Topic-icon Double Opt-In and GDPR

Active Subscriptions:

None
5 years 11 months ago #63970 by Glasairmell
Hi,

In studying the issue of social login-registration and GDPR I came across the double opt-in method.
xeerpa.com/blog/optimize-social-login-double-opt-in/

While the idea is simple the implementation for Joomla! is not. Ideally after FaceBook redirect (as Alex pointed out in another post) the user is redirected to this opt-in page.

When the user checks the options, these selections need to be recorded for GDPR compliance. I currently am using GDPR from storejextensions.org/extensions/gdpr.html

It would be great if some kind of documentation-suggestion would be created on how to use your JFBConnect safely with GDPR. Your extension collects a lot of data and users of the extension would benefit from some input.

However specifically I am looking for a good method to handle the social login-registration and be safe with GDPR.

Cheers!
The topic has been locked.
Support Specialist
5 years 10 months ago #63994 by alzander
Replied by alzander on topic Double Opt-In and GDPR
Thanks for reaching out. We've been doing a ton of investigation into GDPR. Right now, we don't have a good solution integrated into or for Joomla in general. We're investigating multiple options for extending JFBConnect, integration with other GDPR extensions for Joomla as well as some stuff we think may be beneficial to all sites (outside of JFBConnect).

From a high level, I honestly don't think that JFBConnect is the proper place to add GDPR support. There's a lot of logistics that go along with it, it's not 'just a checkbox' on registration and there's a whole lot of complexity that can come along with it, depending on how nuanced you want to ask permission. One box for all communications, or 7 boxes for each newsletter, transactional emails and promos, etc. That really would be a burden on JFBConnect to do properly and/or well.

For now, I'd say that JFBConnect does have the 'manual' registration process (simply turn off Automatic registration) and the user is brought to a registration page after they login the first time. We can show checkboxes that are in the User - Profile extension or from a variety of other community extensions we support. Those checkboxes wouldn't have all the details you need, like IP, type of confirmation, etc to fully comply.. but it's a start.

The other alternative is to use the "New User Registration Redirection" URL in JFBConnect to redirect users to another page on your site that properly collects all this data.

That's all I can recommend for now, but keep an eye out later this Summer for something we're hoping to work on and possibly get out to help make the whole process simpler for any type of registration :)

Thanks,
Alex
The topic has been locked.