Skip to content

GDPR non compliance with Livechat data #12789

@reetp

Description

@reetp

After some discussion on open.rocket.chat it appears there is a major GDPR compliance issue with RocketChat and Livechat data which makes Rocket chat non GDPR compliant at this point of time if you use the Livechat widget (and possibly Form items via the API)

The issue originally raised was how to hide or disable the IP address collected for Livechat agents.

It transpires that not only is this data then stored in the Livechat record, but if that record is deleted the data remains in the database with no easy way to delete it.

This make anyone using a Livechat widget unable to comply with GDPR.

Remedial Actions

  1. On/Off switch for Email address collection in Widget
  2. On/Off switch for background IP address collection in Widget
  3. Deletion of Livechat record should remove all data from the database (retrospectively too)

References:
#9684
#10584

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions