GDPR checklist for community platforms
Running a community platform or an intranet makes your organization the controller of your members' personal data. This checklist lists what the GDPR expects of you, what your hosting provider must provide, and exactly what CUZY provides, no more.
1. Know who is responsible for what
- Controller: the organization that runs the community. It decides why members' data is collected, who sees it and how long it is kept.
- Processor: the hosting provider. It stores and protects the data and acts only on the controller's instructions (GDPR Article 28).
- Sub-processors: the providers the host relies on (data centers, backup storage, email delivery). The host must list them and tell you before changing them.
2. Check what your host must provide
| Requirement | What to ask for | What CUZY provides |
|---|---|---|
| Data Processing Agreement | A written DPA covering Article 28 | Accepted online with every subscription |
| Data location | Where production data and backups are stored | The region you choose: Germany (EU), the USA or Singapore (APAC); backups in the same region, except Singapore communities, backed up in the United States |
| Sub-processor list | Names, purposes, countries, notice before changes | Published in the privacy policy, 30 days' notice before a change |
| Security measures | Isolation, encryption, access control, updates | One isolated stack per community, encrypted backups, logged support access, security fixes within 48 hours (security page) |
| Backups and restore | Frequency, retention, restore tests | Team: daily, 30 days of history; Business: hourly, 60 days of history; automated restore tests |
| Breach notification | How fast the host tells you | A documented procedure: information to affected controllers so they can meet the 72-hour deadline |
| Deletion at the end | When data and backups are erased | Deleted with its backups at the latest six months after the subscription ends, earlier on request |
| Portability | A complete export in a usable format | Database and files, downloadable once a day by subscribers |
3. Set up the community correctly
- Publish a legal notice, privacy policy and terms inside the community, and ask new members to accept them at registration (Legal Tools module, installed in every CUZY community).
- Collect only the profile fields you need, and set who can see each one.
- Decide who can register: invitation, approval or open.
- Require two-factor authentication for administrators, and for everyone if the content is sensitive.
- Write down a retention rule for inactive accounts and apply it, by hand or with the User Cleanup module.
- Keep a record of processing that mentions the community, its purpose, its data and its host.
4. Handle members' rights
- Access and portability: HumHub lets administrators see and export a member's data.
- Correction: members edit their own profile; administrators can correct the rest.
- Erasure: members can delete their account where you allow it, and administrators can delete an account with or without its content.
- Answer within one month, the deadline set by the GDPR.
5. Plan for incidents
Know who in your organization decides whether a breach must be reported to the supervisory authority within 72 hours, and who tells the members. Your host informs you; the notification to the authority is the controller's duty.
The administrator handbook goes through every item above in detail, with the HumHub settings to use.
Questions
Who is responsible for GDPR on a hosted community platform?
The organization that runs the community is the controller: it decides why and how members' data is used. The hosting provider is a processor and must sign a Data Processing Agreement, keep the data secure and only process it on the controller's instructions.
Do we need a Data Processing Agreement with our host?
Yes, Article 28 of the GDPR requires one whenever a provider processes personal data on your behalf. With CUZY it is accepted online with every subscription.