The newsletter of WMIT usually has many links, but, all of them, are replaced from this:
https://www.wikimedia.it/privacy/
https://www.wikipedia.org/
To this (just an example - do not visit these links):
https://sostieni.wikimedia.it/civicrm/mailing/url?u=10001&qid=123 https://sostieni.wikimedia.it/civicrm/mailing/url?u=10002&qid=123
We know that other organizations may need such link tracking, but in WMIT we have more disadvantages than advantages.
This tracking should be de-activated (requested since 2023) at least for internal communication to members.
Reasons
- Increase User Security
- Users should always check the final destination of a link and before visiting the link. This is a basic cybersecurity practices when reading emails.
- Maybe better described here:
- Follow Original Intentions from Tech Stakeholders
- Thanks to CiviCRM, WMIT migrated away from a similar tool called "GIVE". The "GIVE" was a proprietary tool, to do newsletter, but doing aggressive link tracking. So, CiviCRM should be used as solution. CiviCRM should not be used to replicate the same aggressive link tracking. - T323815: Drop tracking URLs in WMIT newsletter (GIVE - 2023)
- Simplify User Consensus
It's not clear when users agreed to be actively monitored, whatever click they do in newsletter contents. We never received a legal confirmation, saying that our link tracking is legit.- update august 2025: WMIT added click tracking in the privacy policy https://web.archive.org/web/20250811210625/https://www.wikimedia.it/privacy/#:~:text=Wikimedia%20Italia%20potr%C3%A0%20inoltre%20utilizzare%20un%20sistema%20di%20tracciamento%20anonimo%20che%20consente%20di%20monitorare%20le%20aperture%20delle%20e-mail%20e%20i%20clic%20sui%20link%20in%20esse%20contenuti
- GDPR Minimization Principle
- Knowing who opens an email, when, which link was clicked, has never been a "success metric" (and it should not - probably). So, for the GDPR "Minimization Principle" we should just avoid to collect such data, unless otherwise requested for specific campaigns for specific external patners.
- Avoid Double Tracking
- The organization already has a content tracker: Matomo (https://wiki.wikimedia.it/wiki/Matomo). So the organization is collecting both all clicks in newsletter links, and web visits. It's unclear why we cannot just have "less aggressive link tracking" - for example - we could adopt the Matomo campaign URL builder - which would be less aggressive - https://matomo.org/faq/tracking-campaigns-url-builder/
- Follow-Up Assemblies
- From WMIT assembly of November 2024 (https://wiki.wikimedia.it/wiki/Associazione:Assemblea_WMI_novembre_2024/Verbale)
- (IT) «Valerio Bozzolan come socio membro della Commissione tecnica, esprime apprezzamento per l'abbandono del software precedentemente usato per gestire i dati dei soci, che tracciava la navigazione attraverso i link. Segnala però che anche nel nuovo applicativo CiviCRM è abilitato il medesimo tracciamento e chiede che vengano rispettare le linee guida, presenti in wikina, sulla scrittura delle email e sulla di scrittura dei link (che devono essere in chiaro per, per ragioni di sicurezza) e chiede che il tracciamento venga eliminato dalla mailing list e da tutte le comunicazioni ai soci. Chiede inoltre che le richieste ai fornitori siano pubbliche e tracciabili, ad esempio su Phabricator. Ringrazia tutti coloro che contribuiscono agli sviluppi software.»
- From WMIT assembly of May 2025 (https://wiki.wikimedia.it/wiki/Associazione:Assemblea_WMI_maggio_2025/Verbale)
- (IT) «Punto 1: Risoluzione tracciamento newsletter Rispetto allo scorso verbale dell'assemblea di novembre, ribadisce i rischi nel tracciare ogni link della newsletter dei soci, e chiede di essere autorizzato a risolvere direttamente la cosa col fornitore CiviHost. »
- From WMIT assembly of November 2024 (https://wiki.wikimedia.it/wiki/Associazione:Assemblea_WMI_novembre_2024/Verbale)
Proposal
De-activate the tracking URLs in CiviCRM.
This should be done, at least, for all communications to members.
Scope / Limitation
This task does not cover specific/limited campaigns to external bodies (e.g. museums). Such specific occasions MAY still require tracking (I clarify this since the board, in 2024 or 2025, clearly expressed the intention to track museums. So, if there is the need to track museums through a dedicated newsletter, that should not be a good reason to also track members).