More on GDPR and your hosting

Updated for May 2018

Somebody shared with me a PDF offer from their hosting company offering to check and lock down their website for a single payment of £497, and proposed that this would be suitable evidence to the ICO office if they ran into problems later that they had tried to meet the requirements of GDPR. I have seen quite a few examples of people trying to make money out of it, some are pretty outrageous, but it comes with the territory.

For my client base I have looked critically at the website and email side of things and there are some things that are worth doing to firm up on security. This is my list, if you want me to work through this list (I mention why in most of the items below) it is a one off charge of £50. In some cases I have already actioned some of these things below on some sites such as turning on SSL for most people and setting up offsite backups. This past two months, more and more of my time is being taken up doing things for free. Unfortunately, I still have expenses to cover, so I cannot do everything for free.

Am I covered for GDPR if I do all of these things?

The short answer is no. The actions listed below cover and protect one part of the information gathering systems. But GDPR is more about what you do internally in your office, how you deal with the data and protect it. You still need to do that work. It starts with a Data Protection Impact Assessment (link to ICO website). Please make sure you have read and understood what GDPR is all about. Your website and email systems are a small part of it. 

Website Lockdown

The General Data Protection Regulation (GDPR) which is about to become law is fundamentally focused on making sure you understand where you hold personal data, why you hold it, and what you do with it, how you control it and process it in your organisation, You need to demonstrate that you have the systems and processes in place to support that. It is not just a case of putting a modified privacy notice on your website, or making that available to the public.

From a GDPR perspective your website is included in the scope of it, but it is much broader than that. For many of you it is more about your internal processes for data handling and control.

While it is not very likely, there is always the risk of someone tapping into your communications. WiFi hot spots are the most obvious area where this can happen. You can protect ALL data by using encryption, it works on several levels. You can encrypt your backups, your email and any accesses to your website over the internet. This is how you do it.

Adding encryption to your website

In many cases I have already done this, the hosting we moved to in 2016 offered free SSL certificates provided we use the DNS servers in the hosting. If we do that, then it is possible to run your site over an https:// encrypted connection like your bank.

What else needs to be done?

There are some other things that are worth considering, these are listed below. You can check through these and make the necessary changes if you wish. I think it would take about 2.5hrs to complete the following.

1) SMTP Plugin

WordPress has a send mail function built into it. This means a site is capable of creating an email formatted message and sending it. However these messages are not encrypted. There is a way to use encryption

Use an SMTP client plugin on your website and force all communications from the website over email to be encrypted. This basically means you configure a send only email agent on your website and force all communications between your site to the mail server to be encrypted. You would need to know the password for the favoured email account, and some settings for email. Assuming you wish to send to a mailbox in your hosting (not an external one like Outlook 365) you need to send the mail to info@yourdomainname.org.uk, You would need to know the following to set it up; your password, use SMTP, port 587, TLS enabled.

Once you do this all mail from the site including admin messages and form data is all encrypted.  See this article for more details on DIY

2) Enable Security Certificate and force SSL

Go to the control panel for your hosting account and turn on SSL (Secure Socket Layer) this is an encryption layer that is used to encode data to and from your site. Many hosting companies charge £75/yr for this. We have them for free. You need to wait 30 minutes. Then login to your website and go to the General Tab, change the base address of your website from http:// to https://. There are two fields where you need to do this. When you save the settings you will be logged out from the site because it now appears at a new address https://mycoolsite.org.uk.  (May 7th: I have already done this for all websites that are using the DNS in the hosting. There are two or three exceptions where I cannot turn this on.)

Update: May 7th. Next you need to go to Settings, Updraftplus, advanced tools and look for Search and Replace the database. Do take care here, you can break everything. Your site was originally built at either http://<yoursite name> or http://www.<yoursite name> and the database holds these old URLS. They need to be updated to https://<yoursite name> or https://www.<yoursite name> if you do that all of the information passed to a visitor will be encrypted provide SSL has been enabled.

This is how you do it

Before starting. Backup your site and make sure the back up is completed and passed to the Dropbox before the next steps.

For the following example replace my example text: wingrove-services.co.uk domain name with your domain name to make the changes.

Enter http://wingrove-services.co.uk in the “Search for” box and enter in the “Replace with” box  https://wingrove-services.co.uk. You are adding an s after http otherwise the domain name and address is the same.

Double check that the Replace with URL is correct. If it isn’t you will destroy your website.

Repeat the process again using the following to filter out any www’s in the database: search for data: http://www.wingrove-services.co.uk replace with https://wingrove-services.co.uk and enter it in the “Replace with” box.

