On May 25, 2018, the General Data Protection Regulation (GDPR) went into effect. GDPR is a set of data privacy laws across Europe that are designed to protect EU citizens’ data privacy and reshape the way organizations approach data privacy.
On January 1, 2020, the California Consumer Privacy Act of 2018 (CCPA) will go into effect and enforcement will begin July 1, 2020. The CCPA is a California privacy law that is applicable to businesses doing business in California and that meet one of three revenue thresholds. It also applies to service providers of those businesses, who are defined under the CCPA as a company handling PI on behalf of a business, for a business purpose.
The following is an update on Khoros’s compliance efforts as they relate to the GDPR and CCPA:
We have worked with outside EU counsel to ensure we are correctly interpreting how the GDPR affects Khoros specifically, and to ensure we are handling EU personal data correctly. For example, we confirmed our interpretations of consent requirements and other legal bases for processing personal data and exporting personal data from the EEA with our EU counsel.
Additionally, Khoros has been working with outside U.S. counsel to ensure we are compliant with the CCPA. One important point to make clear is that Khoros will never sell our customers’ personal information for any reason at all and we will contractually agree to the same.
Khoros has updated its DPA template to expand its scope not just to EU personal data, but to PI covered under the CCPA also. Our DPA template also contains all the necessary GDPR flow-down provisions and accurately reflects the processes used by Khoros to comply with privacy laws. We would be happy to provide you a copy to make it easy for you to check the box in regards to your own GPDR/CCPA compliance efforts.
Khoros is continually examining and documenting our internal processes and any aspects of our product portfolio that relate to personal data handling, not just to ensure regulatory compliance, but more importantly to achieve best practices and satisfy our customers’ needs.
If you’re looking for more information, I’ve included links below to our product specific FAQs, privacy policies, details on our subprocessors, and the official sites for GDPR and CCPA. And I know this is complicated, so if you have specific questions, please leave them in the comments and I’ll make sure they get addressed.
Do you have any specifics yet on what functionality or capabilities will be made available to support businesses with GDPR compliance requests (e.g. API updates)?
We are already reviewing how we might process customer requests in relation to GDPR compliance and how this will impact our community / LSMM platforms.
It is comforting that Lithium are being proactive in this space, however it would be good to have some more specifics 🙂
"As we near the May 2018 effective date for GDPR, Lithium will complete its GDPR compliance measures.".... as a business we will need to have processes and procedures implemented well in advance of this date so the more information you could can provide the better.
Our product management teams are currently in the planning phases for product enhancements related to GDPR compliance, and engaging in discussions with our customers to determine what features our customers would like to see. We do not yet have any specifics in this particular area, as we have been focusing efforts to date on the rights of data subjects - the ability to obtain their personal data, make corrections, and the “right to be forgotten”. We would point out that current features of our Community and Social Media Management offerings do provide opportunity to post information about what your company is doing in the area of GDPR compliance, and to respond quickly to inquiries or other posts of social media about your compliance, but we would love to hear from you if there are features you would like to see that would specifically enhance these capabilities.
Thank you for this. Our company is also working on this. I am neither a lawyer, nor European, but according to our European colleagues this law is already in effect. We are currently under a "grace period" where the law is not being enforced until May 2018. But from what we understand, any company who is in possession of EU-citizen PII and not currently compliant with GDPR is technically breaking the law. [source: http://www.eugdpr.org/eugdpr.org.html]. We would be happy to collaborate with other companies and Lithium so that we can get this taken care of ASAP.
Hi @JohnD I got the communication below and the doc says to ‘See https://community.jivesoftware.com/docs/DOC-242231 for further details on the planned changes that Aurea is making that will affect both Jive-n and Lithium JX.’
Initially the link never worked for me (unauthorized) but now it does but info it goes to is for Jive-N only. What is the correct link please. Or does this apply to JX as well?
Thanks @CeliaB. Probably worth getting someone at Jive to update that post to say that it applies to both
Hi @GrantCostello - You can find all Lithium JX-specific GDPR compliance updates here -
@jasondmcclellan Thanks for the feedback! Yes, we will enhance the download to include a user's private messages in a future release.
I would love to have a copy of the Khoros DPA template as I am working with my company to figure out the inner workings of CCPA compliance.