Social FightIn – GDPR Processes

Purpose

This document outlines the operational processes required to ensure compliance with the General Data Protection Regulation (GDPR) for the Social FightIn platform.

1. Data Collection Process

Objective

Ensure only the minimum personal data required to deliver the service is collected.

Personal Data Collected

Principles

2. Consent Management

Users must actively consent where required before:

Consent must be:

Consent records should be stored securely.

3. User Rights Process

Users may request:

Procedure

  1. Request received through support email — socialfightin@gmail.com
  2. Identity verified.
  3. Request logged.
  4. Request reviewed.
  5. Response provided within one month.
  6. Completion recorded.

4. Account Deletion Process

When a deletion request is received:

5. Data Retention Policy

Data Type Retention Period
User account Until deletion request or prolonged inactivity
Support tickets 24 months
Analytics 26 months (or platform default)
Payment records As required by applicable financial and tax legislation
Moderation records 24 months
Audit logs 24 months

Retention periods should be reviewed annually. See also Data Retention Policy.

6. Security Measures

The platform should implement:

7. Third-Party Processors

Maintain a register of all providers processing personal data. Examples may include:

Each processor should have appropriate contractual safeguards in place. See the Third-Party Processor Register.

8. Data Breach Response

If a personal data breach occurs:

  1. Identify and contain the breach.
  2. Assess affected data.
  3. Assess potential risk to individuals.
  4. Notify senior management.
  5. Notify the relevant supervisory authority where legally required.
  6. Notify affected users where legally required.
  7. Record: cause, impact, resolution, and preventative actions.

See also Data Breach Response Plan.

9. Content Moderation & Personal Data

Moderators may access personal information only where necessary to investigate:

Moderator actions should be logged. See Content Moderation Policy.

10. Privacy by Design

New features should undergo a privacy review before release. Consider:

11. Staff Responsibilities

Anyone with access to user data must:

12. Governance & Review

This document should be reviewed:

The platform should maintain records demonstrating compliance with applicable data protection obligations.