Drupal CMS

Golden standard for privacy and data protection

DrupalDevDays 2025, Leuven

Jürgen Haas

17. April 2025

About myself

Member on drupal.org for almost 18 years
Maintainer of ~100 modules

Find me online:
go.lakedrops.com/jurgenhaas


Track Lead Privacy & Compliance


ECA module maintainer
Gin admin theme co-maintainer


Co-founder and Managing Director

Agenda



  1. Does it matter? Why?
  2. Compliance for a global product
  3. Drupal CMS 1.0 and 1.1
  4. What’s next
  5. Conclusion
  6. Q&A

go.lakedrops.com/privacy-leuven-2025

Does it matter? Why?



Privacy: a fundamental right for individuals

Data protection: preventing damage for visitors and providers

Compliance: an obligation to run a business

Most countries have their own legislation
Provider and its visitors are often in different countries

Does it matter to respect
fundamental rights
of individuals?

Does it matter to protect
sensible data
to avoid real damage?

Does it matter to comply
with legal requirements
when running a business?

We, the Drupal community, are not here to question the regulations.

We are here to build products that can be used without breaking the law.

Regulations are constantly changing, the product has to follow suit.

Existing installations need to adjust without the site admin having to become a legal expert.



“A user’s privacy protection should never be contingent on the presence, or the absence, of a privacy regulation which has formalized those principles into law.”

Heather Burns, Author of Understanding Privacy

Global product compliance

Privacy regulation exists

in Europe (GDPR),
and in California (CPPA),

right?

Source

Should we build a GDPR version?


Perceived as over-reaching


Hated for its cookie banners everywhere


Not solving a single problem


Getting people to think how they can get around all that “useless privacy stuff”

Or rather a CPPA version?





similar to GDPR



just more beautiful?

Or one for every region?

This is just impossible?

So, let’s get back to what
Heather Burns suggests…

Heather Burns

One phrase you will never hear me use is “GDPR-compliant”

Why? Because there’s no such thing as being GDPR-compliant. It is not possible.

GDPR is about systems, processes, and procedures.

It is a journey, not a destination.

That journey, for what it’s worth, should be taken from the positive view of user protection, not a negative view of compliance as a regulatory threat.

So don’t think in terms of becoming GDPR-compliant — think instead of how to work towards a healthy regard for user privacy, using GDPR as your roadmap, every day.

And while you’re on that journey, remember to cast a very suspicious eye at any individual or service provider claiming they can make you compliant.

Drupal CMS 1.0 and 1.1





Objective: Provide default setup for the main target audience, marketers, that allows them to become compliant with regulations.

Building blocks



  1. Consent management

  2. Data protection

  3. Ongoing audits




It’s a journey, not a destination.

This started an interesting process

Short list of modules - dusted quickly

Moule Short name Issue
Cookies Consent Management cookies the external library is not open-source
EU Cookie Compliance eu_cookie_compliance needs a complete rewrite according to its maintainers
General Data Protection Regulation gdpr great components for data protection but no consent management

Found a hidden champion: Klaro

They have paid tiers, which is why we filtered them out in our early research phase. The component for the Drupal integration only requires the BSD-licensed part.

And the functionality is overwhelming. It provides everything we need.

Something exceptional happened


We spoke with the maintainers of eu_cookie_compliance, cookies, and klaro.

They’re interested in joining forces with Klaro and helping to maintain the future de-facto standard for Drupal globally.

They even suggested providing migration paths for existing users of eventually deprecated modules.

Shout out to Jan Kellermann @Werk21 for his outstanding Klaro maintainership.

Default config in Drupal CMS



It just works

It’s invisible, non-intrusive

Auto-config as the site grows

Widgets take action only when really required

Privacy policy prepared and linked in the footer

No third-party components pulled from remote sites



A fresh installation of Drupal CMS

No disturbing widget for the user

Yet, this site is prepared for compliance and has everything needed on board





Let’s add some content with an embedded remote video



There is still no disturbing widget

Because we don’t have to

Instead there is a link to privacy settings in the footer



The widget only shows up on request

It’s clear and easy to use, without any dark patterns

And it contains only those topics that require user consent



While the user has not given consent for remote videos, a placeholder will be loaded giving the user a choice before their data gets transferred to the provider



After consent has been given, either once or always, the video gets loaded and can be watched



Now we have also applied the event and the analytics recipe

The latter requires user consent, which is why the widget on the bottom right of the page appears the get the user’s attention



The widget is now more comprehensive

The topics can be expanded to see the individual services

Consent can be given per topic or service



As with videos, maps from third party providers won’t be loaded before the user consents



The map loads immediately after user consent


Help users understanding what’s going on:

The widget is either not visible at all (=default) or disappears when user have made their decision once

It only comes back, if there are new services available since the user’s previous decision



As with remote videos and maps, the AI chatbot is supposed to send data to a remote service

This is not done without the user’s consent here either


When allowed, the AI chatbot is ready to do its work


What we’ve seen so far, are the default settings of Drupal CMS

The site owner is able to tweak them towards their own needs

Drupal CMS is not preventing anyone from doing what they want

It just helps to get started and be ready for compliance

Documentation

What’s next



Building block Status
Consent management done
- Legal content Issue #3518233
Data protection Issue #3516647
Ongoing audits will follow afterwards

Data protection



  • Identify and configure sensitive data – Personally Identifiable Information

  • Generate reports for data subjects – What’s stored about me?

  • Erase data subject – Right to be forgotten!

Ongoing audits



Let’s remind ourselves with Heather Burns’ quote:
“It is a journey, not a destination.”

For Drupal CMS (and other Drupal sites) this means that there’s no point in o-o-t-b default config alone

Each site will evolve, context will change, and legal requirements will change too

Therefore, Drupal also needs to help site builders to remain compliant

This requires regular explicit audits; we’re working on tools and dashboards for Drupal sites

Conclusion



  • Fundamental right

  • Not a status – a permanent process

  • Consent management doesn’t ruin UX

  • Data protection and audit will follow

Q&A

My sponsors:



Thank you for your attention!





go.lakedrops.com/sponsor