Magento 2 GDPR Compliance
The Magento 2 GDPR is an ingenious extension that provides complete tool-set required to help online website/store comply with the latest EU's regulations in a secure way.
- Ensures EU’s GDPR comply
- Activate & personalize cookie consent
- Delete account option for customer
- Download/erase data on account page
- Manage Privacy consent (upto 3) for admin
- Customer consent tracking grids
- Email verification to protect for data theft
- configure auto erase unwanted data
- Set data handling request (by admin, by customer or auto)
Version 1.0.1 CE (Released on Aug 17, 2018)
- * Bug Fixes & Improvement
- + Enterprise Edition Compatibility
Version 1.0.0 CE (Released on Jun 23, 2018)
- + Core GDPR rules follows for delete-anonymize-export personal data can be managed from 'My Account > Manage Account'
- + To avoid data theft & fraudulent actions, there are Admin Moderation and Email Verification gate on handle request made by the customer.
- + Privacy Consent will be mentioned and show up on a register and checkout. It will also be updated on the Account > Privacy setting page.
- + Customer Consent Grids to tracking for all accepted assent & till which are not accepted the notice.
- + A cookie compliant notice pop-up can be customized with a top & bottom position of your web-page.
- + Admin configuration for auto-deletion of unwanted data like an abandoned cart.
- + Consent Reset when policy update & added 2 new grid for consent visibility
- + Popup appearing when customer get the login for update consent
HOW THE MAGENTO 2 GDPR EXTENSION WORKS?
Manage Account with (Delete, Download & Erase action)Admin can configure each of this request processing immediate, Awaiting admin approval or auto mode as described above after sensing the right need.
Delete Account:According to an EU’s regulation, a user should have an option to delete an account permanently. This compliant plugin empowers users to delete an account from the new “My Account > Manage Account” page. The request is handled securely by sending out the request mail to user ensures action is taken by an authorized user only
Download Personal Data:In order to accomplish with an EU’s right to access rule, the module allows the user to make a download request from “My Account > Manage Account” page. This will export all user’s own personal info, sales history, invoicing etc. into the machine-readable format (atm its CSV only). Once the download is ready, a downloadable attachment link will be sent to the user’s verified the email address.
Erase/Anonymize Account Data:To comply right to be forgotten, this M2 plugin adds an option to Erase/Anonymise user data which replaces customer personal data, sales history with placeholder text in the database which hides customer's information.
Each of these data-related requests (delete, erase & download) allows 3 modes of servicing enhancing the flexibility and security:
- By Customer
- By Admin
In Auto mode when a request raised by the customer and completes email verification, all received requests will then be automatically serviced based on cron setting done by admin and email will be sent out to respective customers who then take control through an email received.
In By Admin mode, when a request raised by the user, the admin receives all request on his dashboard and when the admin approves the request then a mail is sent out to the customer who then takes a relevant action to complete their request. This method is used to ensure more security.
Privacy Consent ManagementA Magento 2 GDPR complant plug-in also sets cronjob for automatically truncate abandoned carts from quote table periodically. admin can set this frequency on the backend via cron settings.
Admin will be presented 2 separate user consents grids loading users who accepted consents & customers pending privacy consents. Admin can reset previously recorded users consent to run through new privacy terms. The customer then has to give their consents again with new privacy updates.
Cookie ConsentsOur Magento plugin enables cookie consent with a customized popup at the top or bottom of the screen to the user.
Important noticeThis Magento module for "EU's General Data Protection Regulation" designed with the best of our knowledge & understanding of regulation to help eCommerce merchants fulfil with EU's regulation. However, please consult your lawyer to confirm compliant accordingly.
Extension Set up:
1. Install the module from the marketplace.
2. For using Magento module, go to STORE> Configuration > SETUBRIDGE > GDPR Tab: