Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| shared:privacy_setup [2021/12/08 11:20] – ggmei | shared:privacy_setup [2022/03/08 18:50] (current) – ggmei | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Privacy Setup ====== | + | ====== Privacy Setup (DRAFT) |
| - | There are several components to be compliant with the GDPR rules, three of which of clear application: | + | The scope of the [[https:// |
| - | | + | |
| - | | + | Some of this processing happens on the website, which has to be compliant with the law. Three elements are strictly needed: |
| - | and two that are less clear about if and how they are required: | + | |
| + | - The design of the website must be compliant | ||
| + | | ||
| + | | ||
| + | |||
| + | There are also two further elements | ||
| * [[# | * [[# | ||
| * [[# | * [[# | ||
| - | |||
| - | This is how they can be addressed. | ||
| ==== Privacy and Cookie policies ==== | ==== Privacy and Cookie policies ==== | ||
| - | References: | + | These policies are meant to give transparency about the data treatments. |
| - | * [it] https://www.iubenda.com/ | + | |
| - | * [en] | + | |
| + | **What to do**: the company can provide their texts, or both policies can be automatically generated by Cone with Iubenda. In both cases, the responsibility of the legal compliance lies on the company, which must control and approve the policies and keep them updated (directly, via third-party services, or via Cone). | ||
| - | Examples: | + | **Costs**: if the company provides the policies, then they are just editorial content and there is no cost. If Cone sets them up with a third-party service, for each language of the website there is an extra annual fee, which includes Cone and third-party' |
| - | | + | |
| - | * [[https:// | + | |
| - | These policies contain transparency information and list the data treatments. | + | References: |
| + | * [it] https://www.iubenda.com/ | ||
| + | * [en] https:// | ||
| - | **What to do**: the company can provide their own, or both can be automatically generated with Iubenda by Cone. In both cases, the responsibility lies entirely on the company, which must control | + | Examples: |
| - | + | | |
| - | **Costs**: if the company provides them they are just editorial content, | + | * separated pages [[https:// |
| ==== Cookie consent ==== | ==== Cookie consent ==== | ||
| - | https:// | + | The //cookie law// exists since before the GDPR and complements it (see [[https:// |
| - | https:// | + | **What to do**: a law-compliant banner must be shown to the user before the navigation starts to block any tracking cookie installation (e.g. YouTube, marketing platforms, ...), provide detailed information, |
| + | |||
| + | **Cost**: extra on the annual fee, which includes Cone and third-party' | ||
| + | |||
| + | Iubenda' | ||
| + | * [it] https:// | ||
| + | * [en] https:// | ||
| ==== Cookie preference log ==== | ==== Cookie preference log ==== | ||
| Line 37: | Line 45: | ||
| Registro Preferenze Cookie | Registro Preferenze Cookie | ||
| + | https:// | ||
| ==== Record of consents ==== | ==== Record of consents ==== | ||
| + | It is also a broad requirement to keep a record of all the given consents. How this applies to the website processing in general is less clear. | ||
| + | |||
| + | One approach is to keep a record of a case by case processing, such as: | ||
| + | * keep a screenshot of the information and registration forms | ||
| + | * keep a list of registration and information requests with date and IP | ||
| + | * see case by case for every other service used (newsletters, | ||
| + | |||
| + | There are on the market also systems to cover this organically (see for example [[https:// | ||
| + | |||
| + | **Cost**: extra on the annual fee | ||
| + | |||
| + | |||
| + | ==== GDPR references ==== | ||
| + | * Iubenda on GDPR and other privacy laws [it] https:// | ||
| + | * Frequent cases (blog, ecommerce, newsletter) [it] https:// | ||