Skip to main content
Associations and communities

GDPR checklist for community platforms

Running a community platform or an intranet makes your organization the controller of your members' personal data. This checklist lists what the GDPR expects of you, what your hosting provider must provide, and exactly what CUZY provides, no more.

Last updated: . Written by CUZY, which hosts HumHub; facts about other products are linked to their sources.

In shortYour organization is the controller and decides what data the community holds; the host is a processor and must sign a Data Processing Agreement. This page is a checklist, not legal advice: when in doubt, ask your data-protection officer or a lawyer.

1. Know who is responsible for what

  • Controller: the organization that runs the community. It decides why members' data is collected, who sees it and how long it is kept.
  • Processor: the hosting provider. It stores and protects the data and acts only on the controller's instructions (GDPR Article 28).
  • Sub-processors: the providers the host relies on (data centers, backup storage, email delivery). The host must list them and tell you before changing them.

2. Check what your host must provide

RequirementWhat to ask forWhat CUZY provides
Data Processing AgreementA written DPA covering Article 28Accepted online with every subscription
Data locationWhere production data and backups are storedThe region you choose: Germany (EU), the USA or Singapore (APAC); backups in the same region, except Singapore communities, backed up in the United States
Sub-processor listNames, purposes, countries, notice before changesPublished in the privacy policy, 30 days' notice before a change
Security measuresIsolation, encryption, access control, updatesOne isolated stack per community, encrypted backups, logged support access, security fixes within 48 hours (security page)
Backups and restoreFrequency, retention, restore testsTeam: daily, 30 days of history; Business: hourly, 60 days of history; automated restore tests
Breach notificationHow fast the host tells youA documented procedure: information to affected controllers so they can meet the 72-hour deadline
Deletion at the endWhen data and backups are erasedDeleted with its backups at the latest six months after the subscription ends, earlier on request
PortabilityA complete export in a usable formatDatabase and files, downloadable once a day by subscribers

3. Set up the community correctly

  • Publish a legal notice, privacy policy and terms inside the community, and ask new members to accept them at registration (Legal Tools module, installed in every CUZY community).
  • Collect only the profile fields you need, and set who can see each one.
  • Decide who can register: invitation, approval or open.
  • Require two-factor authentication for administrators, and for everyone if the content is sensitive.
  • Write down a retention rule for inactive accounts and apply it, by hand or with the User Cleanup module.
  • Keep a record of processing that mentions the community, its purpose, its data and its host.

4. Handle members' rights

  • Access and portability: HumHub lets administrators see and export a member's data.
  • Correction: members edit their own profile; administrators can correct the rest.
  • Erasure: members can delete their account where you allow it, and administrators can delete an account with or without its content.
  • Answer within one month, the deadline set by the GDPR.

5. Plan for incidents

Know who in your organization decides whether a breach must be reported to the supervisory authority within 72 hours, and who tells the members. Your host informs you; the notification to the authority is the controller's duty.

The administrator handbook goes through every item above in detail, with the HumHub settings to use.

Questions

Who is responsible for GDPR on a hosted community platform?

The organization that runs the community is the controller: it decides why and how members' data is used. The hosting provider is a processor and must sign a Data Processing Agreement, keep the data secure and only process it on the controller's instructions.

Do we need a Data Processing Agreement with our host?

Yes, Article 28 of the GDPR requires one whenever a provider processes personal data on your behalf. With CUZY it is accepted online with every subscription.

Read next

Try HumHub with your own content

A hosted community in two minutes, all paid CUZY modules included, no card asked. Keep everything when you subscribe.

Loading...