Hey, just went through a few different checklists, and discovered that Lemmy does not meet GDPR requirements for notifying users for how servers handle the data. I've brought up this request on github, and I hope to get it fixed soon, but in the meantime I've compiled a list of EU address blocks and intend to add them to my firewall. Just thought you all should know.
PSA - Lemmy is not GDPR-compliant
https://github.com/LemmyNet/lemmy-ui/issues/1347
6 Comments
sinnerdotbin@lemmy.ca · 2 pts · 3y
I have had this concern for a few days and adapted the Mastodon privacy policy (adapted from the Discourse policy) and published it https://github.com/BanzooIO/federated_policies_and_tos/blob/main/lemmy-privacy-policy.md
Discussion on this has been started: https://lemmy.ml/post/1431759 and https://lemmy.ml/post/1431930. Open to any recommendations
RoundSparrow@lemmy.ml · 1 pts · 3y
There is also not a "cookie accept" when you first visit the site that is now standard convention.
sunaurus@lemm.ee · 9 pts · 3y
That's because Lemmy does not use tracking cookies! Lemmy only uses one authentication cookie, cookies such as these do not require user consent (at least under the GDPR). More info: https://gdpr.eu/cookies/
RoundSparrow@lemmy.ml · 1 pts · 3y
Cool, thank you.
mrwiggles@prime8s.xyz · 7 pts · 3y
I was told by the owner of Beehaw that login cookies are excluded from the cookie dialog requirement, and Lemmy doesn't use tracking cookies which are subject to the requirement.