Another GDPR Issue! Member Hiding Their Details

4 months 3 weeks ago #304885 by bins
Whilst we run a membership organisation for business people to connect, do business etc, we have had a few questions about authority to publish member details in a list.

Our member list is only available to other members, however, is there a way to hide members details from the list? They can already select which bits are published but getting them to confirm initial publication (i.e. switch listing & profile on/off) would be extremely GDPR compliant.

I have been looking around and am sure this feature exists or can be created, but cannot find out how to do this. Anyone with pointers?
4 months 3 weeks ago - 4 months 3 weeks ago #304886 by krileon
You can use CB Privacy and its profile privacy field, which will hide them from userlists as well. If you mean to just be excluded from specific userlists you can create a checkbox field then add a filter to your userlist to not show anyone that doesn't have the field checked or does have it checked.

With that said I believe you've a misunderstanding of GDPRs "Privacy by Design", which has actually nothing to do with forward facing aspect of your site and everything to do with the security of their data (e.g. no exposing passwords to others, no plain text stored passwords, plain text stored credit card numbers, or other plain text stored highly sensitive personal data). You do not have to offer them an option to be excluded from your userlist. You don't have to offer them privacy selection options on the forward facing aspect of your site at all in fact. This is covered in my blog below, which I highly recommend everyone read.

www.joomlapolis.com/blog/kyle/18788-gdpr-compliance-with-community-builder


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Templates - CBSubs - Hosting - Forge - Incubator - GroupJive
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM EST to 4:00 PM EST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.
The following user(s) said Thank You: mikerotec
4 months 3 weeks ago #304889 by bins
Kyle,

thanks for the confirmation.

There is some interpretation needed in the guidelines and it is more about giving members choice. No one ever congratulates you for doing a good job (unless it is you guys, here!), but, give someone the chance to complain and BANG!
The following user(s) said Thank You: nant, krileon
4 months 3 weeks ago #304924 by bins
Kyle,

we are being advised to take a strong & cautious approach to member details (it maybe overkill, but we want to very 'clean' with GDPR).

Is there an easy way to move everyone to Profile Privacy 'Private'? I have been looking at amending everyone on the db, but cannot see which field to change. Ideally, I would to not touch the db, but if I have to, can you advise what to change?
4 months 3 weeks ago #304925 by krileon
Again, you do not have to do that. That is not what GDPR is about. Will making everyone's profile private defeat the purpose of your site? Is it not clear what is visible (the visible on profile icon is satisfactory for this disclosure)? Your members will no longer be able to see each others profiles in any way. This again is not necessary to be GDPR compliance as explained above and in my blog.

With that said delete all the profile.USER_ID privacy rules within backend CB Privacy > Privacy and set the Profile Privacy fields default to Private. This will force everyone, new and existing, profiles to private.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Templates - CBSubs - Hosting - Forge - Incubator - GroupJive
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM EST to 4:00 PM EST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.
Moderators: beatnantkrileon
Time to create page: 0.403 seconds
Facebook Twitter Google LinkedIn