Skip Navigation

Anything else to consider when hosting a Lemmy instance in the EU?

I'd be really keen to host a lemmy instance but just wondering with GDPR and everything, if there is anything else to consider outside of the technical setup and provisioning of hardware?

Lemmy is storing users data so is there any requirement to do anything GDPR wise?

Hope this is the right place for this - But seen a lot of posts interested in hosting their own lemmy instance, and this is an extension of that

59 comments
  • I'd put a legal blob in the Legal section clearly outlining the nature of the fediverse and making it clear to the user that really deleting stuff from Lemmy is near impossible because every instance has a copy of it. That you'll happily comply and purge the user's data upon request but that it will still be cached on every other server.

    I'd be interested to see what lawyers have to say about it. Technically the data sharing is absolutely required by the protocol so it might be okay with the GDPR, but it's also possible that as worded it can't possibly be GDPR compliant. It was designed with big companies like Google, Meta and big advertisers in mind, and didn't really account for decentralized services like the fediverse...

  • First of all, I'm not a lawyer or a legal consultant, just a instance admin that wants to make sure that his instance complies.

    Lemmy does not store any PII (birthdates, legal names, addresses,securitynumbers). But users are able to share whatever they want. And that can be a problem.

    Check out my instances legal page: https://Laguna.chat/legal

    In the future I want to make sure that my instances content can only be shared by GDPR respecting instances.

  • IANAL, but if you use an external service to process personal data such as sending registration emails, this needs to be clearly mentioned on the legal page.

  • I think if you just let people delete their data whenever and clearly state how that data is used/ stored everything will be fine.

59 comments