PSA - Lemmy is not GDPR-compliant

https://github.com/LemmyNet/lemmy-ui/issues/1347

Hey, just went through a few different checklists, and discovered that Lemmy does not meet GDPR requirements for notifying users for how servers handle the data. I've brought up this request on github, and I hope to get it fixed soon, but in the meantime I've compiled a list of EU address blocks and intend to add them to my firewall. Just thought you all should know.

7 points · 6 comments · view on lemmy.world

6 Comments

sinnerdotbin@lemmy.ca · 2 pts · 3y

I have had this concern for a few days and adapted the Mastodon privacy policy (adapted from the Discourse policy) and published it https://github.com/BanzooIO/federated_policies_and_tos/blob/main/lemmy-privacy-policy.md

Discussion on this has been started: https://lemmy.ml/post/1431759 and https://lemmy.ml/post/1431930. Open to any recommendations

RoundSparrow@lemmy.ml · 1 pts · 3y (3 replies)

There is also not a "cookie accept" when you first visit the site that is now standard convention.

sunaurus@lemm.ee · 9 pts · 3y (1 reply)

That's because Lemmy does not use tracking cookies! Lemmy only uses one authentication cookie, cookies such as these do not require user consent (at least under the GDPR). More info: https://gdpr.eu/cookies/

RoundSparrow@lemmy.ml · 1 pts · 3y

Cool, thank you.

mrwiggles@prime8s.xyz · 7 pts · 3y

I was told by the owner of Beehaw that login cookies are excluded from the cookie dialog requirement, and Lemmy doesn't use tracking cookies which are subject to the requirement.