About GDPR and my websites

4 min read

Deviation Actions

LuanaRayART's avatar
By
Published:
663 Views
Hi darlings,

this entry is to let you know about some changes I'm forced to apply because of the GDPR law taking effect as of May 25, 2018. You might have heard of it.

I always took care of my visitors', clients' and fans' right to privacy and I've never asked more information than what I absolutely need to make something work that benefits both of us. I also always deleted their information if they wanted me to (right? It's their own stuff, after all.)

However, this is no longer sufficient under the GDPR. They can fine me (up to 20 million Euros) for not having the right disclaimers on my website(s) or because the software I use automatically saves IP addresses even though I don't want to and there's nothing I can do about it (and I can't afford the 'okay' alternative) or because... you ask for changes to your data and I don't it within a month (what if I'm in hospital? LOL).

The base principle behind the following updates is this: I'm only one person running business and personal websites, I don't have a team and I can't monitor data 24/7. I have nobody to look after security when I'm on vacation or I'm sick, so that means the only way I have to comply with GDPR is to shut down almost all interactive functions of my websites.

Therefore:
  • I'm shutting down ALL my websites until free/open source GDPR tools come out (or at least when the software I currently use is made compliant). I barely have money to buy food lately, I definitely don't have €200+ a month for all that stuff :/
  • When my sites are back, I will no longer allow email addresses in comments (I'm looking for a commenting software that does that, or I'll have to learn to write my own) and I'm going to discourage the use of real names - even though that shouldn't be a problem because a user who makes their name public together with their comment deliberately makes that all public, so it wouldn't be a problem if there's a data breach and the database content is put online... since it was already online. However, no more email addresses (so no more Gravatars nor comment notifications or subscriptions) and I'm going to erase all emails from old comments in my databases.
  • On some websites I might shut down comments entirely. We'll see... If comments and forum software used encryption, I could bring these two things back to life, but I don't know whether that will be available. For now, this stuff's getting out of the way.
  • All forum-based communities (including Facebook groups) and Facebook pages will be closed and I will ask Archive.org to delete any archived versions.
  • For the *** newsletter, I'm going to send you an email to re-confirm your opt-in and then we're set to go. However, I won't accept new subscribers to the newsletter until I fully understood the breadth of this new law. This is probably the only form of safe opt-in interaction we can have from now on (beside private DeviantART notes). I might close down every newsletter but the *** one.
  • I disabled visitor comments and ratings on luana.me/gallery because (guess what?) the software stores IP address and there's nothing I can do to avoid it. If you want to comment any artwork from that gallery, please do so in a DA Note or via email to lu@luana.me
In other words, I don't want your data if that means I have to live in the fear of a possible killer fine if a data breach happens while I'm in hospital. If that means our ways to interact have to be restricted, so be it.

Sorry about this, but in this case the protection of people's data is not my priority... my priority is to preserve my mental health and my own freedom of expression... and all the worlds I created and shared online with everyone.

Please know that your love and support has always meant the world to me, so I hope you understand why I'm doing this.

Don't worry - we always have Notes and personal email (and newsletter, maybe, until it's safe to keep).

Take care. :hug:

- Lu
Β© 2018 - 2024 LuanaRayART
Comments8
Join the community to add your comment. Already a deviant? Log In
pika's avatar
As far as I've understood, all you have to do is to state clearly what your site does to its visitors. Make a pop up warning before entry, like "If you want to enter this site, you give consent to store your IP address, and your IP address will be removed if user wants so." Something something like that, and for example you can send newsletters to people who have GIVEN you your email and permission to sent them out. The GDPR is basically all about private people's consent over their information on your site. The law wants the private person to have full control of their data online. 

I haven't indulged myself more than scrape the surface of it with wikipedia, blog post guides and Google so I wish you good luck figuring this out. Just don't go and shut down/delete everything just yet.