J3 Issue ?
avatar PhilETaylor
PhilETaylor
19 Oct 2018

Steps to reproduce the issue

Generate and confirm an information request by user

Note that a super admin will get a private message in Joomla admin, containing the email address (personal information) about a user

Expected result

pffff no idea...

I'm guessing when a GDPR request says delete all personal data, this should include the data in these private messages - after all these are automated messages and could be crafted without personal data, maybe instead of

User phil@phil-taylor.com has confirmed their information request.

it could say

A User has confirmed the information request ##6.

and then this would not be an issue?

There is no real need for personal data to be "leaked" into the private messages of a Super Admin (and further our in unencrypted email to the super admin's mailbox)

Actual result

Personal data about a person is stored in private messages in Joomla database even after a remove request has been made.

avatar PhilETaylor PhilETaylor - open - 19 Oct 2018
avatar joomla-cms-bot joomla-cms-bot - change - 19 Oct 2018
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 19 Oct 2018
avatar PhilETaylor PhilETaylor - change - 19 Oct 2018
The description was changed
avatar PhilETaylor PhilETaylor - edited - 19 Oct 2018
avatar brianteeman
brianteeman - comment - 19 Oct 2018

This is a legitimate use of pii as it is required to perform the requested action

avatar PhilETaylor
PhilETaylor - comment - 19 Oct 2018

Its not needed at all. There is no need for the personal data to be in that message. The request could be referenced by its id, like it is in the action logs.

avatar brianteeman brianteeman - change - 30 Oct 2018
Labels Added: J3 Issue
avatar brianteeman brianteeman - labeled - 30 Oct 2018
avatar PhilETaylor PhilETaylor - change - 10 Feb 2019
Status New Closed
Closed_Date 0000-00-00 00:00:00 2019-02-10 21:32:17
Closed_By PhilETaylor
avatar PhilETaylor PhilETaylor - close - 10 Feb 2019

Add a Comment

Login with GitHub to post a comment