With the switch to the Zynatic membership system most GDPR issues should be resolved.
See e.g.: https://www.datainspektionen.se/lagar-och-regler/personuppgiftslagen/molntjanster/
We might however need the following:
- Sign a "Personuppgiftsbiträdesavtal" T189094: Sign personuppgiftsbiträdesavtal with Zynatic
- A solution for ensuring parental consent of under-aged members T189098: Create routine for ensuring parental consent for underaged members
- A decision on how to handle any accounts without explicit permission (parental or data retention approval) when GDPR kicks in. T189097: Policy for members lacking essential information or consents
- Ensure security corresponds to the sensitivity of the stored data T189296: Enable 2FA in Zynatic