Skip to main content
christophrooms
Gainsight Employee ⭐️
inSided Product Team
February 12, 2018

How we are preparing for GDPR

Related products:CC Others
  • February 12, 2018
  • 37 replies
  • 1016 views
The EU General Data Protection Regulation (GDPR) will set a new standard for how companies use and protect EU citizens’ data. It will take effect from May 2018.

At inSided, we are working hard to prepare for GDPR, to ensure that we fulfil its obligations and maintain our transparency about data protection, i.e. information privacy citizen rights.

Our first step towards GDPR compliance was to create a new role for Rens van Dongen as Privacy Officer, in addition to his responsibilities as Information Security Officer.

I am working closely with Rens to figure out how to convert GDPR legal provisions into tangible actions. We’ve been asking lots of questions, and our customers have been asking us questions.

These tangible actions will first be focussed mainly on the right to erasure, also referred to as the right to be forgotten.

The Regulation describes erasure as the process by which information is rendered inaccessible and unusable for all relevant parties. Personal data can be erased in a number of ways, including by masking the relevant personal information, so long as the erasure is irreversible, even by the institution carrying out the erasure process. That is also known as anonymization of personal data records.

Erasing posts from a specific user from a community, so removing his profile and posts, would drastically affect the integrity and consistency of community conversations and render them unusable to transfer knowledge and help other customers. To avoid this, we will be using true anonymization to make sure we don’t have to remove public community content, while ensuring that personal data in fact will be removed where needed.

Here’s an overview of the two initiatives we we are planning to provide in our platform by May 25, 2018, the moment the regulation will be enforced by the supervising authorities.

First, we will provide the ability to ‘erase’ a user from your community. This feature will become available for moderators and community managers in Control, and will be available as a REST API. The feature will fully anonymize the user profile, by replacing the username with a random text and delete all other profile data, such as email address, avatar and custom fields that have been set by yourself. While any posts from this user will still be available, it won’t possible able to link them back to the identity of the user. We will make sure that we will anonymize this user in all the data stores of our platform that can contain personal data.

Second, we have a process in place, that will assure the removal of all community and personal data from inSided customers, within 30 days after their contract has ended and we stopped providing our services.

If you have any questions or remarks on how GDPR will impact our platform, please don’t hesitate to comment below or reach out to me. For other questions related to our Data Protection program, you can always get in touch with Rens, our Privacy Officer, by mailing privacy@insided.com.

37 replies

Jurgen
Helper ⭐️
April 5, 2018
And also private messages sent by the user to a moderator that may contain personal information.

Unfortunately, Insided may "replace the username with a random text and delete all other profile data". But if there's any way to retrieve any personal information linked to these 'random text' accounts this counts as pseudonimization not anonymization.
christophrooms
Gainsight Employee ⭐️
inSided Product Team
April 5, 2018
And also private messages sent by the user to a moderator that may contain personal information.

Unfortunately, Insided may "replace the username with a random text and delete all other profile data". But if there's any way to retrieve any personal information linked to these 'random text' accounts this counts as pseudonimization not anonymization.



Private messages will be deleted. So the moderator will also not be able to see these messages anymore. So the moderator should not be able based on the private messages be able to identify the user.
christophrooms
Gainsight Employee ⭐️
inSided Product Team
April 5, 2018
Related question: are any stored IP addresses related to anonimized accounts also removed from Control?


IP addresses are also removed from our system, if possible immediately. There are a few use cases where we remove the IP addresses not immediately but within a specific period. For example, we store IP addresses in our log files for defect and threat detection. We need to be able to trace back what happened in the community in case of misbehaviour. We will keep these log files for 180 days.
christophrooms
Gainsight Employee ⭐️
inSided Product Team
April 5, 2018
@Rens @christophrooms Do you have more information on the process from A to Z on removing a user from the platform?

Any information on how SSO and SAML enabled communities will be able to handle this without too much hassle?
For instance someone contacts us through phone or email, but also have a community profile that the agent will need to erase.

Cheers,
Ditte


We will provide both an API and an option in Control to remove a user.

When you are using SSO, it probably makes most sense to use our API to remove a user.
Ditte
Helper ⭐️⭐️
April 13, 2018
Hi guys,

Sonos is going live with a new privacy statement to our end-users by April 24th, so we're expecting a few customers wanting to exercise their right to be forgotten already then.

Any news on the API and process? Will you be sending an email with documentation and instructions that we can share internally with the people that need to include these processes? Who can our privacy officers reach out to for technical support for the integration of the api?

Thanks in advance :)

Ditte
Currently rocking the Sonos Communities
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
April 13, 2018
Hi @Ditte,

Could you please share the new privacy statement? I am currently working with the legal department in order to review ours terms and conditions and yours may help us 😇
Regards, Tomás Mouton
Ditte
Helper ⭐️⭐️
April 13, 2018
Hi @Ditte,

Could you please share the new privacy statement? I am currently working with the legal department in order to review ours terms and conditions and yours may help us 😇


I would if I could, @tomasmouton ! :D
I'm talking about the overall Sonos corporate privacy statement, though. 🙂
We don't currently have anything in the works to change the T&C for the community, but thanks for the reminder!
Maybe InSided has some inspiration for us?

Best,
Ditte
Currently rocking the Sonos Communities
tomasmouton
Contributor ⭐️⭐️⭐️⭐️
April 13, 2018
I totally understand you! We are also reviewing all the privacy statement (we already have a landing page taliking about 8 points of the new regulation).

Regarding the terms and conditions, our legal staff is making the adjustments needed!

Yes, it would be great to have some advices from Insided 🤓
Regards, Tomás Mouton
christophrooms
Gainsight Employee ⭐️
inSided Product Team
April 13, 2018
@Ditte I hope to share with you by the end of this month the documentation of the API. Expect that we will deliver API by mid May.
Ditte
Helper ⭐️⭐️
April 13, 2018
Thanks @christophrooms
And if we have a user that want to be forgotten in the meantime, will there be a work-around?

Best,
Ditte
Currently rocking the Sonos Communities