Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suspected violation of the GDPR #20720

Open
Hu1buerger opened this issue Jul 26, 2022 · 4 comments
Open

Suspected violation of the GDPR #20720

Hu1buerger opened this issue Jul 26, 2022 · 4 comments
Labels
kind/feature Categorizes issue or PR as related to a new feature.

Comments

@Hu1buerger
Copy link

Dont be alarmed but i do find it important to point out this issue.

Summary

The personal data handled by mattermost are not exportable, violating the GDPR for all systems deployed in or with the eu / eu citizens.

Expected behavior

As per art. 25 in conjunction with 15 and 12ff GDPR the controller shall make the subjects data available. Art 25 enforces the controller to design his* technology in a way that furthers the dataprotection. And art 12 2. states The controller shall facilitate the exercise of data subject rights under Articles 15 to 22 .

Therefore the gdpr implies that in case of mattermost the user should be able to download their data electronicaly and or in a machine readable format i.e. json, as this reduces the need for documentation, and pdf as users might not be as tech savy.

Observed behavior (that appears unintentional)

see #20719 for an example of this issue.

Possible fixes

As stated

@Hu1buerger Hu1buerger closed this as not planned Won't fix, can't repro, duplicate, stale Jul 29, 2022
@Hu1buerger Hu1buerger reopened this Aug 10, 2022
@Hu1buerger
Copy link
Author

As #20719 was closed as unplaned, and i do suspect a violation of the gdpr, i am asking for a second review.

@amyblais
Copy link
Member

I asked our team about this and they mentioned that we do have APIs that should enable people to get their user data from our platform. Does this help, or do you have additional questions?

@Hu1buerger
Copy link
Author

I asked our team about this and they mentioned that we do have APIs that should enable people to get their user data from our platform. Does this help, or do you have additional questions?

Jep this kinda helps but as I already mentioned, any user shall have the ability to export their data easily. And as most of the data subjects do not hold the ability to export with an API, and mostly because of other reasons, the gdpr mandates a export functionality that is accessible by any user (and in this case by the web and app ui).

Therefore I strongly believe this feature is required.

@amyblais
Copy link
Member

Thank you @Hu1buerger, would you like to share this in our feature idea forum here? Please include a link back to this GitHub issue. If you're interested in implementing the feature and submitting a pull request, please let us know.

@amyblais amyblais added the kind/feature Categorizes issue or PR as related to a new feature. label Aug 12, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature.
Projects
None yet
Development

No branches or pull requests

2 participants