Mastodon: Make Mastodon GDPR-compliant

Created on 2 Sep 2020  ·  4Comments  ·  Source: tootsuite/mastodon

Pitch

Mastodon should include outgoing reports in data exports.

Motivation

Mastodon doesn't currently include outgoing reports in data exports, which means data exports are incomplete and thus Mastodon is in violation of the GDPR.

Most helpful comment

I think mastodon should try to make GDPR compliance easier for admins where possible.

All 4 comments

I'm not gonna threaten anyone over this tho, I just think it's something that needs to be looked into. :p

This seems like a reasonable request, although since a similar request came up elsewhere, I would like to note again for the record that Mastodon, as a piece of software, cannot violate or satisfy the GDPR, only enterprises using Mastodon can satisfy or violate the GDPR.

Since we retain information about reported accounts which have been deleted, we should probably exclude that information from the archive, and only include information about reported accounts which have not been deleted.

I think mastodon should try to make GDPR compliance easier for admins where possible.

You should definitely not purposefully allow admins to violate the GDPR on the regular and set them up to get tons of possible fines in the future simply because you are lazy.

Was this page helpful?
0 / 5 - 0 ratings