DSGVO
Vorlage:GDPR Vorlage:Zum Überarbeiten
Überblick
GDPR stands for General Data Protection Regulation and refers to the European Union regulation for data protection for all individuals within the European Union. The regulation (Regulation (EU) 2016/679)2 becomes enforceable on 25 May 2018 and replaces the data protection directive (officially Directive 95/46/EC)3 from 1995.
Wer ist betroffen?
Any individual or organisation that stores or processes personal information on an identifiable person from an EU member state (regardless if the processing or storage of information occurs in the EU or not). It also applies if the individual or organisation themselves is located in an EU member state.
Welche Art von Informationen umfassen persönliche Daten in einer Moodle-Installation?
It is all information that can be associated with a natural person. Each user account and all the activity associated with that user account is classified as personal information. This also extends to associated information such as web server log files.
Wie unterstützt das Moodle HQ die Einhaltung von GDPR in Moodle?
Earlier this year we reached out to the community through our forums and social media to gauge the needs of different organisations on how they would need to comply with GDPR. We received direct input from a number of Moodle institutions, our Moodle Partner network and developers.
We have a plan to meet those needs and are scheduling the development within our Open Source team under the lead of Sander Bangma, our Open Source Development Coordinator. The plan involves the development of a set of features (made available through plugins and some minimal changes to core) which will assist Moodle sites meeting GDPR compliance needs. The features cover the following areas:
- Onboarding of new users, including; age and location check to identify minors, versioning of privacy policies and the tracking of user consents;
- Handling of subject access requests and erasure requests, and maintaining a data registry.
Important note: Installing the developed plugins alone will not be enough to meet the GDPR requirements. Correct configuration and implementation of the required processes and procedures is also required.
We at Moodle HQ highly recommend that you also engage your IT and legal departments on what is required for GDPR compliance.
GDPR Plugins
- Richtlinien und Einwilligungen - requires Moodle 3.4.2 onwards, and will be included as standard in Moodle 3.5
- Schutz persönlicher Daten - also requires Moodle 3.4.2 onwards, and will be included as standard in Moodle 3.5
GDPR für Moodle-Administrator/innen
If you are a Moodle system administrator and have a Moodle site older than the 3.3.5 or 3.4.2 version, or have a site that is not affected by GDPR but would still like to do as much as possible towards compliance, we recommend you read our “GDPR for Moodle Administrators” guide.
If you are on Moodle 3.4.2 version and above, please refer to our “GDPR for Moodle Administrators (Moodle 3.4.2+)” guide for information on GDPR functionalities that have been released recently and continuing to develop.
Moodle & GDPR für Plugin-Entwickler/innen
Wenn Sie Moodle-Plugins entwickeln wollen, die GDPR-konform sind, dann empfehlen wir folgende Schritte:
- Lesen Sie die Spezifikation GDPR für Plugin-Entwickler/innen in der Entwickler-Dokumentation (englisch).
- Beteiligen Sie sich an der Diskussion EU General Data Protection Regulation (GDPR) Compliance.
Moodle & GDPR für Lehrende und Lernende
Wenn Sie als Lehrende/r oder Lernende/r mehr über Ihre Rechte in Bezug auf GDPR erfahren wollen oder wissen wollen, wie Moodle den Schutz Ihrer Privatsphäre ermöglicht, dann empfehlen wir Ihnen:
- Fragen Sie Ihre Moodle-Administration, welche spezifischen Richtlinien in Ihrer Intitution oder Organisation gelten.
- Erfahren Sie mehr über GDPR im Abschnitt “Siehe auch” weiter unten.
Aktuelle Nachrichten und Aktualisierungen
- Moodle 3.4.2, 3.3.5, 3.2.8 und 3.1.11 stellen im Standardpaket APIs zur Unterstützung der GDPR-Plugins bereit.
- GDPR-Plugins jetzt verfügbar
Siehe auch
Englisch-sprachige Quellen:
- Home Page of EU GDPR
- GDPR Regulation
- Directive 95/46/EC
- Guide to the General Data Protection Regulation (GDPR) des Information Commissioner's Office Großbritannien