Zen Cart Logo
Forums / General Questions / General Data Protection Rules GDPR

General Data Protection Rules GDPR

Views: 266,303

Results 41 to 60 of 177
17 Apr 2018, 8:50 PM
#41
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

General Data Protection Rules GDPR

https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en

Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.

Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the law.

Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.

17 Apr 2018, 9:16 PM
#42
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

in a certain way, this all comes down to politics losing the power to big data processors and data controllers.
And a huge amount of data anarchy using user tags, like email, id , cart connections, etc.
The internet moved from piracy to piracy.

17 Apr 2018, 10:41 PM
#43
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Money Laundering statutory requirements, as well as accounting requirements trump GDPR

Sorry, I must have been day-dreaming when I thought there were minimum thresholds for compliance because I can't fine it now but we eliminated any 'targeting' for EU sales and removed the euro as an acceptable currency.

18 Apr 2018, 8:42 AM
#44
brittainmark avatar

brittainmark

Totally Zenned

Join Date:
Apr 2009
Posts:
507
Plugin Contributions:
1

Re: General Data Protection Rules GDPR

Been trying to think this through with customer deletions.
If a customer request their record be deleted. If we remove all records from the following tables.
zen_address_book
zen_customers
zen_customers_basket
zen_customers_basket_attributes
zen_customers_wishlist
zen_files_uploaded
zen_products_notifications
zen_reviews
zen_whos_online

Not sure about coupons if they need to be kept.
zen_coupon_gv_customer
zen_coupon_gv_queue
zen_coupon_redeem_track

Could we keep the following tables intact with out breaking zen cart. This way we still hold records of the transactions and customer and shipping details.
zen_authorizenet
zen_orders

if this appears ok a delete function could be added to the My account processing.
Could also change this to hold an optin for marketing messages/newsletters.
This works for people who create an account.
Might need equivalent added to admin for people who use paypal express checkout or check out as guest (not sure if customer account is created when they checkout in this way).

18 Apr 2018, 11:31 AM
#45
brittainmark avatar

brittainmark

Totally Zenned

Join Date:
Apr 2009
Posts:
507
Plugin Contributions:
1

Re: General Data Protection Rules GDPR

Done a bit more research. It appears that if someone uses PayPal express checkout they have an account created for them (in our store) each time they use it. So Admin function to delete also needed.

19 Apr 2018, 3:15 PM
#46
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: General Data Protection Rules GDPR

brittainmark:

Been trying to think this through with customer deletions.
If a customer request their record be deleted. If we remove all records from the following tables.
zen_address_book
zen_customers
zen_customers_basket
zen_customers_basket_attributes
zen_customers_wishlist
zen_files_uploaded
zen_products_notifications
zen_reviews
zen_whos_online

Not sure about coupons if they need to be kept.
zen_coupon_gv_customer
zen_coupon_gv_queue
zen_coupon_redeem_track

Could we keep the following tables intact with out breaking zen cart. This way we still hold records of the transactions and customer and shipping details.
zen_authorizenet
zen_orders

if this appears ok a delete function could be added to the My account processing.
Could also change this to hold an optin for marketing messages/newsletters.
This works for people who create an account.
Might need equivalent added to admin for people who use paypal express checkout or check out as guest (not sure if customer account is created when they checkout in this way).

Remember that the "Delete" button for deleting a customer already handles deleting non-order-related information: https://github.com/zencart/zencart/blob/v156/admin/customers.php#L362-L414

Remember: deleting the customer record means they can no longer gain access to anything that requires a login ... including virtual purchases. Might want to inform them of that if you're entertaining such requests.

brittainmark:

Done a bit more research. It appears that if someone uses PayPal express checkout they have an account created for them (in our store) each time they use it. So Admin function to delete also needed.

Those same "accounts" are listed along with all other customer accounts, so nothing extra/special needed.

Remember: the "right to be forgotten" initiated with the problem of public social media posting, not with ecommerce transactions. With your store, the public-facing data would primarily be "product reviews", or other features you've added such as "testimonials".
Double-check with your legal team whether you're going too far with the amount of data you're considering deleting. Check also with your accountant about transaction data retention requirements, particularly if your online store is the primary record of your transactions.

27 Apr 2018, 3:25 PM
#47
heathenmagic avatar

heathenmagic

Totally Zenned

Join Date:
May 2005
Location:
England
Posts:
730
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

A lot of websites are sending email to ask to resubscribe to newsletter. Are there any implications for not doing this? I asked the newsletter people I use, even they are not sure how to proceed.

