this post was submitted on 01 Jul 2023
124 points (96.3% liked)

Selfhosted

62027 readers
1400 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I'd be really keen to host a lemmy instance but just wondering with GDPR and everything, if there is anything else to consider outside of the technical setup and provisioning of hardware?

Lemmy is storing users data so is there any requirement to do anything GDPR wise?

Hope this is the right place for this - But seen a lot of posts interested in hosting their own lemmy instance, and this is an extension of that

you are viewing a single comment's thread
view the rest of the comments
[–] TheButtonJustSpins@infosec.pub 3 points 3 years ago* (last edited 3 years ago) (1 children)

However, this duplication mechanism renders content deletion or rectification more difficult. In case of deletion by the user, the platforms with duplicates receive usually an automated deletion request and must be trusted to comply and delete their duplicate.

Seems like sending the delete notice is all that's required?

[–] Max_P@lemmy.max-p.me 2 points 3 years ago

Seems like sending the delete notice is all that’s required?

Yes, but

and must be trusted to comply and delete their duplicate.

So because of that trust factor, if you really want to protect yourself and be 100% GDPR compliant, you'd probably want a legal contract with every instance to federate with ascertaining that they are GDPR compliant too to legally deflect blame if you're unable to comply with a data delete request.