GDPR Functions 4.9.6 need improvements
-
When attempting to use the GDPR enhancements such as Export Personal Data & Erase Personal Data in WordPress 4.9.6 they create more issues than that address. It seems to have good intent but seems to have been rushed into implementation.
1. These tools are only accessible by the supersite admin, good practice should limit the use of this account. These functions should also be available to a lower level authority such as Editor or you may need a new level called Data Administrator.
2. When as the site admin, you select a user for Export personal data, this generates a default email. There needs to be greater control over this email. For example you need to be able to configure:
– Specify if you want an email to be generated Y/N
– Specify the sender address (default is wordpress@site).
– Customise the email generated.
– Customise link generated3. When the email is received by the baffled user (GDPR requestor), it contains a link to a website and no instructions of what to do. Some of this could be helped by configuration flexibility as identified above.
4. When clicking on the link the GDPR requestor email, the user is then forced to login to WordPress. Then when loggin in, nothing seems to occur and the requestor state on the admin account stays at Pending state.
5. There is no way to explicitly delete the request if one was made in error (until the request times out).
6. There is no way to resend the request if if were lost in transit or it there were other issues (until the request times out).
7. Also it you use tools like All in One WP Security with brute force login, the admin address for WordPress is exposed in the associated email.
Beyond these issues – There is no way for a user of the site to request or access this functionality, this would require a user contacting the person responsible for the WordPress site and requesting the data via email. Then the site administrator would have to then act on that email and then generate a request in WordPress, which then send another email to the requestor.
- The topic ‘GDPR Functions 4.9.6 need improvements’ is closed to new replies.