27 Apr 2018, 4:35 PM
#48
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

HeathenMagic:

A lot of websites are sending email to ask to resubscribe to newsletter. Are there any implications for not doing this? I asked the newsletter people I use, even they are not sure how to proceed.

They must have a way to opt-out. If you use ie: mailchimp, there's always a footer with your details and a unsubscribe link.
I was told today, that even if a customers agrees with with company's privacy policies, that should be renewed 1 year later. ie: cookies, etc

Another thing that I still didn't find, it's a Document that must be keap, because even if we do all correct, if we don't fill that kind of form saying what we did and why, it useless. Wich makes sense. It has to be save, recorded, somewhere.

If anyone knows the name of that form or file, please post

27 Apr 2018, 4:45 PM
#49
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

What Sage is doing on upcoming updates ( at least here for what I've been told ), it's to delete all data that it's not required to be in a invoice.
I've extended the zencart delete function, to check other tables, like rewards points, etc, it really depends on what's installed, and in the Orders, If a customer wants to delete the account, but has placed a order, I'll update the email to empty or something that the table default value accepts.

27 Apr 2018, 5:57 PM
#50
heathenmagic avatar

heathenmagic

Totally Zenned

Join Date:
May 2005
Location:
England
Posts:
730
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

mesnitu:

They must have a way to opt-out. If you use ie: mailchimp, there's always a footer with your details and a unsubscribe link.
I was told today, that even if a customers agrees with with company's privacy policies, that should be renewed 1 year later. ie: cookies, etc

Another thing that I still didn't find, it's a Document that must be keap, because even if we do all correct, if we don't fill that kind of form saying what we did and why, it useless. Wich makes sense. It has to be save, recorded, somewhere.

If anyone knows the name of that form or file, please post

Thanks for that. I don't use mailchimp, but I will have to see if I can put something in the footer

2 May 2018, 7:38 AM
#51
darkmen avatar

darkmen

New Zenner

Join Date:
Jan 2013
Posts:
45
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Has anyone solved complications with GDPR? I solve this for a long time now, and I still don't have a complete solution, just minor modifications.
I'm looking for a module or someone who will be able to solve the problem of customer deletion + all the links with. Please for info, thanks in advance.

2 May 2018, 8:10 AM
#52
mesnitu avatar

mesnitu

Totally Zenned

Join Date:
Aug 2014
Location:
Lisbon
Posts:
597
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

@DarkMen,
Really depends on your site data collection , etc.
For cookies opt-in : there is a "free" script from One trust ( just in english last time I saw) . But if you need more, perhaps you'll have to pay.
Is it worth it or not ? Depends on your site sales, etc.

The one from cookie consent can be altered also , but it takes some work, etc...

Deleting a customers: Zencart already does that, the only issue is on orders. I've opt to update the customers data that I don't need for a invoice. Also you must check other tables ( additional modules that may have customers info).
There is a post here in this thread where you have a way to do this in the account files. Perhaps it's a start.

13 May 2018, 11:47 AM
#53
andy_c27 avatar

andy_c27

Zen Follower

Join Date:
Oct 2010
Location:
United Kingdom
Posts:
477
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Hey all is there a way to add a memorable question to the sign in forms with FEC that we can see on their account ..Both account and non account, it's so we can prove it is really them and not someone else ..It's 1 of the GDPR requirements.
I've got the delete account sorted as it can be done

Also got to add a data capture form on website ,but can't exactly remember what I was told so need to check on that

14 May 2018, 12:08 PM
#54
marton_1 avatar

marton_1

Totally Zenned

Join Date:
Apr 2013
Location:
eglisau switzerland
Posts:
568
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

mesnitu:

What Sage is doing on upcoming updates ( at least here for what I've been told ), it's to delete all data that it's not required to be in a invoice.
I've extended the zencart delete function, to check other tables, like rewards points, etc, it really depends on what's installed, and in the Orders, If a customer wants to delete the account, but has placed a order, I'll update the email to empty or something that the table default value accepts.

