mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #45629
[Bug 1734169] [NEW] Explicit consent switches for the GDPR
Public bug reported:
We need to make a series of changes in Mahara to comply with the GDPR.
More info is available on the wiki at
https://wiki.mahara.org/wiki/Developer_Area/Specifications_in_Development/GDPR_compliance
We need to be able to add explicit consent boxes / Yes/No switches to
the T&C. These should come at the end of the site agreement and the
institution agreement if needed to make it clear in which section
consent is given.
The consent should be configurable by site and institution admins as
that may change. It also needs to be versioned and the consent date and
time recorded as well as the wording to which a user consented to. This
could become a report in the administration area. In future it would
also be good for the user to see reports that show the data that was
collected for them, but that is not the focus here.
For the MVP, users would need to consent to all items for an account to
be created. If they leave out any items, they will receive a modal
letting them know that their account won't be able to be created and
that they have two choices:
1. Revise their selection / double-check that they didn't miss anything by accident
2. Send a message to their institution administrator(s) letting them know why they don't want to consent to a particular item so that the institution can then deal with that. The easiest might be a message field directly on that screen so a message can be dispatched to all institution admins for the institution in which the user is a member / wanting to be a member or if there are no institutions or there is no institution admin, contact the site admin. This behavior should be similar to what we currently see when we have pending registrations: All institution admins receive a message and if there is none, the site admin receives it.
It would be good to create a new admin menu item "Privacy" in which all
privacy related items that require configuration and text changes can be
collected. Then we could switch between site and specific institution
information like we do on the "Institutions" screen.
** Affects: mahara
Importance: Wishlist
Status: Confirmed
** Tags: gdpr
** Changed in: mahara
Importance: High => Wishlist
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1734169
Title:
Explicit consent switches for the GDPR
Status in Mahara:
Confirmed
Bug description:
We need to make a series of changes in Mahara to comply with the GDPR.
More info is available on the wiki at
https://wiki.mahara.org/wiki/Developer_Area/Specifications_in_Development/GDPR_compliance
We need to be able to add explicit consent boxes / Yes/No switches to
the T&C. These should come at the end of the site agreement and the
institution agreement if needed to make it clear in which section
consent is given.
The consent should be configurable by site and institution admins as
that may change. It also needs to be versioned and the consent date
and time recorded as well as the wording to which a user consented to.
This could become a report in the administration area. In future it
would also be good for the user to see reports that show the data that
was collected for them, but that is not the focus here.
For the MVP, users would need to consent to all items for an account
to be created. If they leave out any items, they will receive a modal
letting them know that their account won't be able to be created and
that they have two choices:
1. Revise their selection / double-check that they didn't miss anything by accident
2. Send a message to their institution administrator(s) letting them know why they don't want to consent to a particular item so that the institution can then deal with that. The easiest might be a message field directly on that screen so a message can be dispatched to all institution admins for the institution in which the user is a member / wanting to be a member or if there are no institutions or there is no institution admin, contact the site admin. This behavior should be similar to what we currently see when we have pending registrations: All institution admins receive a message and if there is none, the site admin receives it.
It would be good to create a new admin menu item "Privacy" in which
all privacy related items that require configuration and text changes
can be collected. Then we could switch between site and specific
institution information like we do on the "Institutions" screen.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1734169/+subscriptions
Follow ups
-
[Bug 1734169] Re: Explicit consent switches on the privacy statement for the GDPR
From: Robert Lyon, 2018-04-05
-
[Bug 1734169] A change has been merged
From: Mahara Bot, 2018-02-12
-
[Bug 1734169] A change has been merged
From: Mahara Bot, 2018-02-12
-
[Bug 1734169] A change has been merged
From: Mahara Bot, 2018-02-12
-
[Bug 1734169] Re: Explicit consent switches on the privacy statement for the GDPR
From: Kristina Hoeppner, 2018-02-09
-
[Bug 1734169] A change has been merged
From: Mahara Bot, 2018-02-08
-
[Bug 1734169] A change has been merged
From: Mahara Bot, 2018-02-08
-
[Bug 1734169] Re: Explicit consent switches on the privacy statement for the GDPR
From: Maria Sorica, 2018-01-31
-
[Bug 1734169] A patch has been submitted for review
From: Mahara Bot, 2018-01-26
-
[Bug 1734169] A patch has been submitted for review
From: Mahara Bot, 2018-01-25
-
[Bug 1734169] A patch has been submitted for review
From: Mahara Bot, 2018-01-19
-
[Bug 1734169] A patch has been submitted for review
From: Mahara Bot, 2018-01-18
-
[Bug 1734169] Re: Explicit consent switches on the privacy statement for the GDPR
From: Maria Sorica, 2018-01-17
-
[Bug 1734169] Re: Explicit consent switches for the GDPR
From: Kristina Hoeppner, 2017-12-26
-
[Bug 1734169] Re: Explicit consent switches for the GDPR
From: Kristina Hoeppner, 2017-11-23
-
[Bug 1734169] Re: Explicit consent switches for the GDPR
From: Kristina Hoeppner, 2017-11-23