protection!
Roving @mrm­jprice |
Spirits of Arianwyn
@SoA_RS |
RuneFest 2010-16

11-Mar-2018 17:43:46

Quick find code: 86-87-496-65996603 Back to Top