Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| shared:privacy_setup [2021/12/08 11:50] – ggmei | shared:privacy_setup [2022/03/08 18:50] (current) – ggmei | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Privacy Setup ====== | + | ====== Privacy Setup (DRAFT) |
| - | There are several components to make a website compliant with the GDPR rules, three of which of clear application: | + | The scope of the [[https:// |
| - | | + | |
| - | | + | Some of this processing happens on the website, which has to be compliant with the law. Three elements are strictly needed: |
| - | and two that are less clear about if and how they are required: | + | |
| + | - The design of the website must be compliant | ||
| + | | ||
| + | | ||
| + | |||
| + | There are also two further elements | ||
| * [[# | * [[# | ||
| * [[# | * [[# | ||
| - | |||
| - | This is how they can be addressed. | ||
| ==== Privacy and Cookie policies ==== | ==== Privacy and Cookie policies ==== | ||
| These policies are meant to give transparency about the data treatments. | These policies are meant to give transparency about the data treatments. | ||
| + | |||
| + | **What to do**: the company can provide their texts, or both policies can be automatically generated by Cone with Iubenda. In both cases, the responsibility of the legal compliance lies on the company, which must control and approve the policies and keep them updated (directly, via third-party services, or via Cone). | ||
| + | |||
| + | **Costs**: if the company provides the policies, then they are just editorial content and there is no cost. If Cone sets them up with a third-party service, for each language of the website there is an extra annual fee, which includes Cone and third-party' | ||
| References: | References: | ||
| Line 22: | Line 29: | ||
| * separated pages [[https:// | * separated pages [[https:// | ||
| - | **What to do**: the company can provide their texts, or both policies can be automatically generated by Cone with Iubenda. In both cases, the responsibility of the legal compliance lies on the company, which must control and approve the policies and keep them updated (directly or through Cone). | + | ==== Cookie consent ==== |
| - | **Costs**: if the company provides them they are just editorial content, | + | The //cookie law// exists since before |
| - | :!: list typical services | + | **What to do**: a law-compliant banner must be shown to the user before the navigation starts to block any tracking cookie installation (e.g. YouTube, marketing platforms, ...), provide detailed information, |
| - | :!: add the legal text for mentioning | + | **Cost**: extra on the annual fee, which includes |
| + | |||
| + | Iubenda' | ||
| + | * [it] https:// | ||
| + | * [en] https:// | ||
| - | ==== Cookie | + | ==== Cookie |
| - | * Cookie | + | Registro Preferenze |
| - | * [it] https:// | + | |
| - | * [en] https:// | + | |
| + | https:// | ||
| + | ==== Record of consents ==== | ||
| - | https://www.iubenda.com/ | + | It is also a broad requirement to keep a record of all the given consents. How this applies to the website processing in general is less clear. |
| - | https://www.iubenda.com/ | + | One approach is to keep a record of a case by case processing, such as: |
| + | * keep a screenshot of the information and registration forms | ||
| + | * keep a list of registration and information requests with date and IP | ||
| + | * see case by case for every other service used (newsletters, | ||
| - | ==== Cookie preference log ==== | + | There are on the market also systems to cover this organically (see for example [[https:// |
| - | Registro Preferenze Cookie | + | **Cost**: extra on the annual fee |
| - | ==== Record of consents ==== | ||
| + | ==== GDPR references ==== | ||
| + | * Iubenda on GDPR and other privacy laws [it] https:// | ||
| + | * Frequent cases (blog, ecommerce, newsletter) [it] https:// | ||