Standard Zen Cart emails have EMAIL_DISCLAIMER in every email footer, Why not simply add a suitable sentence there? It is defined in emailextras.php to be found in includes/languages/[language]/

14 May 2018, 9:59 PM
#55
andy_c27 avatar

andy_c27

Zen Follower

Join Date:
Oct 2010
Location:
United Kingdom
Posts:
477
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

That's actually not a bad idea ... Once the order is completed..Well I send a final email , you could also add would you like to delete account yes / no

15 May 2018, 5:33 AM
#56
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: General Data Protection Rules GDPR

Andy-C27:

Hey all is there a way to add a memorable question to the sign in forms with FEC that we can see on their account ..Both account and non account, it's so we can prove it is really them and not someone else ..It's 1 of the GDPR requirements.
Are you saying somebody has told you that GDPR requires that you add a "please tell us your mother's maiden name" question that you force everyone to answer every time they login?

15 May 2018, 2:34 PM
#57
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Question for the GDPR knowledgeable folks...

How does "Canvas Fingerprinting" relate to GDPR since it identifies a specific piece of hardware (computer, tablet, phone, etc) and then has ability to track that hardware presence across the internet in a seemingly more intrusive manner than a cookie? But since it does not identify a person or any PII, does that make a Canvas Fingerprint OK in terms of GDPR?

Not trying to open a can of worms but I am seeing more canvas fingerprinting popup notices and some websites actually stop working if fingerprinting is blocked or if a fake fingerprint is transmitted.

16 May 2018, 3:55 PM
#58
ryk avatar

ryk

Totally Zenned

Join Date:
Oct 2004
Location:
Southport, UK
Posts:
3,644
Plugin Contributions:
6

Re: General Data Protection Rules GDPR

@Darkmen

Please PM me if you still need help.

17 May 2018, 11:58 PM
#59
ryk avatar

ryk

Totally Zenned

Join Date:
Oct 2004
Location:
Southport, UK
Posts:
3,644
Plugin Contributions:
6

Re: General Data Protection Rules GDPR

To summarise the essentials of GDPR ....your users must

give **Explicit Consent** for you to use their data for the purposes you intend,
have **Access** to their information and
have the **Option to remove** their information.

Zencart has Consent (you may need to set admin> configuration > regulations ...Confirm Privacy Notice During Account Creation Procedure to true) and Access (through My Account) in place while the Option to Remove exists in the sense that the user must inform you that they want to have their data removed upon which you can delete their account from admin > customers > customers, but there is not really the clear guidance that GDPR demands.

Giving consent extends to your existing clients, so they need to have the opportunity to review and Accept/Decline your privacy policy.

So we've added 2 new links in My Account for** Review and accept privacy statement** and Delete My account.

The former takes the user to a page which displays the contents of admin > tools > define_pages_editor...define_privacy.php, with buttons to Accept or Decline. If they Accept, they continue with whatever they were doing, but if they decline, they are logged out and taken to a page which explains why, and lets them know they can log back in and change their mind, otherwise their account will be deleted.

Whichever decision they make, the date is recorded in the database and a flag also set to show the decision. These flags can then be used by those with appropriate skills to identify and automatically delete accounts. You would need to action Delete Requests manually via admin > customers > customers where, as a reminder, deleting the customer does not delete their past orders which you are legally required to retain in the UK by HMRC for 6 years.

It would also be necessary to email your existing customer base to invite them to visit the site and login to update their preferences.

Admin functions

You can specify the email address to which the Delete requests are sent.
Should you need to modify your privacy statement and require people to re-consent, you can reset so that the client will have to review the privacy on their next login.
The date of acceptance (or otherwise) displays in the customer info page.
There is a sortable and "searchable by email" display of all those who HAVE accepted

This manual version of our GDPR package for Zencart was written for ZC155 (although it will work on older) and for now you can download it from http://jsweb.uk/gdpr_service/gdpr4zc.zip as we haven't had time yet to meet the documentation requirements for submitting to the plugins section.

19 May 2018, 7:29 PM
#60
andy_c27 avatar

andy_c27

Zen Follower

Join Date:
Oct 2010
Location:
United Kingdom
Posts:
477
Plugin Contributions:
0

Re: General Data Protection Rules GDPR

Thank you will use your package ...
Re** memorable question** I have been advised to have this option as it can prove who you are if you actually want your details known or not.. Don't blame me I'm just trying to do what I have been advised to do by a legal advisor...Apparently if you have a account and you separate your partner or who ever cannot access your account without knowing the memorable password

Apparently we are also suppose to have a data capture form on website ..

I personally do not want all this, so if anyone can advise that would be great