These two steps will correct any old database URLS referring to the non secure pages and elements. Once you have done that you will see a padlock against the website address in your browser.

If you are not sure please contact me. I have started doing this on some sites already.

3) Encrypt backups

Your site creates a backup automatically every week, or sometimes over several weeks if the site is lightly modified. There will be between 3 and 6 weeks worth of backups available. Those backups are currently unencrypted. If a third party was able to access the backup, they could restore the site somewhere else, and if the site had personal information in it (newsletter subscriber database), then they may be able to access it. You can prevent that from happening by using an encryption word or sequence of characters. Don’t ever forget it, and of course that gives you yet another piece of information you need to keep safe. You will need it and so will I if we ever need to restore the site. You enter your encryption string of characters into one of the settings in Updraftplus.

4) Offsite backup

Set up Updraftplus to send the backup offsite to another location. In the event of a catastrophic failure in the hosting your website data would be safe somewhere else, and can be recovered from that location.  From April 1st 2018 I will have available Dropbox Professional 1TB cloud storage where I will send all backups from sites. You can have access to the folder for your site. So you would be covered there as well. Update May 7th 2018. All sites are backing up to this new dropbox account unless you have changed anything. 

5) Remove all forwarders to personal accounts

Many organisation use a forwarder from an email account associated with their website to a personal email account. Generally this is ok, and saves the individual the time in checking their charity email accounts. However it is also an opportunity for the propagation of personal information. This is because contact form information (which carries personal information) is now outside the direct control of the charity. So you may wish to change your policy, and remove all forwarders making sure that mail for the charity, stays within the charity. This will make data easier to control.

6) Make sure all email sent and received is encrypted

All email accounts using the hosting available is capable of being encrypted. I have recommended to everyone for some time to make sure mail accounts are using encrypted connections.  You do this by checking your email settings on your computer or handheld device. All connections must be over an SSL connection, or a TLS connection using ports 995 (POP3) or 993 (IMAP) for the receiving mail server, and ports 587 (POP3) or 465 (IMAP) for the SMTP (sending) server. At this time it would be worth checking if you do not know.

7). Add in your privacy notice

Your website will carry some information on Cookies and how they are used. You need to augment that with a privacy statement which covers the requirements of GDPR. This is not something I can do for you, I have elsewhere on this site a “things to think about” Privacy statement. In this article I have described how the hosting works. But you will need to add into the privacy statement the things you do inside your charity relating to data. Once you have your prepared privacy statement and have checked it and approved it, it needs to go on your website.  You can create a page to cover this, or add it to an existing section on your site. Add it as a PDF downloadable document, or have it as a discrete page.

8). User Consent

One of the requirements of GDPR is that users have to opt in, we must not assume that they have opted in by default. The website collects personal identifiable information in the form of cookies in order for it to work properly. Various temporary logging is carried out to help rectify communications problems in the hosting. If we needed to know who the person is at the other end, it would be practically impossible to find out, but according to one EU ruling an IP address (the internet works on the basis of IP addresses) is considered personal information. So we need to inform people of the privacy policy and seek their consent before they can access the website. The best way to do that currently is to have a page you cannot get past unless you have checked a box. This can be done with a plugin.

9). Replace Form Handler

Back in September 2017 one of the Forms that are used on many sites was suddenly withdrawn. The circumstances related to someone that had purchased the plugin and then attempted (but failed) to infect the plugin, and would therefore infect all of the sites that used it. The attempt and several others was detected within the WordPress community, the original author rolled back the changes to a clean version and that is what we have been using on around 80% of the sites. At the time the plugin did many things that other plugins did not do so I was not in a rush to change it.

I now have an equivalent solution, maybe not quite so easy to create a form, but similar results can be obtained and the form handler is also supported by the author, which means it will continue to be updated.

I will replace your contact us form on your site with a new combination of plugins such that messages are not stored on the site (important for privacy) a message is generated and sent to you, formatting is controllable. A copy of the message is sent to the sender. The sender is also taken to a thank you page. Feedback is present on the screen as well. The form also supports Google Captcha version 2 which I will also set up. I recommend using Contact Form 7 plugin.

Need help?

There is nothing in this list you cannot do. You will need access to the control panel for your account, you can get that from me. If your mail is with another provider, you will need to check with them for passwords and other details for setting up the SMTP agent plugin.

I can do most of the heavy lifting for you in this list, particularly around your website for a single cost of £50 per website (including replacing the contact us  form). For me to proceed, you will need to provide me with some information about your site and configuration. Contact me for more information.

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)