Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Opt-Out does not disable tracking / has no effect if IP-hashing is active #125

Closed
adlerweb opened this issue Apr 29, 2018 · 8 comments
Closed
Assignees

Comments

@adlerweb
Copy link
Contributor

At the moment we've got a way to allow users to "opt-out" (398), according to the standard Text this is supposed to affect "any future tracking".

As far as I can see the Cookie however only hashes the users IP but doesn't prevent any other information to be recorded - right? So the plugin is still tracking the user, just not recording the unhashed IP (which results in no change if hashing is enabled globally). Shouldn't at least things like Referrer, User-Agent, etc also be stripped if a no-track-cookie is present?

@mostafasoufi
Copy link
Member

As far as I can see the Cookie however only hashes the users IP but doesn't prevent any other information to be recorded - right?

Yes, That's right. Just the hashes IP address enabled in the plugin, because it is one of the GDPR criteria.

@adlerweb
Copy link
Contributor Author

adlerweb commented May 4, 2018

First of all: I am not a lawyer, just repeating things I picked up from other projects:
To be DSGVO/GDP-compliant IPs must always be anonymized when used for tracking/statistics. Additionally users must be able to fully opt-out of the tracking process. For me this sounds like the opt-out should not only enforce hashing but deactivate all recordings as far as possible.

@mostafasoufi
Copy link
Member

To be more reliable, we can apply this in the next version.

@mostafasoufi mostafasoufi self-assigned this May 5, 2018
@adlerweb adlerweb changed the title Opt-Out: What to record and what not Opt-Out does not disable tracking / has no effect if IP-hashing is active May 24, 2018
@cgogolin
Copy link

Ouch. If the information in this bug report is correct then this is a rather serious problem. It is pretty mean to trick your users into thinking they can lawfully use the plugin while in fact they cannot, as the opt out does not actually do what it is supposed to do. This is definitely not an "improvement" but a serious bug and should not be labeled "wontfix".

@cgogolin
Copy link

I see that there have been a number of updates recently. Has this been resolved so that it is now again possible to use WPStatistics in a GDPR compliant way?

@mostafasoufi
Copy link
Member

Thank you for your all comments and explanations about this problem. They will be considered in the next versions. We are trying hard to make WP Statistics GDPR compliant as soon as possible. We are going to represent our documents to explain the compliance soon.

@cgogolin
Copy link

Great that you are looking into this! I am looking forward to using WP-Statistics again once it it GDPR complaint. Please keep this issue open until the problem has actually been resolved, so that other users can see it. Thank you!

@cgogolin
Copy link

Also it would be good to remove the nofix tag, now that you are actually planing to fix this...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants