In this lunchtime #WPQuickies, I talk about WordPress privacy tools for users.
Private data includes but is not limited to things like users’ name, email, phone, physical and IP addresses etc.
You may also be required to provide your users with the means to request a copy of the information you hold about them, or request its deletion.
This is certainly the case for the 2018 General Data Protection Regulation (GDPR) European law. So if you specifically target users that reside in the EU, your sire will need to be GDPR compliant. Here’s a link to what GDPR is all about https://en.wikipedia.org/wiki/General_Data_Protection_Regulation
From the WordPress dashboard navigate to Settings > Privacy.
Headings such as: Contact Forms, Cookies, Analytics, Data Retention, Where We Send Your Data, Where We Store Your Data
If you are looking for a more legal document but don’t have the money to hire a lawyer to put one together I suggest using Lawpath https://lawpath.com.au/ They have specific legal documents for Australia and New Zealand and you get one free document on registering.
Exporting User Data
From the WordPress dashboard navigate to Tools > Export Personal Data
The process here is to send an email to the person requesting the data for their verification.
Once they have verified their email address, you can download a zip file of their user data from your site and email it to them.
A link is also sent to the verified email so they can download the data themselves..
The data is stored in a .json file.
Remember that the data is only from within WordPress and participating plugins – there is likely more information you store about the user on your website.
Erasing User Data
From the WordPress dashboard navigate to Tools > Erase Personal Data
The process here is similar to the previous exporting user data, where you should verify the requesters email address first before erasing any personal data.
An administrator must manually approve the request to remove the data in question.
Deleted data is permanently removed from the database. Erasure requests cannot be reversed after they have been confirmed.
Note that it does not remove the data from backups or archive files so if you do restore a backup, please respect any data removal requests and redo them.
Again this only removes user data from WordPress and participating themes and plugins.
This tool does not delete registered users or their user profile – an administrator will have to manually delete the user from the Users dashboard area.
Also, note that a site administrator is not obliged to delete data that they may be required to keep for other legal or statutory reasons; tax on sales, or investigations etc.
Consent To Do/Store/Process…
User some national and international regulations you may be legally obliged to explicitly ask a user for their consent before you do or store or process their personal information.
e.g. for storing cookies – cookie bar, or submitting a contact form.
WordPress doesn’t have this ability built into core because its application can vary depending on what you are trying to achieve.
There are heaps of plugins out there that deal with GDPR, cookie and other consents.
It is considered best practice, however, to include a consent box on all your forms – a simple checkbox with the words “I consent to my submitted data being collected and stored” would cover the basics of consent.
Join me every Thursday at 1 pm Sydney time for some more WPQuickies – WordPress tips and tricks in thirty minutes or less.
Broadcasting live on YouTube and Facebook.
Suggest a #WPQuickies Topic
If you have an WordPress topic you’d like to see explained in 30 mins or under, fill out the form below.