DigitalExcellence / dex-backend

Backend for Digital Excellence Platform
https://dex.software
GNU Lesser General Public License v3.0
21 stars 10 forks source link

GDPR - Ability to request and remove your own data #77

Open Brend-Smits opened 4 years ago

Brend-Smits commented 4 years ago

In GitLab by @Brend-Smits on Apr 14, 2020, 10:24

We want users to be able to login and request their own data, but also remove their own data and account. What should happen to projects that belong to this user? Should they be removed or should they be kept on the platform and passed on to one of the contributors? All of these things have to be considered.

Brend-Smits commented 3 years ago

I'm gonna block this issue until I have some more insights on how we want to handle project deletion

Brend-Smits commented 3 years ago

When making a request to delete your data, we should probably add a wizard in the frontend that will show all the projects that the user owns, and ask for each project individually:

I'm not sure if we also have to remove the user from each project that they are tagged in as a collaborator, perhaps we can ask them per project like described above. I will have to talk with our data officer about this to see what is legally required and what not.

Brend-Smits commented 3 years ago

@wotwot563 how's this going? I moved it to Sprint 6 board.

niraymak commented 3 years ago

If you pickup this issue, please check if the research done (if there is any research done) is relevant.