<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Make Ghost fully GDPR compatible?]]></title><description><![CDATA[<p dir="auto">Hey,<br />
I wonder if a self-hosted Ghost blog can be fully operated from my own server (if I do not embed third-party content like YouTube Videos)?</p>
<p dir="auto">Ghost relies – like many websites – on some scripts like jquery which are delivered through a CDN. You <em>can</em> copy those scripts to your server. At least this is what <a href="https://dani.gg/de/ghost-dsgvo-konform-machen/" target="_blank" rel="noopener noreferrer nofollow ugc">this blog post (in German)</a> states. I'm not into the details, but could it be possible to integrate that in the self-hosted version of Ghost that comes with Cloudron?</p>
]]></description><link>https://forum.cloudron.io/topic/10554/make-ghost-fully-gdpr-compatible</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 23:51:57 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/10554.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Nov 2023 22:23:33 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Make Ghost fully GDPR compatible? on Thu, 30 Nov 2023 19:36:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/78495">Make Ghost fully GDPR compatible?</a>:</p>
<blockquote>
<p dir="auto">If you want to remove the CDN, we will have to take it up with Ghost to make the assets be self-hostable</p>
</blockquote>
<p dir="auto">I guess that would be the best option.</p>
<p dir="auto">As <a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> mentioned, there are some overly strict rules set in Germany. It's quite complicated to understand what's allowed for whom and how to achieve the level of data protection that's required. Especially if you don't have a background in law or aren't a trained web developer who knows exactly how to tell your server what to store/retrieve and how.</p>
<p dir="auto">This unsettles ambitious amateurs (like me), so I'd rather be overly cautious than run into an open knife.</p>
]]></description><link>https://forum.cloudron.io/post/78549</link><guid isPermaLink="true">https://forum.cloudron.io/post/78549</guid><dc:creator><![CDATA[David 0]]></dc:creator><pubDate>Thu, 30 Nov 2023 19:36:09 GMT</pubDate></item><item><title><![CDATA[Reply to Make Ghost fully GDPR compatible? on Thu, 30 Nov 2023 15:43:48 GMT]]></title><description><![CDATA[<p dir="auto">@humptydumpty This might be interesting: <a href="https://forum.cloudron.io/topic/7204/">https://forum.cloudron.io/topic/7204/</a> and <a href="https://fonts.coollabs.io/" target="_blank" rel="noopener noreferrer nofollow ugc">https://fonts.coollabs.io/</a></p>
]]></description><link>https://forum.cloudron.io/post/78532</link><guid isPermaLink="true">https://forum.cloudron.io/post/78532</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Thu, 30 Nov 2023 15:43:48 GMT</pubDate></item><item><title><![CDATA[Reply to Make Ghost fully GDPR compatible? on Thu, 30 Nov 2023 14:05:40 GMT]]></title><description><![CDATA[<p dir="auto">I'm seeing connections to google fonts also. I think this because of the theme I'm using, but if not, could you please tell the ghost team to shove google where the sun don't shine? <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/78523</link><guid isPermaLink="true">https://forum.cloudron.io/post/78523</guid><dc:creator><![CDATA[humpty]]></dc:creator><pubDate>Thu, 30 Nov 2023 14:05:40 GMT</pubDate></item><item><title><![CDATA[Reply to Make Ghost fully GDPR compatible? on Thu, 30 Nov 2023 08:50:28 GMT]]></title><description><![CDATA[<p dir="auto">There is / was some - over excessive, in my humble lawyer opinion - court ruling in Germany that use of a CDN without proper data protection agreements in place (usually US providers) is not GDPR compliant, see for "Google Fonts" over a CDN <a href="https://www.theregister.com/2022/01/31/website_fine_google_fonts_gdpr/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/2022/01/31/website_fine_google_fonts_gdpr/</a></p>
<blockquote>
<p dir="auto">The decision, by Landgericht München's third civil chamber in Munich, found that the website, by including Google-Fonts-hosted font on its pages, <strong>passed the unidentified plaintiff's IP address to Google without authorization</strong> and without a legitimate reason for doing so. And that violates Europe's General Data Protection Regulation (GDPR).</p>
</blockquote>
<p dir="auto">... and for CDNs in general: <a href="https://www.taylorwessing.com/en/insights-and-events/insights/2021/12/vg-wiesbaden-prohibits-use-of-content-delivery-networks" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.taylorwessing.com/en/insights-and-events/insights/2021/12/vg-wiesbaden-prohibits-use-of-content-delivery-networks</a></p>
<blockquote>
<p dir="auto">The university was obliged to terminate the integration of the cookie service on its website, <strong>as this was accompanied by the unlawful transmission of personal data of the website users - the IP address -</strong> and thus in particular of the applicant. <strong>The cookie service processes the complete IP address of the end users due to the use of Akamai's Content Delivery Network on servers of a group of companies whose parent company was located in the USA.</strong> Whether the data actually reached the USA or remained on a server in the EU and whether Cybot's contractual partner was the US parent or a German subsidiary was irrelevant; the above questions could therefore apparently not be conclusively clarified in the proceedings.</p>
</blockquote>
<p dir="auto">It's based on the - again, overly excessive - interpretation of GDPR that a mere IP is "personal data"; it's further based on the view that US companies are inter alia subject to the "Cloud Act" which allows US authorities more or less unlimited access to such data (if this still holds true now after the agreement on the <a href="https://ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752" target="_blank" rel="noopener noreferrer nofollow ugc">EU-US-Data-Privacy-Framework</a> is doubtful).</p>
<p dir="auto"><em>Don't get me wrong, an argument <strong>can</strong> be made for the protection of IP addresses as e.g. abortion websites in the US may have aided prosecutions by selling data such as IP-addresses, see <a href="https://ldi.upenn.edu/our-work/research-updates/abortion-clinic-websites-may-unwittingly-aid-patient-prosecutions/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ldi.upenn.edu/our-work/research-updates/abortion-clinic-websites-may-unwittingly-aid-patient-prosecutions/</a></em></p>
<blockquote>
<p dir="auto"><em>More than 99% of abortion clinic web pages studied in May included widely used code that transferred user data to a median of nine external entities, which in turn could sell the data or provide it to law enforcement, according to the team’s Research Letter, which appears Sept. 8 in JAMA Internal Medicine. The clinics may not even be aware that visitors’ data is being disseminated since the practice is so standard across the web.</em></p>
</blockquote>
]]></description><link>https://forum.cloudron.io/post/78502</link><guid isPermaLink="true">https://forum.cloudron.io/post/78502</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Thu, 30 Nov 2023 08:50:28 GMT</pubDate></item><item><title><![CDATA[Reply to Make Ghost fully GDPR compatible? on Thu, 30 Nov 2023 07:14:33 GMT]]></title><description><![CDATA[<p dir="auto">IANAL</p>
<p dir="auto">This wasn't in the question but I think use of CDN alone doesn't mean your website is not GDPR compliant. It's possible to use a CDN and be compliant. See <a href="https://www.cloudflare.com/trust-hub/gdpr/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudflare.com/trust-hub/gdpr/</a> for example.</p>
<p dir="auto">If you want to remove the CDN, we will have to take it up with Ghost to make the assets be self-hostable.</p>
]]></description><link>https://forum.cloudron.io/post/78495</link><guid isPermaLink="true">https://forum.cloudron.io/post/78495</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 30 Nov 2023 07:14:33 GMT</pubDate></item></channel></rss>