Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Matomo Analytics - GDPR Compliance Project #12600

Closed
mattab opened this issue Mar 6, 2018 · 7 comments
Closed

Matomo Analytics - GDPR Compliance Project #12600

mattab opened this issue Mar 6, 2018 · 7 comments
Labels
c: Privacy For issues that impact or improve the privacy.
Milestone

Comments

@mattab
Copy link
Member

mattab commented Mar 6, 2018

This issue is the master issue where we discuss new features and changes needed in Matomo to make it easier for users be GDPR compliant.

With Matomo, privacy is built-in. We offer several privacy controls already, but this is not enough for GDPR compliance.

Steps we will take to make Matomo GDPR compliant:

GDPR rights which we won’t cover (at least for now):

  • GDPR - Right to data portability: Not applicable to Matomo.
  • GDPR - Rights around automated decision making and profiling: By default, automated decision making and profiling is not possible with Matomo so we won’t cover this right, at least for now.

We’re planning to finish this work at least 1 month before the GDPR start date of May 25th.

Please check these issues and feel free to comment.

@mattab mattab added the c: Privacy For issues that impact or improve the privacy. label Mar 6, 2018
@mattab mattab added this to the 3.4.0 milestone Mar 6, 2018
@tsteur
Copy link
Member

tsteur commented Mar 7, 2018

At some point it will be also good to have an action button in the visitor log for "Managing the rights" for that visitor. We would not be able to find the same visitor across sites though very likely. It may be useful though as it can offer a lot of flexibility in finding visitors (for one site).

@mattab
Copy link
Member Author

mattab commented Mar 23, 2018

And we'll likely also build a new very useful little tool: Personal Data Anonymisation & Removal tool #12641

@mattab
Copy link
Member Author

mattab commented Mar 27, 2018

information architecture of the Privacy features and tools.

As the current "Settings" and GDPR Tools and GDPR Manager menu entries all refer to different tools and maybe we can simply the structure like something like this:

  • "Anonymise data" (anon IP + delete logs + delete reports + anon old logs) ,
  • "Privacy policy" (remind how important it is to have a good privacy policy + link to users opt-out)
  • "Users opt-out" (iframe + DNT),
  • "Asking for consent" (JS API doc, later the consent UI),
  • "GDPR tools" (request to access+delete tool, + link to the tools available in the other sections)
  • "GDPR overview"

@HannesSE
Copy link

HannesSE commented Apr 9, 2018

Could you also create a stripped-down "non personal data" only version of Matomo (that could be selected in the settings)?

That stripped-down version would not collect personal at all. For example, only the following could be tracked:

  • How often a particular page was viewed (but not by whom)
  • Which campaigns received the most clicks (but not by whom)
  • Which campaigns received the most goals, etc.

As far as I understand it, such a Matomo version would be GDPR compliant without the need to show a cookie banner and without the need for consent (as no personal data is collected).

@tsteur
Copy link
Member

tsteur commented Apr 9, 2018

I don't think we will be working on this, however, you can disable plugins to trim down the amount of features and data being recorded etc.

stripped-down version would not collect personal at all

This could be a bit misleading as for example page titles, page URLs, or even campaign names may include personal data.

@mattab
Copy link
Member Author

mattab commented Apr 24, 2018

@HannesSE see #12737

@mattab
Copy link
Member Author

mattab commented Apr 24, 2018

Hi Everyone, we have released the GDPR Compliant Matomo in 3.5.0-b2 -> Please help us test all the new tools! You can grab it from the beta release channel, learn more: http://piwik.org/faq/how-to-update/faq_159/

Your feedback welcome, please open new issue if you have any feedback or find a bug 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: Privacy For issues that impact or improve the privacy.
Projects
None yet
Development

No branches or pull requests

3 participants