General Data Protection Regulation

Component ID

2847337

Component name

General Data Protection Regulation

Component type

module

Maintenance status

Development status

Component security advisory coverage

not-covered

Downloads

96

Component created

Component changed

Component body

This module is in active development

"After four years of preparation and debate the GDPR was finally approved by the EU Parliament on 14 April 2016. It will enter in force 20 days after its publication in the EU Official Journal and will be directly application in all members states two years after this date. Enforcement date: 25 May 2018 - at which time those organizations in non-compliance will face heavy fines." - http://www.eugdpr.org/

This module gives end user visibility to the data stored about himself/herself and aims to help site admins follows the guidelines and legislation set by the EU.

Milestone: D7 MVP

  • Allow logged in user to see all raw data stored about himself/herself (user entity)
  • Allow user to initiate “forget me” action from site admins
  • Checklist for site admin (recommend modules like cookie consent, check if there is privacy policy page etc)

Future features

  • Make sure user can rectify all data about himself/herself
  • Allow user to remove the account (content is not removed)
  • More items and recommendations to checklist
  • Add Drush hooks to sanitize data when syncing databases
  • Make API for other contrib modules to announce user data stored

Please use the issue queue for issues of feature requests.