Skip to main content
christophrooms
Gainsight Employee ⭐️
inSided Product Team
February 12, 2018

How we are preparing for GDPR

Related products:CC Others
  • February 12, 2018
  • 37 replies
  • 1016 views
The EU General Data Protection Regulation (GDPR) will set a new standard for how companies use and protect EU citizens’ data. It will take effect from May 2018.

At inSided, we are working hard to prepare for GDPR, to ensure that we fulfil its obligations and maintain our transparency about data protection, i.e. information privacy citizen rights.

Our first step towards GDPR compliance was to create a new role for Rens van Dongen as Privacy Officer, in addition to his responsibilities as Information Security Officer.

I am working closely with Rens to figure out how to convert GDPR legal provisions into tangible actions. We’ve been asking lots of questions, and our customers have been asking us questions.

These tangible actions will first be focussed mainly on the right to erasure, also referred to as the right to be forgotten.

The Regulation describes erasure as the process by which information is rendered inaccessible and unusable for all relevant parties. Personal data can be erased in a number of ways, including by masking the relevant personal information, so long as the erasure is irreversible, even by the institution carrying out the erasure process. That is also known as anonymization of personal data records.

Erasing posts from a specific user from a community, so removing his profile and posts, would drastically affect the integrity and consistency of community conversations and render them unusable to transfer knowledge and help other customers. To avoid this, we will be using true anonymization to make sure we don’t have to remove public community content, while ensuring that personal data in fact will be removed where needed.

Here’s an overview of the two initiatives we we are planning to provide in our platform by May 25, 2018, the moment the regulation will be enforced by the supervising authorities.

First, we will provide the ability to ‘erase’ a user from your community. This feature will become available for moderators and community managers in Control, and will be available as a REST API. The feature will fully anonymize the user profile, by replacing the username with a random text and delete all other profile data, such as email address, avatar and custom fields that have been set by yourself. While any posts from this user will still be available, it won’t possible able to link them back to the identity of the user. We will make sure that we will anonymize this user in all the data stores of our platform that can contain personal data.

Second, we have a process in place, that will assure the removal of all community and personal data from inSided customers, within 30 days after their contract has ended and we stopped providing our services.

If you have any questions or remarks on how GDPR will impact our platform, please don’t hesitate to comment below or reach out to me. For other questions related to our Data Protection program, you can always get in touch with Rens, our Privacy Officer, by mailing privacy@insided.com.

37 replies

Ditte
Helper ⭐️⭐️
March 21, 2018
We're also starting to get questions from higher up.
Specifically around processes on how we are going to deal with users that have requested to be forgotten, what that means, and how it will look in our databases, the users profile, and toward 3rd parties on the community.
Currently rocking the Sonos Communities
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
March 22, 2018
@Jurgen and @Ditte , when you have anything more concrete, would you be able to share with us?

I will do the same after having the meeting with our Legal department 🙂
Regards, Tomás Mouton
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
March 26, 2018
Hello :)

I had the meeting with our Legal Department. Let me share with you the main conclusions so far:
  • our terms and conditions must be update considering the GDPR;
  • if the newsletter could be seen from the platform itself, none of this would be necessary;
  • once we are using the email to send a communication, we need to ask permission or tell the purpose during the sign in;
  • an opt-in/opt-out box would be ideal for the user to check or uncheck that box
@Jurgen and @Ditte , do you have any updates on your side?
@Rens, are you considering having an additional field to do the opt-in/opt-out ?
Regards, Tomás Mouton
Rens
inSided
March 27, 2018
Thanks for following up with us Tomas, and sharing your insights!

I think there must be made a clear distinction between two activities:
  1. the community platform automatically sends notification emails to alert community users about activity which relates to them. Improving the opt-out functionality in this regard is discussed above and is requested for in this topic. In my opinion, that functionality could indeed be improved from an UX perspective, however, it's GDPR compliant already as it does not relate to marketing.
  2. the community database might be exported (manually as CSV, or through the API) and used by community managers as a source of customers' contact details to send marketing newsletters, using another system, such as Mailchimp. This activity still is outside of the community platform's technical scope of supported functionality. Indeed, the user needs to provide his or her consent for wanting to receive such newsletters, in order to be compliant with the GDPR. However, asking for this consent already is possible in the community platform by setting custom registration/profile fields as radio buttons. But again, to further improve UX, a request has been made to allow for checkboxes and a more flexible registration form UI. I can absolutely see and support the functional added value in this request. But from a legal -GDPR- point of view, it's not absolutely necessary in the context of our community platform service, as Christoph explained in the ideation topic.
I hope this will help to streamline our discussions regarding email communications and GDPR, so we can properly distinguish between legal needs (this topic) and functional needs (ideation topics).

If you haven't already done so, I'd also recommend for you to vote for these two ideation topics (here and here) so we can help the product team prioritize and deliver the most value. After all, we all want to see the community grow more and more towards the center of your customer communications, so for me there's no doubt that maturing these functional possibilities, aligned with privacy law, makes a lot of sense. ☺️
This could have been your ad.
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
March 27, 2018
Thanks for following up with us Tomas, and sharing your insights!

I think there must be made a clear distinction between two activities:
  1. the community platform automatically sends notification emails to alert community users about activity which relates to them. Improving the opt-out functionality in this regard is discussed above and is requested for in this topic. In my opinion, that functionality could indeed be improved from an UX perspective, however, it's GDPR compliant already as it does not relate to marketing.


In this point I totally agree with you 🙂 Indeed, users can choose not to receive further notifications from the paltform.

Regarding the second point, what you are saying is that we can ask the user´s permission to receive the newsletter using this profile fields?



Already voted on those topics 😀
Regards, Tomás Mouton
Rens
inSided
March 27, 2018

Regarding the second point, what you are saying is that we can ask the user´s permission to receive the newsletter using this profile fields?



That's right, by adding a new profile field that's "shown on registration", you can make them choose between two radio boxes and thus actively provide consent. @Leatham actually demonstrated how that'd look in his screenshot in his ideation topic. It could be improved upon, but it works.
This could have been your ad.
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
March 27, 2018
Thanks @Rens :)

Just one final question (at least for now):
  • users can change this anytime?
Regards, Tomás Mouton
Rens
inSided
March 27, 2018
Just one final question (at least for now):
  • users can change this anytime?


Yes, such field values can be changed at any time by the users through their "my profile settings".
This could have been your ad.
Ditte
Helper ⭐️⭐️
March 29, 2018
@Rens @christophrooms Do you have more information on the process from A to Z on removing a user from the platform?

Any information on how SSO and SAML enabled communities will be able to handle this without too much hassle?
For instance someone contacts us through phone or email, but also have a community profile that the agent will need to erase.

Cheers,
Ditte
Currently rocking the Sonos Communities
Jurgen
Helper ⭐️
April 4, 2018
Related question: are any stored IP addresses related to anonimized accounts also removed from Control?