Bug Report: Analytics MUST be opt-in, not opt-out,
Reproduction steps
According to the documentation, every Pocket ID installation transmits data to a central Pocket ID server by default; see https://pocket-id.org/docs/configuration/analytics.
This is not permitted in the European Union.
According to the EU ePrivacy Directive, retrieving information from the terminal equipment (the server) is only permitted if it is based on the user’s request or if the user has given informed consent. This is clearly not the case. (The “user” in this case is the administrator or their supervisor.)
A random ID constitutes personal data. Therefore, the scope of the GDPR applies, and a legal basis for processing this personal data is required. In this case, this can only be consent. Without consent, it is not allowed.
What should be done?
Option A: Completely remove the analytics feature. Option B: Implement a process to determine whether the administrator WANTS this data transfer, and whether his employer permits it; provide him with detailed information about all the data; and request informed consent.
Note: The fact that other software has similar tracking features — or even more — does NOT make this lawful in this specific case.
GDPR fines can reach up to €20 million or 4% of a company’s global annual turnover, whichever is higher, for serious violations.
Expected behavior
No data is ever transferred from the Pocket ID server to any other destination unless it is absolutely necessary for the service to function.
Actual Behavior
According to the documentation, personal data is transferred: https://pocket-id.org/docs/configuration/analytics
Pocket ID Version
Current, v2.14.0
Database
doesn't matter
OS and Environment
doesn't matter
Log Output
No response
Source: pocket-id/pocket-id